Legal

Data Policy

How Momentra processes, stores, retains, and governs product and operational data across moments and systems.

Last updated: 22 July 2026

This Data Policy complements our Privacy Policy. It describes categories of data Momentra processes to operate the product, how long we keep it, and how processing roles work for personal, group, and business moments.

If there is a conflict between this Data Policy and the Privacy Policy on a personal-information topic, the Privacy Policy controls for that topic.

1. Roles and responsibilities

For consumer and end-user accounts, Momentra generally acts as a controller (or similar role under applicable law) for account data and product telemetry we determine how to process.

For content inside moments, especially group and business moments, users who create or administer moments may determine purposes for shared content. In those cases, Momentra typically acts as a processor/service provider for that User Content, while still acting as controller for platform operations, security, and billing or account administration where applicable.

Business customers may request a data processing agreement where required. Contact us to discuss enterprise terms.

2. Data categories we process

Operational data categories include:

  • Identity and authentication records
  • Moment metadata (type, status, timeline, participants, roles)
  • Financial coordination entries users enter (amounts, goals, contributions, budgets)—not bank credentials unless a future feature explicitly collects them with separate notice
  • Activity streams, pulse/health signals, and suggested next steps generated by the product
  • Memory artifacts users attach (notes, photos, learnings)
  • Invite tokens and acceptance outcomes
  • Support tickets and operational logs
  • Analytics events (including marketing CTA and screen views where enabled)

3. Processing purposes

We process data to:

  • Deliver core moment lifecycle features (create, invite, plan, contribute, coordinate, complete, remember, learn)
  • Maintain integrity, availability, and security of the platform
  • Provide customer support and investigate abuse
  • Improve reliability, performance, and product design
  • Meet legal and accounting obligations

4. Storage and infrastructure

Momentra uses reputable cloud infrastructure and service providers for application hosting, databases, authentication, file storage, and analytics. Data may be replicated across availability zones for resilience.

Access to production systems is limited to authorized personnel with a need to know, subject to internal controls.

5. Subprocessors and vendors

We use vendors to help run the Services. Categories include authentication, application hosting, databases, analytics, email/transactional messaging, and monitoring.

Current examples may include providers such as Firebase (authentication/analytics), Supabase or equivalent database/auth infrastructure, and hosting platforms used to serve the web application. The specific vendor set can change as we scale; we require appropriate contractual protections.

For an updated vendor list relevant to your account, contact hello@momentra.app.

6. Retention schedules

Unless a shorter or longer period is required by law or product settings:

  • Account profile data: retained while the account remains active, then deleted or de-identified within a reasonable period after deletion request or account closure (subject to legal holds)
  • Active and completed moment content: retained while needed for the moment’s lifecycle and user access expectations; archived or deleted according to product workflows and deletion requests
  • Invite tokens: retained until used, expired, or revoked
  • Security and server logs: typically retained for a limited operational window (often up to 12 months) unless needed longer for investigations
  • Analytics events: retained according to the analytics provider configuration and our measurement needs, often in aggregate or pseudonymous form
  • Support correspondence: retained as needed to resolve issues and for a reasonable follow-up period

7. Deletion and export

You may request deletion or export of personal data by contacting hello@momentra.app. We will verify the requester and complete requests within timeframes required by applicable law.

Deleting an account may not immediately remove content that other users still need for a shared moment (for example historical contributions visible to remaining participants). We will explain limitations when they apply.

8. Security controls

Controls may include encryption in transit (TLS), access controls, least-privilege practices, monitoring, and secure development processes. We continually improve these controls as threats evolve.

9. Security incidents

If we become aware of a personal-data breach affecting the Services, we will investigate and notify affected users and authorities as required by law.

10. Product intelligence data

Pulse, health, and AI-assisted insights are generated from moment context you and other participants provide. We use this context to power in-product guidance. We do not sell moment content to third parties for their independent advertising.

Where models or tooling are provided by vendors, we configure them to support product functionality and apply contractual and technical safeguards appropriate to the use case.

11. Changes

We may update this Data Policy as our systems and legal requirements change. The “Last updated” date will reflect the latest version.

Contact

Data protection requests: hello@momentra.app

Email hello@momentra.app.