Draft — not yet in force

This document is still being written and has not been reviewed. It does not yet govern your use of Momentbound, and parts of it describe behaviour that is not built. Contact privacy@momentbound.app with any question in the meantime.

Version v0.7-draft · Last updated 2026-09-03

Privacy Policy

In short

Momentbound stores your photos and videos so you can organise them into albums and journeys and share them with people you invite.

  • Your media is private by default. It is visible to you, to people you invite to a library, and to anyone holding an invite link you create.
  • We do not sell your data, we do not use it for advertising, and we do not use it to train AI models.
  • Error, performance, and product-usage tools (crash reports, basic analytics, and masked session replay) help us fix the product. They are not used to profile you for ads or to sell usage patterns. Optional tools need your consent on the web (a cookie banner) and an equivalent in-app choice on mobile. See sections 4.9a and 12.
  • Your photos may contain location data. If they do, we read it to place them on maps. To turn coordinates into place names we send a reduced-precision version to Google — never the exact position we hold. Guest and shared downloads never contain embedded GPS; library members may get original metadata restored when they download. You can control how precisely locations appear to guests.
  • We never see your password or your card details. Our sign-in provider and our payment provider hold those.

The full policy below is the binding version.

1. Who we are

Momentbound is operated by:

Tollånes Development (enkeltpersonforetak, Norway) Organisation number: 836547152 Postal address: 4639 Kristiansand, Norway

We are the data controller for the personal data described in this policy.

Contact:

  • Privacy questions and rights requests: privacy@momentbound.app
  • General support: support@momentbound.app
  • Reporting abuse or illegal content: abuse@momentbound.app
  • Security vulnerabilities: security@momentbound.app

We have not appointed a Data Protection Officer.

2. Who this policy covers

  • Account holders who sign up and own or join libraries.
  • Guests who open an invite link without creating an account.
  • People appearing in uploaded media, who may not be users at all.

If someone uploaded a photo of you and you want it removed, contact privacy@momentbound.app. Section 5.1 explains on what basis we hold media that shows you, and section 11 explains what you can ask us to do about it.

3. Minimum age

You must be at least 13 to create an account, and guests must be at least 13 to upload. When you first sign in we ask for your date of birth. We store it as a calendar date, write-once, and use it only to apply two product rules: whether you may hold an account (13), and whether you may buy a paid plan (18). We do not verify the date. We do not use it for marketing. Optional analytics and similar consent tools, when they ship, stay off until 18.

Guests on an invite link do not give a date of birth. Before their first upload they confirm they are 13 or older with a checkbox, and we record that they confirmed it and when.

We do not knowingly create accounts for anyone under 13. If we learn that an account belongs to someone younger, we will delete it.

13 is both Momentbound's account floor and the Norwegian age at which a child can generally give their own consent to processing of personal data in connection with online services where consent is the legal basis (GDPR Article 8). Other EEA countries set that Article 8 age between 13 and 16. Paid plans are a separate question: Stripe Checkout is only offered to accounts whose recorded date of birth makes them 18 or over. Under-18 accounts stay free.

Adults do upload photos and videos containing children — family libraries are a core use case. That media belongs to the uploader's library and is governed by the same privacy rules as any other media. It is the uploader's responsibility to have the right to upload and share it.

4. What we collect

4.1 Account and profile

Data Why Required
Email address Account identity, service emails Yes
Username Public handle other members see Yes
First and last name Optional; held by Clerk and synced as a display name when present No
Date of birth Account floor (13+) and purchase floor (18+). Self-asserted, write-once Yes (accounts)
Profile picture Shown to other members No
Short bio Optional self-description No
Notification and cellular-upload preferences Honour your choices No
Friend connections The friends feature No

Sign-in is handled by Clerk. Passwords, social-login identities, sessions, and any multi-factor settings are held by Clerk. We never receive or store your password.

