Privacy policy

Last updated: July 30, 2026.

MomentBackup is published by Watari Labs Pty Ltd (ACN 696 983 829 / ABN 84 696 983 829), an Australian company registered in New South Wales ("Watari Labs", "we", "us"). This policy explains how we handle personal information, consistent with the Australian Privacy Principles under the Privacy Act 1988 (Cth).

The short version

MomentBackup is software you run on your own computer. A free account is required to download the app and start its one 21-day account trial, but your backups go only to storage you own or rent directly — we never receive, hold, or can read your files. The app sends no usage data unless you turn on optional usage statistics, which are off by default. Paid licenses remain self-contained and can be activated offline without signing in.

What we don't collect

  • The trial account holds no backup data. An account is required to download the app and start one trial. It stores that trial’s start and end dates, and is also used to re-download keys and manage website sign-ins. Your files, passphrases, recovery keys, and storage credentials never enter it.
  • No app telemetry unless you opt in. The app does not phone home with usage data. You can optionally turn on pseudonymous usage statistics — off by default, individual action events kept for no more than 90 days, never your files (see “Usage statistics” below).
  • No file contents, ever. Backups go from your machine to your chosen destination. There is no MomentBackup server in that path.

The trial account

You create an account on our website to unlock the download. Signing in inside the app starts the account’s one 21-day trial; another computer receives the same fixed end date. The same account can re-download your license key, show website sign-ins, and manage your account data. It is not required to activate a paid license offline, and your backups never depend on it. We are the controller of this small account dataset, which we handle as follows:

  • What we hold. Your email address (used to sign in and to send your key), your trial’s opaque id and start/end dates, the metadata of your sign-in sessions (a device label where available, approximate last-seen time, and the IP address of a sign-in for security), and the record linking your purchase to your issued license. We never hold your backups, passphrases, or recovery keys.
  • Passwordless sign-in. There is no password. We email you a one-time sign-in link; we store only a hashed form of that link and of your session token, never the raw value.
  • Account email delivery. Sign-in links and account emails are sent through our email provider, Resend (Resend, Inc., United States), acting on our behalf. The separate post-purchase license-fulfillment email uses the same provider whether or not you create an account.
  • Export and delete, yourself. From your account you can export your account profile, trial record, session history, linked license records, and account-email delivery history as a file, and request deletion. Deletion removes the account and its trial access. It never disables, revokes, or weakens a paid license, and your backups and your ability to restore them are untouched.

If you are in the EU or UK

Where the EU or UK GDPR applies to your account data, our lawful basis is the performance of a contract — providing the download, account, and trial you asked for, and re-delivering your license key — together with our legitimate interest in keeping sign-in secure, which is why we record the IP address and device details of a sign-in. You can object to that security-related processing at any time by emailing us or deleting your account. You have the rights described in “Accessing and correcting your information” below (access, a copy/export, correction, and erasure), and — in addition to contacting us — you may lodge a complaint with your local data protection authority.

What stays on your machine

  • Settings, schedules, and the local backup index.
  • Encryption keys. They are generated locally and never transmitted. If you lose your passphrase and recovery key, your backups cannot be decrypted — by anyone.
  • Crash logs. Written locally only; nothing is uploaded automatically.

What reaches us, and when

  • Update checks. The app fetches release metadata to keep itself current. This is an ordinary HTTPS download and carries no personal data.
  • Trial account. We receive your email address and the security metadata described above when you create or use the account. When you start the trial inside the app, we also store its opaque id and fixed start/end dates and return a signed offline trial pass. That pass contains no email or account id.
  • Support email. If you write to us, we receive what you send. The optional diagnostics export is built to exclude file contents, passphrases, and credentials, and you can read it before sending.
  • License purchase. Payment is handled by our merchant of record, Polar (Polar Software, Inc.). We receive the order id and buyer email needed to issue the license, keep an order-to-license fulfillment record for support and re-delivery, and send the key through Resend. We receive nothing about your backups.
  • Pseudonymous usage statistics, only if you opt in. Off by default; nothing is sent unless you turn it on. See the next section for exactly what an event contains.

Usage statistics (opt-in)

To help us understand which features matter, you can turn on pseudonymous usage statistics. It is off by default and you can change it any time in Settings. When you first turn it on, the app tells you what it sends. When it is on, the app sends a tiny event when an action happens (for example, a backup finishing). Each event contains only:

  • a random install id — a rotatable pseudonymous identifier, not an account, email address, or hardware serial; it links events from the same install until you reset it;
  • the app version, your operating system (Windows, macOS, or Linux), and CPU architecture;
  • which action happened, from a fixed list: app opened, backup completed, restore used, verification run, image capture, or an error;
  • for an error, a coarse category (such as backup_failed) — never an error message.

