Privacy policy
MomentBackup is published by Watari Labs Pty Ltd (ACN 696 983 829 / ABN 84 696 983 829), an Australian company registered in New South Wales ("Watari Labs", "we", "us"). This policy explains how we handle personal information, consistent with the Australian Privacy Principles under the Privacy Act 1988 (Cth).
The short version
MomentBackup is software you run on your own computer. It needs no account to work, and backs up only to storage you own or rent directly — we never receive, hold, or can read your files. The app sends no usage data unless you turn on optional usage statistics, which are off by default. We offer an optional account you can sign in to on our website to re-download your license key and manage your devices; you never have to create one.
What we don't collect
- No account required. The app works fully without signing up for anything. An account is optional, used only to re-download your key and manage devices on our website (see “The optional account” below).
- No app telemetry unless you opt in. The app does not phone home with usage data. You can optionally turn on pseudonymous usage statistics — off by default, individual action events kept for no more than 90 days, never your files (see “Usage statistics” below).
- No file contents, ever. Backups go from your machine to your chosen destination. There is no MomentBackup server in that path.
The optional account
You can create an account on our website to re-download your license key, see your devices, and manage your data. It is entirely optional — the app and your backups never depend on it. If you choose to use it, we become the controller of a small account dataset, and we handle it as follows:
- What we hold. Your email address (used to sign in and to send your key), the metadata of your sign-in sessions (a device label where available, approximate last-seen time, and the IP address of a sign-in for security), and the record linking your purchase to your issued license. We never hold your backups, passphrases, or recovery keys.
- Passwordless sign-in. There is no password. We email you a one-time sign-in link; we store only a hashed form of that link and of your session token, never the raw value.
- Account email delivery. Sign-in links and account emails are sent through our email provider, Resend (Resend, Inc., United States), acting on our behalf. The separate post-purchase license-fulfillment email uses the same provider whether or not you create an account.
- Export and delete, yourself. From your account you can export your account profile, session history, linked license records, and account-email delivery history as a file, and request deletion of the optional account. Deletion removes only this convenience record — it never disables, revokes, or weakens any license, and your backups and your ability to restore them are untouched.
If you are in the EU or UK
Where the EU or UK GDPR applies to your optional-account data, our lawful basis is the performance of a contract — providing the account you asked for and re-delivering your license key — together with our legitimate interest in keeping sign-in secure, which is why we record the IP address and device details of a sign-in. You can object to that security-related processing at any time by emailing us or deleting your account. You have the rights described in “Accessing and correcting your information” above (access, a copy/export, correction, and erasure), and — in addition to contacting us — you may lodge a complaint with your local data protection authority.
What stays on your machine
- Settings, schedules, and the local backup index.
- Encryption keys. They are generated locally and never transmitted. If you lose your passphrase and recovery key, your backups cannot be decrypted — by anyone.
- Crash logs. Written locally only; nothing is uploaded automatically.
What reaches us, and when
- Update checks. The app fetches release metadata to keep itself current. This is an ordinary HTTPS download and carries no personal data.
- Support email. If you write to us, we receive what you send. The optional diagnostics export is built to exclude file contents, passphrases, and credentials, and you can read it before sending.
- License purchase. Payment is handled by our merchant of record, Polar (Polar Software, Inc.). We receive the order id and buyer email needed to issue the license, keep an order-to-license fulfillment record for support and re-delivery, and send the key through Resend. We receive nothing about your backups.
- Pseudonymous usage statistics, only if you opt in. Off by default; nothing is sent unless you turn it on. See the next section for exactly what an event contains.
Usage statistics (opt-in)
To help us understand which features matter, you can turn on pseudonymous usage statistics. It is off by default and you can change it any time in Settings. When you first turn it on, the app tells you what it sends. When it is on, the app sends a tiny event when an action happens (for example, a backup finishing). Each event contains only:
- a random install id — a rotatable pseudonymous identifier, not an account, email address, or hardware serial; it links events from the same install until you reset it;
- the app version, your operating system (Windows, macOS, or Linux), and CPU architecture;
- which action happened, from a fixed list: app opened, backup completed, restore used, verification run, image capture, or an error;
- for an error, a coarse category (such as
backup_failed) — never an error message.
