Draft for legal review. This page is implemented for review and must be approved before public release.
Privacy

Privacy Policy

Draft updated September 7, 2026

1. Who operates Momento

Momento is operated by Xier Gabriel Mangunay in the Philippines. This notice describes the information handled by the Momento mobile app, vendor web portal, and public document and inquiry pages.

2. Information Momento handles

Account and profile information may include your email address, authentication provider identifier, full name, business name, vendor category, phone number, business address, tax details you choose to add, and profile image. Business records may include client names and contact details, events and schedules, locations, pricing, payment records, quotations, contracts, signatures, invoices, tasks, notes, intake form responses, notification preferences, and document-sharing links. Momento does not receive payment-card numbers for App Store or Google Play purchases. Technical information may include push notification tokens, device platform and name, app version, IP address and browser user agent on public form, quotation, or contract interactions, and authentication cookies in the web portal. Optional submissions may include chat screenshots sent for AI extraction, feedback messages and attached screenshots, and photos submitted through public intake forms.

3. Device calendar and permissions

If you grant calendar permission and select calendars, the app reads calendar events on your device so it can display them and help you spot conflicts. A device event is copied to Momento’s hosted database only when you choose to import it. Hiding a device event in Momento does not delete it from your device calendar. Notification and photo-library permissions are requested only for their related features. You can change device permissions in system settings.

4. How the information is used

Momento uses this information to authenticate you; provide event, client, contract, quotation, invoice, payment, calendar, notification, and inquiry features; generate documents; maintain subscription access; respond to support and feedback; detect abuse; and diagnose and improve the service.

5. AI-assisted import

When you choose an AI-assisted feature, the screenshot or selected device-calendar event details needed for that request are sent through Momento’s authenticated backend to Google’s Gemini API. Gemini returns suggested event fields or classifications for you to review before saving. Do not submit unrelated private conversations, identification numbers, banking details, or other information that is unnecessary for the event. Google processes the submitted content under its own service terms and privacy commitments.

6. Service providers and sharing

Momento uses service providers to operate the product, including Supabase for authentication, database, server functions, and file storage; RevenueCat for subscription status; Apple and Google for app distribution, authentication where selected, and store billing; Google Gemini for optional screenshot analysis; Expo for push notification delivery; and the web hosting provider for the vendor portal. Momento also discloses information when you direct it to do so, such as when you share a contract, quotation, invoice, or intake link; when required to respond to lawful process; or as part of a business transfer subject to applicable obligations. Momento does not use customer data for third-party advertising.

7. Public links

Contracts, quotations, invoices, and intake forms can be shared through bearer links. A person who has a valid link can access the information presented on that page without creating a Momento account and may be able to sign or respond. Treat these links as sensitive and send them only to intended recipients. Public pages do not provide access to the vendor’s other records.

8. Storage, security, and international processing

Momento relies on HTTPS/TLS in transit, Supabase authentication, private storage where configured, database row-level access policies, and server-side checks for sensitive public actions. No internet service can guarantee absolute security. Cloud providers may process information outside the Philippines. Their infrastructure, contractual terms, and retention practices apply to the services they provide to Momento.

9. Retention and account deletion

Account and business data is kept while needed to provide the service and operate its features. You can request in-app deletion from Settings. The current deletion process removes the authentication account, vendor-linked database records, and identified vendor storage objects from the live Momento project. If a cleanup step fails, deletion stops so it can be retried instead of reporting partial cleanup as complete. Some information may remain temporarily in provider backups, security logs, or records that must be retained for legitimate operational or legal reasons under the relevant provider or legal retention period. If you cannot access the app, contact support from the email address associated with the account.

10. Your choices and requests

You can edit many profile and business fields in the app, change notification and device permissions, cancel a paid subscription through the store that sold it, and request access, correction, deletion, or other assistance by contacting support. Available privacy rights depend on applicable law and the circumstances of the request.

11. Age and policy changes

Momento is intended for business users who are at least 18 years old. This notice may change as the product and its providers change. The date above will be updated when a revised notice is prepared.

12. Contact

Privacy and data requests: mangunaygabriel@gmail.com Operator: Xier Gabriel Mangunay Location: Philippines