Privacy Policy
Last updated: 2026-03-24
momentake (controller) processes personal data to provide file hosting, transcoding, galleries, and delivery. This policy explains data categories, legal bases, recipients, transfers, retention, and data subject rights under GDPR.
Data we collect
We process account data (email, profile data, Firebase auth identifiers), service data (uploaded content, galleries, technical transcoding artifacts), billing metadata, and security and diagnostic data (logs, IP, user-agent, error events).
How we use data
Lawful bases include contract performance, legal obligations, legitimate interests (security, fraud prevention, service reliability), and consent when required. We do not sell personal data.
Storage and security
Primary storage uses Backblaze B2 (EU region). Delivery and edge processing use Cloudflare services. Data in transit is protected by HTTPS, and access is limited by role and technical necessity.
Your rights
You can submit self-service DSAR requests in Settings to export your data or request account erasure, and track status. Erasure requests require step-up verification (fresh Firebase idToken) and explicit DELETE confirmation. You may also request rectification, restriction, objection, and portability where applicable.
Cookies and technical data
We use cookies/tokens for authentication, sessions, and protected media delivery, plus analytics and marketing tracking on the main site (GA4, Meta Pixel). We may process technical events (such as user-agent, IP, and page/event views) for product analytics and campaign measurement. Where international transfers apply, we rely on provider safeguards and contractual protections.
Policy changes
Retention baseline: account profile data is kept while account is active; media/galleries are removed on valid erasure; DSAR exports expire after 7 days; payment records are retained per legal obligations in anonymized form when applicable. Policy updates are published on this page with the “Last updated” date.