4.2 Photos and videos

When you upload media we store:

  • The original file you uploaded, subject to the retention rules in section 8. Embedded GPS / location is removed when the file arrives and stored separately. For photos we keep presentation metadata in the stored file (orientation, capture time, camera and exposure) so the picture still displays the right way up; location-bearing EXIF, XMP, and IPTC leave the object. For videos only the location box is overwritten; capture date and the rest of the container stay. Nothing about the picture or footage itself changes: removal does not re-encode, so the file keeps its full resolution and quality.
  • The location metadata we removed, kept so we can put it back when a library member downloads the original. Guest and shared-link downloads receive the stored file without embedded GPS. The sidecar is never handed to guests, is never served as its own object, and is deleted with the photo or video.
  • Optimised versions we generate for fast display — previews, thumbnails, and compressed video. These are re-encoded and carry no location or camera metadata.
  • File details: original filename, format, size, dimensions, video duration.
  • Capture time and its timezone offset, read from the file's metadata, used to order journeys chronologically.
  • Captions you write.

4.3 Location

This is the most sensitive data in the product, so we describe it precisely.

Photos and videos from phones and cameras often contain GPS coordinates. When present, we read those coordinates and store them at the precision contained in the file (typically up to six decimal places). Decimal storage is not the same thing as GPS accuracy — a phone is usually far less precise than that. You can also set a location manually by searching for a place.

We use coordinates to:

  • Place media on album trip maps and your personal life map
  • Group media into journeys and sections by place
  • Derive a human-readable place name

Three separate things happen with third parties, and it is worth being precise about which is which.

Place names. To convert coordinates into a place name ("Bergen, Norway") we send them to Google Maps Platform, which may process them outside the EEA and which receives them as an independent controller rather than as our processor — see section 6.3. We reduce their precision before we send them. We round latitude and longitude to three decimal places, so what leaves us identifies a grid cell rather than a point: roughly 110 m north to south, and narrower east to west the further north you are — around 60 m in southern Norway, under 40 m in Finnmark. Google never receives the precise position stored against your photo. Reducing precision can occasionally change the label we get back, where a cell straddles the boundary between two named areas. We store the resulting place name on that photo, album, or journey section only. Nearby photos at the same reduced-precision cell each get their own Google lookup. We do not keep a shared cell cache.

We discard any street-level result Google returns — place names are never street addresses.

Map backgrounds. The map images themselves come from Mapbox, which receives the area of the map you are looking at and your IP address. Mapbox does not receive your photo locations. Your coordinates travel from us to your own device, which draws them on top of Mapbox's background images.

Place search. When you search for a place by name:

  • On the website, the typed text is sent to Google Places through our servers when that path is configured. No coordinates and no account identifiers are included, and Google does not receive your IP address for those searches.
  • If that path is empty or unavailable, the website falls back to Mapbox Search in your browser.
  • On mobile, place search goes to Mapbox Search from the device.

Mapbox Search receives the text you typed and your device IP. It does not receive your photo coordinates.

Your controls

  • New albums default to city-level precision for shared maps. Guests see the city, not the exact spot. (If you change your account default, new albums follow that instead.)
  • You can change precision per album. If you choose exact coordinates for a shareable link, we warn you at the time, because exact locations of a home, school, or workplace can be used to find people.
  • Guest and shared downloads never contain embedded GPS. Authenticated library members may receive restored original metadata — including location — when they download the file through the member download path. This applies to the stored original; optimised previews never carry location.
  • You can delete media, which removes it from view immediately. Coordinates stored on the row are purged with the file after the 30-day recovery window in section 8.

