Momento is an event photo-sharing app: guests join an event, take photos that stay private until the host “develops” the roll, and then everyone with the event link can see the shared gallery. This policy explains what we collect, how we use it, who helps us run the service, and the choices you have.
We do not sell your personal information. We do not use your photos to train models, for advertising, or for unrelated marketing.
Before an event is developed, a guest can only see their own photos. Hosts can see all photos for events they host. These rules are enforced on our servers, so other guests cannot reach photo records that have not been revealed yet.
After the host develops the roll,the shared gallery opens up: anyone holding the event's invite link can view it. Photos may be served from unlisted web addresses that are not listed publicly and are designed not to be browsed or guessed. A photo link can remain valid for as long as the photo exists. Treat event and photo links like shared album links: anyone you send them to may be able to open them.
Location Lock is optional and controlled by the host. Hosts can set a venue by address lookup or by using their current location. When a guest joins a location-locked event before reveal, the browser or app asks for location permission and sends the guest's location for a one-time venue check. Once the roll is developed, Location Lock no longer limits gallery viewing.
We use PostHog to understand how Momento is used and where the product fails. Analytics events are kept free of photo contents, event names, display names, coordinates, and other personal content. Signed-in hosts may be identified in analytics by account ID and email so we can understand host usage and support account-specific issues. Anonymous guests are not identified by email. We do not use advertising identifiers, ad networks, or session replay.
We rely on a small set of vendors to operate Momento. They process data for us to provide their services:
We may also disclose information if required by law, to protect rights and safety, or as part of a merger, acquisition, financing, or sale of assets.
We keep event and photo data while the event exists. When a host deletes an event, or when a user deletes an individual photo they are allowed to delete, the related records and underlying media files are removed from active storage where supported, which also stops previously shared links to those files from working. We keep limited operational, security, support, billing, and legal records for as long as needed for those purposes.
Depending on where you live, you may have additional rights to know, access, correct, delete, or limit use of your personal information. To exercise rights, contact us at lw.kelwin@gmail.com. We may need to verify your request before acting on it.
We use technical and organizational safeguards designed to protect information, including account-based access controls, database row-level security, private or unlisted media storage, and HTTPS. No internet service can guarantee perfect security, so please keep copies of photos that are important to you.
Momento and our service providers may process and store information in countries other than where you live. Those countries may have different data-protection laws from your region.
Momento is not directed to children under 13 (or the minimum age in your region). We do not knowingly collect personal information from children. If you believe a child has provided us data, contact us and we'll remove it.
We may update this policy as the product evolves. We'll revise the “last updated” date above, and for material changes we'll provide additional notice where appropriate.
Questions about privacy? Email lw.kelwin@gmail.com. See also our Terms of Service.