Security whitepaper

How Moments protects your family's memories

This document explains how Moments keeps your family's moments private: what is encrypted, who holds the keys, what our servers can and cannot see, and — because trust is earned with honesty — exactly where the limits are.

Version 1.1 — July 2026 Applies to the Moments apps for Android, iOS, and Windows

1. The core guarantee

Moments is built around one promise: our servers store only encrypted data, and never hold a key that can unlock your content. Every photo, video, caption, comment, and reaction is encrypted on your device before it leaves it, and can be decrypted only on the devices of the people you have chosen.

The consequence is blunt: a complete breach of our systems would reveal who shares with whom, when, and how much — but zero content. There is no admin view of your photos, no support tool that can open a moment, and nothing usable to hand over in response to a legal demand for content.

Our servers never see, store, or process a readable moment. All encryption and decryption happens inside the apps, on your family's devices.

2. Our design principles

  • The server is never trusted with your content. It stores locked data and enforces who may fetch what — it is never able to read your moments or create keys.
  • Access is cryptography, not checkboxes. Wherever possible, "this person can't see this" means they hold no key that opens it — not that a setting says no.
  • Fail closed. Whenever there is any doubt that a key is still safe to use, the app refuses to post until that is resolved — it never takes the risk on your behalf.
  • An archive, not a chat. Moments is a permanent family record: content must stay readable for decades and be recoverable on new devices. Our encryption is designed for durability, not for disappearing messages.
  • Honesty about limits. Where we accept a trade-off (and every real system has them), it is written down in this document, not hidden.

3. How your moments are protected

  • Encrypted before upload. Every moment is encrypted on your device using industry-standard, widely audited encryption — the same AES-256 family trusted for banking and government data. No home-grown ciphers, anywhere.
  • Keys stay with your family. The keys that unlock your moments exist only on your family's devices. What our servers hold are locked boxes they cannot open.
  • Every moment sealed on its own. Each moment is protected individually, so even in the worst imaginable case, exposure would be limited to a single moment — never your whole journal.
  • Tampering is detected. All stored data is cryptographically authenticated: anything altered, truncated, or spliced is detected and refused rather than silently displayed.

4. Who can see what

A space is invitation-only, and the invitation is the only door. From there, access is enforced by encryption, not by settings:

  • Removing a member really removes them. From the moment someone is removed, new moments are sealed with fresh keys they never receive. Even if they somehow obtained the stored data, nothing new would ever open for them.
  • "Only from now on" means it. A member invited without history cannot read earlier moments — and our servers never even deliver those moments to them, so they can't see how many exist, when, or by whom.
  • Group audiences are real walls. Restricting a moment to "grandparents only" is not a visibility flag: only that group's members ever receive the key to it. For everyone else, the moment might as well not exist — it is absent, not hidden.
  • Admins keep stewardship. Space admins always retain oversight of the space they are responsible for, including restricted moments.

5. Photos, videos & the Secure tag

  • Media is encrypted like everything else. Photos and videos — even long ones — are encrypted on your device before upload and stored in a tamper-evident form: cutting, reordering, or splicing the stored file is detected.
  • Videos never exist unprotected on disk. Videos play instantly while staying encrypted at rest; they are decrypted only in memory on the viewer's device, never written out as a playable file.
  • The Secure tag. A moment marked Secure cannot be saved, shared, or downloaded by viewers, and its media never exists unencrypted on the viewer's device storage.
  • Screen capture is blocked app-wide. On Android, screenshots are refused and recordings render blank. On Windows, the app appears black in captures and screen shares. On iOS, we use the same protection relied on across the industry — with an honest caveat: iOS offers no official way to block capture, so if a future iOS update disabled it, the app would simply lose the blocking rather than risk your photos rendering blank. We check this on every iOS release.

What no app can prevent: a rooted or jailbroken device can read its own screen, and nothing stops a second phone photographing the first one's display. The Secure tag raises the bar meaningfully; it does not repeal physics, and we won't pretend otherwise.

6. Your devices & recovery

  • A new device must be approved. A new phone cannot simply sign in and read your spaces. One of your existing devices must approve it, with both screens showing a matching verification code — which also means no one, not even our own servers, can slip an impostor device into your account.
  • Losing everything is a human decision, not an automatic one. Someone who loses all their devices starts fresh with no content. A space admin must personally confirm restoring their access — regaining entry after total loss is treated like being admitted anew.
  • Owners hold a recovery phrase. Space owners keep a 12-word recovery phrase that can restore their spaces with no surviving device at all. The app verifies you have actually saved it before relying on it, and we never see it.

There is no key escrow. We never hold your recovery phrase or any key derived from it. If an owner loses both their devices and their phrase, we cannot restore their content — that is the honest cost of a system where we cannot read it either.

7. Signing in

  • No passwords, anywhere. You sign in with a one-time link sent to your email. Links expire within minutes and work exactly once — there is nothing to reuse, phish, or leak in a breach.
  • Sessions are short-lived and rotate automatically. Signing out ends the session on our servers, not just on your device.
  • Signing in is not the same as reading. Even someone who controlled your email could only log in as you — they could not decrypt anything, because their device would still need approval from one of yours.

8. Translation & encryption

Families write in different languages, and Moments can translate posts and comments into each reader's language. Wherever the platform allows it, this now happens on the device itself; cloud AI translation is the consent-gated exception, not the rule:

  • On-device translation (on Android today) translates locally, after a small one-time language download. The text never leaves the end-to-end envelope, and no third party is involved.
  • Cloud AI translation covers platforms without an on-device engine yet, plus the optional "Improve with AI" step on any on-device result. Your device decrypts the text locally, and only then relays it, over an encrypted connection through our servers, to a third-party AI translation service. We never log or store the text, and it is not used to train models.
  • Translations are kept only on your device, protected at rest, and wiped when you log out.
  • Even which languages your family speaks is not something our servers can read.

The honest trade: for the duration of a cloud AI translation call, the text leaves the end-to-end envelope — it is readable in transit to us and to the AI provider. Cloud translation is therefore strictly opt-in and consent-based: nothing is ever sent to the cloud until you ask, and not before a consent dialog that explains exactly this. On-device translation carries no such trade — the text never leaves your device at all — and we are bringing it to more platforms; see section 10.

9. Honest limits

Protected against

  • A full breach of our servers or storage — your content is encrypted throughout.
  • A curious or legally compelled host: there is no content to see and no usable key to hand over.
  • A removed member reading future moments, even with access to the stored data.
  • A member invited without history reaching past moments — or even learning they exist.
  • Tampering with stored content or media — alterations are detected and refused.
  • Password-database-style breaches — there are no passwords.

Accepted trade-offs, on record

  • When a moment happened is visible to our servers. This is the deliberate trade that powers the age filter and timeline. Your child's birth date stays encrypted, so a date never becomes an age anywhere but on your family's devices.
  • Comments added to old moments. A removed member who kept their device could — only if our stored data were also breached — read comments added later to moments they already had. Our servers refuse them the instant they stop being a member; this exception requires a breach on top.
  • The Secure tag itself is visible — the app must know a moment is Secure before unlocking it. It reveals exactly that one fact and no content.
  • Cloud AI translation transits in the clear during the call — opt-in and disclosed (section 8); on-device translation is unaffected.

Not protected against

  • A compromised member device. A device that can show you a photo necessarily holds what it needs to decrypt it. This is inherent to every end-to-end encrypted system.
  • Metadata. Who shares with whom, when, how often, and how much data — visible to our servers, as with effectively all practical systems.
  • A second camera pointed at a screen.

10. What's next

  • On-device translation on more platforms — delivered on Android, where text never leaves the encrypted envelope; we are bringing the same local translation to our other platforms, so the trade described in section 8 disappears everywhere.
  • Continued hardening — we keep strengthening how devices and keys are verified against each other, and we review these protections with every platform release.

This whitepaper is updated whenever our protections change. If you believe you have found a vulnerability in Moments, we want to hear from you: security@momentsapp.eu.