4.4 Libraries, sharing, and guests

  • Library details: name, owner, plan, storage used.
  • Membership: who is a member of which library, and their role.
  • Albums, journeys, and sections, including titles and ordering.
  • Invite links: the link code, what it permits, when it expires, upload caps.
  • Guest identity: if you use an invite link without an account, we store the name you give and a random technical identifier generated in your browser (a UUID kept in local storage). It lets us attribute your uploads and reactions consistently within that library on that device. It is not derived from your hardware, IP address, or cookies from other sites; clearing the site's data creates a new identifier; and it is not linked to any Momentbound account.
  • Guests who upload also confirm they are 13 or older, and accept the Terms and Acceptable Use. We record those assertions against the guest contributor row.
  • Reactions and comments you leave.
  • Scrapbooks, their pages, stickers, and exported PDFs.
  • Physical tag links, where used.

A guest can erase what they contributed from the invite page while they still have a guest session, or by writing to privacy@momentbound.app. Erasure anonymises that guest record in the library; the row is kept in anonymised form because it is what the Terms/AUP acceptance evidence hangs off.

4.5 Devices and notifications

If you enable notifications we store a push token for each device, the platform, and when it was last seen. Tokens are sent to Expo, which relays messages to Apple or Google for delivery.

4.6 Payments

Paid plans are handled by Stripe. We store your Stripe customer identifier and your plan state. Card numbers, billing addresses, and tax details go directly to Stripe and never reach our servers. We do not send your date of birth to Stripe. Checkout is refused on our side if the account is under 18.

4.7 Support and email

If you email us we hold the message and your address for as long as needed to handle the request, and for up to 24 months afterwards so we can recognise a recurring problem or a follow-up to an earlier conversation. After that the thread is deleted. (Mailbox hygiene is manual; there is no automatic job.)

If you request early access through our launch waitlist, your email is stored with Clerk, which manages approval and the account invitation.

If you separately subscribe to product news in the website footer, your email is stored with Resend until you unsubscribe. Joining the access waitlist does not subscribe you to marketing email.

4.8 Abuse reports

Anyone who can see content can report it, including guests with no account. When a report is filed we store:

  • The category chosen and any description written.
  • Which content was reported, and which shared page or album it was reported from.
  • A snapshot of the reported item taken at that moment — for a photo, its filename, caption, and who uploaded it. We keep this so a report stays reviewable if the content is later edited or deleted; otherwise anyone could erase the evidence of a report against them.
  • A contact email, only if the reporter chooses to give one. Reporting anonymously is fully supported.
  • The reporter's account or guest identity, where we already know it from the session. We do not ask for it.

Reports are stored in our own database. We send ourselves a notification when one arrives. That notification is a pager, not the case file: it contains the reference, category, target identifiers, and — if the reporter chose to leave one — their contact email. It does not contain the reporter's free-text description.

We look at reported content in order to act on the report. Access is limited to the reported item — there is no route from a report into the surrounding album — and every time reported content is opened for review it is recorded in our application logs (who opened it, and which report). See section 6.4.

4.9 Technical and security data

Our hosting providers log requests, IP addresses, and errors, and we count requests for rate limiting. This protects the service against abuse and helps us fix faults.

4.9a Website analytics, errors, and product usage

Page views (website only). We use Vercel Web Analytics to understand which pages are used. It records page paths (with invite, share, tag, join, album, and similar identifiers removed), referrers, and coarse device or region signals. Visitors are counted with a one-day hash derived from the request, not a cookie or a lasting identifier. It does not set a cookie or write to local storage. There is no cross-site tracking and no advertising profile.

Errors, performance, and masked session replay — product improvement only, not advertising. After you accept Analytics on the web cookie banner or the mobile first-launch screen (section 12), we use Sentry on web and mobile:

  • Crashes, errors, and performance (what broke, how slow a screen was).
  • Sentry Session Replay, with all on-screen text masked and all photos, videos, and other media blocked, so private media is not sent as readable frames.

These tools exist so we can improve Momentbound. We do not sell usage patterns, we do not build advertising profiles, and we do not share this with other companies for their marketing. If you refuse Analytics, the Sentry client SDK does not initialise on that device. Server-side error reporting on our API, worker, and website host does not store or access information on your device and is not gated by that banner.

