# Momentan — Privacy Policy

**Effective Date:** August 1, 2026 · **Last updated:** August 1, 2026 · **Version:** 2026-08-01-r13

## 1. Scope and operator

This Privacy Policy explains how "OMNIA-MEDIC" d.o.o. Zenica, Bistua Nuova no. 10, 72000 Zenica, Bosnia and Herzegovina ("Momentan," "we," "us," or "our"), as the legal operator and data controller where applicable, handles personal information through the Momentan mobile app, iOS widgets, web companion at app.momentan.app, website at momentan.app, support channels, and related services (the "Service"). Momentan is a product name, not a separate legal entity.

This Policy should be read with our [Terms of Service](/terms) and [Consumer Health Data Privacy Notice](/health-data). The Service is for adults who are at least 18 years old.

## 2. Summary of current practices

- We do not currently sell personal information or share it for cross-context behavioral advertising.
- We do not currently serve third-party ads or use advertising or cross-app tracking identifiers.
- Supported structured records sync to the user's account. Photos, videos, contact photos, and voice recordings are device-local media unless the user deliberately invokes a feature that requires a bounded upload, such as optional transcription or business-card scanning.
- Cloud AI features are optional. The app presents a Cloud Processing disclosure before supported private content is sent for an AI request.
- Account deletion is available in the app. After confirmation, a retryable flow attempts to remove covered production records, owned storage, and the authentication account. Once authentication deletion succeeds, protected account access ends. After authoritative confirmation, the requesting supported installation locks and retries logical removal of that account's exact app-controlled local vault. Other local or external copies have the limitations described below.

## 3. Information we collect

### 3.1 Account and identity data

We collect an email address, authentication records, and an optional display name. If a user signs in with Apple or Google, we receive the identity information that provider supplies under the user's approved scopes. Passwords are handled by our authentication provider in hashed form; we do not receive a plaintext password.

### 3.2 User content and relationship records

Users may create moments, notes, comments, lists, tasks, tags, person profiles, birthdays, contact details, work and preference fields, family or relationship context, relationship-tracking records, transcripts, reminders, and other structured records. A record may include information about the user or another person. Users decide what they enter and are responsible for having the rights or other lawful basis needed to collect, store, disclose, and ask us to process information about other people. We may act on the user's instructions for that content, but our role under a particular privacy law depends on the facts and that law.

Ask Momentan can save conversation titles, visible messages, draft proposals, and save receipts in the app's private on-device database. That database relies on the device's operating-system sandbox and device security; Momentan does not claim separate application-layer encryption for the live local vault. Ask history remains on that device, does not enter ordinary account sync, and can be disabled or deleted in Preferences. Disabling history does not prevent a user from having a temporary conversation during the current app session.

### 3.3 Contact import and refresh

When a user chooses Import or Refresh and grants contacts permission, the app reads contacts available under that permission and creates or refreshes person profiles. A one-time import does not turn on ongoing refresh. On supported iPhones and iPads, a user may separately opt in to continuous refresh. While enabled, Momentan checks permitted contacts when the app becomes active and may perform opportunistic background checks that iOS can delay or skip. With Apple's Selected Contacts access, Momentan can see and refresh only the contacts the user permits.

Imported structured fields can include names, nicknames, birthdays, phone numbers, email addresses, postal addresses, and work details. Momentan does not import Apple Contact notes during import or refresh. The resulting Person fields become ordinary Momentan User Content: they may sync securely to the user's account, appear in the web companion, and be included when the user invokes an AI feature under the existing Cloud Processing controls. Contact photos, Apple contact identifiers, change-history tokens, source snapshots, conflicts, and refresh choices stay in that device's local Momentan vault and are excluded from Momentan backup, export, web, AI context, widgets, notifications, analytics, and diagnostics.

