Privacy · MomentLog
Privacy Policy
MomentLog starts with local recording. Data is sent to our services only when you choose to use an account, AI analysis, or Personal Premium cloud video or Team sharing.
1. Information we process
On-device journals
Videos, audio, thumbnails, recording time, projects, mission day, camera settings, and HUD settings are stored on your device by default. When you are signed out, journals are not uploaded to MomentLog services. An exported video is written to your system photo library only when you choose Save to Photos.
Account and settings
When you sign in, we process your email address, identifiers from your sign-in provider, MomentLog user ID, session information, and settings such as projects, time zone, Recap time, subscription status, and AI allowance usage. Apple or Google may provide your name and email. If you use Hide My Email, we receive only the relay address provided by Apple.
Location and weather
With your permission, the app uses an approximate location while recording to obtain local weather and a readable location label, then saves that moment's context with the journal. MomentLog does not continuously track your location.
2. How AI analysis works
AI analysis is optional. MomentLog sends audio from journals you choose to analyze, plus necessary context such as recording time, duration, project, mission day, location label, and time zone, to Alibaba Cloud DashScope / Qwen, a third-party AI provider, for transcription, titles, summaries, and Recaps. AI analysis does not upload video frames.
Inputs for titles and summaries also include transcript text, project names, descriptions, hotwords, and your summary style settings. Recaps process existing titles and summaries with relevant time and project context; Team Recaps also process member display names and Team Recap Style to summarize shared journals. Do not include information about others that you are not entitled to provide in this content or these settings.
By choosing a sign-in method and continuing, you confirm that you have read and agree to this Privacy Policy and the AI data processing described above. Automatic AI is on by default. If you previously turned it off, that choice is preserved. While it is on, saving an eligible new journal automatically submits its audio for AI analysis. You can turn it off at any time in Settings to stop future automatic submissions. Manual AI submits a journal only when you choose to analyze it. A task submitted before Automatic AI is turned off may finish; you can delete the related journal or account to delete results retained within MomentLog's control.
MomentLog deletes temporary audio as soon as practicable after transcription results are obtained. Remaining temporary files are cleaned up by a scheduled task once the related task has been completed or terminally failed for 3 days; files without a related task are cleaned up once 3 days have passed since creation or update. Files for tasks still being processed may be retained longer. Transcripts, titles, summaries, Recaps, task status, and allowance records remain in your account until you delete the related journal or account.
The temporary-file cleanup rules above apply only to storage controlled by MomentLog and do not define the retention period of the third-party AI provider. Alibaba Cloud processes and retains invocation data under its privacy notice, applicable service terms, and legal obligations; its terms prohibit using customer data for model training without authorization. MomentLog does not submit your journals for model training and does not treat use of AI features as your authorization for provider training. The provider does not publish one deletion period for all invocation records; deleting a MomentLog journal or account does not mean records the provider must retain are deleted at the same time.
3. Personal Premium cloud video and Team sharing
When you choose to use Personal Premium cloud video, the original video, thumbnail, and playback snapshot are uploaded to private storage for recovery across your signed-in devices. After subscription benefits end, cloud media follows the retention period described in the app. The current period is 7 days after the subscription period ends; if the subscription is not restored, that cloud media is permanently deleted. Your on-device original is not automatically deleted.
When you save a journal to a Team Project or choose to share it with a Team, its video, thumbnail, playback snapshot, author display name, journal context, transcript, and summary are used for team sharing. Team Recaps summarize shared journals. Team members with valid access can view this content and download videos on demand for local playback or export. The Team owner can see member names and email addresses needed for membership management; that role does not grant access to all of your private journals.
After you leave or are removed from a Team, you cannot obtain its content through the shared access features; previously issued temporary download links may remain usable until they expire. The cloud shared-content read-access window currently lasts 7 days after the relevant subscription entitlement ends; after that, the related videos and AI content are no longer available through cloud sharing; this does not mean all cloud data is deleted on day 7. MomentLog cannot remotely retrieve copies that other members have already downloaded or exported, and leaving a Team or deleting your account does not automatically remove those copies from their devices or photo libraries.
After a Personal plan downgrade, cloud media exceeding the new limit is retained for 7 days, then whole videos are removed oldest-recorded first until usage fits the limit. An expired Team subscription provides 7 days of read-only downloads before automatic dissolution. A shared project without a Team subscription dissolves 7 days after its creator’s Personal entitlement ends. Each author with videos receives a same-name Personal project containing only their own videos and individual AI text; shared Recaps are not transferred. Cloud copies follow each author’s Personal subscription, capacity and retention rules; on-device originals remain.
4. Why we use information
- To provide recording, archiving, search, AI analysis, Recaps, and cross-device recovery;
- To maintain sessions, subscription access, AI allowances, and user settings;
- To secure the service, diagnose failures, and meet legal obligations.
MomentLog does not sell personal information, show advertising, or use cross-app tracking technology.
5. Service providers and international processing
We use Apple (sign-in, StoreKit, WeatherKit, and photo permissions), Google (sign-in), Supabase (accounts, database, private storage, and server functions), Alibaba Cloud DashScope / Qwen (audio transcription and AI organization), and Brevo (account-deletion completion emails) where necessary to provide the service. Depending on the feature, data may be processed outside your country or region, including in the United States and China. We provide only the information needed for the relevant function.
6. Retention, security, and your choices
We use encryption in transit, private storage, and account access controls, but no system can guarantee absolute security. AI and Recap tasks, subscription events, and error records are retained for as long as needed to provide the service, diagnose failures, protect service security, and meet legal obligations. These records are deleted with the related journal or account, except for the minimal account-deletion record described below.
You can withdraw camera, microphone, location, or photo permission in iOS Settings, and turn off Automatic AI in MomentLog Settings. If you do not request manual AI, have not enabled Automatic AI, or do not use Personal Premium cloud video, the related uploads do not occur. You can also sign out, delete an individual journal, or permanently delete your account in Settings.
After an account-deletion request is accepted, access to the account is disabled immediately, existing sessions are revoked, and asynchronous cleanup begins immediately. Cleanup normally completes within minutes and no later than 7 days. It removes the sign-in account, server-side journal content, AI results, and cloud media within our control. An account that uses Sign in with Apple must first reauthorize so MomentLog can revoke the corresponding Apple authorization.
To prevent old credentials from regaining access to deleted data, document completion, and diagnose failures, we retain a minimal account-deletion record indefinitely. It includes the former MomentLog user ID, sign-in provider types, processing times, status, attempt and error information, processed counts, and notification status. This minimal record also includes an email snapshot, which remains retained indefinitely after the completion email is sent to identify the deleted account, verify deletion outcomes, and resolve notification failures. It is not used for marketing or made available to other ordinary users.
Files you exported to the system photo library are outside the app sandbox and must be deleted separately in Photos. Deleting your MomentLog account does not cancel an Apple auto-renewable subscription; Apple subscriptions must be canceled separately in system subscription management.
7. Website and policy updates
The MomentLog website provides a new-password form only when you open a password reset email. The page uses a one-time recovery session issued by Supabase to update the password, does not retain that session or password, and does not use administrator privileges, advertising, or analytics cookies. Selecting the support email opens your own email client.
We may update this policy when our product, providers, or legal obligations change. We will communicate material changes through this page or an appropriate in-app notice and update the effective date.
8. Contact us
For a privacy request, an explanation of your data, or a report about a privacy issue, contact:
contact@twincurrentstudio.com