Privacy Policy
Last updated: August 26, 2026
Who we are
Momento is operated by M/S JYOTI TRADERS (HANUMAT KRIPA) (Jyoti Traders). The Service is available at https://momento.camera. For privacy, legal, or support requests contact admin@momento.camera.
Momento is a digital product made with love by Jyoti Traders.
Roles: When you host an event, you decide who is invited and what is collected — you are typically the data controller for guest photos in your event. Momento processes that data on your behalf as a processor to provide the Service. For your host account, Momento is the controller.
Overview
This policy covers https://momento.camera, the Momento web app, and the Momento mobile app (together, “Momento,” “we,” or the “Service”). We collect only what we need to run the Service. We do not sell your personal information or use it for advertising. Contractual terms, including limitations of liability and dispute procedures, are in our Terms of Service.
What we collect
- Hosts: Email address and name (Supabase Auth). Google account info if you choose Google sign-in.
- Guests: A nickname you choose when joining. A guest token stored on your device so you can upload and manage your photos. No email or account required.
- Photos you upload: Images guests and hosts upload to an event.
- Generated recaps: AI recap videos created for your event (not guest-uploaded video files).
- Event metadata: Event name, type, dates, reveal settings, and host configuration.
- Payments: Purchase records processed by Razorpay. We do not store card numbers.
- Device info: IP address for rate limiting and abuse prevention only. We do not use analytics cookies or ad tracking. We use privacy-first, cookieless product analytics (PostHog) for pageviews and feature tests. Session replay is enabled only on our marketing site and host dashboard — not on guest camera, gallery, join, or other event guest pages.
- Find me (optional): Where the host enables it, Momento may analyze faces in event photos and store event-scoped face descriptors to help guests find their own photos in that event. This can include people who have not joined as guests. A guest's reference selfie is used only for the requested match and is not retained after the search completes; matching runs against Momento's internal event-only face index, not Google Gemini. Face descriptors are used only for event photo search, not for advertising or sale, and are deleted when the source photo is deleted or when you use “Remove me from this event.”
- Upload authority (Find me events): Before the first upload, Momento records the uploader's confirmation that they have the right to upload and have provided or obtained any notice or permission required for people shown. The record includes the actor, time, declaration version, and upload flow.
How Find me face descriptors are stored
Face descriptors are derived from upload thumbnails, tied to one event and one photo, and used only for Find me in that event. They are not used for advertising, sale, or cross-event identification. Searchable descriptors are removed when the source photo is deleted, when the event is deleted, when you use “Remove me from this event,” or when we honour a valid removal request under this policy.
AI photo processing
Some optional features send image previews or image data from event uploads to Google Gemini for the specific feature requested or enabled: host-triggered recap curation and awards, photo-challenge verification, and optional upload moderation. Find me does not use Google Gemini. Momento uses Google Gemini API services under Google's applicable terms for those features. See Google's Privacy Policy and Gemini API Terms. We keep only the resulting score, status, reason, or selected item needed to run the feature. Do not use these features if you do not want the relevant event images processed this way.
Legal bases (EEA/UK)
- Contract: Providing the Service you request (host account, event, uploads, recap).
- Legitimate interests: Security, fraud prevention, abuse detection, and improving reliability — balanced against your rights.
- Consent: Where required (e.g. optional features). You may withdraw consent by stopping use or deleting data.
- Legal obligation: Tax, accounting, and lawful requests.
We do not use automated decision-making that produces legal or similarly significant effects.
How we use data
- To provide the Service: event creation, photo uploads, gallery, recap generation, awards, and sharing.
- To authenticate hosts and manage event ownership.
- To process payments and prevent fraud.
- To enforce rate limits and protect the Service from abuse.
- To improve the marketing site and host experience via anonymized session replays (never on guest event pages).
- We do not sell your data. We do not serve ads. We do not share your information with third parties for marketing.
Photo access & storage security
- Photos belong to the person who took them. Uploading grants Momento a license to store, display, and include photos in the event gallery and AI recap.
- Event hosts can view, moderate, and delete photos in their events. Guests can delete their own uploads with their guest token.
- Photos are stored on Cloudflare R2 (or legacy Supabase Storage), encrypted in transit (HTTPS/TLS) and at rest.
- Gallery APIs return time-limited signed URLs — direct storage links expire and are not indexed publicly.
- Events are private by default, not listed in search engines, and only accessible via QR code, share link, or event code.
Third-party processors
- Supabase — database and authentication
- Cloudflare — event photo and video storage (R2)
- Vercel — web hosting and APIs
- Razorpay — payment processing (paid plans)
- Resend — transactional email (receipts, alerts, support)
- Google — optional OAuth sign-in; Gemini AI for recap, awards, challenge verify, and upload moderation
- PostHog — cookieless analytics and scoped session replay (marketing/host only)
These providers process data on our behalf under their own terms and security standards. See our DPA for the full subprocessor list. We disclose only the data needed for the relevant feature.
Data retention
- Event data is kept while the event exists. Hosts can delete an event at any time, which permanently removes photos, guests, recaps, and related records.
- Photo retention periods — we aim to retain event photos, videos, and recaps for approximately 6 months (free plan) or 1 year (paid plans) after the event end date. Events created under an earlier paid window keep that original period. Photographer-imported photos (bulk import add-on) are retained for approximately 30 days after the event end date. These are operational targets, not contractual guarantees — see our Terms of Service for full details. We recommend downloading important photos promptly.
- Deleted accounts: personal data removed within 30 days of confirmed deletion (hosted events are deleted immediately).
- Purchase records may be kept up to 7 years for tax and legal compliance.
- Photos you uploaded to someone else's event may remain in that event; your attribution can be anonymized on account deletion.
- Find me removal: A person can ask us to remove their face data from an event, whether or not they are a Momento user. “Remove me from this event” deletes searchable face descriptors for that person in that event and turns off Find me for that guest.
Your choices & rights
- Delete photos: Guests delete their own uploads from the gallery (guest token required). Deleted photos and related face descriptors cannot be restored through Momento.
- Delete events: Hosts delete entire events from host settings. This permanently removes hosted photos, recaps, and related records from active Service storage.
- Delete account: Hosts use Dashboard → Delete account, or mobile Settings → Delete Account. Type DELETE to confirm.
- Access / export / correction: Download JSON from Dashboard → Download your data, or email admin@momento.camera — we aim to respond within 48 hours.
- People shown in event photos: You do not need an account to request removal of a photo or Find me face data. Email admin@momento.camera with the event link, photo link or screenshot, and enough information for us to verify and locate the content. We may ask for limited information to prevent fraudulent removal requests.
Regional rights
- India (DPDP Act): Access, correction, and erasure. Grievance officer: M/S JYOTI TRADERS (HANUMAT KRIPA) (India). Email admin@momento.camera — we respond to privacy grievances within 30 days.
- California (CCPA/CPRA): Right to know, delete, and correct. We do not sell or share personal information for cross-context behavioral advertising. Submit requests to admin@momento.camera.
- EEA/UK (GDPR): Access, rectification, erasure, restriction, portability, and objection where applicable. Lodge a complaint with your supervisory authority. Contact admin@momento.camera; we will appoint an EU/UK representative where required by law.
- Brazil (LGPD): Confirmation, access, correction, anonymization, portability, and deletion — admin@momento.camera.
- Canada (PIPEDA): Access and correction — admin@momento.camera.
- Australia: Access and correction under the Privacy Act — admin@momento.camera.
Grievance redressal (India)
Grievance officer: M/S JYOTI TRADERS (HANUMAT KRIPA) (India). Email admin@momento.camera — we respond to privacy grievances within 30 days.
For access, correction, or deletion requests that are not resolved through the app, email admin@momento.camera with your event link or account email.
Photos of other people
Uploading a photo that includes other people may affect their privacy. Hosts and uploaders must have a lawful basis to share those images and, in Find me events, must provide or obtain the notice and permission required for the people shown. If you appear in a photo and object, contact admin@momento.camera or ask the event host to remove it. See our Copyright & Takedown policy.
Children
Momento is not directed at children under 13 (or under 16 in the EEA/UK without parental consent). Under India's DPDP Act, a child is anyone under 18. Find me events require guests to confirm they are at least 18 before joining. We do not knowingly collect personal information from children below these ages without appropriate consent. Contact admin@momento.camera if you believe a child has provided data without consent. Event hosts must not invite anyone under 18 to join or upload as a Momento user in Find me events, and must obtain appropriate permission for minors who appear in photos.
Security
We use reasonable technical and organisational safeguards, including encryption in transit, private storage, time-limited signed URLs, role-based access, rate limiting, and image validation. If a security incident affects your personal data, we will notify you and regulators when legally required.
International transfers
Data may be processed in India, the United States, and other countries where our processors operate. We use appropriate safeguards where required by law.
Host and uploader obligations
If you host an event or upload photos, you — not Momento — are primarily responsible for telling attendees what will happen to their images, obtaining any permission required by law (including where Find me is enabled), complying with venue or employer rules, and handling removal requests from people shown in photos. Momento records versioned acknowledgments to support audit where the product requires them.
Changes
We will update this page when the policy changes. Continued use after changes take effect means you accept the updated policy.
Contact
Privacy questions, access, or deletion requests: admin@momento.camera
Momento is operated by M/S JYOTI TRADERS (HANUMAT KRIPA) (Jyoti Traders).
Momento is a digital product made with love by Jyoti Traders.
Grievance officer: M/S JYOTI TRADERS (HANUMAT KRIPA) (India). Email admin@momento.camera — we respond to privacy grievances within 30 days.
General contact: admin@momento.camera