Legal
Privacy Policy
The full policy. If you want the short version first, the Trust & Privacy page says the same things in plainer language.
Last updated September 16, 2026
AI NOTICE — PLEASE READ. The Services include AI-powered features (assistants, named "personas," suggestions, summaries, voice commands, OCR-based event creation, and similar). To deliver these features we transmit content you provide—including your profile, goals, calendar events, chat history, voice transcripts, and uploaded images (including photos of your children)—to our AI/agent service ("Momeaze Agent") and to third-party AI / OCR / cloud providers described in Section 9 (Disclosures). AI output can be wrong, incomplete, biased, fabricated, or inappropriate and is not medical, mental-health, parenting, legal, or financial advice; AI features cannot call 911 or contact emergency services.
In an emergency, call 911 (United States) or 988 (Suicide & Crisis Lifeline). Full AI terms are in Section 7 of the Terms of Service; data handling for AI is in Section 3.4 and Section 9 below.
1. Who We Are
Business responsible for this Policy: Momeaze, LLC (a Texas limited liability company)
Contact (privacy requests): Momeaze, LLC · privacy@momeazeapp.com
Postal address: 5900 Balcones Drive, Suite 100, Austin TX 78731
Website / App: https://momeazeapp.com
2. Scope
This Privacy Policy describes how we collect, use, disclose, and otherwise process personal information in connection with the Momeaze mobile application (iOS and Android, distributed through Apple App Store and/or Google Play), website, and related services offered in or directed to the United States (collectively, the "Services").
United States-only phase: At launch, our contractual commitments, disclosures, and rights processes apply to U.S. residents using the Services subject to U.S. law. We offer the Services through U.S. storefronts only and do not direct or support use outside the United States.
Children: The Services are not intended for children under 13, and we do not knowingly collect personal information from children under 13 as described in Section 11.
Related legal documents: Terms of Service · Service Limitations & Medical Disclaimer · End User License Agreement (EULA) · Consumer Health Data Privacy Notice.
3. Personal Information We Collect
Depending on how you use the Services, we collect the categories of information described below.
3.1 Account and Identity Information
When you create or use an account, we collect:
- Name, email address, phone number (optional), date of birth, profile photo, locale, and time zone;
- Authentication credentials, including refresh-token hashes for our app sessions and—if you sign in with Apple Sign-In or Google Sign-In—identity-provider claims returned at login;
- Family-life context you choose to share, such as your motherhood stage and lifestyle category. Pregnancy- and fertility-related selections may be treated as sensitive or consumer health data under U.S. state law—see Section 6.3.
3.2 Family Members (Including Children) and Household Profile
If you create profiles for family members—partners, children, or others—we collect what you enter for each profile, including:
- Name, date of birth, gender, relationship, color tag, and an optional photo of the family member;
- For child profiles, additional details you choose to add, such as care arrangement type, grade level, home-school flag, school name, daycare or provider name, schedule start and end times, and attendance days;
- Tags linking family members to your calendar events and moments / photos.
Information about children: When you add a child profile or include a child in a photo, event, or chat message, that information is treated as children's data and handled as described in Section 11 (Children's privacy).
3.3 Calendar Connections and Event Metadata
If you connect a calendar provider (Google Calendar, Microsoft Outlook, or Apple iCloud / CalDAV), we receive and store:
- The email address and provider-side account identifier on the connected account;
- An OAuth refresh token (for Google / Outlook) or an app-specific password (for Apple iCloud), stored encrypted at rest (AES-256-GCM with our service key; RSA-encrypted for Apple);
- The list of calendar IDs you opt to sync, read-only / read-write flag, and provider name;
- A lightweight per-event shim (provider-side calendar and event IDs, optional UI color, and a link to the source OCR image if the event was created from an uploaded picture) so we can reference events without copying their full contents. Underlying event details are fetched on demand from the provider and are not persisted in our database.
