Privacy policy
MomentBackup is published by Watari Labs Pty Ltd (ACN 696 983 829 / ABN 84 696 983 829), an Australian company registered in New South Wales ("Watari Labs", "we", "us"). This policy explains how we handle personal information, consistent with the Australian Privacy Principles under the Privacy Act 1988 (Cth).
The short version
MomentBackup is software you run on your own computer. No account is needed to download or install it. A free account is needed only when you start the one 7-day trial inside the app. Your backups go only to storage you own or rent directly — we never receive, hold, or can read your files. The app sends no usage data unless you turn on optional usage statistics, which are off by default. Paid licenses remain self-contained and can be activated offline without signing in.
What we don't collect
- The trial account holds no backup data. It is needed only when you start one trial inside the app. It stores that trial’s start and end dates, and is also used to re-download keys and manage website sign-ins. Your files, passphrases, recovery keys, and storage credentials never enter it.
- No app telemetry unless you opt in. The app does not phone home with usage data. You can optionally turn on pseudonymous usage statistics — off by default, individual action events kept for no more than 90 days, never your files (see “Usage statistics” below).
- No file contents, ever. Backups go from your machine to your chosen destination. There is no MomentBackup server in that path.
The trial account
Anyone can download and install MomentBackup. When you choose to start the trial, you create or sign in to an account inside the app. The account’s one 7-day trial starts there; another computer receives the same fixed end date. The same account can re-download your license key, show website sign-ins, and manage your account data. It is not required to activate a paid license offline, and your backups never depend on it. We are the controller of this small account dataset, which we handle as follows:
- What we hold. Your email address (used to sign in and to send your key), your trial’s opaque id and start/end dates, the metadata of your sign-in sessions (a device label where available, approximate last-seen time, and the IP address of a sign-in for security), installer-click dates and platform, and the record linking your purchase to your issued license. If you came from a campaign, the account may also hold a coarse source such as Google, X, or Reddit and a short campaign label. We never store the ad click id or referrer with your account. Your Google ad-measurement choice is recorded on the account when it is created and lowered on later website sign-ins, together with any conversion reports, whether still queued or already sent — the hash of your email address, the event, its time, whether and when it was sent, and for a purchase its order number, value, and currency. We never hold your backups, passphrases, or recovery keys.
- Passwordless sign-in. There is no password. We email you a one-time sign-in link and 6-digit code, and you can use either one. We store only protected hashes of the sign-in credentials and session token, never their raw values.
- Account email delivery. Sign-in links, codes, and account emails are sent through our email provider, Resend (Resend, Inc., United States), acting on our behalf. The separate post-purchase license-fulfillment email uses the same provider whether or not you create an account.
- Export and delete, yourself. From your account you can export your account profile, trial record, session history, linked license records, account-email delivery history, and any conversion reports as a file, and request deletion. Deletion removes the account and its trial access. It never disables, revokes, or weakens a paid license, and your backups and your ability to restore them are untouched.
If you are in the EU or UK
Where the EU or UK GDPR applies to your account data, our lawful basis is the performance of a contract — providing the account and trial you asked for, and re-delivering your license key — together with our legitimate interest in keeping sign-in secure, which is why we record the IP address and device details of a sign-in. You can object to that security-related processing at any time by emailing us or deleting your account. You have the rights described in “Accessing and correcting your information” below (access, a copy/export, correction, and erasure), and — in addition to contacting us — you may lodge a complaint with your local data protection authority.
What stays on your machine
- Settings, schedules, and the local backup index.
- Encryption keys. They are generated locally and never transmitted. If you lose your passphrase and recovery key, your backups cannot be decrypted — by anyone.
- Crash logs. Written locally only; nothing is uploaded automatically.
What reaches us, and when
- Update checks. The app fetches release metadata to keep itself current. This is an ordinary HTTPS download and carries no personal data.
- Trial account. We receive your email address and the security metadata described above when you create or use the account. When you start the trial inside the app, we also store its opaque id and fixed start/end dates and return a signed offline trial pass. That pass contains no email or account id.
