Privacy Policy
Last updated: July 23, 2026
Effective: July 14, 2026. Last updated: July 23, 2026 (narrowed: removed the voice-journaling collection — the feature was removed from the product; we collect no voice data). This Privacy Policy describes the data practices of the Moment mobile app and of visitors to the ownthemoment.app marketing website. The two are different products with different data practices; this policy addresses both so there is a single canonical privacy page.
Who we are
The Moment app (“Moment,” “the app,” “we,” “us,” “our”) is operated by OTM App LLC (DBA "Own the Moment"), 1934 Old Gallows Rd, Ste 350, Vienna, Virginia 22182-4050, USA. Contact: support@ownthemoment.app.
Moment is an adults-only (18+) self-help wellness app. It is not medical care, therapy, diagnosis, or a crisis service. If you are in danger, contact local emergency services.
The short version
- In the app we collect what you give us (your check-ins, urge logs, setback notes, and related reflections), your email address, an optional phone number, an anonymous device identifier and device / app signals, first-party product analytics, and — if you turn on notifications — a push token. If you turn on the matching optional layers, we also collect health & motion and a coarse location history.
- We use it to provide the app’s features to you. We do not sell your personal information, and we do not use your data to advertise to you. With your separate, opt-in permission, we may share aggregated, de-identified data that cannot reasonably be linked to you (see Aggregated, de-identified data).
- Because the app concerns sexual behaviour and wellbeing, we treat your inputs as sensitive information.
- Your data is encrypted in transit and protected by per-user access controls on our servers.
- You can delete your account and all associated data at any time from inside the app (Profile → Delete account) or at ownthemoment.app/delete-account.
- Paid subscriptions are billed and processed by the Apple App Store or Google Play — we never receive your full card or banking details.
Information we collect (in the app)
You provide:
- Email address — to create, verify, and recover your account.
- Age confirmation — to confirm you are 18 or older. The app does not serve anyone under 18.
- Self-help inputs — your onboarding baseline (e.g., goals, frequency, situations that tend to be difficult, the times / places / devices you associate with urges), daily check-ins (e.g., stress, urge level, fatigue, mood), in-the-moment urge logs (urge intensity before/after, trigger, mood, setting, outcome, and any free-text notes you write), setback / repair details, and safety-screening answers (including whether you indicate risk of harm to yourself or others). Because this relates to sexual behaviour and wellbeing, we treat it as sensitive information and handle it accordingly.
- Phone number (optional) — you may add one for two-factor sign-in and account recovery. It is transactional only (never marketing texts) and never sold.
Optional — only if you turn them on (each gated by its own consent choice):
- Health & motion data — steps, sleep, resting heart rate, and mindfulness minutes from Apple Health / Health Connect. Used to power the support engine (and, only with the matching consent, de-identified research). It is never used for marketing and never sold in a form that identifies you; Apple and Google developer terms independently forbid selling health data in any form.
- Support contacts — people you type in yourself. We never read your address book, and typed contacts are encrypted and never sold.
Collected automatically:
- Anonymous device identifier — a per-installation identifier (it is not your phone number, advertising ID, or hardware serial) used to start sessions and to enforce the 18+ requirement. It is a direct identifier and is never sold.
- Device and app signals — your device model, operating-system and app version, carrier, network type, and a jailbroken / rooted flag, used for compatibility, crash triage, and security.
- Product analytics — we run our own first-party, self-hosted analytics (screens, taps, and feature use) to improve the app. There is no third-party analytics SDK, no ad tracking, and no cross-app tracking.
- Push notification token — only if you enable notifications, so we can send the notifications you opt into.
- Consent choices — which optional uses (e.g., product analytics, research) you have or haven’t agreed to.
- Limited server logs — our hosting/backend provider may process technical data (e.g., IP address, timestamps) to operate and secure the service. We do not use these for advertising or profiling.
