Privacy Policy
Effective date: August 21, 2026
Momora is a private family memory journal operated by How do you turn this on LLC ("Momora," "we," "us," or "our"). This Privacy Policy explains how we handle information when you use the Momora mobile application (also listed as "UseMomora" in some app stores), our website at usemomora.com, and related services (together, the "Service").
Momora is designed for adults to record family memories. It is not designed for children to create accounts or use independently.
1. Information we collect
Account and profile information
When you create an account, we collect your name, email address, timezone, and account settings. We also store information needed to operate your account, such as your active family journal, onboarding status, notification preferences, account-deletion status, and authentication records. Production sign-in uses a one-time code sent to your email; Momora does not ask you to create a password in the production app.
Subscription and billing information
If you are a family owner, we process information needed to offer and manage Momora Plus, including the store and product selected, plan period, purchase and entitlement status, trial eligibility, purchase, renewal, expiration, cancellation, billing-retry, and grace-period dates, transaction identifiers, whether automatic renewal is enabled, and any subscription-management link supplied by the store. We also store whether an owner has complimentary or temporary access and the information needed to send a trial-ending reminder.
Purchases are processed by Apple or Google and managed for us through RevenueCat. Momora does not receive your full payment-card number. RevenueCat and the app store may process device, account, receipt, purchase-token, transaction, and subscription information under their own privacy practices. Momora identifies the subscription to RevenueCat using the same pseudonymous account identifier used for your Momora account, not your email address.
Family and child profile information
You may add information about children and other people in your family journal, including names, nicknames, dates of birth, gender, profile photos, and additional notes. We also store AI-generated character portraits and their generation status.
Memories and household activity
We collect the content you choose to add to a family journal, including:
- Memory text, captions, dates, and tagged family profiles.
- Photos, videos, and kept sound recordings attached to memories, along with the editable note and hidden search transcript created for a kept sound.
- AI-generated illustrations, prompts, detected emotions, and related generation status.
- Links included in memory text and the page titles fetched for those links.
- Likes, comments, timestamps, and creator attribution within a shared family journal.
- Family names, household memberships, roles, invite status, and invite activity.
- Looking Back package membership and your personal opened or completed status for those packages.
- Private, derived memory-card images created to support user-directed sharing.
Reports and personal safety controls
Any active member of a family journal can submit an in-app report about a memory, AI-generated illustration, comment, active household member, family profile, or AI-generated character portrait. A report includes the family, reporter, type and identifier of the reported item or membership, a selected reason, an optional note of up to 500 characters, status, and review or resolution timestamps. The report does not create a copy of the reported journal text, comment, image, portrait, or profile content.
You can also choose to hide another active household member's activity from your own view. We store the family and account identifiers needed to apply that choice. This setting is personal to you and remains in place for that account in that family until you undo it, either account or the family is deleted, or Momora can no longer associate retained content with that account.
Momora may read a selected photo's capture-date metadata on your device to suggest a memory date. Only the resulting date is kept; the raw metadata is not saved or sent with the memory. Images attached to memories are re-encoded before upload to remove EXIF data, including GPS and device metadata. Video-container metadata is not currently stripped and may remain in an uploaded video.
Voice input
If you use voice input, the recording and the active family's names, nicknames, and approximate ages are sent for transcription and cleanup. What happens to the recording depends on what you choose after it stops.
- Turn into text: the voice audio is processed temporarily and is not stored by Momora after transcription. The transcript is placed in the editor, and it becomes part of your journal only if you choose to save it.
- Keep the sound: the recording itself is saved as the memory. It is stored in the same private storage as photos and videos, together with a short AI-written note (which you can edit or replace) and a hidden transcript used only so you can search for the memory. A kept sound is deleted when you delete that memory, and with the family journal or account under the retention and deletion rules below.
Archive exports and memory-card sharing
If a family owner requests an archive export, we create a short-lived export job linked to that owner, assemble a structured manifest, and stream the available private journal files into a ZIP archive. The archive is downloaded temporarily to the app's cache and handed to the device's share sheet. Momora does not create a public archive URL or retain a completed copy of the ZIP after the share flow.
When a shareable memory is created or changed, Momora may create and privately cache a watermarked memory-card image so it is ready if an authorized family member chooses to share it. Creating a card can use the memory text or caption, date, photo or illustration, emotion color, and available tagged-member portraits. The cached card stays in private storage and is not given a public URL. If you choose a recipient or third-party app from the device's share sheet, that destination receives a copy and handles it under its own terms and privacy practices.
Notifications and technical information
If you enable notifications, we collect a push-notification token and your notification preferences. Notification providers may also receive technical routing information needed to deliver a notification. Momora's push messages use generic text and do not include memory text, comments, photos, or child details.
We and our infrastructure providers also process limited technical information needed to operate and secure the Service, such as IP addresses, request timestamps, identifiers, error information, and device or operating-system information supplied with network requests. For example, we temporarily log account and IP information to rate-limit family-invite attempts. Production logs are designed to use record identifiers and status codes rather than journal text, transcripts, audio, or child details.