3.4 AI Interactions and AI-Derived Content
If you use AI Features, we process the following:
- Your inputs, including: prompts you type, voice you speak to the assistant, photos and screenshots you upload, and the profile, goals, tasks, habits, routines, calendar events, family-member context, and chat history that we provide to the AI/agent as context;
- AI Output, which we store in your account as AI-generated captions and tags on photos / moments, AI-generated summaries of chat threads, AI-generated suggestions, and assistant messages returned to you;
- Third-party AI / OCR processors: our Momeaze Agent, which routes to the model providers OpenAI, Anthropic and Google; AWS Textract for OCR; and other third-party AI / ML providers we may add. See Section 9.1 for the current sub-processor list.
We do not sell your AI inputs or outputs, and our written agreements with AI / OCR / model sub-processors prohibit them from using your content to train, fine-tune, evaluate, or benchmark their own AI models.
Applicable AI law. Our processing of AI inputs and outputs is subject to the Texas Responsible AI Governance Act (TRAIGA), Tex. Bus. & Com. Code Ch. 551 (effective January 1, 2026). TRAIGA is enforced exclusively by the Texas Attorney General and provides no private right of action.
3.5 Photos and Uploads
We store photos and images you upload in object storage (AWS S3) in up to five renditions per image. Our database stores metadata pointers only. Image bytes that include children are treated as children's data—see Section 11.
3.6 Moments and Journaling
If you save a moment, we store the title, free-text description, place name, timestamp, media URL / thumbnail URL, AI-generated caption and tags, and any tagged family members.
3.7 Goals, Tasks, Habits, Routines, Streaks, Achievements, and Gamification
We store the items you create and progress against them:
- Goals (title, description, pillar, target date, completion timestamp);
- Tasks (title, description, due date, completion timestamp, optional links to a parent goal or event);
- Habits and per-completion logs (label, description, frequency, reminder time);
- Routines and their ordered steps and completion logs;
- Streaks, achievements, and XP / levels.
Note on health and money pillars. If you select health or money as a pillar—or enter health-, mental-health-, reproductive-, or financial-status information in free-text fields—those entries may constitute sensitive personal information or consumer health data under U.S. state law (see Section 6.3).
3.8 Preferences and Self-Reported Wellbeing
In your preferences we store choices such as preferred AI persona, AI tone, app intensivity, active life pillars, language, hotword on/off, voice commands on/off, notification level and quiet hours, and onboarding / paywall state.
We also store self-reported 0–5 scales for wellbeing, burnout, and presence / engagement if you choose to enter them. These scales are treated as sensitive / consumer health data—see Section 6.3.
3.9 Chat and Assistant Messages
We store chat threads and individual messages with the assistant, including a per-thread AI-generated summary, the message body, a flag for whether the message was spoken, and the sender (user or assistant). Chat-message content is the densest personal-information surface in the Services and is handled accordingly.
3.10 Notifications
We store in-app and push notifications generated for you (title, subtitle, body, category, read/unread state, send time, snooze count, snooze-until time, and links to the source task or event). We also store your per-category notification preferences.
3.11 Sessions, Device, and Security Information
For each device session we collect:
- IP address of last activity, last-active timestamp, refresh-token expiry, revocation timestamp;
- A hashed refresh token;
- A device info record including app version and build, OS and OS version, a stable per-install device identifier, and—if push is enabled—an APNs or FCM push token.
We process error and performance diagnostics (including crash data and a session-replay sample (approximately 10%) of mobile UI events) through Sentry to debug and improve the Services.
3.12 Transaction and Subscription Information
We store subscription state and payment records (Stripe payment-intent ID, amount, currency, payment-method label, status). We do not store full payment-card numbers—those are held by Stripe and by the relevant app store.
3.13 Location-Adjacent and Third-Party-API Queries (Not Persisted)
Certain features make on-the-fly queries to third-party APIs:
- Google Maps / Routes for geocoding and ETA based on origin / destination derived from your events or input. Results are used transiently and not persisted.