Optional preferences on the device. After you accept Preferences on the same banner or first-launch screen, we store the last album type you created and timestamps for when you last looked at an album or your home feed, so unread badges still work the next time you visit. If you refuse Preferences, those values last only for the current visit.

4.10 What we do not collect

We use no advertising tools and no cross-site tracking. We do not build advertising profiles, we do not infer interests for ads, and we do not track you across other services. We do not run face recognition or automated analysis of image content. We do not use your photos, videos, or captions to train AI models.

We use error reporting on our servers, and — with Analytics consent — Sentry on your device including masked session replay, for product improvement. That is a change from earlier drafts that said we used none of those SDKs.

5. Why we process it, and on what legal basis

Purpose Legal basis
Providing your account, libraries, albums, and media storage Performance of a contract
Processing uploads into optimised versions Performance of a contract
Reading capture time and location from your files to organise journeys and maps Performance of a contract — organising memories by time and place is part of the service you asked for. Location is not required to store or share a photo; you can still use Momentbound if a file has no GPS
Sharing with members and invited guests as you direct Performance of a contract
Taking payment and enforcing storage limits Performance of a contract
Sending service emails (security, invites, failures, storage warnings, retention notices) Performance of a contract
Push notifications Your consent, via your device permission
Security, abuse prevention, fraud prevention, rate limiting Legitimate interests
Understanding which website pages are used (Vercel Web Analytics) Legitimate interests
Error and performance monitoring (Sentry) Legitimate interests in keeping the service working; and consent where the client SDK stores or accesses information on your device beyond what is strictly necessary
Product-usage analytics and masked session replay (Sentry Session Replay) Your consent (Analytics on the cookie banner / mobile first-launch screen)
Optional interface preferences in local storage (last album type, last-seen timestamps) Your consent (Preferences on the cookie banner). They are not strictly necessary
Receiving abuse reports, reviewing the reported content, and acting on it Legitimate interests — keeping the service safe for the people using it and for the people appearing in it
Keeping a record of reports and what we decided Legitimate interests; and legal obligation where an authority requires us to preserve or hand over something specific
Storing and displaying media that shows people who are not our users Legitimate interests — see 5.1
Attributing guest contributions within a library Legitimate interests
Access-waitlist requests and invitations Your consent
Marketing emails Your consent through the separate mailing-list form
Responding to legal requests and keeping accounting records Legal obligation

Where we rely on legitimate interests, we have weighed them against your interests and rights and believe the processing is limited and expected. Short internal assessments covering depicted people, abuse and security, guest attribution, and analytics are kept with our data inventory. You may object — see section 11.

5.1 People who appear in media

Our agreement is with the person who holds the account. Someone who simply appears in a photo has no agreement with us, so we cannot rely on that agreement to justify holding their image. We rely on legitimate interests instead: the uploader's interest in keeping and sharing their own memories, and our interest in running a service that lets them.

We believe that is a fair balance largely because of what this service deliberately does not do. We run no face recognition and no automated analysis of image content, so we do not identify anyone in a photo and cannot search for a person across the service. Media is private by default and reaches only the people an uploader invites. Guest and shared downloads never contain embedded GPS, album maps default to city-level precision, and we do not use media for advertising, for profiling, or to train AI models.

We usually cannot tell you directly that we hold a photo of you, because we do not know who is in it and have no way to contact you. Identifying every person in uploaded family media would itself require invasive processing such as face recognition, which we refuse to do. Where we do become aware — for example because you write to us — we will tell you what we hold. For everyone else, this policy is that notice. The internal Article 14 assessment is in ../article-14-assessment.md.

You can object. Use the Report action on the item, which works without an account, or write to privacy@momentbound.app. Section 11 explains what happens next. It is the uploader's responsibility to have the right to upload and share media showing other people; ours is to act when someone tells us they object.