We store each accepted event as one row with its server receipt time and the fields above for no more than 90 days, then delete it. It never includes your file names, paths, or contents, your credentials or recovery keys, or your backup destinations. We do not write your IP address to the telemetry database. The receiving server rejects fields and values outside this exact shape.

Website analytics

Our website uses Cloudflare Web Analytics, a privacy-friendly, cookieless measurement tool provided by Cloudflare, Inc. It uses no cookies and no client-side state, does not fingerprint or track you across sites, and is not used for advertising. It gives us only aggregate, non-identifying figures such as page views and load times. We do not run advertising trackers on the site. We also keep daily totals for four actions: starting account creation, opening checkout, downloading the trial, and downloading after purchase. Those totals contain only the action and a fixed plan or platform label. We do not store an email, account, cookie, IP address, browser, page URL, or free-form text with them. Daily totals are deleted after 180 days.

Your storage providers

If you back up to your own cloud bucket or NAS, your relationship with that provider is governed by their terms — your data there is encrypted by MomentBackup before it leaves your machine when encryption is enabled.

Optional provider account access

Connecting a provider account is entirely optional and happens only when you choose it. MomentBackup runs on your computer; provider data and tokens are never sent to or stored by us.

  • Google Drive (backup destination, when enabled). If a release build exposes Google Drive and you pick it as a destination, MomentBackup requests the drive.file permission and uses it solely to create and manage its own backup folder. It cannot see, read, or modify any other file in your Drive.
  • Gmail (notifications, when enabled). If a release build exposes Gmail sending, and you turn on email notifications and connect Gmail, MomentBackup requests the gmail.send permission and uses it solely to send backup-status emails from your own address to the recipient you choose (usually yourself). It never reads, deletes, or otherwise accesses your mail, and we never send you marketing this way.
  • Tokens stay on your machine. The sign-in token is stored in your operating system's secure keychain and is used only to talk to Google directly from your computer. You can disconnect at any time, which removes the stored token.

MomentBackup's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer or use Google user data for advertising, and no human reads it.

Overseas recipients

We keep no hosted copy of your backups, so your files never leave your machine through us. A small amount of personal information is handled on our behalf by service providers outside Australia:

  • Polar Software, Inc. (United States) — our merchant of record, which processes your purchase and the email address used to issue your license.
  • Cloudflare, Inc. (United States) — hosts our website and update feed, runs the endpoint that receives pseudonymous usage events if you opt in, runs the trial account service, and provides our cookieless website analytics where enabled (see “Website analytics” above).
  • Resend, Inc. (United States) — delivers account sign-in links and account emails, plus the separate license-fulfillment email after a purchase.
  • Google LLC (United States) — only if you choose to connect Google Drive or Gmail, in which case your computer talks to Google directly; we do not receive or store that data.

Before using these providers we take reasonable steps to ensure they handle personal information consistently with the Australian Privacy Principles.

How long we keep things

We keep support emails only as long as we need them to help you and to keep a basic record, then delete them. Polar holds the purchase record under its terms. We keep the order id, issued-license record, and buyer email only as long as needed for license fulfillment, support, fraud/refund handling, and applicable accounting or legal obligations; deleting an account does not delete this separate purchase record or invalidate its offline key. We keep account data until you delete the account (which you can do yourself at any time, with a 30-day grace period before the record is permanently removed); expired sign-in links and revoked sessions are pruned automatically. Opt-in usage statistics are stored as pseudonymous event rows, using a rotatable install id and no IP-address field, for no more than 90 days. A daily cleanup and cleanup before each new event remove older rows. We take reasonable steps to destroy or de-identify personal information we no longer need.

Accessing and correcting your information

You can export your account profile, session history, trial record, linked license records, and account-email delivery history, and request deletion directly from the account page. You can also ask us what other personal information we hold about you (in practice, your support correspondence and the email address used to buy a license), ask for a copy, and ask us to correct it. Email [email protected] and we will respond within a reasonable time, normally within 30 days. If we cannot give access or make a correction, we will explain why.

Complaints

If you think we have mishandled your personal information, email [email protected] and we will investigate and respond. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or 1300 363 992.

Changes

If this policy changes in a way that matters, the app's release notes and this page will say so plainly.

Contact

Questions about privacy: [email protected].