- Google Weather using latitude / longitude for current conditions. Not persisted.
3.14 Marketing and Communications Preferences
Your choices about promotional emails / SMS / push, unsubscribe records, consent logs, and similar records.
4. Sources of Personal Information
We collect personal information:
- Directly from you when you register, use the Services, communicate with support, subscribe, or interact with onboarding flows.
- Automatically through the Services via cookies/SDKs/logs (primarily web; mobile equivalents as applicable).
- From third parties such as analytics providers, authentication partners, calendars, payment processors/app stores, and AI/backend infrastructure vendors, where permitted.
5. Why We Process Personal Information (Purposes)
We use personal information to:
- Provide the Services, including syncing, personalization, reminders, dashboards, integrations, AI features where enabled, and customer support.
- Authenticate accounts and maintain security, including fraud prevention and abuse detection.
- Operate and improve reliability, debugging, analytics, internal research/product development.
- Communicate with you about operational messages, confirmations, announcements, surveys, and optional marketing where permitted.
- Comply with law, respond to lawful requests, and enforce our Terms of Service.
- Protect rights and safety, including safeguarding users and enforcing policies.
6. PII, Personal Information, PHI, and Health-Adjacent Data
6.1 Personal Information / PII
In this Policy, "personal information" means information that identifies, relates to, describes, or is reasonably capable of being associated with you or your household—including identifiers, commercial information, electronic or network activity, geolocation, inferences, and content you submit (consistent with definitions under California and analogous U.S. state consumer privacy laws).
6.2 Protected Health Information (PHI) and HIPAA
HIPAA defines Protected Health Information (PHI) in the context of covered entities (for example, most healthcare providers, health plans, and healthcare clearinghouses) and their business associates.
Momeaze offers a consumer family-life productivity application — it is not your clinic, insurer, or medical record system. In v1, Momeaze has not entered into a Business Associate Agreement (BAA) with any covered entity, has not integrated with a regulated telehealth provider, and does not operate an employer-sponsored HIPAA program. Accordingly, we do not treat information you enter in the consumer Services as HIPAA PHI in our role operating the app. If that posture changes, we will update this Section 6.2 and Section 5.1 of the Terms of Service before processing for any such program.
6.3 Consumer Health Data and Sensitive Categories
Depending on what you enter and how features work, the Services may process data that some states classify separately from generic personal information, including:
- Sensitive personal information (examples: precise geolocation, certain account credentials, contents revealing mental or physical health);
- Consumer health data under laws such as Washington's My Health My Data Act, Connecticut SB 3, Nevada SB 370, and similar frameworks;
- Reproductive / pregnancy / fertility information, which several U.S. states protect specifically.
Concrete fields in the Services that may fall in these categories:
- momEra (motherhood-stage selections) — values such as trying-to-conceive, pregnancy, newborn, toddler, preschooler, school-age, teen, adult-children. Pregnancy- and fertility-related selections are treated as special-category information.
- Self-reported 0–5 scales for wellbeing, burnout, and presence / engagement in your preferences.
- Goals or tasks under the health or money pillars, and free-text descriptions that reveal mental or physical health, medications, therapy, reproductive or hormonal topics, or financial status.
- Photos you upload that imply health, pregnancy, or family-medical status.
- AI-derived inferences about wellbeing, captions, or tags on your moments and chats.
- Calendar patterns that could imply healthcare visits, even though we do not persist event bodies.
6.4 FTC Health Breach Notification Rule
If the FTC's Health Breach Notification Rule applies to how we handle your information, we maintain our security and breach-response page at /trust with procedures to assess incidents and notify users and regulators within the timelines required.
7. Sensitive / Wellness Data (How This Policy Fits with Other Notices)
Section 6 describes how personal information, PII, PHI/HIPAA, and state-level consumer health concepts interact for the Services. This Policy is not a substitute for the Consumer Health Data Privacy Notice where that notice is required or for in-app consent screens.
