# Momentan — Privacy Policy

**Effective Date:** July 11, 2026 · **Last updated:** July 11, 2026 · **Version:** 2026-07-11-r2

## 1. Scope and operator

This Privacy Policy explains how "OMNIA-MEDIC" d.o.o. Zenica, Bistua Nuova no. 10, 72000 Zenica, Bosnia and Herzegovina ("Momentan," "we," "us," or "our") handles personal information through the Momentan mobile app, iOS widgets, web companion at app.momentan.app, website at momentan.app, support channels, and related services (the "Service"). "OMNIA-MEDIC" d.o.o. Zenica is the legal operator and data controller where applicable. Momentan is a product name, not a separate legal entity.

This Policy should be read with our [Terms of Service](/terms) and [Consumer Health Data Privacy Notice](/health-data). The Service is for adults who are at least 18 years old.

## 2. Summary of current practices

- We do not currently sell personal information or share it for cross-context behavioral advertising.
- We do not currently serve third-party ads or use advertising or cross-app tracking identifiers.
- Supported structured records sync to the user's account. Photos, videos, contact photos, and voice recordings are device-local media unless the user deliberately invokes a feature that requires a bounded upload, such as optional transcription.
- Cloud AI features are optional. The app presents a Cloud Processing disclosure before supported private content is sent for an AI request.
- Account deletion is available in the app. Production account data is deleted through that flow, the active on-device vault is removed, residual encrypted backups age out, and minimal legal-acceptance evidence may be retained as described below.

## 3. Information we collect

### 3.1 Account and identity data

We collect an email address, authentication records, and an optional display name. If a user signs in with Apple or Google, we receive the identity information that provider supplies under the user's approved scopes. Passwords are handled by our authentication provider in hashed form; we do not receive a plaintext password.

### 3.2 User content and relationship records

Users may create moments, notes, comments, lists, tasks, tags, person profiles, birthdays, contact details, work and preference fields, family or relationship context, relationship-tracking records, transcripts, reminders, and other structured records. A record may include information about the user or another person. Users decide what they enter and are responsible for having the rights or other lawful basis needed to collect, store, disclose, and ask us to process information about other people. We may act on the user's instructions for that content, but our role under a particular privacy law depends on the facts and that law.

### 3.3 Contact import and refresh

When a user chooses Import or Refresh and grants contacts permission, the app reads contacts available under that permission and creates or refreshes person profiles. Imported structured fields can include names, nicknames, birthdays, phone numbers, email addresses, postal addresses, notes, and related fields. Contact photos remain on the device. After an import, while contacts permission remains enabled, Momentan may check for new or updated contacts when the app starts. We do not use imported contacts to contact people, build advertising audiences, or obtain data from data brokers.

### 3.4 Device-local media

Photos, videos, contact photos, and voice recordings are stored in the app's device storage and are not part of ordinary structured-record sync. A voice recording is transmitted when the user deliberately requests optional transcription. Device-local media is not included in the password-encrypted backup of structured records. Removing the app or losing a device can remove local media, so users should keep separate copies they need.

### 3.5 Technical, security, and service data

We and our service providers process identifiers and records needed to operate the Service, including database record identifiers and timestamps, deletion markers, authentication cookies or tokens, IP address and user-agent in infrastructure logs, request and security metadata, rate-limit counters, device platform, timezone, push tokens, notification preferences and delivery records, consent preferences, app version, crash or diagnostic information made available through our infrastructure, and records of legal-document acceptance.

### 3.6 Subscription and transaction data

Apple and RevenueCat provide product, entitlement, renewal, expiration, and subscription-event information. We do not receive payment-card details or Apple Account credentials. Current price, billing, and tax information is presented by Apple.

### 3.7 Communications

We collect messages and attachments a person sends to our support, privacy, legal, or general contact addresses, along with our responses and records needed to resolve the request.

