momento.

Privacy Policy

Last updated August 5, 2026

Momento is an event photo-sharing app: guests join an event, take photos that stay private until the host “develops” the roll, and then everyone with the event link can see the shared gallery. This policy explains what we collect, how we use it, who helps us run the service, and the choices you have.

Information we collect

  • Account information. Hosting requires signing in with a supported provider such as Google or Apple. We receive account details from that provider, such as your email address, provider account identifier, and basic profile information.
  • Guest and event information. Guests can join without creating a named account. We keep the display name a guest enters, their event membership, event names, dates, invite and join details, capacity settings, reveal timing, cover images, and host settings.
  • Photo content and interactions. We collect the photos you upload, generated thumbnails, metadata needed to store and display them, and interaction data such as favorites or saved photo status.
  • Location information for Location Lock.If a host turns on Location Lock, the host may store a venue location and radius. A guest's approximate location is checked when they join to confirm they are at the venue. We do not track your location over time or store a movement history.
  • Usage, device, and diagnostic data. We collect product events such as screens opened, actions taken, uploads, purchases, and errors. This may include device and browser details, app version, timestamps, and similar technical information.
  • Purchase and support information. If paid capacity is enabled, we receive purchase status, product identifiers, transaction identifiers, and fulfillment details. If you contact support, we collect what you send us, such as your email address, event details, device information, and a description of the issue.

How we use information

  • To create, join, host, manage, and delete events.
  • To capture, upload, store, process, thumbnail, display, and delete photos.
  • To enforce the reveal gate before a host develops the roll.
  • To provide invite links, QR codes, galleries, and event dashboards.
  • To check Location Lock when a host enables it.
  • To process and fulfill purchases of additional guest capacity.
  • To understand product usage, diagnose errors, and improve reliability.
  • To respond to support requests, protect the service, prevent abuse, and comply with legal obligations.

We do not sell your personal information. We do not use your photos to train models, for advertising, or for unrelated marketing.

Photos, reveal, and sharing

Before an event is developed, a guest can only see their own photos. Hosts can see all photos for events they host. These rules are enforced on our servers, so other guests cannot reach photo records that have not been revealed yet.

After the host develops the roll,the shared gallery opens up: anyone holding the event's invite link can view it. Photos may be served from unlisted web addresses that are not listed publicly and are designed not to be browsed or guessed. A photo link can remain valid for as long as the photo exists. Treat event and photo links like shared album links: anyone you send them to may be able to open them.

Location Lock

Location Lock is optional and controlled by the host. Hosts can set a venue by address lookup or by using their current location. When a guest joins a location-locked event before reveal, the browser or app asks for location permission and sends the guest's location for a one-time venue check. Once the roll is developed, Location Lock no longer limits gallery viewing.

Analytics and similar technologies

We use PostHog to understand how Momento is used and where the product fails. Analytics events are kept free of photo contents, event names, display names, coordinates, and other personal content. Signed-in hosts may be identified in analytics by account ID and email so we can understand host usage and support account-specific issues. Anonymous guests are not identified by email. We do not use advertising identifiers, ad networks, or session replay.

Service providers we share with

We rely on a small set of vendors to operate Momento. They process data for us to provide their services:

  • Supabase — database, authentication, storage fallback, and server functions.
  • Cloudflare R2 — photo and cover-image storage and delivery when R2 media is enabled.
  • RevenueCat and Stripe — guest-capacity purchases and payment fulfillment. Payment card details are handled by the payment processor; we do not see or store full card numbers.
  • PostHog — product analytics and diagnostics.
  • Google / Apple — host sign-in, if you use it.
  • OpenStreetMap (Nominatim) — address lookup and reverse-geocoding for Location Lock venue setup.

We may also disclose information if required by law, to protect rights and safety, or as part of a merger, acquisition, financing, or sale of assets.

Data retention

We keep event and photo data while the event exists. When a host deletes an event, or when a user deletes an individual photo they are allowed to delete, the related records and underlying media files are removed from active storage where supported, which also stops previously shared links to those files from working. We keep limited operational, security, support, billing, and legal records for as long as needed for those purposes.

Your choices and rights

  • Delete an event. Hosts can delete an event from its dashboard, which removes its photos.
  • Delete a photo. Guests can delete their own photos where the product provides that control.
  • Delete your account or data. You can delete your account yourself at momento.gallery/delete-account, or from Settings in the app. This removes your account, the events you host and all their photos, and photos you took in other people's events. If you can't sign in, email lw.kelwin@gmail.comand we'll do it for you. Limited records may be retained for security, billing, and legal compliance.
  • Access or correction. Contact us to access, correct, or receive a copy of personal data we hold about you.
  • Location. Location Lock only runs when a host enables it and you grant permission at join time; you can decline at your device level.
  • Analytics. You can use browser or device controls to limit cookies, storage, and permissions, though some controls may affect how Momento works.

Depending on where you live, you may have additional rights to know, access, correct, delete, or limit use of your personal information. To exercise rights, contact us at lw.kelwin@gmail.com. We may need to verify your request before acting on it.

Security

We use technical and organizational safeguards designed to protect information, including account-based access controls, database row-level security, private or unlisted media storage, and HTTPS. No internet service can guarantee perfect security, so please keep copies of photos that are important to you.

International processing

Momento and our service providers may process and store information in countries other than where you live. Those countries may have different data-protection laws from your region.

Children

Momento is not directed to children under 13 (or the minimum age in your region). We do not knowingly collect personal information from children. If you believe a child has provided us data, contact us and we'll remove it.

Changes to this policy

We may update this policy as the product evolves. We'll revise the “last updated” date above, and for material changes we'll provide additional notice where appropriate.

Contact

Questions about privacy? Email lw.kelwin@gmail.com. See also our Terms of Service.

HomeSupportPrivacyTerms