6. Who we share it with

We do not sell personal data and we do not share it for advertising.

6.1 People you choose

  • Members of libraries you belong to
  • Anyone holding an invite link you create or a scrapbook share link
  • Anyone those people show it to

Invite links work for whoever holds them. If a link is forwarded, the new holder gets the same access until the link expires or you revoke it. You can revoke and rotate links at any time.

6.2 Service providers

Provider What it does What it receives Acts on our instructions?
Clerk Sign-in, accounts, and access waitlist Identity, credentials, sessions, waitlist email, IP Yes — DPA by reference
Cloudflare Media storage and delivery (R2, EU jurisdiction by configuration) Your photos and videos Yes — DPA by reference
Railway Hosting for our API, background worker, and database (EU West — Amsterdam) Everything stored in the database Yes — DPA executed
Vercel Hosting for our website and web app; privacy-friendly Web Analytics Requests, IP addresses; analytics events No — not during our beta. See below
Mapbox Map rendering, and place search from the device (mobile; web fallback) Map viewport, IP, device details; typed search text Yes — DPA by reference
Expo App builds and notification delivery Push tokens, device details Yes — processor terms in Expo ToS
Resend Operational email and optional marketing mail Mailing-list email addresses; abuse-report notifications (pager fields, never free-text description) Yes — DPA by reference
Sentry Errors, performance, and masked session replay (client SDK only after Analytics consent) Device/app diagnostics, stack traces, performance traces; masked replay events if enabled Processor — DPA not yet accepted
Stripe Payments Billing identity, payment method, tax data Partly — see below
Apple, Google Play App distribution and notification delivery Push tokens, store account data No — see below

Everyone marked yes processes that category of your data only on our instructions, under a data processing agreement with us, provided the DPA actually applies to our account and plan. We keep an internal register of which arrangement applies to which provider.

Vercel is not under a data processing agreement with us during the beta. Vercel's data processing agreement covers its Pro and Enterprise plans. Our website runs on the free plan, so that agreement does not apply to us, and we will not claim otherwise. In practice this means Vercel receives the ordinary technical details of every request to our website — the page you asked for, your IP address, your browser and device type — and what it does with that is governed by Vercel's own privacy policy, not this one. Vercel is based in the United States. We keep the free plan while the service is a small beta; we will move to a plan the agreement covers before Momentbound is generally available, and this row will change when we do.

Stripe is a mixed case. It takes payments on our instructions, but it also decides for itself how to meet its own fraud-prevention, anti-money-laundering, and financial record-keeping duties. For those purposes Stripe's own privacy policy governs, not this one.

Apple and Google Play are not our providers in this sense. They distribute the app and relay notifications under their own developer and platform terms, and they decide their own purposes for what they collect when you install or update an app, or when a notification passes through their systems. We cannot instruct them, and their own privacy policies apply to that data.

6.3 Google Maps Platform

Google is not one of our service providers. When we turn coordinates into a place name, or when you search for a place through the server-side Google path, Google receives that request as an independent controller of the data — it decides its own purposes for it, under its own privacy policy, rather than acting on our instructions.

For European customers, Google's controller terms identify Google Ireland Limited as the European controller of that data. Google may still process it outside the EEA under those terms. Saying the request “is sent outside the EEA” would overstate what we control; saying Google may process it outside the EEA is the accurate version.

What Google receives is limited:

  • Coordinates reduced to a three-decimal-place grid cell (section 4.3), never your stored precise location
  • The place text you type when a search uses the server-side Google path

Google's handling of that data is governed by the Google Maps Platform terms and Google's own privacy policy, not by this one.

6.4 Us, when handling a report or a support request

We do not browse private libraries out of curiosity, and there is no internal tool for wandering through albums.