### 3.8 Website and web companion

The authenticated web companion uses necessary authentication cookies, browser storage, and security controls. Cloudflare Turnstile may process browser and network signals to protect authentication. The public marketing site does not currently use advertising or analytics cookies. Its pages may request font files from Google Fonts, which can disclose ordinary request information such as IP address and user agent to Google.

## 4. Why we use information and legal bases

We use information to provide accounts, sync and display supported records, operate requested features, manage subscriptions, deliver notifications, provide support, secure and debug the Service, prevent fraud or abuse, comply with law, enforce agreements, and establish or defend legal claims.

Where the GDPR, UK GDPR, or a similar law applies, our legal bases are performance of the user contract for core account and Service functions; consent for optional Cloud Processing and any processing that law requires to be consent-based; legitimate interests in security, reliability, support, and enforcing legal rights where those interests are not overridden; and legal obligation where applicable. A user may withdraw consent for future processing without affecting processing already lawfully completed.

We may create and use aggregated, anonymized, or de-identified information for security, measurement, product improvement, research, reporting, and lawful business purposes. Where law treats that information as de-identified, we will maintain it in de-identified form and will not attempt to re-identify it except to test our de-identification controls or as law otherwise permits.

## 5. Optional AI and Cloud Processing

Cloud AI features may include transcription, typed or spoken capture, question answering, AI briefing, and AI-composed notifications. The app's Cloud Processing control is off until the user accepts the disclosure. A request may send only the bounded content reasonably needed for that feature, which can include audio for transcription, a prompt, recent context, names, contact fields, or relevant moment, note, task, profile, and relationship snippets. AI output and transcripts the user saves become account content.

Our current AI and transcription processor set includes Deepgram, OpenRouter, Anthropic, and DeepSeek. Depending on availability, safety, reliability, or cost, the exact provider or model used may change over time. Google currently supports sign-in and website font delivery; it is not a default AI model provider for Momentan. Provider processing is subject to our service configuration and applicable provider terms. We do not authorize providers to use identifiable private content for their independent advertising purposes.

AI output may be incomplete or wrong. Users should not use Momentan as a substitute for professional medical, legal, financial, or emergency advice.

## 6. When we disclose information

We disclose information to service providers acting for us, including Supabase for database, authentication, and server functions; Apple and Google for supported sign-in; Apple for distribution, billing, and push delivery; RevenueCat for subscription entitlement; Expo for app and push infrastructure; Resend for transactional email; Cloudflare for security; Vercel for web hosting; Google Fonts for public-site font delivery; and the AI providers listed above for features a user invokes.

We may also disclose information when directed by a user; to complete a corporate transaction such as a merger, financing, restructuring, or asset sale subject to applicable notice and legal requirements; or when reasonably necessary to comply with law, respond to valid process, protect a person from serious harm, secure the Service, or establish, exercise, or defend legal claims.

We do not permit service providers to use private content for their own advertising. Vendors may process data in countries different from the user's country.

## 7. No current sale, ads, or behavioral advertising

Momentan does not currently sell personal information or share it for cross-context behavioral advertising, and we have not done so during the preceding 12 months. We do not currently serve third-party ads, use an advertising SDK, or access an advertising identifier for tracking.

We may change our business model in the future, but this Policy is not consent to a future sale, targeted-advertising program, or materially different use of private content. Before any future sale or sharing begins, we will update this Policy and implement the advance notice, consent, opt-out, Global Privacy Control, sensitive-data, risk-assessment, contractual, and platform disclosures required by the laws and platform rules then applicable. Where prior opt-in consent is required, we will obtain it before processing. Where an opt-out is required, it will be available before the activity starts. We will not rely on continued use alone where law requires a more specific choice.

This future-change section preserves our ability to adopt a lawful business model; it does not create present permission to sell or share information. Any program would exclude data or jurisdictions where the activity is prohibited and would be assessed under the law and platform rules in effect at that time.