- Location — only with your device permission. There are two separate uses, each optional. (a) One-time weather check:when you use the urge tool, and only if you have granted your device’s location permission, we take a one-time coarsereading to check current local weather, so the tool won’t suggest going outside when it isn’t safe (e.g., late at night or in bad weather). We do not store the coordinates for that check. (b) Location consent layer: separately, if you turn on the Location consent layer, we keep a coarse region history (roughly city / state level, not precise coordinates) to map your trigger locations. It is capped in age, one-tap deletable, and never sold except as a large de-identified regional aggregate. Neither use is background or continuous tracking, and neither builds a precisemovement track. If you don’t grant permission, the tool uses only your time zone and no location is collected.
We do NOT use third-party analytics or advertising SDKs in the app. The in-the-moment “location” you log — e.g., “bathroom,” “car” — is a category you pick, not GPS. Device location is used only for the two optional, permission-gated purposes described above; we do not track your location in the background or build any precise movement track.
Sensitive information
Some of this information reveals aspects of your sexual behaviour, health, and wellbeing — including your check-ins and urge logs, any health & motion metrics you connect, your coarse location history, and may include self-harm or harm-to-others disclosures. We treat it all as sensitive consumer-health data, collect and process it only on the basis of your consent and to provide the support you asked for, restrict access on a per-user basis, and never sell it in a form that identifies you or use it for advertising, marketing, or use-based data mining. You can withdraw consent at any time. Moment is a direct-to-consumer app and is not a HIPAA covered entity; we protect this data under the FTC Act, the FTC Health Breach Notification Rule, Washington’s My Health My Data Act, and the GDPR.
How we use information
- To provide the core features: your guided urge support, daily check-ins, pattern insights, and the repair flow.
- To authenticate you and keep your account secure (including fraud and abuse prevention).
- To enforce the adults-only (18+) requirement.
- To send notifications you opt into.
- To provide and manage paid subscriptions (see “Payments and subscriptions”).
- For optional purposes only with your separate, revocable, opt-in consent — improving the app (product analytics), supporting de-identified research, sharing aggregated partner insights (Commercial cohort), and — for the Health and Location layers — engine personalization and regional insights. Each is a distinct choice that is off by default and presented on the app’s consent screen. The core product works fully if you decline every optional layer. See Consent layers and Aggregated, de-identified data.
Payments and subscriptions
Moment offers optional paid subscriptions (e.g., monthly or annual plans). All payments are processed by the Apple App Store or Google Play, under their own terms and privacy policies. We receive confirmation of your subscription status (e.g., active / expired) so we can unlock features, but we do not receive or store your full payment-card or bank details. Manage or cancel a subscription in your App Store or Google Play account settings.
Consent layers
Your consent is six separate choices: Care (required — it powers the core support engine) plus five optional, opt-in layers you can review and change at any time:
- Care — required. The core behavioral-support engine, your account, security, and safety resources.
- Product analytics — optional. First-party, self-hosted analytics to improve the app.
- Research — optional. De-identified behavioural-health research.
- Commercial cohort — optional. Sharing large de-identified aggregates only with our affiliate and vetted partners (see Aggregated, de-identified data).
- Health — optional. Connecting Apple Health / Health Connect metrics to personalize the engine.
- Location — optional. Keeping a coarse region history to map your trigger locations.
Turning an optional layer off means we don’t collect or use data for that purpose; the core product still works. Product analytics is optional — it is not required to use the engine; only Care is required.
How we share information
- Service providers that host and run the app on our behalf (our backend and database provider), under contract and bound to protect your data. Service providers acting on our behalf are not “third parties” to whom we “sell” or “share” data for advertising.
- App store billing: Apple / Google process subscription payments (above).
- Aggregated, de-identified data — only with your separate, opt-in consent, and never in a form that identifies you (see below).
- We do not sell your personal information and do not share it for cross-context behavioural advertising.
- We may disclose information if required by law or to protect the safety of you or others.
Aggregated, de-identified data
If you opt in to the Commercial cohort layer, we may share de-identified, aggregated cohort insights with our affiliate Hofund Labs LLC and vetted partners — always grouped across 100 or more people (k ≥ 100), with small groups suppressed so no one is singled out. These aggregates may include:
- Behavioural-support outcomes and patterns — which interventions help, urge and lapse-recovery trends, and risk-window timing.
