MOMENTO Türkçe

Privacy Policy

Last updated: 28 September 2026 · Includes the disclosure required under Turkey's KVKK.

The short version: Momento has no advertising, no analytics and no tracking. No tracking tool of any kind (Firebase, the Facebook SDK, Sentry, an ad network) is present in the app. We do not sell your data and we do not use it for marketing. Your photographs are visible only to the people at the event you joined, and they are permanently deleted from the server 60 days after the event ends or the album opens, whichever is later.

1. Data controller

The data controller operating the Momento app is Mehmet Seha Tanrıkulu, acting as an individual. Momento is not a company; it is a product run by one person.

2. How Momento works

Momento is a digital disposable camera for events. One person (the host) creates an event; guests join with a QR code or a link and take a limited number of frames. No photograph taken is shown to anybody, the host included, until the reveal time that was set.

The host sets that reveal time, choosing one of three options while creating the event:

So "nobody can see them until the reveal time" holds in all three modes; it is just that with "during the event" that time is the event's own beginning, and the frames are visible straight away. Which mode is in force is stated in the app on the step where the event is created, and everyone who joins sees the remaining time on the album screen.

This is not a feature of the privacy policy; it is the product itself. The lock is enforced on the server, not in the client. Before the reveal time the server hands a photograph's file to nobody: not to the host, not to the person who took it, and not to somebody who knows its address either. The rule does not live in the app's code; it lives in the database's access policies, so a bug in the app cannot show a photograph to somebody who should not see it.

3. The data we process

3.1 Users with an account (hosts)

DataWhere fromWhat for
Name / display name Sign in with Apple, or Sign in with Google Showing who the host is on their events
Email address Apple or Google Recognising your account. If you choose “Hide My Email” with Sign in with Apple, only the relay address Apple generates reaches us; we never see your real address.
Link to a profile picture Google (if there is one) Display in the interface

3.2 Guests

A guest does not need an account. For a guest who joins over the web we keep only the name they typed and an anonymous session identifier. No email address, no phone number, and no access to contacts is requested.

3.3 Photographs

No location data is taken from photographs. The app does not ask for location permission and does not write location data into frames.

3.4 Purchases

Payment happens entirely through Apple. We never see and never store your card details. All that reaches us is which package was bought; we use the RevenueCat service to verify it.

3.5 Data we do not process

4. Who can see the photographs

5. Service providers

Only the providers below process your data on our behalf. No data is transferred to any of them for marketing purposes, and none of them may use it for their own ends.

ProviderWhat for
SupabaseDatabase, authentication and photo storage
AppleSign in with Apple, in-app purchases
GoogleSign in with Google (only if you choose that method)
RevenueCatPurchase verification
VercelHosting for capturemomento.com and the web invitation page

These providers' servers may be located outside Turkey; data is transferred abroad so that the service can be provided (KVKK art. 9).

Notifications are absent from the list because they do not pass through a provider: the reveal reminder is set against your own device's clock. We send no notifications from a server, and we hold no device identifier for doing so.

6. Retention and deletion

7. Objectionable content and moderation

Any participant can report a frame in the album. A reported frame is shown blurred even to the person deciding on it. The decision belongs to the event's host: they can delete the frame or leave it. A host can also remove and block a participant, in which case all of that person's frames are deleted.

Who filed a report is never shown to anybody, the host included.

8. Your rights under the KVKK

Under article 11 of Turkey's Personal Data Protection Law No. 6698 (KVKK) you have the right to learn whether your personal data is being processed; to request information about it if it is; to learn the purpose of the processing; to know the third parties, in Turkey or abroad, to whom it has been transferred; to have it corrected if it is incomplete or wrong; to request its erasure or destruction; to request that these actions be communicated to the third parties the data was transferred to; and to claim compensation if you suffer loss because of unlawful processing.

You can send your request to support@capturemomento.com; it is answered within 30 days at the latest.

9. Children

Momento is not directed at children under 13 and we do not knowingly collect data from them. If we learn that we have collected such data, we delete it.

10. Security

All connections are encrypted with TLS. Access to photographs, the reveal lock and participant control are all enforced at the database level: a bug in the app's code cannot show a photograph to somebody who should not see it.

11. Changes

If this text changes, the date at the top is updated. For a significant change you are told inside the app.