We do allow limited, authorised access for specified purposes:

  • Reported content, so we can decide whether it breaks the rules. That access is limited to the specific item reported, restricted to accounts we have granted moderation access, recorded when the item is opened, and used only to handle that report.
  • Support you ask for — for example if you write to us about a corrupted file and we need to look at that file to help. We use storage and subscription information first; we open content only when the request cannot be answered without it.
  • Security and legal investigations, narrowed to what is required.

If we decide reported content breaks the rules we may remove it. See section 10.

6.5 Legal and safety

We may disclose data where legally required, to respond to a valid legal request, to protect someone's safety, or to investigate abuse. We verify requests, narrow them to what is required, and tell you unless we are prohibited from doing so.

7. International transfers

We have configured our media files to be stored in Cloudflare R2 under the European Union jurisdiction, and our API, background worker, and database to run on Railway in EU West (Amsterdam). We keep those primary stores in the EEA as a matter of how we have set the services up. Both providers reserve the right to process data elsewhere under their agreements, so where that happens the transfer safeguards below apply.

Several other providers are based in the United States or process data globally. In particular, sign-in data is not held in the EEA — Clerk may process it wherever it and its own providers operate — and our email provider, Resend, is US-only. Payments, map rendering, push delivery, and (once shipped) error and usage analytics are likewise global.

Where personal data leaves the EEA we rely on one of:

  • an adequacy decision, such as the EU–US Data Privacy Framework (DPF), or
  • the European Commission's Standard Contractual Clauses (SCCs).
Provider Safeguard we rely on Where to read it
Clerk DPF; SCCs as fallback clerk.com/legal/dpa
Cloudflare SCCs and DPF. EU R2 is configuration, not a contractual residency guarantee Cloudflare customer DPA
Railway SCCs and DPF (DPA executed). Compute configured in Amsterdam Copy of the executed DPA available on request
Vercel SCCs (2021, modules 1–3) and UK IDTA, if the DPA applies to our plan vercel.com/legal/dpa
Mapbox SCCs module 2, deemed signed with the DPA mapbox.com/legal/dpa
Expo SCCs named in Expo Terms §3.2 Expo Terms of Service
Resend DPF and SCCs Resend DPA / Terms
Stripe DPF and SCCs modules 1–2 Stripe DPA
Google Maps Platform Independent controller. Google Ireland Limited is the European controller for European controller data; Google's own onward-transfer terms apply Google controller terms
Sentry / Microsoft To be recorded when those tools are added —

You can ask us for a copy of the clauses, or where they are available, at privacy@momentbound.app.

8. How long we keep it

Your media

  • Paid plans on Original quality keep your original files for as long as your subscription stays on that plan for the library.
  • Free libraries, and paid plans on a compressing quality setting, keep the optimised version indefinitely and the original only for a grace window: 30 days for photos, 7 days for video, counted per item. After that the original is removed and the optimised version remains — that is what you see and share.
  • If you move a library to Original quality while originals are still inside their grace window, those originals are kept rather than removed, and start counting toward the plan's storage.
  • If you move away from Original quality, existing originals start their grace window from that point. If a paid plan ends and the library was not already on Space saver, we lower quality to Space saver and restart that clock. Changing the setting back does not restore originals that were already removed.
  • When you delete media, it is recoverable for 30 days, then permanently removed from storage. That 30 days is the whole recovery window; it is not extended by the separate 7-day cleanup of unreferenced files described in the table below, which by definition holds nothing you could restore.
  • We may close a free library after a long period of inactivity (our current rule of thumb is 24 months). If we start doing this, we will email the owner in advance. There is no automated job for this today.