Companion document: Consumer Health Data Privacy Notice — covers U.S. state-law consumer-health frameworks (Washington's My Health My Data Act, Nevada SB 370, and similar) aligned to our specific subprocessors and consent flows.
8. Selling, Sharing, Targeted Advertising
Depending on statutory definitions:
We do not sell your personal information for money.
The Momeaze app. The app contains no advertising SDKs. Nothing you enter in or generate through the app, including family-member profiles, calendar data, chat history, wellness information, and consumer health data, is sold or shared for advertising.
Our website uses the Meta Pixel. On most pages of our website (momeazeapp.com), we use the Meta Pixel, a tool provided by Meta Platforms, Inc. When it loads, the Meta Pixel may collect the page you viewed, the website that referred you, whether you tapped an App Store or Google Play button, your IP address, browser and device information, and a cookie identifier. Meta may combine this with other information it holds about you and uses it to help us measure our advertising and to show Momeaze ads to you on Facebook, Instagram, and other Meta services. Under the laws of some states, including California, this may be considered "sharing" personal information for cross-context behavioral advertising, or "targeted advertising." Meta's use of this information is also governed by Meta's Privacy Policy.
We limit what the Meta Pixel receives:
- It does not receive anything you type into a form on our website, and we do not send Meta your name, email address, or phone number.
- It does not load on our blog, our legal and privacy pages, our contact page, or our privacy request page.
- It never receives information from the Momeaze app or your Momeaze account.
Separately, we use Vercel Web Analytics, a first-party analytics tool that sets no cookies, to count page views, referring sites, and taps on our download buttons.
Do Not Sell or Share / targeted advertising opt-out: You can opt out of the Meta Pixel at any time on our Your Privacy Choices page, which is also linked in the footer of every page of our website. Your choice is saved in a cookie on that browser, so you will need to opt out again if you clear your cookies or use a different browser or device. You can also email privacy@momeazeapp.com.
Global Privacy Control (GPC): If your browser sends a GPC signal, we treat it as a request to opt out of sale, sharing, and targeted advertising for that browser, and the Meta Pixel does not load.
You may also be able to limit ads through your Facebook or Instagram ad settings or your device's advertising settings.
Privacy rights / DSAR hub: /privacy/rights
9. Disclosures to Third Parties (Categories)
We may disclose personal information to:
- Service providers / processors that help us host, secure, deliver, analyze, communicate, process payments, or provide AI / OCR / messaging infrastructure (see the sub-processor table in Section 9.1);
- Advertising partners: Meta Platforms, Inc., through the Meta Pixel on our website only, as described in Section 8 (never data from the Momeaze app);
- Professional advisors (lawyers / accountants), potential acquirers in a merger or asset sale (subject to confidentiality), authorities, when legally required.
Public sub-processor / service provider list: /legal/sub-processors. We update it when vendors materially change.
