Privacy Policy
Last updated: 28 September 2026 · Includes the disclosure required under Turkey's KVKK.
The short version: Momento has no advertising, no analytics and no tracking. No tracking tool of any kind (Firebase, the Facebook SDK, Sentry, an ad network) is present in the app. We do not sell your data and we do not use it for marketing. Your photographs are visible only to the people at the event you joined, and they are permanently deleted from the server 60 days after the event ends or the album opens, whichever is later.
1. Data controller
The data controller operating the Momento app is Mehmet Seha Tanrıkulu, acting as an individual. Momento is not a company; it is a product run by one person.
- Data controller: Mehmet Seha Tanrıkulu (an individual)
- Contact: support@capturemomento.com
- Web: capturemomento.com
2. How Momento works
Momento is a digital disposable camera for events. One person (the host) creates an event; guests join with a QR code or a link and take a limited number of frames. No photograph taken is shown to anybody, the host included, until the reveal time that was set.
The host sets that reveal time, choosing one of three options while creating the event:
- During the event: the album is open from the start; a frame is visible to the event's participants the moment it is taken. There is no wait in this mode.
- When it ends: frames stay hidden for the whole event and all of them open at the closing time.
- A while after: they open once a delay the host chooses has passed from the end.
So "nobody can see them until the reveal time" holds in all three modes; it is just that with "during the event" that time is the event's own beginning, and the frames are visible straight away. Which mode is in force is stated in the app on the step where the event is created, and everyone who joins sees the remaining time on the album screen.
This is not a feature of the privacy policy; it is the product itself. The lock is enforced on the server, not in the client. Before the reveal time the server hands a photograph's file to nobody: not to the host, not to the person who took it, and not to somebody who knows its address either. The rule does not live in the app's code; it lives in the database's access policies, so a bug in the app cannot show a photograph to somebody who should not see it.
3. The data we process
3.1 Users with an account (hosts)
| Data | Where from | What for |
|---|---|---|
| Name / display name | Sign in with Apple, or Sign in with Google | Showing who the host is on their events |
| Email address | Apple or Google | Recognising your account. If you choose “Hide My Email” with Sign in with Apple, only the relay address Apple generates reaches us; we never see your real address. |
| Link to a profile picture | Google (if there is one) | Display in the interface |
3.2 Guests
A guest does not need an account. For a guest who joins over the web we keep only the name they typed and an anonymous session identifier. No email address, no phone number, and no access to contacts is requested.
3.3 Photographs
- The frame taken: the filtered version and the untouched original.
- A blurred preview (blurhash), a very small summary derived from the frame's colour and shape, from which the original cannot be recovered. It is used to draw the “developing” view in the album before the reveal.
- The time it was taken, its dimensions, and the date stamp on the frame.
No location data is taken from photographs. The app does not ask for location permission and does not write location data into frames.
3.4 Purchases
Payment happens entirely through Apple. We never see and never store your card details. All that reaches us is which package was bought; we use the RevenueCat service to verify it.
3.5 Data we do not process
- Location
- Contacts, calendar, health data
- The advertising identifier (IDFA). We show no ads and ask for no tracking permission
- Usage analytics, heat maps, session recording
- Cookies (on the web, browser storage is used only to keep your session going; there are no tracking cookies)
4. Who can see the photographs
- Before the reveal time: nobody. Including the person who took the frame, and the host.
- After the reveal: only the participants of that same event.
- If the host chose "During the event", the reveal time is the event's own beginning: there is no wait, and frames are visible to participants as they are taken. The two lines above still hold; there is simply no “before” left.
- Nobody outside the event can see the album, not even with the link in hand. Access is enforced by row-level security rules on the server.
5. Service providers
Only the providers below process your data on our behalf. No data is transferred to any of them for marketing purposes, and none of them may use it for their own ends.
| Provider | What for |
|---|---|
| Supabase | Database, authentication and photo storage |
| Apple | Sign in with Apple, in-app purchases |
| Sign in with Google (only if you choose that method) | |
| RevenueCat | Purchase verification |
| Vercel | Hosting for capturemomento.com and the web invitation page |
These providers' servers may be located outside Turkey; data is transferred abroad so that the service can be provided (KVKK art. 9).
Notifications are absent from the list because they do not pass through a provider: the reveal reminder is set against your own device's clock. We send no notifications from a server, and we hold no device identifier for doing so.
6. Retention and deletion
- Events and photographs: permanently and automatically deleted 60 days after the event ends or the album opens, whichever is later. Both dates count for a reason: in “during the event” mode the album opens as the event begins, so counting only from the reveal would delete the frames before the party was over. The period cannot be extended; the deletion is carried out by a scheduled job on the server.
- If you delete an event yourself, every record belonging to it and every participant record are deleted at the same moment; access to the photographs ends there and then, because the access rule is built on those records. The stored files are removed by the clean-up job that follows.
- If you delete your account, every event you host, every photograph record in those events, and your account details are deleted; for the files the sentence above applies. Account deletion is available inside the app, under Settings; you do not need to write to us for it.
7. Objectionable content and moderation
Any participant can report a frame in the album. A reported frame is shown blurred even to the person deciding on it. The decision belongs to the event's host: they can delete the frame or leave it. A host can also remove and block a participant, in which case all of that person's frames are deleted.
Who filed a report is never shown to anybody, the host included.
8. Your rights under the KVKK
Under article 11 of Turkey's Personal Data Protection Law No. 6698 (KVKK) you have the right to learn whether your personal data is being processed; to request information about it if it is; to learn the purpose of the processing; to know the third parties, in Turkey or abroad, to whom it has been transferred; to have it corrected if it is incomplete or wrong; to request its erasure or destruction; to request that these actions be communicated to the third parties the data was transferred to; and to claim compensation if you suffer loss because of unlawful processing.
You can send your request to support@capturemomento.com; it is answered within 30 days at the latest.
9. Children
Momento is not directed at children under 13 and we do not knowingly collect data from them. If we learn that we have collected such data, we delete it.
10. Security
All connections are encrypted with TLS. Access to photographs, the reveal lock and participant control are all enforced at the database level: a bug in the app's code cannot show a photograph to somebody who should not see it.
11. Changes
If this text changes, the date at the top is updated. For a significant change you are told inside the app.