In-app product analytics
Momora uses PostHog to understand onboarding, subscription, journaling, illustration, family-sharing, notification, and Looking Back usage. Analytics data can include a randomly generated pre-sign-in identifier, your pseudonymous Momora account identifier after sign-in, a family identifier, your household role and subscription-access category, membership and tagged-profile counts, app lifecycle events such as installation or opening, device and operating-system information, and event-specific counts, booleans, and closed categories. RevenueCat may also send subscription events to PostHog using the same pseudonymous account identifier.
Momora does not send memory text or captions, voice recordings or transcripts, child or family-member names, family names, email addresses, dates of birth, profile notes, comment text, invite codes, media files or URLs, illustration prompts, or child-linked emotion results to PostHog. We do not use PostHog session replay, interaction autocapture, or automatic screen tracking in the app.
Website information
Our website uses Google Tag Manager and related analytics technologies to understand visits and improve the site. These technologies may process information such as your browser or device type, IP address, pages viewed, referring page, and cookie or similar identifiers. You can limit cookies through your browser settings.
If you use our web account-deletion form, Google Forms processes the information you submit on our behalf. Please do not include memory text, child photos, or other journal content in the form.
2. How we use information
We use information to:
- Create, authenticate, and maintain your account.
- Provide private family journals, family roles, invitations, timelines, calendars, search, Looking Back packages, likes, comments, and notifications.
- Store and display the memories, family profiles, photos, videos, and other content you choose to provide.
- Transcribe voice input, suggest family-profile tags, and store the sounds you choose to keep.
- Analyze memory text or photos and generate optional character portraits and memory illustrations.
- Offer and administer subscriptions, purchases, restores, complimentary access, entitlement checks, and trial reminders.
- Create owner-requested archive exports and private, user-shareable memory cards.
- Measure product adoption, reliability, and feature use without sending private journal content to our analytics provider.
- Fetch titles for links you include in memory text.
- Respond to support, privacy, and account-deletion requests.
- Review and resolve in-app reports, apply personal hide settings, and respond to safety concerns.
- Protect the Service, prevent abuse, troubleshoot problems, and enforce our Terms, including by removing content or restricting accounts after review when appropriate.
- Comply with law and protect the rights, safety, and integrity of Momora, our users, and others.
Where applicable law requires a legal basis, we process information as necessary to provide the Service under our contract with you, based on your consent or choices, for our legitimate interests in operating and securing the Service, and to meet legal obligations.
3. AI processing
Momora uses OpenAI's API to provide AI features. Depending on the feature you choose, we may send OpenAI:
- A family-profile photo and relevant profile details to create a character portrait.
- Memory text, tagged profile details, and character portraits to analyze tone, apply a safety rewrite, and create an illustration.
- The first photo in a photo memory and its optional caption to classify its emotional tone. All-video memories are not analyzed this way.
- Voice audio and the active family's names, nicknames, and approximate ages (for example "3 years old", calculated on our server; the date of birth itself is not sent) to transcribe a recording, clean up the text, and write the short note for a kept sound. The note and hidden transcript of a kept sound are analyzed for emotional tone in the same way as memory text.
We send only the information needed for the requested feature. Pasted URLs are removed from AI prompts, and page titles fetched for links are not sent to OpenAI. OpenAI states that data submitted through its API is not used to train its models by default. OpenAI processes this information under its own privacy practices and business-data commitments.
AI output can be inaccurate, unexpected, or imperfect. You can save a memory as plain text or attach your own media without requesting an AI-generated memory illustration.
4. How information is shared
People in your family journal
Momora is private, but it can be shared with people you approve. Active members of a family journal can view its memories, family profiles, media, comments, and creator attribution. Owners and managers can add, edit, or delete journal content and manage other non-owner members. Viewers can browse and may like or comment. An owner or manager reviewing a redeemed invite can see the applicant's name and email address to verify their identity.
Only invite people you trust. Their access continues until they leave, are removed, the family journal is deleted, or their account is deleted.
Reports are private. Other members of the family journal, including its owner and managers, cannot read a report you submit. Only Momora-authorized operators can access reports as needed to review, resolve, and enforce them. A personal hide setting affects only what you see; it is not shared with the hidden member or other household members.
Sharing and exporting at your direction
An authorized family member can choose to send a watermarked memory card through the device's share sheet, and a family owner can export an archive to a destination they select. The recipient, app, or storage service you choose then receives a separate copy. Momora cannot control how that external copy is stored, used, forwarded, or made public, so share only with people and services you trust.
Service providers
We use service providers to operate Momora, including:
- Supabase for authentication, database hosting, and server-side functions.
- Cloudflare for private storage, illustration workflows, archive export streaming, and memory-card processing.
- OpenAI for transcription, text and image analysis, and image generation.
- RevenueCat, Apple, and Google for subscription offerings, purchases, restores, receipts, entitlement status, and subscription management.
- PostHog for limited in-app product analytics and subscription-event measurement.
