This policy explains what Momenti collects, why, and what happens to it. It describes the closed beta as it works today. Questions or requests: maya@momenti.me.
1. What Momenti is, in privacy terms
Momenti is a shared photo space. You create a Moment, share a link, QR code or 6-character code, and the people you share it with can add photos.
In the current beta all Moments are Unlisted: they are not listed anywhere public, but anyone who obtains the link, QR code or code may be able to open the Moment and see its limited preview. Momenti cannot control who a link is forwarded to. Treat the link and code as the access control.
Momenti supports photos only. There are no reactions, comments, followers, or social/home feed or discovery features in the beta. The in-Moment gallery view exists only inside an individual Moment you have access to.
2. Age and audience scope
The current Momenti closed beta is intended for people 18 and older. It is not directed to children or minors under 18.
Although the beta is intended primarily for users in the United States, access is not currently restricted by country.
If Momenti later intentionally opens to younger users or materially expands internationally, privacy practices and safeguards will be reviewed first.
3. What we collect
a. Authentication and account information. If you create a permanent account, our authentication provider stores your email address and, for password accounts, a hashed password. If you sign in with Google, we receive basic account identifiers from Google (such as your email address and Google account id) to identify you — we do not receive your Google password.
b. Guest / anonymous identity. When a signed-out person takes an action that requires an identity — submitting a photo or a report — Momenti may create an anonymous account for them. This is a real account identifier stored on our systems; it has no email address attached. Its session lives in the browser it was created in, so clearing that browser's data or switching devices can make a guest identity unreachable. A guest can upgrade to a permanent account through Google or email sign-in, which keeps the same underlying identity.
c. Profile information. A display name and, if you set one, an avatar or profile image. These are shown to other people in Moments you take part in.
d. Moment and media metadata. Records needed to run the service: Moment identifiers, Moment codes, who hosts a Moment, who uploaded which photo and when, the storage paths of the processed image files, image dimensions and sizes, and status flags (for example whether a photo has been removed and by whom).
e. Uploaded photos. The JPEG derivatives produced by your browser (see section 3), stored in private storage.
f. Reports and moderation records. If you report a photo, we store who reported it, which photo, the reason category, and any note you write, plus what action was taken.
g. Operational analytics and error logs. See section 6.
h. Browser storage. Momenti stores data in your browser: your authentication session, a small amount of state so an action you started (such as creating a Moment or adding photos) can resume after sign-in, an interface preference or two, and a random session-scoped analytics id (see section 6). This is functional storage, not advertising tracking. Clearing it signs you out and can make a guest identity unreachable.
We do not ask for your phone number, contacts, precise device location, or payment details.
4. How photos are processed and stored
Photos are processed in your browser before anything is uploaded. Your original file is decoded and re-encoded into JPEG derivatives at different sizes. The original file bytes are not uploaded.
Because of this re-encoding, embedded metadata such as EXIF and GPS location is not preserved in the uploaded derivatives. This is a property of how we process images rather than a promise that a photo cannot be identifying in other ways — visible content, faces, landmarks and text in the image itself are unaffected.
The resulting files are stored in private storage. They are not publicly listable or publicly readable by URL.
Authorised access is delivered through temporary signed URLs. Signed URLs expire. A URL that has already been issued may remain usable until it expires, even after the content has been removed or your access has changed.
5. Who can see what
- Signed-out or non-contributing viewers who open a Moment see a limited preview of its photos.
- Full gallery access is available to the Host and to current contributors — users who currently have at least one successfully published photo in that Moment. Access is evaluated each time content is requested and can change over time.
- Opening a Moment does not make you a contributor, and it does not on its own grant full access.
- Your display name and avatar are visible to other people in the Moments you take part in.
We do not sell personal data, and we do not share it for advertising.
6. How we use data
- To operate Moments: authenticate you, create and resolve Moments, accept uploads, and serve media to people entitled to see it.
- To apply access rules, rate limits and abuse limits.
- To handle reports, moderate content, and keep the service safe.
- To diagnose errors and understand how the product is used (section 6).
- To respond to your support, privacy or deletion requests.
- To comply with legal obligations and to establish, exercise or defend legal claims.
7. Operational analytics and error logs
Momenti records a limited set of first-party product and operational events. There is no third-party advertising SDK and no third-party behavioural-analytics SDK in the app.
Events include: opening a Moment, clicking Add Photos, the upload lifecycle and upload errors, creating a Moment, identity and account-upgrade steps, unlocking a Moment, submitting a report, removing media, and application errors.
An event may be associated with:
- a server-derived actor identifier and actor class (for example: signed-out, guest, permanent) — determined on our servers from your session, not supplied by the browser;
- Moment and media identifiers;
- a random, session-scoped analytics id kept in the browser tab's session storage. It is not linked to your account, is not written to long-term browser storage, and disappears when the tab closes.
Event properties are restricted to a small, fixed set of values. They are not intended to contain uploaded photo content, image URLs, authentication tokens, email addresses, display names, or free-text such as the note you write in a report.
We also keep short-lived technical logs generated by our infrastructure providers in the ordinary course of serving requests.
We retain these records for product, security and operational purposes and may delete or de-identify them as part of our operational processes. We do not currently promise a fixed retention period during the beta.
8. Removal, retention and deletion
Removing a photo takes it out of the visible Moment. It does not necessarily destroy every related record at that moment:
- a record of the media row and of the removal (who removed it, when) may be retained for moderation, security, audit, legal, or operational purposes;
- underlying copies of stored files may remain in our systems for a period after the photo is no longer visible. For example, when a Host removes a photo uploaded by someone else, the Host cannot delete that uploader's stored copies directly; those files may be removed later as part of our operational cleanup processes;
- signed URLs already issued may stay usable until they expire.
Account deletion. There is no self-service Delete Account control in the current beta. To request deletion, email maya@momenti.me. Requests are processed manually during the beta. We will confirm the request and tell you what was done.
When we process a deletion we remove or de-identify your profile/authentication information, handle media uploaded by you as appropriate, and handle Moments hosted by you as part of the deletion process, subject to the safety, moderation, legal and operational retention exceptions stated above.
We do not promise an immediate or fixed permanent-deletion timeline during the beta.
9. Service providers
Momenti uses these providers to run the beta:
| Provider | Purpose |
|---|---|
| Supabase | Authentication, database, and private media storage |
| Resend | Transactional authentication email, such as sign-up confirmation and account-recovery emails |
| Optional OAuth sign-in, if you choose to sign in with Google | |
| Lovable | Hosting and serving the Momenti web application |
These providers process data on our behalf to deliver the service. If you sign in with Google, your interaction with Google is also governed by Google's own privacy policy.
10. Your choices and requests
- Access, correction, deletion, or a copy of your data: email maya@momenti.me. We handle these manually during the beta and may need to verify that the request comes from the account holder.
- Profile: you can change your display name and avatar in the app.
- Guest identity: you can upgrade a guest identity to a permanent account so it is recoverable, or stop using it.
- A photo you uploaded: you can remove it yourself; a Host can also remove media from their Moment.
- A photo of you that someone else uploaded: report it in the app, or email us.
11. Beta status and changes
Momenti is a closed beta. Functionality — including how data is handled — may change as the product develops. We will update this policy when practices change and will update the date at the top. Where a change is material, we will make a reasonable effort to notify users through the app or by email.
12. Contact
Privacy questions and data requests: maya@momenti.me.
Last updated: September 2026