- Support email. If you write to us, we receive what you send. The optional diagnostics export is built to exclude file contents, passphrases, and credentials, and you can read it before sending.
- License purchase. Payment is handled by our merchant of record, Polar (Polar Software, Inc.). We receive the order id and buyer email needed to issue the license, keep an order-to-license fulfillment record for support and re-delivery, and send the key through Resend. We receive nothing about your backups.
- Pseudonymous usage statistics, only if you opt in. Off by default; nothing is sent unless you turn it on. See the next section for exactly what an event contains.
Usage statistics (opt-in)
To help us understand which features matter, you can turn on pseudonymous usage statistics. It is off by default and you can change it any time in Settings. When you first turn it on, the app tells you what it sends. When it is on, the app sends a tiny event when an action happens (for example, a backup finishing). Each event contains only:
- a random install id — a rotatable pseudonymous identifier, not an account, email address, or hardware serial; it links events from the same install until you reset it;
- the app version, your operating system (Windows, macOS, or Linux), and CPU architecture;
- which action happened, from a fixed list: app opened, backup completed, restore used, verification run, image capture, or an error;
- for an error, a coarse category (such as
backup_failed) — never an error message.
We store each accepted event as one row with its server receipt time and the fields above for no more than 90 days, then delete it. It never includes your file names, paths, or contents, your credentials or recovery keys, or your backup destinations. We do not write your IP address to the telemetry database. The receiving server rejects fields and values outside this exact shape.
Website analytics
Our website uses Cloudflare Web Analytics, a privacy-friendly, cookieless measurement tool provided by Cloudflare, Inc. It uses no cookies and no client-side state, does not fingerprint or track you across sites, and is not used for advertising. It gives us only aggregate, non-identifying figures such as page views and load times. We also keep daily totals for four actions: creating a verified account, opening checkout, clicking a trial installer, and downloading after purchase. Those totals contain only the action and a fixed plan or platform label. We do not store an email, account, cookie, IP address, browser, page URL, or free-form text with them. Daily totals are deleted after 180 days.
Optional ad measurement
When you arrive from a paid Google or X ad, we may ask whether you want to allow ad measurement. Google's base tag loads with ad storage, ad user data, ad personalisation, and analytics storage denied. In that denied state it uses no ad cookies, but Google may receive limited cookieless measurement data. X's tag does not load unless you choose Allow. If you allow a provider, it may store or access cookies and receive the page address, referrer, ad click id, IP address, and browser or device information. It can use this for conversion measurement and interest-based advertising under its own policies.
Apart from the hashed email described below, we do not send Google or X your email address, account details, file information, license key, or backup data. We do not upload email or phone lists. A lead event is sent only after the first verified account sign-in, never when someone merely asks for a sign-in email. Choose No thanks to keep that provider's tag off. You can change both choices later with “Ad measurement choices” in the footer. Turning a provider off stops its code from loading on future page views, except that Google's base tag remains loaded in denied Consent Mode. You can also use Google's My Ad Center or X's privacy controls.
Your ad-measurement choice is recorded with your account when you create it. If you sign in inside the app instead, the code email includes a link that, opened in the browser where you made your choice, records that choice — and the coarse campaign source described above — on the account, under the same rules as a website sign-in; the link itself carries only a one-time token and cannot sign you in. With that consent, after you create an account and later start a trial or buy a license, we send Google Ads a SHA-256 hash of your account email address, and for a purchase its order number, value, and currency — never the address itself, and never an ad click id — so the advertising click can be counted as a conversion. A trial report carries an opaque reference instead of an order number, so Google can count each report once.
A withdrawal is re-recorded each time you sign in on this website; a later sign-in never turns consent back on — only the choice recorded when the account was created can allow it. Choosing No thanks, or a browser privacy signal, is recorded as a withdrawal at your next website sign-in, which also cancels any conversion reports still queued for your account. If you do not sign in here again, email support or delete your account to withdraw.
Your storage providers
If you back up to your own cloud bucket or NAS, your relationship with that provider is governed by their terms — your data there is encrypted by MomentBackup before it leaves your machine when encryption is enabled.