9.1 Current Sub-Processors and What Each Handles
| Sub-processor | Role | Categories of data processed |
|---|---|---|
| AWS (S3) | Image / file object storage | User-uploaded image bytes (profile, family-member, moments, chat attachments, OCR source images) in up to five renditions each. Includes children's photos when applicable. |
| AWS Textract | OCR on user-uploaded images | Images you send for OCR-based event creation; extracted text is returned to our server and used to create events. Not persisted as a distinct column. |
| Stripe | Payments and subscriptions | Stripe customer, subscription, payment-method, and payment history for paying users. We do not store full card numbers. |
| Google Calendar API | Calendar integration | OAuth refresh token for the connected Google account (stored encrypted); event content is read on demand and not persisted. |
| Microsoft Graph (Outlook) | Calendar integration | Same shape as Google Calendar. |
| Apple iCloud (CalDAV) | Calendar integration | App-specific password for the connected Apple ID (stored RSA-encrypted); event content read on demand and not persisted. |
| Apple Sign-In / Google Sign-In | Identity / authentication | Email and name claims returned at login. |
| APNs (Apple Push Notification service) | iOS push delivery | Device push token and outbound push payloads (title / subtitle / body — may include family-member names). |
| Firebase Cloud Messaging (Google) | Android push delivery | Same shape as APNs for Android. |
| Momeaze Agent | AI Features | The densest user payload: profile, goals, calendar events, chat history, image attachments, plus AI-derived content. Momeaze Agent routes this content to the model providers named directly below. All providers are contractually prohibited from training on your content. Processing routed through U.S. regions only. |
| OpenAI | AI model provider behind Momeaze Agent | Prompts and the context Momeaze Agent sends with them. Contractually prohibited from using your content to train, fine-tune, evaluate or benchmark its models. |
| Anthropic | AI model provider behind Momeaze Agent | Same shape as OpenAI. |
| Google (AI models) | AI model provider behind Momeaze Agent | Same shape as OpenAI. |
| Google Maps + Routes | Geocoding / ETA | Origin / destination addresses derived from events or your input; queried transiently and not persisted. |
| Google Weather | Local weather | Latitude / longitude for current conditions; not persisted. |
| Sentry | Error monitoring and session replay | Crash / error events with user ID and email context, plus a session-replay sample (approximately 10%) of mobile UI events for diagnostic purposes. |
| Vercel | Website hosting | Requests to momeazeapp.com, and website form submissions while they are being processed by a serverless function. Form contents are passed to Resend and are not stored. |
| Resend | Website form delivery | The name, email address and message you submit through a form on the website, for delivery to the relevant Momeaze inbox. |
Any addition or removal from this list, and any change in what a vendor receives, is reflected here and at /legal/sub-processors before deployment.
10. Google API Services Limited Use Disclosure
Momeaze's use and transfer of information received from Google APIs (including Google Workspace APIs such as the Google Calendar API) to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, for data accessed through Google APIs, Momeaze:
- Uses Google user data only to provide and improve user-facing features within the Services, as described in this Privacy Policy.
- Does not transfer Google user data except as necessary to provide or improve those features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with user notice.
- Does not use Google user data for serving advertising of any kind, including personalized, retargeted, or interest-based advertising.
- Does not allow humans to read Google user data unless we have your affirmative consent for specific items, it is necessary for security purposes or to comply with applicable law, or the data has been aggregated and anonymized.
11. Children's Privacy (COPPA)
The Services are not directed to children under 13, and children do not have their own Momeaze accounts. If you believe we inadvertently collected personal information from a child under 13 as a direct user, contact privacy@momeazeapp.com and we will promptly review and delete as required.
Parent-managed child profiles in the Services. The Services are designed for parents and caregivers, and we offer features that allow you—the adult account holder—to add family-member profiles for your children. When you do so, you provide and we store information about each child you choose to enter, which may include:
- Name, date of birth, gender, relationship, color tag, and an optional photo of the child;
- Care arrangement details (school, daycare, mother's-day-out, at-home, nanny), grade level, home-school flag, school name, daycare or MDO provider name, schedule start and end times, and attendance days;
- Tags linking the child to your calendar events, moments, and photos, and references to the child in your chat messages with the assistant.
We treat child profile data, photos of children, and references to children in your chats and moments as children's data and apply additional safeguards consistent with COPPA and relevant state children's privacy laws. A parent or legal guardian may delete a child profile at any time in-app.
Schedule-sensitive information. School names, daycare / MDO provider names, attendance days, and pickup / drop-off times can reveal where a child is at a given time. We minimize use of this information to features that require it and apply access controls accordingly.
12. Where We Store and Process Data (U.S. Phase)
For this United States-focused launch, we host and process personal information primarily in the United States (primary region: AWS us-east-1; U.S.-only backup replication; no non-U.S. regions in use). Specifically:
- Primary application database (Postgres): hosted on AWS us-east-1 with U.S.-only backups.
- Image / file storage: AWS S3, us-east-1 (with U.S.-only backup replication).