## 8. Retention and deletion

Account content is generally retained while the account is active. Account deletion removes the account and covered production records and removes the active on-device vault. Residual encrypted backup copies may persist for up to 30 days before aging out. Device-local media on other devices or copies a user exported are not controlled by server deletion.

We retain different operational records for only as long as reasonably needed for their purpose. Under our current application retention jobs, notification delivery records and stale push tokens are purged after 90 days, and soft-deleted synced-record tombstones are purged after 180 days. Security and infrastructure logs follow provider rotation periods. Transactional and support records remain while needed to complete the request and protect legal rights, and subscription records remain as needed for entitlement, accounting, fraud prevention, and legal obligations.

To prove formation and versions of the user agreement, we retain narrowly scoped legal-acceptance evidence, including user identifier, one-way email hash, document versions and hashes, acceptance method, platform, app version, and server timestamp. After account deletion, the acceptance record is marked deleted and may be retained for five years, then purged, unless a longer period is required for an active dispute, legal hold, or binding legal obligation. It contains no contacts, moments, notes, media, location content, or advertising identifiers.

We may retain information longer where necessary to comply with law, resolve a dispute, enforce an agreement, or prevent fraud or abuse. We may retain de-identified information where it can no longer reasonably be linked to a person or household.

## 9. International processing

We are established in Bosnia and Herzegovina and use providers in the United States and other countries. Those countries may have different data-protection laws. Where applicable law requires a transfer mechanism, we use an available lawful mechanism such as an adequacy decision, approved contractual clauses, or another valid safeguard. Users may contact privacy@momentan.app for information about applicable safeguards.

## 10. Privacy rights and choices

Depending on location, a person may have rights to know or access personal information, correct it, receive a portable copy, delete it, restrict or object to processing, withdraw consent, opt out of sale, sharing, targeted advertising, or certain profiling, limit certain sensitive-data uses, and appeal a denied request. A person may also complain to a competent data-protection authority.

Bosnia and Herzegovina requests are handled under the 2025 Personal Data Protection Law of Bosnia and Herzegovina and other applicable law. EEA and UK users may contact their local supervisory authority. California and other US residents may exercise rights provided by their state law. Momentan will honor a legally recognized Global Privacy Control when it applies to an active practice; there is no current sale or behavioral-advertising sharing to opt out of.

Use in-app export, correction, consent, subscription, and account-deletion controls where available, or email privacy@momentan.app. We may need to verify identity and authority. Authorized agents must provide legally sufficient authorization. We do not discriminate for exercising a privacy right, though a requested deletion or withdrawn consent can make a feature unavailable.

If a person asks about information another user stored in a private relationship record, we may direct the request to that user or take other action required by applicable law.

## 11. Security

We use administrative, technical, and organizational safeguards designed for the nature of the information, including encrypted transport, hosted encryption at rest, access controls, account-bound authorization, security logging, rate limiting, deletion controls, and a password-encrypted structured backup. No system is perfectly secure, and we cannot guarantee that unauthorized access, loss, or misuse will never occur. Users are responsible for device security, account credentials, exported files, and media copies.

## 12. Children

The Service is not offered to anyone under 18. We do not knowingly permit a person under 18 to create an account. If we learn that an underage person provided personal information, we may suspend the account and delete the information as required. Contact privacy@momentan.app with a supported concern.

## 13. Changes to this Policy

We may update this Policy to reflect product, legal, security, or business changes. We will post the updated version and effective date and, when reasonably practicable, give advance notice of a material change. We will request renewed acceptance or consent where required. A prior version is not advance consent to a materially different future practice. If a user does not accept a change required for continued account use, the user may stop using the Service and delete the account.

## 14. Contact

"OMNIA-MEDIC" d.o.o. Zenica
Bistua Nuova no. 10, 72000 Zenica, Bosnia and Herzegovina
Privacy: privacy@momentan.app
Support: support@momentan.app
Legal: legal@momentan.app

Users may contact the Personal Data Protection Agency of Bosnia and Herzegovina or another competent authority where applicable.