Optional provider account access
Connecting a provider account is entirely optional and happens only when you choose it. MomentBackup runs on your computer; provider data and tokens are never sent to or stored by us.
- Google Drive (backup destination, when enabled). If a
release build exposes Google Drive and you pick it as a destination,
MomentBackup requests the
drive.filepermission and uses it solely to create and manage its own backup folder. It cannot see, read, or modify any other file in your Drive. - Gmail (notifications, when enabled). If a release build
exposes Gmail sending, and you turn on email notifications and connect
Gmail, MomentBackup requests the
gmail.sendpermission and uses it solely to send backup-status emails from your own address to the recipient you choose (usually yourself). It never reads, deletes, or otherwise accesses your mail, and we never send you marketing this way. - Tokens stay on your machine. The sign-in token is stored in your operating system's secure keychain and is used only to talk to Google directly from your computer. You can disconnect at any time, which removes the stored token.
MomentBackup's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer or use Google user data for advertising, and no human reads it.
Overseas recipients
We keep no hosted copy of your backups, so your files never leave your machine through us. A small amount of personal information is handled on our behalf by service providers outside Australia:
- Polar Software, Inc. (United States) — our merchant of record, which processes your purchase and the email address used to issue your license.
- Cloudflare, Inc. (United States) — hosts our website and update feed, runs the endpoint that receives pseudonymous usage events if you opt in, runs the trial account service, and provides our cookieless website analytics where enabled (see “Website analytics” above).
- Resend, Inc. (United States) — delivers account sign-in links, codes, and account emails, plus the separate license-fulfillment email after a purchase.
- X Corp. (United States) — receives website and device data only after you allow optional X ad measurement, as described above.
- Google LLC (United States) — receives limited cookieless measurement data from its base tag while Consent Mode is denied, and receives cookie-based website and device data only after you allow optional Google Ads measurement, as described above. With that consent, Google also receives a SHA-256 hash of the account email — and, for a purchase, the order number, value, and currency — when you start a trial or buy a license, so the ad click can be counted. Separately, if you choose to connect Google Drive or Gmail, your computer talks to Google directly; we do not receive or store that provider data.
Before using these providers we take reasonable steps to ensure they handle personal information consistently with the Australian Privacy Principles.
How long we keep things
We keep support emails only as long as we need them to help you and to keep a basic record, then delete them. Polar holds the purchase record under its terms. We keep the order id, issued-license record, and buyer email only as long as needed for license fulfillment, support, fraud/refund handling, and applicable accounting or legal obligations; deleting an account does not delete this separate purchase record or invalidate its offline key. We keep account data until you delete the account (which you can do yourself at any time, with a 30-day grace period before the record is permanently removed); expired sign-in links and codes, and revoked sessions, are pruned automatically. Opt-in usage statistics are stored as pseudonymous event rows, using a rotatable install id and no IP-address field, for no more than 90 days. A daily cleanup and cleanup before each new event remove older rows. We take reasonable steps to destroy or de-identify personal information we no longer need. Your ad measurement choices stay in your browser until you change them or clear site data. Your Google choice is also recorded on the account when it is created and lowered on later website sign-ins. Conversion reports — the email hash, the event, its time, whether and when it was sent, and for a purchase its order number, value, and currency — are kept with the account and deleted with it. Google and X control the retention of information they receive after you opt in under their own privacy policies. Coarse campaign source and installer-click fields stay with the account until it is deleted.
Accessing and correcting your information
You can export your account profile, session history, trial record, linked license records, account-email delivery history, and any conversion reports, and request deletion directly from the account page. You can also ask us what other personal information we hold about you (in practice, your support correspondence and the email address used to buy a license), ask for a copy, and ask us to correct it. Email [email protected] and we will respond within a reasonable time, normally within 30 days. If we cannot give access or make a correction, we will explain why.
Complaints
If you think we have mishandled your personal information, email [email protected] and we will investigate and respond. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or 1300 363 992.
Changes
If this policy changes in a way that matters, the app's release notes and this page will say so plainly.
Contact
Questions about privacy: [email protected].