- OCR: AWS Textract, us-east-1.
- AI / agent processing: routed through our Momeaze Agent to third-party model providers under contract, all operating in U.S. regions with no-training-on-customer-content commitments.
- Calendar providers (Google, Microsoft, Apple), payments (Stripe), push (APNs, FCM), maps / weather (Google), and error monitoring (Sentry) operate from their own infrastructure under each vendor's terms.
Sub-processors outside the United States: None in v1. All sub-processors listed in §9.1 operate from U.S. regions for Momeaze's data. If that changes, this Policy and the public sub-processor URL will be updated before the change takes effect.
13. Retention
We retain personal information for as long as needed to provide the Services, maintain security/legal compliance, and resolve disputes/enforce agreements, then delete or de-identify it according to the retention schedule: account-tied data is retained for the duration of your account plus a 30-day grace period; after grace expiration, data is purged from production within 60 days and from encrypted backups within 180 days.
14. Security
We maintain reasonable administrative, technical, and organizational safeguards appropriate to the risk. No method is 100% secure; use strong passwords and multi-factor authentication (MFA)—MFA is available in v1; we recommend enabling it in Settings → Security.
Specific safeguards reflected in our current design include:
- Calendar refresh tokens for Google and Outlook are stored encrypted at rest using AES-256-GCM with our service key.
- Apple iCloud app-specific passwords are stored RSA-encrypted at rest.
- Refresh tokens for our own app sessions are stored as hashes, not in plaintext.
- Payment card numbers are not stored by us; Stripe, Apple, or Google handle card data when you pay through them.
- Image bytes live in AWS S3; the application database stores only metadata pointers.
- Chat-message content, momEra, self-reported wellbeing / burnout / presence scales, wellbeing-relevant free text, and children's profile fields are treated as our most sensitive data surfaces and receive elevated access and logging controls.
14.1 Data Minimization
We aim to collect and retain personal information that is adequate, relevant, and limited to what is reasonably necessary for the purposes described in Section 5 and the features you enable.
14.2 Data Accuracy
We take reasonable steps to keep personal information accurate for its intended use. You may update certain information in-product or request correction as described in Section 14.
15. Your Privacy Rights (U.S. States)
Depending on where you live, you may have rights such as:
- Access, knowing/categories, correct, delete
- Portability / export
- Opt-out of sale/sharing (if applicable), limit use of sensitive data (state-dependent)
- Appeal a denied request (states that require appeals)
- Non-discrimination for exercising rights
How to submit requests: Email privacy@momeazeapp.com, use the in-app path Settings → Privacy → Submit a Request, or use the web form at /privacy/rights.
Verification: We verify requests consistent with fraud prevention.
Authorized agents: You may designate an authorized agent to submit a request on your behalf where your state's law allows. We will require written authorization from you and identity verification of both you and the agent before acting.
Timing: Responses within timelines required by law.
15.1 Texas Residents (Sensitive Data)
Momeaze, LLC is organized under Texas law. If you are a Texas resident, the Texas Data Privacy and Security Act (TDPSA) may give you rights to confirm, access, correct, delete, and obtain a portable copy of your personal information, and to opt out of sale, targeted advertising, or certain profiling. We do not sell personal information. Our website uses the Meta Pixel for targeted advertising as described in Section 8; you can opt out at Your Privacy Choices, and we honor Global Privacy Control signals. We do not use data from the Momeaze app, including sensitive data, for targeted advertising. To exercise other TDPSA rights, use the channels in Section 14.
16. Automated Decision-Making / Profiling (Transparency)
We may personalize the Services based on usage and preferences, and we use AI Features to:
- Generate captions and tags on photos and moments;
- Summarize chat threads with the assistant;
- Suggest goals, tasks, routines, and nudges based on your profile, prior inputs, family-member context, calendar, and chat history;
- Personalize notifications (titles, subtitles, bodies—templated and may reference family-member names);
- Surface assistant responses to your prompts and voice commands.