- Coarse demographic and context dimensions — your age band, region / time zone, and device type.
- Product-engagement and usage cohorts — de-identified feature-use and engagement patterns.
- Subscription-status cohorts — for example, paid-versus-free trends.
This is a commercial arrangement. It is never your individual data and never advertising; it never includes your identity, your written notes, your health data, your contacts, or your precise location. It is not personal information, is never used to contact you individually, and we do not sell your personal information. You can grant or withdraw this permission at any time in the app (Profile → Data & Privacy); withdrawing stops any future use of your data. The app works fully whether or not you grant it, and no such sharing occurs unless you opt in and a data-rights agreement between Own the Moment and Hofund Labs LLC is in force.
This use is strictly limited. We de-identify to a threshold of k ≥ 100 and suppress small groups so individuals cannot be singled out. We never include raw free text (such as your notes or narratives), and we never sell health data (Apple / Google developer terms forbid it in any form), precise location, direct identifiers (email, phone, device identifier), safety-screening data (self-harm, harm-to-others, or illegal-content concerns), or any data from anyone under 18 for research or commercial purposes — that information is walled off and used only to keep people safe and to operate the service. Aggregated data is never used for advertising, marketing, insurance underwriting, employment, credit, or eligibility decisions.
Storage, security, and retention
- Authentication tokens are stored on your device in the platform’s secure storage (Apple Keychain on iOS, encrypted storage on Android).
- Data is encrypted in transit (HTTPS). Server-side access is restricted on a per-user basis.
- We retain your data while your account is active and delete it when you delete your account, except where the law requires us to retain certain records.
Your choices and rights
- Delete your account and data — in the app (Profile → Delete account) or at ownthemoment.app/delete-account. Deletion removes your account and associated behavioural, check-in, and safety records, subject to limited legally-required retention.
- Withdraw optional consentsat any time in the app (Profile → Data & Privacy) — withdrawing is as easy as granting, and stops any future use of your data.
- Disable notifications in your device settings.
Region-specific rights:
- If you are in the EEA / UK (GDPR / UK GDPR): you have rights to access, correct, delete, restrict, object to, and port your personal data, and to lodge a complaint with a supervisory authority. Our legal bases are consent (optional uses, notifications) and performance of a contract / legitimate interests (providing and securing the core service). Where we rely on consent, you may withdraw it at any time.
- If you are in California (CCPA / CPRA): you have rights to know, access, correct, and delete your personal information, and to limit the use of sensitive personal information. We do not “sell” or “share” your personal information as those terms are defined under the CPRA, and we do not use your sensitive personal information to infer characteristics about you or for purposes beyond providing the service — other than the aggregated, de-identified data described above, which is not personal information and which we use or share only with your separate, opt-in consent.
To exercise any of these rights, contact support@ownthemoment.app. We will not discriminate against you for exercising them.
Children
Moment is for adults only. We do not knowingly collect data from anyone under 18; sign-ups indicating an age under 18 are refused.
Crisis note
Moment is not an emergency service. If you are in crisis, use the in-app crisis resources or contact local emergency services. In the United States you can call or text 988(Suicide & Crisis Lifeline), text HOME to 741741 (Crisis Text Line), or call 911.
Website visitors (ownthemoment.app)
For people who only visit our marketing website (and do not use the app): the website does not require an account and does not host your personal app data. If you submit the waitlist form, we store your email address with our email provider (Resend) so we can send you a confirmation and let you know when Moment launches. At the same time we record basic, non-identifying context about how you arrived — the page you signed up on and any campaign or referral tags in your link (for example, a “utm_source” value) — so we can understand which channels bring people in. You can unsubscribe at any time using the link in our emails or by contacting support@ownthemoment.app. We do not sell this information, and the site uses no advertising cookies or cross-site tracking. Our hosting provider may log technical data (e.g., IP address) to operate and secure the site.
Changes to this policy
We’ll post changes on this page and update the “Last updated” date above; we’ll surface material changes in the app.
Contact
OTM App LLC (DBA "Own the Moment") · 1934 Old Gallows Rd, Ste 350, Vienna, Virginia 22182-4050, USA · support@ownthemoment.app