We store each accepted event as one row with its server receipt time and the fields above for no more than 90 days, then delete it. It never includes your file names, paths, or contents, your credentials or recovery keys, or your backup destinations. We do not write your IP address to the telemetry database. The receiving server rejects fields and values outside this exact shape.
Website analytics
Our website uses Cloudflare Web Analytics, a privacy-friendly, cookieless measurement tool provided by Cloudflare, Inc. It uses no cookies and no client-side state, does not fingerprint or track you across sites, and is not used for advertising. It gives us only aggregate, non-identifying figures such as page views and load times. We do not run advertising trackers on the site.
Your storage providers
If you back up to your own cloud bucket or NAS, your relationship with that provider is governed by their terms — your data there is encrypted by MomentBackup before it leaves your machine when encryption is enabled.
Optional provider account access
Connecting a provider account is entirely optional and happens only when you choose it. MomentBackup runs on your computer; provider data and tokens are never sent to or stored by us.
- Google Drive (backup destination, when enabled). If a
release build exposes Google Drive and you pick it as a destination,
MomentBackup requests the
drive.filepermission and uses it solely to create and manage its own backup folder. It cannot see, read, or modify any other file in your Drive. - Gmail (notifications, when enabled). If a release build
exposes Gmail sending, and you turn on email notifications and connect
Gmail, MomentBackup requests the
gmail.sendpermission and uses it solely to send backup-status emails from your own address to the recipient you choose (usually yourself). It never reads, deletes, or otherwise accesses your mail, and we never send you marketing this way. - Tokens stay on your machine. The sign-in token is stored in your operating system's secure keychain and is used only to talk to Google directly from your computer. You can disconnect at any time, which removes the stored token.
MomentBackup's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer or use Google user data for advertising, and no human reads it.
Overseas recipients
We keep no hosted copy of your backups, so your files never leave your machine through us. A small amount of personal information is handled on our behalf by service providers outside Australia:
- Polar Software, Inc. (United States) — our merchant of record, which processes your purchase and the email address used to issue your license.
- Cloudflare, Inc. (United States) — hosts our website and update feed, runs the endpoint that receives pseudonymous usage events if you opt in, runs the optional account service, and provides our cookieless website analytics where enabled (see “Website analytics” above).
- Resend, Inc. (United States) — delivers the license-fulfillment email after a purchase and, if you use the optional account, its sign-in links and account emails.
- Google LLC (United States) — only if you choose to connect Google Drive or Gmail, in which case your computer talks to Google directly; we do not receive or store that data.
Before using these providers we take reasonable steps to ensure they handle personal information consistently with the Australian Privacy Principles.
How long we keep things
We keep support emails only as long as we need them to help you and to keep a basic record, then delete them. Polar holds the purchase record under its terms. We keep the order id, issued-license record, and buyer email only as long as needed for license fulfillment, support, fraud/refund handling, and applicable accounting or legal obligations; deleting an optional account does not delete this separate purchase record or invalidate its offline key. If you use the optional account, we keep its data until you delete the account (which you can do yourself at any time, with a 30-day grace period before the record is permanently removed); expired sign-in links and revoked sessions are pruned automatically. Opt-in usage statistics are stored as pseudonymous event rows, using a rotatable install id and no IP-address field, for no more than 90 days. A daily cleanup and cleanup before each new event remove older rows. We take reasonable steps to destroy or de-identify personal information we no longer need.
Accessing and correcting your information
If you use the optional account, you can export its profile, session history, linked license records, and account-email delivery history, and request deletion of that optional account, directly from the account page. You can also ask us what other personal information we hold about you (in practice, your support correspondence and the email address used to buy a license), ask for a copy, and ask us to correct it. Email [email protected] and we will respond within a reasonable time, normally within 30 days. If we cannot give access or make a correction, we will explain why.
Complaints
If you think we have mishandled your personal information, email [email protected] and we will investigate and respond. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or 1300 363 992.
Changes
If this policy changes in a way that matters, the app's release notes and this page will say so plainly.
Contact
Questions about privacy: [email protected].