AI Features are assistive, not determinative. We do not use AI Features to make legal or similarly significant decisions about you. AI Output may be wrong and should not be relied on without verification.
17. Communications Choices
Transactional messages may be necessary to operate the Services (for example, security notices, receipts).
Marketing communications require consent where mandated; unsubscribe links and preference centers must comply with CAN-SPAM, TCPA (SMS), push rules, and platform policies.
18. Third-Party Links and Integrations
Third-party integrations are governed by their own policies; read them before enabling access.
19. Apple App Store and Google Play (Android) Disclosures
Storefront accuracy: If you install Momeaze from Google Play, information about data collection, sharing, security practices, and optional Data safety labels is also presented in the Google Play listing. Those declarations match how the app actually works and stay consistent with this Policy. The same alignment principle applies to Apple's App Privacy details for iOS.
Payments: Purchases processed by Apple or Google may result in Apple or Google sharing limited transactional or anti-fraud information with us (not your full payment card number, typically).
Push notifications: On Android, you can manage notifications in device settings or in-product controls.
Permissions: Android and iOS may prompt for permissions. We request permissions only where needed for the functionality offered and explain purposes in onboarding / system prompts.
20. Changes to This Privacy Policy
We will post updates with a new effective date and provide additional notice as U.S. law requires. Material changes affecting sensitive or consumer health processing may require new consent (state-dependent).
21. Contact; Complaints
For privacy inquiries: privacy@momeazeapp.com
For mail: 5900 Balcones Drive, Suite 100, Austin TX 78731
Appendix A — Categories Table (California-Style Summary)
This table is a plain-language summary of categories collected.
| Category examples | Collected? | Purpose summary | Sold? | Shared? |
|---|---|---|---|---|
| Identifiers (name, email, phone, DOB, profile photo, user / device / session IDs, push tokens) | Yes | Account creation, authentication, push delivery, support | No | No |
| Customer records content (tasks, habits, routines, goals, moments, notes, photos, chat messages) | Yes | Provide and personalize the Services; AI Features | No | No |
| Family-member profiles, including children's data (name, DOB, photo, school / care provider, schedule) | Yes | Family calendar, reminders, nudges, AI Features | No | No |
| Calendar tokens and event metadata (encrypted refresh tokens; provider-side calendar / event IDs) | Yes | Calendar sync; event-driven reminders | No | No |
| Sensitive personal information / consumer health data — momEra (incl. trying-to-conceive / pregnancy), self-reported wellbeing / burnout / presence scales, health- or money-pillar entries, photos that imply health | Yes | Wellness features, opt-in flows, AI Features | No | No |
| Reproductive / pregnancy information specifically | Yes | Stage-appropriate features | No | No |
| Voice transcripts of spoken AI commands | Yes | AI Features (voice to assistant) | No | No |
| Image content including children's photos and OCR source images | Yes | Moments, profile, OCR-based event creation, AI captioning | No | No |
| Internet / network / device activity (IP, device info, app version, OS, push token, session timestamps) | Yes | Security, diagnostics, anti-abuse | No | No |
| Geolocation (time zone, locale; transient lat/lng for weather and routes) | Yes | Features (weather, ETA); not stored as a location history | No | No |
| Inferences / AI-derived content (captions, tags, summaries, suggested goals / tasks) | Yes | Personalization, AI Features | No | No |
| Financial information (Stripe customer ID, subscription / payment-intent records; no card numbers) | Yes | Subscriptions, billing | No | No |
| Website activity on momeazeapp.com (pages viewed, referring site, App Store / Google Play button taps, IP address, browser and device information, cookie identifier) | Yes (website only) | Website analytics; measuring and delivering Momeaze ads through the Meta Pixel (Section 8) | No | Yes: Meta, for advertising, unless you opt out |
| PHI / HIPAA-regulated payloads | No — default consumer posture | — | — | — |