- Expo, Apple Push Notification service, and Firebase Cloud Messaging for push-notification delivery.
- Bento for transactional email, including authentication, family-invite approval, and trial-ending messages.
- Google Tag Manager and Google Forms for website analytics and the web account-deletion request form.
These providers receive only the information reasonably needed to perform their services for us and process it under their own terms and privacy commitments.
When Momora fetches a title for a link in a memory, the destination website receives a server request and may receive normal request information such as an IP address and user-agent string. Momora does not send your full memory to that website.
Legal, safety, and business transfers
We may disclose information when reasonably necessary to comply with law or legal process, enforce our agreements, investigate abuse, or protect rights, property, or safety. Information may also transfer as part of a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, subject to this Policy and applicable law.
We do not sell personal information. We do not use private journal content for targeted advertising.
5. Storage and security
Family-journal records are protected by access controls that check active family membership and role. Photos, videos, kept sound recordings, portraits, illustrations, and cached memory cards are stored in private object storage and displayed through authenticated requests or time-limited signed links. Export jobs are owner-scoped and short-lived, and completed archives are streamed rather than placed at a public URL. Information is encrypted in transit. Service credentials for storage, billing, export, and AI providers are kept on the server rather than in the mobile app.
No security method is perfect. You are responsible for protecting access to your email account and device and for inviting only trusted people to a family journal.
6. Retention and deletion
We generally retain information while your account or a family journal you belong to remains active and as needed to provide, measure, and secure the Service. Reports may be retained as needed for safety, enforcement, dispute resolution, or legal obligations, and are deleted or de-identified when no longer needed for those purposes. Product analytics is retained only as long as reasonably needed for product measurement, security, and legal obligations, then deleted or de-identified. You can delete individual memories and family profiles in the app if your family role permits it. Deleted journal content is not recoverable through the app.
Archive export jobs expire after one hour. Momora does not persist the completed ZIP on its servers, and the app deletes its temporary cached copy after the share flow. Cached memory cards are invalidated when their source content changes and are deleted with the related memory or family journal.
You can schedule account deletion in the app under Settings → Delete account, or request it through our account-deletion page if you cannot access the app. Account deletion has a 15-day grace period. During that period, you can cancel deletion from Settings.
- If you own a family journal: requesting account deletion immediately hides each family journal you own from other members. If you cancel within 15 days, the journals are restored. After the grace period, your account, subscription-access records tied to it, each family journal you own, its memories, family profiles, memberships, invites, likes, comments, photos, videos, kept sound recordings, portraits, illustrations, cached memory cards, Looking Back packages and view state, reports, and personal hide settings are permanently deleted.
- If you do not own a family journal: your account profile, authentication record, likes, comments, and personal hide settings are deleted after the grace period. Memories or family profiles you added to a journal owned by someone else may remain as part of that family's shared journal, but your account attribution is removed. For reports you submitted, the optional note is deleted and the minimum report metadata is de-identified where it must be retained for safety, enforcement, dispute resolution, or legal obligations. The family owner or a manager can delete your remaining content from the journal.
We may retain limited records when required by law, to resolve disputes, or to protect the Service from fraud and abuse. Apple, Google, RevenueCat, and other providers may retain transaction, receipt, security, or accounting records under their own legal obligations and retention schedules. Infrastructure providers may retain encrypted backups or security logs for a limited period under their normal retention schedules. Voice audio used only for dictation is not retained by Momora after transcription. A recording you chose to keep as a memory is retained as part of that memory until the memory, its family journal, or the owning account is deleted.
7. Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a copy of personal information we hold about you. You may also have the right to withdraw consent and to complain to a local data-protection authority. These rights can be subject to legal exceptions.
You can edit many profile and journal fields directly in the app, control notification preferences in Settings, and revoke camera, photo-library, microphone, or notification permissions in your device settings. You can report supported content or conduct in the app. A reported item is obscured only for you, and you can choose Show anyway; submitting a report does not automatically delete the item for the household. You can also hide another active household member's authored memories, comments, and related notifications from your own view, and undo that choice in the app.
For support or if you cannot use the in-app reporting route, email hello@usemomora.com. To make another privacy request, including a request concerning product analytics or billing records under our control, use the same address. We may need to verify that the request comes from the account holder.
8. Children's privacy
Momora is intended for parents, guardians, and other adults. It is not directed to children, and children may not create accounts. By adding information about a child, you confirm that you are the child's parent or legal guardian, or otherwise have the authority and appropriate permission to provide and allow us to process that information.
If you believe a child's information was provided without appropriate authority, contact us at hello@usemomora.com.
9. International data transfers
Our providers may process information in the United States and other countries. Where required, we use appropriate legal mechanisms for international transfers. Privacy protections and government-access rules may differ from those in your country.
10. Changes to this Policy
We may update this Policy as the Service changes. We will post the updated Policy and revise the effective date. If a change materially affects how we use personal information, we will provide additional notice when required by law.
11. Contact us
How do you turn this on LLC is responsible for Momora. For privacy questions or requests, contact: