Privacy Policy
Moment Snap · Last updated: July 5, 2026 · Effective immediately for all users
This Privacy Policy explains how the developer of Moment Snap ("Moment Snap", "we", "us", or "our") collects, uses, stores, shares and protects personal data when you use the Moment Snap iOS application (the "App"). Moment Snap is a personal photo diary: by its nature it stores content that is deeply personal — your photographs, diary entries, drawings, moods and signature. We treat that responsibility seriously. This Policy is designed to satisfy the transparency requirements of the EU/UK General Data Protection Regulation ("GDPR"), the Turkish Personal Data Protection Law No. 6698 ("KVKK"), the California Consumer Privacy Act as amended ("CCPA/CPRA"), and Apple's App Store requirements.
Data controller: the individual developer of Moment Snap, reachable at fthhdmr@gmail.com (the "Controller"). If the App is later operated by a legal entity, that entity will be named here.
1. Data we collect and why
| Category | Data | Purpose | Legal basis (GDPR) |
|---|---|---|---|
| Account data | Display name you enter, e-mail address, sign-in provider (Apple or Google), a unique user ID issued by Firebase Authentication | Creating and securing your account; syncing your diary across devices | Art. 6(1)(b) — performance of a contract |
| Diary content | Photos you capture or select, diary notes, finger drawings, finger signature, selected frame/filter, day mood, Spotify track links you attach, entry dates and timestamps | Providing the core service: storing and displaying your personal diary | Art. 6(1)(b); where content reveals special categories (e.g. health, beliefs) — your explicit action of saving it, Art. 9(2)(a) |
| Notification data | Apple push token / Firebase Cloud Messaging token; your notification preference | Sending the daily reminder you opt into | Art. 6(1)(a) — consent (revocable at any time) |
| Purchase data | Subscription status, product identifier, anonymised transaction identifiers processed by Apple and RevenueCat | Unlocking premium features; managing trials and renewals. We never receive your payment card details — Apple processes all payments. | Art. 6(1)(b) |
| Usage & diagnostics | Aggregated app-interaction events, crash logs, device model, OS version, app version, coarse locale (via Firebase Analytics/Crash reporting) | Fixing crashes, improving the App | Art. 6(1)(f) — legitimate interest in a functioning product |
We do not collect your precise location, contacts, browsing history, or advertising identifiers, and we do not perform cross-app tracking as defined by Apple's App Tracking Transparency framework.
2. What we never do
- We never sell your personal data, and never have. ("Sale" and "sharing" as defined by the CCPA/CPRA do not occur.)
- We show no advertising and share no data with advertising networks or data brokers.
- Your photos, notes, drawings, moods and signatures are never used to train AI models, never analysed for marketing, and never disclosed to third parties except the processors listed in Section 3 acting on our documented instructions.
- Nobody at Moment Snap browses your diary. Access to production data is restricted, logged, and used only where strictly necessary to resolve a support request you initiate or to comply with law.
3. Processors (sub-processors) we rely on
We use a small set of established service providers, each bound by their own data-processing terms:
- Google Firebase (Google Ireland Ltd. / Google LLC) — authentication, Cloud Firestore database (account data and diary text/metadata), Cloud Messaging (push), analytics and crash reporting. Firebase privacy documentation.
- Cloudinary Ltd. — storage and delivery of your photos, drawings and signature images. Media is stored in a folder namespaced to your user ID. Cloudinary privacy policy.
- RevenueCat, Inc. — subscription entitlement management. Receives your app user ID and Apple transaction data; never your diary content. RevenueCat privacy policy.
- Apple Inc. — sign-in with Apple, payment processing, push delivery.
- Spotify AB — only if you attach a song: we call Spotify's public oEmbed endpoint with the track link you provide to fetch the title and cover art. No account data or diary content is transmitted to Spotify. Opening a song takes you to Spotify, whose own terms then apply.
4. International transfers
Our processors store data on servers that may be located in the United States and the European Union. Where personal data is transferred outside the EEA, the UK or Türkiye, the transfer is protected by appropriate safeguards — the EU Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework certifications of the providers above, together with the safeguards required by KVKK Art. 9.
5. Retention and deletion
- Your diary content and account data are retained for as long as your account exists — that is the product: a permanent diary.
- Account deletion is built into the App: Profile → Delete account. This permanently deletes your Firestore records (diary entries, profile) and your media stored with Cloudinary, and deletes your authentication account. This action is irreversible; there is no recovery period and no undo.
- Residual copies in encrypted backups of our processors are purged within their standard backup-rotation windows (typically ≤ 30 days).
- You may also request deletion, or a machine-readable export of your data, by e-mail; we act on verified requests within 30 days (KVKK: without undue delay and at the latest within 30 days; GDPR: within one month).
6. Security
- All data is encrypted in transit (TLS 1.2+) and at rest on Google and Cloudinary infrastructure.
- Database access is governed by Firebase Security Rules: only your authenticated account can read or write your own records; past days are additionally write-locked server-side.
- Media files are stored under unguessable, user-scoped identifiers.
- No security measure is absolute. If we become aware of a personal-data breach likely to result in a risk to you, we will notify you and the competent supervisory authority as required by GDPR Art. 33–34 and KVKK Art. 12.
7. Your rights
Depending on your jurisdiction (GDPR Arts. 15–22, KVKK Art. 11, CCPA/CPRA), you have the right to:
- Access the personal data we hold about you and learn how it is processed;
- Rectify inaccurate data (your name can be edited in the App);
- Erase your data ("right to be forgotten") — available directly in-app;
- Export / portability — receive your diary data in a structured, machine-readable format;
- Restrict or object to processing based on legitimate interests (e.g. analytics);
- Withdraw consent at any time (e.g. turn off notifications) without affecting prior processing;
- Non-discrimination for exercising any of these rights (CCPA);
- Complain to a supervisory authority — e.g. your local EU Data Protection Authority, the UK ICO, or the Turkish KVKK Board (Kişisel Verileri Koruma Kurumu).
To exercise any right, use the in-app controls or e-mail fthhdmr@gmail.com. We will verify your identity (e.g. via your registered e-mail) before acting.
8. Children
Moment Snap is not directed at children under 13 (or the higher age of digital consent in your country, up to 16 in parts of the EEA). We do not knowingly collect personal data from children below that age. If you believe a child has created an account, contact us and we will delete it promptly.
9. Notifications
Daily reminders are optional. They are scheduled locally on your device and, where enabled, via Apple/Firebase push. You can disable them anytime in Profile → Notifications or in iOS Settings; disabling stops the processing of your push token for reminders.
10. Changes to this Policy
We may update this Policy as the App evolves or the law changes. Material changes will be announced in the App before they take effect, and the "Last updated" date above will change. Continued use after the effective date constitutes acceptance where permitted by law; where consent is required, we will ask for it.
11. Contact
Privacy questions, requests and complaints: fthhdmr@gmail.com. We aim to respond within 7 days and resolve requests within the statutory deadlines described above.
Moment Snap · Terms of Use