Everything else

Data Kept
Account and profile Until you delete your account
Library, album, and journey structure Until deleted, or with the library
Invite links Until they expire or you revoke them; default 30 days
Guest contributor records With the library (anonymised if the guest erases)
Push tokens Until revoked, replaced, or the account is deleted
Billing records Stripe retains these to meet accounting and tax law, typically several years
Support email 24 months after the conversation ends
Access waitlist Until it is approved, denied, or withdrawn
Marketing mailing list Until you unsubscribe; we keep a suppression record so you are not re-added
Security and request logs Short retention set by our hosting providers
Abuse reports 24 months after the case is closed. Kept even if you delete your account, so a report cannot be erased by the person who filed it — but your contact detail is removed with the account. Evidence we are legally required to preserve for an authority is kept for as long as that obligation lasts
Unreferenced files in our storage Files that no longer belong to any record — usually an interrupted upload, or a leftover after a deletion finishes. They are not a copy of anything you can still see or restore, so there is nothing to recover from them. Deleted within 7 days of us detecting them
Place names on a photo With that photo
Error / usage analytics (once shipped) Provider defaults; we will not keep session recordings longer than needed to debug a product question

Deleted data may persist in encrypted backups for a limited period before ageing out. Backups are not used to restore individual deleted items.

9. Deleting your account

You can delete your account from within the app, or from our website at momentbound.app/delete-account if you no longer have the app installed.

We ask you to confirm your identity first, because deleting an account is irreversible and we will not act on a session someone else may have left open.

If you own a library that has other members, we will not delete your account yet. We stop and ask you to transfer that library to one of its members first. This is deliberate: deleting it would destroy photos belonging to people who never asked to lose them. Transferring hands the library, its albums, and its media to the new owner, who then chooses their own plan. It does not hand over your payment method.

Once no shared library stands in the way, deletion runs in this order:

  1. Any active subscription for a library you own is cancelled. This happens before anything is deleted, and if the cancellation fails we stop and delete nothing — so an account can never be deleted while its subscription keeps billing.
  2. Libraries you own are deleted, along with all media in them, including media that other members or guests uploaded to them.
  3. Your profile, memberships, friend connections, and push tokens are deleted, and your identifying fields are cleared.
  4. Media is purged from storage on the normal 30-day schedule.
  5. Your identity record with our sign-in provider is deleted.
  6. The app confirms when deletion has completed, then signs you out.

Some data survives deletion where the law requires it — chiefly billing and accounting records held by Stripe, and abuse or security records where we need them to protect the service or to meet a legal obligation.

Abuse reports you filed are kept, so that someone cannot erase the record of a report they made about another person by closing their account. Your contact detail is removed from those reports along with the rest of your account.

Guests who never had an account use the guest erasure control in section 4.4 instead of this flow.

10. Who can delete media in a shared library

  • The library owner can delete anything in their library.
  • The album owner can delete any media in that album.
  • Other signed-in members can delete only media they uploaded.
  • Guests on an invite link can delete only media they uploaded themselves, unless that invite explicitly allows deleting others' media.
  • We can remove an individual photo or video that has been reported to us, if we decide it breaks our rules. We remove the reported item only, and we record the decision and the reason. We do not delete albums, libraries, or an uploader's other content this way.

If you need something removed that you cannot delete yourself, ask the library owner, or use the Report action on the item itself. Contact privacy@momentbound.app if neither is possible or appropriate.

11. Your rights

Under the GDPR you can ask us to:

  • Give you access to the personal data we hold about you
  • Correct inaccurate data
  • Delete your data
  • Restrict processing, or object to processing we base on legitimate interests
  • Send you a copy of your data in a portable format

You can also withdraw consent at any time, for notifications, marketing, and (once shipped) optional analytics and replay, and complain to a supervisory authority.

Each of these rights carries conditions and exceptions set by the GDPR itself, so none of them is absolute. Most of the time we will simply do what you ask. Where a right does not apply — because we have to keep something to meet a legal obligation, for instance, or because acting would harm someone else's rights — we will tell you what we are relying on and why.

To exercise any of these, email privacy@momentbound.app. We respond within one month, and will tell you if we need longer.

We may need to verify your identity before acting on a request about private media, because acting on an unverified request is itself a privacy risk. We will ask for the minimum needed.