Continuous refresh is read-only with respect to Apple Contacts: it does not edit or delete Apple Contacts. Turning refresh off keeps imported People and stops future automatic checks. Forgetting Apple links or deleting Momentan data does not delete Apple Contacts. Users can change or revoke Contacts access in iOS Settings. We do not upload a raw address book wholesale, use imported contacts to contact people, build advertising audiences, or obtain contact data from data brokers.

When a user saves a new Person in the native app, Momentan may request Contacts permission and make one best-effort Apple Contacts entry from the fields the user confirmed, such as name, contact details, birthday, and work information. Later Person edits and continuous refresh do not edit or delete that Apple Contact. The entry remains under the user's control in Apple Contacts; removing a Momentan link, Person, vault, or account does not delete it.

### 3.4 Device-local media

Photos, videos, contact photos, and voice recordings are stored in the app's device storage and are not part of ordinary structured-record sync. A voice recording is transmitted when the user deliberately requests optional transcription. Device-local media is not included in the password-encrypted backup of structured records. Removing the app or losing a device can remove local media, so users should keep separate copies they need.

### 3.5 Business-card scanning

If Scan business card is available on iPhone or iPad, a user may explicitly take or choose one front image and, optionally, one back image. After the user accepts Cloud Processing, Momentan removes embedded metadata, bounds the images, and sends only those selected images through our server function and AI providers to extract contact details. We do not upload the user's photo library, and scanning is not available in the web companion.

The card images and extraction review metadata are temporary: they are not added to the person profile, structured-record sync, backup, export, Ask history or context, widgets, notifications, Calendar, or analytics. Temporary device copies are deleted after processing, review, cancellation, or expiry, and our application does not persist the card image or raw model response. A user must review New Person and press Save before extracted fields become ordinary Momentan person data. Confirmed fields may then sync, export, appear on the web, enter existing AI context, and be added to device Contacts under the user's existing choices and permissions.

### 3.6 Apple Calendar on-device access

On iPhone and iPad — phone and tablet only — a user may choose Connect Apple Calendar. Momentan reads the selected event calendars locally on that device. When the user opens a meeting, Momentan may temporarily inspect that exact event's invitation participants and organizer on-device and exactly match an email only to an email already saved on a Momentan Person. This does not require Contacts permission, does not create a Person, and never modifies an invitation. Raw attendee, organizer, and participant identity is discarded after matching and is never synced, uploaded, logged, sent to AI, or retained as account content.

Apple Calendar events and local Calendar source choices, person links, bounded post-event prompt state, cached Meeting Briefings, and invitation-derived matching state are not collected as Momentan account content. Retained matching state contains only a local opaque event-person association plus local provenance or suppression state. Calendar content and this local state are excluded from Momentan sync, backup, export, import, web, widgets, notifications, analytics, diagnostics, logs, and persistent general AI context. Backup, export, and import refer to Momentan's in-app password-encrypted backup of structured Momentan records, not to an Apple full encrypted device backup. Importing a Momentan backup does not transfer a Calendar connection, selected source, link, prompt state, cached briefing, event, provenance, or suppression; it preserves the receiving device's existing local Calendar setup.

When a visible event has a location, the app may use Apple Maps and MapKit on that device to resolve address-like event location text and render a temporary map preview. Depending on the event data, Apple may receive the search text or coordinates and ordinary service, device, and network information under Apple's terms and privacy policy. Momentan does not send the map request to its own servers, access the device's current location, or persist the search result, coordinates, or map image after the bounded in-memory preview is cleared.

After a user enables the current Cloud Processing disclosure, a schedule or meeting question in Ask Momentan may cause the app to derive a bounded, question-relevant date range and send an identifier-free, size-limited set of visible event details. Those details can include title, date and time, source-calendar display name, all-day and recurrence state, location, website, notes, availability, event status, names of people linked in Momentan, and an exact-signature cached Meeting Briefing when relevant. The app does not include Apple event, occurrence, calendar, or source identifiers; local person or vault identifiers; raw attendees, organizers, or participants; or alarms. Raw attendee or organizer data never reaches AI. A resulting ordinary saved Person ID or name may reach consent-gated Ask or Meeting Briefing exactly as it can after a manual link. Ask receives no Calendar content for an unrelated request and does not passively prompt for Calendar permission. The request context is not written to Ask history, but if Ask history is enabled, the user's visible question and the visible answer — which may refer to an event — can be saved in the private on-device Ask archive described above.

If a user links one or more people to a selected event, enables Cloud Processing, and explicitly opens Meeting Briefing, Momentan sends an identifier-free, size-limited copy of that event's visible title, date, time, all-day and time-zone state, location, website, and notes together with bounded Momentan context for the linked people. The generated initial briefing may be cached in the active device-local vault and reused only while the event details and linked-person set still match; follow-up answers remain limited to the open briefing. The event and cached briefing are excluded from Momentan sync, backup, export, web, Ask history, widgets, analytics, and notifications. Meeting Briefing cannot edit the Apple event or save, edit, or delete Momentan records.

Apple owns event editing, invitations, recurrence, and source-calendar sync. Invitations remain unmodified. Apple Calendar alerts are managed by Apple Calendar, and Momentan does not duplicate them. Disconnecting removes Momentan's local source choices and links but does not delete Apple events. An event may sync through iCloud, Google, or another account selected in Apple's editor; that is outside Momentan's control.

A post-event prompt is in-app and bounded; it is never a push or local notification. A task, reminder, or moment becomes ordinary Momentan data only after the user completes a visible review in a Momentan editor and presses Save. It may then sync, export, appear on the web, or enter existing AI context, but contains no Apple identifier or hidden Calendar provenance.

### 3.7 Technical, security, and service data

We and our service providers process identifiers and records needed to operate the Service, including database record identifiers and timestamps, deletion markers, authentication cookies or tokens, IP address and user-agent in infrastructure logs, request and security metadata, rate-limit counters, device platform, timezone, push tokens, notification preferences and delivery records, consent preferences, app version, crash or diagnostic information made available through our infrastructure, and records of legal-document acceptance.

To enforce account-wide AI allowances without storing relationship content in the usage system, we process a Momentan account identifier; random request and event identifiers; keyed, non-reversible request or operation fingerprints; the meter and policy applied; integer amount, reservation, completion, refund, retry, reset, and bounded failure state; database timestamps; and an opaque Meeting-session scope identifier where needed. This ledger does not contain prompts, transcripts, names, notes, generated answers, media, filenames, or Person, Moment, Calendar, or other customer-record identifiers.

For limited Premium measurement, we process content-free events such as paywall shown or dismissed, purchase or restore started/completed/failed, Customer Center opened, allowance warning or reached, and daily active eligibility. Fields are limited to an account identifier, random event identifier, client and receipt times, reporting day, allowlisted event, source, policy, meter, outcome, reason, environment, amount, model category, and cache-age category. There is no free-text or general JSON event field. We use this information to enforce allowances, reconcile purchases, prevent duplicate charging, operate retries, diagnose billing and allowance problems, measure whether the offer works, support a user's request, and protect the Service.

For personalized push notifications, delivery records may include the generated notification title and body transmitted through Expo and Apple. Current application jobs remove those delivery records after 90 days.

### 3.8 Subscription and transaction data

Apple and RevenueCat provide product, entitlement, billing-period, trial, renewal, grace-period, billing-issue, expiration, refund, revocation, ownership, store environment, and subscription-event information. We store the bounded state needed to decide current access and reconcile webhook or client observations, including the RevenueCat app-user identity and last event identity. We do not receive payment-card details or Apple Account credentials. Current price, billing, tax, and offer-eligibility information is presented by Apple.

### 3.9 Communications

We collect messages and attachments a person sends to our support, privacy, legal, or general contact addresses, along with our responses and records needed to resolve the request.

### 3.10 Website and web companion

The authenticated web companion uses necessary authentication cookies, browser storage, and security controls. Cloudflare Turnstile may process browser and network signals to protect authentication. The public marketing site does not currently use advertising or analytics cookies. Its pages may request font files from Google Fonts, which can disclose ordinary request information such as IP address and user agent to Google.

The web companion may hold account-bound session state, caches, and unsaved drafts in the open browser profile. Ordinary sign-out attempts to finish or asks the user to resolve an unsaved draft before clearing that account's app-controlled web session data. When account deletion is pending, the web companion blocks protected access and discards rather than uploads a pending draft. A supported open tab can react to that change, but Momentan cannot remotely clear a browser profile that is closed or never opened again. Browser or operating-system backups, copied text, printouts, screenshots, and downloaded exports are outside Momentan's control.

### 3.11 Device vaults, sign-out, removal, backup, import, and export

Each signed-in account uses a separate account-bound local vault on a device. Ordinary sign-out immediately hides the account's protected content, stops account-bound work, and closes the vault, but retains that exact local vault so the same account can use it again after authentication and security checks. Another account cannot open, display, import into, or write to that retained vault.

“Sign Out and Remove From This Device” is a separate action. It signs out and retries logical removal of only the selected account's app-controlled vault, local media, managed temporary files, account-scoped preferences and caches, pending sync or import state, widgets, and notifications on that device. It does not delete the cloud account, another account's vault, originals in Photos, Calendar events, Contacts records, user-controlled exports or shares, or historical operating-system backups. Logical removal deletes app-controlled names and files; it is not a promise that flash storage blocks are physically overwritten.

“Clear All App Data” is a separate authenticated device-wide action. It retries logical removal of every Momentan vault and app-controlled namespace on that device. It does not delete any cloud account or recall copies outside the app.

Momentan's in-app password-encrypted backup, export, and import cover supported structured Momentan records. They exclude device-local photos, videos, contact photos, and recordings; Apple Calendar content and local Calendar choices or links; device Contacts originals and local Apple Contacts link, snapshot, token, conflict, suppression, and refresh state; platform credentials; and operating-system or browser backups. Importing a backup turns off and forgets local Apple Contacts refresh links in the destination vault without changing imported People or any Apple Contact; the user may explicitly enable a fresh local bootstrap afterward. An exported or downloaded file is controlled by the user and remains until the user deletes it and any copies or shares. An import is staged inside the destination account's app-controlled area and is not allowed to cross into another account's vault. A legacy backup whose owner cannot be verified may be opened only through a clearly disclosed local-only recovery flow; it cannot be imported into cloud sync without a separately authenticated adoption flow.

The native app may keep a content-free Premium status and allowance snapshot in the account's local vault for up to 72 hours so Profile can show recent status and core data remains usable during a temporary outage. It contains entitlement lifecycle, allowance counts and reset times, server receipt time, and the exact account/vault-incarnation binding, but no relationship content. The app may also keep at most one failed daily-active event per day for up to seven days for retry. That retry record contains only a random event identifier, occurrence time, and the fixed daily-active event/source fields. These local records are removed with the exact app-controlled vault and are excluded from Momentan's portable backup, export, import, sync, and web companion.

## 4. Why we use information and legal bases

We use information to provide accounts, sync and display supported records, operate requested features, manage subscriptions, deliver notifications, provide support, secure and debug the Service, prevent fraud or abuse, comply with law, enforce agreements, and establish or defend legal claims.

Where the GDPR, UK GDPR, or a similar law applies, our legal bases are performance of the user contract for core account and Service functions; consent for optional Cloud Processing and any processing that law requires to be consent-based; legitimate interests in security, reliability, support, enforcing legal rights, and assessing the bounded content-free Premium measurement described in Section 3.7 where those interests are not overridden; and legal obligation where applicable. A user may withdraw consent for future processing without affecting processing already lawfully completed.

Content that a user chooses to enter may reveal health or another category of information protected by special rules. Where those rules apply, we process that information only when an applicable legal condition permits it. Optional Cloud Processing is consent-based, but that choice does not authorize a user to disclose another person's sensitive information without a lawful basis. Users should not submit another person's sensitive information unless they are legally permitted to do so.

We may create and use aggregated, anonymized, or de-identified information for security, measurement, product improvement, research, reporting, and lawful business purposes. Where law treats that information as de-identified, we will maintain it in de-identified form and will not attempt to re-identify it except to test our de-identification controls or as law otherwise permits.

## 5. Optional AI and Cloud Processing

Cloud AI features may include transcription, typed or spoken capture, question answering, person and meeting briefings, AI-composed notifications, and business-card scanning. The app's Cloud Processing control is off until the user accepts the disclosure. A request may send only the bounded content reasonably needed for that feature, which can include audio for transcription, a prompt, recent context, names, contact fields, relevant moment, note, task, profile, and relationship snippets; the question-scoped or selected-event Calendar details described in Section 3.6; or a business-card image the user explicitly selects for one extraction. Saved photos and media are not included automatically. AI output and transcripts the user saves become account content.

A generated Person Briefing is automatically cached with the account for that Person and in the active device vault so an unchanged briefing can be reused. It is replaced when regenerated and removed from live production data with the Person or account. The Cloud Processing choice is stored separately for the current account installation or browser profile; enabling it in one installation or browser does not enable it everywhere.

For business-card scanning, the Service sends the bounded card image or images selected for that scan to OpenRouter and an available vision-model provider. The feature extracts a structured draft and opens New Person for review; it does not auto-save or auto-merge a person. Temporary card images and extraction-only evidence, review flags, provider metadata, and label hints are not retained as account content. Only the person fields the user confirms and saves enter ordinary storage and sync.

For an Ask Momentan cloud turn, the Service sends the current prompt, no more than 20 recent visible conversation messages, and a topic-selected, identifier-free context bundle subject to size and record-count limits. The whole device vault and local conversation archive are not uploaded. The model may return text or a typed action plan. The app independently validates every supported action and may execute routine in-app creates and updates requested by the user; ambiguous targets require clarification, destructive changes require explicit confirmation, and external actions remain unsupported. Editor handoffs are saved only after the user reviews them and presses Save. Hidden model reasoning is excluded from responses and is not stored in Ask history.

AI and transcription providers used for a request may include Deepgram, OpenRouter, OpenAI, Anthropic, DeepSeek, and Google. Depending on availability, safety, reliability, or cost, the exact provider, endpoint host, or model used may change over time. Google also supports sign-in and website font delivery; it is not Momentan's default AI model. Provider processing is subject to our service configuration and applicable provider terms.

OpenRouter requests are configured to deny endpoints that OpenRouter identifies as collecting request content. OpenRouter states that it does not store prompts or responses unless an API customer opts into optional logging or content-use features, which are off by default; Momentan does not enable those optional features through the Service. OpenAI states that API inputs and outputs are not used to train or improve models by default unless an API customer explicitly opts in; Momentan does not opt in. Providers may retain limited content or metadata for abuse monitoring, security, legal compliance, or service operation under their terms and the configuration applicable to a request. We therefore do not promise zero retention unless a request is actually routed under an applicable zero-data-retention configuration. We do not authorize providers to use identifiable private content for their independent advertising purposes.

AI output may be incomplete or wrong. Users should not use Momentan as a substitute for professional medical, legal, financial, or emergency advice.

## 6. When we disclose information

We disclose information to service providers acting for us, including Supabase for database, authentication, and server functions; Apple and Google for supported sign-in; Apple for distribution, billing, push delivery, and a user-requested Apple Maps or MapKit preview; RevenueCat for subscription entitlement; Expo for app and push infrastructure; Resend for transactional email; Cloudflare for security; Vercel for web hosting; Google Fonts for public-site font delivery; and the AI providers listed above for features a user invokes.

We may also disclose information when directed by a user; to complete a corporate transaction such as a merger, financing, restructuring, or asset sale subject to applicable notice and legal requirements; or when reasonably necessary to comply with law, respond to valid process, protect a person from serious harm, secure the Service, or establish, exercise, or defend legal claims.

We require service providers that process personal information for us to use it only for specified service purposes and to provide confidentiality, security, deletion or return, and assistance protections appropriate to their role and consistent with this Policy and applicable law. We do not permit service providers to use private content for their own advertising. Vendors may process data in countries different from the user's country and may have independent security, abuse-prevention, and legal obligations.

## 7. No current sale, ads, or behavioral advertising

Momentan does not currently sell personal information or share it for cross-context behavioral advertising, and we have not done so during the preceding 12 months. We do not currently serve third-party ads, use an advertising SDK, or access an advertising identifier for tracking.

We may change our business model in the future, but this Policy is not consent to a future sale, targeted-advertising program, or materially different use of private content. Before any future sale or sharing begins, we will update this Policy and implement the advance notice, consent, opt-out, Global Privacy Control, sensitive-data, risk-assessment, contractual, and platform disclosures required by the laws and platform rules then applicable. Where prior opt-in consent is required, we will obtain it before processing. Where an opt-out is required, it will be available before the activity starts. We will not rely on continued use alone where law requires a more specific choice.

This future-change section preserves our ability to adopt a lawful business model; it does not create present permission to sell or share information. Any program would exclude data or jurisdictions where the activity is prohibited and would be assessed under the law and platform rules in effect at that time.

## 8. Retention and deletion

Account content is generally retained while the account is active. After account deletion is confirmed, a retryable flow attempts to remove covered production records, owned storage, and the authentication account. A transient provider, storage, authentication, process, or network failure before authentication deletion succeeds can leave the account usable so the user can obtain a new confirmation challenge and retry. Once authentication deletion succeeds, protected account access ends and the live account-bound database rows are removed through the current deletion path.

Residual encrypted infrastructure backup copies may remain inaccessible to ordinary product use until they age out under the provider's applicable recovery-retention period. A disaster-recovery restore can reintroduce data deleted after the selected recovery point. Momentan's current deletion system does not maintain an immutable external ledger of every deletion; a restored production environment must remain isolated until post-recovery deletion risk is evaluated and the documented recovery process permits service to reopen.

After authoritative confirmation, the requesting supported installation locks and retries best-effort logical removal of that account's exact app-controlled local vault. Account deletion does not guarantee remote erasure of an installation that is offline, uninstalled, never reopened, network-blocked, tampered with, or running an unsupported old build. A retained copy on another device remains protected by that device and app version until it is opened and authoritatively handled or the user removes the app data. Device-local media on another device, user-controlled exports or shares, browser downloads, screenshots, Photos or Contacts originals, Calendar data, and operating-system or browser backups are not controlled by server deletion.

Business-card images and extraction-only review data are request-transient application data rather than account content. Temporary device files are deleted after processing, review, cancellation, or expiry. AI and infrastructure providers may still process limited content or metadata under their operational retention, security, abuse-monitoring, and legal terms as described in Section 5.

When Ask history is enabled, the app retains up to 30 nonempty local conversations and up to 100 visible messages per conversation, pruning older completed turns. Pending unsaved drafts are protected from routine pruning. A user can delete one conversation, delete all Ask history, or disable future history saving. Removing the local vault or deleting the account on that device removes its local Ask history.

We retain different operational records for only as long as reasonably needed for their purpose. Ordinary finalized Premium allowance evidence is removed after 45 days; Meeting-session and follow-up evidence is retained for 180 days so the per-session allowance remains enforceable. Content-free Premium telemetry is removed after 90 days. Under our current application retention jobs, notification delivery records and stale push tokens are purged after 90 days, and soft-deleted synced-record tombstones are purged after 180 days. Account deletion cascades or purges account-bound Premium allowance and telemetry rows, subscription state, recovery sessions, challenges, rate-limit state, notification claims, reservations, and push tokens; late subscription-provider events for a deleted or non-live account do not recreate it. Security and infrastructure logs follow provider rotation periods. Transactional records held by Apple or RevenueCat follow those providers' obligations and policies. Support records remain while needed to complete the request and protect legal rights, and limited transaction records may remain as needed for accounting, fraud prevention, disputes, and legal obligations.

A privacy access or portability response may include an understandable, content-free summary of the requester's Premium status, applied policy, allowance usage, resets, and relevant purchase or telemetry history where required. We do not expose secret fingerprints, abuse defenses, another account's data, or provider-controlled Apple records. Premium operational records are not relationship content and are excluded from the app's ordinary portable backup, but this does not narrow a privacy right available under applicable law.

While an account is active, we process narrowly scoped legal-acceptance evidence, including user identifier, one-way email hash, document versions and hashes, acceptance method, platform, app version, and server timestamp. The current account-deletion path removes the account-bound acceptance record from the live database. It contains no contacts, moments, notes, media, location content, or advertising identifiers. Separate transaction, dispute, legal-hold, or provider records may remain only as permitted or required by law and the other retention terms in this Policy.

We may retain information longer where necessary to comply with law, resolve a dispute, enforce an agreement, or prevent fraud or abuse. We may retain de-identified information where it can no longer reasonably be linked to a person or household.

## 9. International processing

We are established in Bosnia and Herzegovina and use providers in the United States and other countries. Those countries may have different data-protection laws. Where applicable law requires a transfer mechanism, we use an available lawful mechanism such as an adequacy decision, approved contractual clauses, or another valid safeguard. Users may contact privacy@momentan.app for information about applicable safeguards.

## 10. Privacy rights and choices

Depending on location, a person may have rights to know or access personal information, correct it, receive a portable copy, delete it, restrict or object to processing, withdraw consent, opt out of sale, sharing, targeted advertising, or certain profiling, limit certain sensitive-data uses, and appeal a denied request. A person may also complain to a competent data-protection authority.

Bosnia and Herzegovina requests are handled under the 2025 Personal Data Protection Law of Bosnia and Herzegovina and other applicable law. EEA and UK users may contact their local supervisory authority. California and other US residents may exercise rights provided by their state law. Momentan will honor a legally recognized Global Privacy Control when it applies to an active practice; there is no current sale or behavioral-advertising sharing to opt out of.

Use in-app export, correction, consent, subscription, and account-deletion controls where available, or email privacy@momentan.app. We may need to verify identity and authority. Authorized agents must provide legally sufficient authorization. We do not discriminate for exercising a privacy right, though a requested deletion or withdrawn consent can make a feature unavailable.

If a request concerns information another user stored about the requester, we may need additional details to locate the record and authenticate the request. We will respond to and act on the request to the extent required by applicable law. Where law permits, we may also direct the requester to or notify the user who controls the private relationship record.

## 11. Security

We use administrative, technical, and organizational safeguards designed for the nature of the information, including encrypted transport, hosted encryption at rest, access controls, account-bound authorization, security logging, rate limiting, deletion controls, and a password-encrypted structured backup. No system is perfectly secure, and we cannot guarantee that unauthorized access, loss, or misuse will never occur. Users are responsible for device security, account credentials, exported files, and media copies.

## 12. Children

The Service is not offered to anyone under 18. We do not knowingly permit a person under 18 to create an account. If we learn that an underage person provided personal information, we may suspend the account and delete the information as required. Contact privacy@momentan.app with a supported concern.

## 13. Changes to this Policy

We may update this Policy to reflect product, legal, security, or business changes. We will post the updated version and effective date and, when reasonably practicable, give advance notice of a material change. We will request renewed acceptance or consent where required. A prior version is not advance consent to a materially different future practice. If a user does not accept a change required for continued account use, the user may stop using the Service and delete the account.

## 14. Contact

Momentan — Privacy: privacy@momentan.app · Support: support@momentan.app · Legal: legal@momentan.app

Users may contact the Personal Data Protection Agency of Bosnia and Herzegovina or another competent authority where applicable.