Data export. You can request a copy of your media and album information in a format usable without Momentbound from Settings → Your data in the app or on the website. We prepare a multi-part archive (including media), notify you when it is ready, and delete it after 24 hours. The archive does not count against your library storage.

If you appear in someone else's media, you can use the Report action on the item — you do not need an account to do this — or contact privacy@momentbound.app. We will assess the request and, where appropriate, remove the content. We may need to contact the library owner.

A note on reports about you. If someone reports content you uploaded, we keep a record of the report, our decision, and the reason. You can ask what we hold about you, but we will not disclose the reporter's identity or contact details, because doing so would expose them to retaliation and discourage people from reporting at all.

Supervisory authority

Our lead authority is the Norwegian Data Protection Authority:

Datatilsynet — https://www.datatilsynet.no Postboks 458 Sentrum, 0105 Oslo, Norway

If you live elsewhere in the EEA you may also complain to your national authority.

12. Cookies, app storage, and consent

Norwegian e-commerce law (Ekomloven § 3-15) applies to cookies and similar technologies that store or access information on your device, including local storage. The exemption is narrow: the storage must be a prerequisite for the service you asked for.

Strictly necessary (no consent banner):

  • Sign-in and session cookies, set by our sign-in provider, so you stay logged in.
  • A guest session token for an invite link you opened, so your uploads and reactions are accepted.
  • The random guest identifier described in section 4.4, so contributions on that device stay attributed inside that library.

Optional convenience — these are not strictly necessary. They remember the album type you last created, and when you last looked at an album or at your home feed, so we can show you what is new. They are written to the device only after you accept Preferences. Refusing Preferences still lets you use Momentbound; unread badges and last album type then last only for that visit.

Optional product-improvement tools (consent required before they load on your device):

  • Web: a cookie banner (and Settings controls) for Sentry, masked session replay, and optional preference storage.
  • Mobile: a first-launch consent screen (and Settings controls) before optional analytics, crash, or replay SDKs initialise. Store privacy labels (App Store / Play) will list them. We do not use these tools for advertising, so we do not expect Apple's App Tracking Transparency prompt to apply; if that changes we will show it.

You can refuse optional tools and still use Momentbound. Vercel Web Analytics, as used today, does not set a cookie or write to local storage; it is not an excuse to skip consent for the optional items above.

In the mobile app the equivalent values are held in the app's own storage and are removed when you uninstall it.

We store nothing for advertising or cross-site tracking, in either place, and none of it is readable by another site for that purpose.

13. Security

  • All traffic is encrypted in transit.
  • Media is held in a private storage bucket that is not publicly listable, and is served through short-lived signed links or a controlled delivery domain.
  • Embedded location is removed from uploaded files when they arrive and held separately. Guest and shared downloads therefore cannot reveal where a file was taken from the file itself. Member original-downloads may restore that metadata.
  • Administrative access is limited to the purposes in section 6.4.
  • We apply rate limits and validate uploaded files.

No service is perfectly secure. If you find a vulnerability, please tell us at security@momentbound.app rather than publishing it.

14. AI and automated decisions

We do not use your photos, videos, or captions to train AI models. We do not run face recognition or automated content analysis. We make no automated decisions that have a legal or similarly significant effect on you.

If this ever changes, we will update this policy and, where required, ask for your consent first.

15. Beta

Momentbound is early software. During beta:

  • We intend to keep your uploads and to migrate them as the product changes.
  • We cannot guarantee against data loss. Keep your own copies of anything irreplaceable.
  • Features, limits, and this policy may change.

16. Changes to this policy

We will post any new version here with a new effective date. For changes that materially affect how we use your data, we will notify you by email or in the app before they take effect. Previous versions are archived and available on request.

17. Contact

Tollånes Development Privacy: privacy@momentbound.app Support: support@momentbound.app Abuse: abuse@momentbound.app Security: security@momentbound.app