Legal / Privacy
Privacy Policy.
Last updated: 2026-09-23
This policy explains what the Momstash app and the momstashapp.com website collect, why, who else touches it, how long we keep it and what you can do about it. We've tried to write it the way we'd want it explained to us: plainly, and without hiding anything in the small print.
The short version
- Momstash is your private stash. The links, screenshots, recipes, places and notes you save are yours. We use them to run Momstash for you and for nothing else.
- To read a link, we have to open it. When you save a link or a screenshot, our server fetches the public post and uses AI (OpenAI) to turn it into a recipe, a place, a product or whatever it contains. Details are in section 5.
- Your account is a username and a password. The iPhone app does not ask for your email address or phone number.
- Your location never leaves your phone. If you let Momstash show where you are on your map, that position stays on the device.
- No ads in the app, no selling. We don't sell your data and there are no ads in Momstash. We do use one attribution service, Singular, to learn which of our own ads and links bring people to Momstash. It gets your device's advertising identifier only if you allow tracking when iOS asks, and it never gets anything you saved (section 3.5).
- Apple takes your payment. We never see your card.
- You can wipe your data or delete your account entirely from inside the app (section 12).
1. Who we are
Momstash is operated by Mimi Studio d.o.o., a limited liability company organized under the laws of the Republic of Slovenia, with its registered office at Trubarjeva cesta 79, 1000 Ljubljana, Slovenia ("Mimi Studio", "we", "us").
For the General Data Protection Regulation (GDPR), Mimi Studio is the controller of the personal data described here. Because we are established in the European Union, we don't need a separate EU representative.
Questions about this policy or your data: [email protected].
2. Who Momstash is for
Momstash is made for grown-ups, mostly busy parents, who want one place for everything they save. It is not directed at children. You must be at least 16 to use Momstash, and if you are under 18 you need a parent or guardian's permission (the Terms of Use say the same). We don't knowingly collect data from children under 16. If you think a child has given us information, write to us and we'll delete it.
3. What we collect
3.1 Things you give us
| What | Details | Where it lives |
|---|---|---|
| Account | A username and a password you choose. The password is stored only as a secure hash by our sign-in service. The iPhone app does not ask for an email address or phone number. | Our sign-in server (Logto), section 9 |
| Links and screenshots you import | The web address of each link you share to Momstash (TikTok, Instagram, YouTube, Reddit, Pinterest, Google Maps, articles and so on), and any screenshot or photo you choose to import. | Our servers |
| Your library | Your saves and what was extracted from them, collections, meal plans, grocery lists, notes, ratings and reviews, comments on your own saves, archived items and custom save types. | On your phone, and backed up to our servers while you're signed in |
| Profile | The name, username and short bio you type into your Momstash profile, and your profile visibility choices. | On your phone, and backed up to our servers while you're signed in |
| Onboarding answers | What you tell us during setup: where and what you save, what frustrates you, what matters most, your age range and how you heard about Momstash. We use the save answers to create your first collections. | On your phone, and backed up to our servers while you're signed in |
| Posts and social activity | Posts and replies you write in the Social tab, who you follow, and what you like. | Our servers |
| Settings | Language, appearance, notification choices and similar preferences. | On your phone, and backed up to our servers while you're signed in |
| Support emails | Whatever you write to us, and the email address you write from. | Our support mailbox |
Please don't put things into Momstash that you would not want stored on a server, such as health records, ID documents or passwords. If a screenshot you import contains other people's details, that's something you've chosen to save; please be thoughtful about it.
3.2 Things collected automatically
- Account identifiers. A random account ID created by our sign-in service. It links your library, your imports and your subscription to you. It is not your name or email.
- Account activity. When your account was created (this is what starts your 14-day free access, see the Terms) and the last day you used it.
- Import records. For each import: the link, its status, timing, which of our providers answered, and what it cost us to process. We keep these to show your import history, to retry failed imports, and to apply daily limits.
- Technical data. Like any internet service, our servers see the IP address your phone connects from. Our API uses it briefly in memory for rate limiting and doesn't store it in its logs. Our sign-in service records sign-in events, which can include the IP address and device/browser type, for security. Our server logs record each request's time, path and result, and error logs can include your account ID.
3.3 Things we get from others
- Subscription status from Apple, via RevenueCat: which product you have, whether it's active, when it renews or expires, and transaction identifiers. We never receive your card number or billing address.
- Public information about the posts you save: when we fetch a link, we get what the post publicly shows, such as its title, caption, the creator's name or handle, images, video, audio and public comments. See section 5.
3.4 Things Momstash does not collect
- No precise location on our servers. If you allow location access, Momstash uses it on your phone only, to put a "you are here" dot on your map of saved places. It isn't sent to us or anyone else.
- No contacts, calendar, microphone or health data.
- Photos only when you choose them. Momstash sees only the screenshot or photo you pick or take to import, never the rest of your library.
- No ad networks inside the app and no data brokers. The one attribution tool we use, and exactly what it receives, is described in section 3.5.
- No crash-reporting service is built into the app.
- No usage analytics in the current version. The app contains code for product analytics (Mixpanel), but the released build has no key for it, so it never starts and sends nothing. The Storage & data screen says so too. If we ever switch it on, we'll update this policy first. It will only ever count things like "an import finished, from TikTok, with 3 results", never titles, links, notes, places or searches, and you'll be able to turn it off in the app.
3.5 Ad attribution (Singular)
When we advertise Momstash, we want to know which ads and links actually bring people to the app, so we don't pay for the ones that don't. For that the iPhone app includes the software kit of Singular (Singular Labs, Inc., United States), an attribution service.
What Singular receives from the app:
- Device and install information: your iPhone's vendor identifier (IDFV, a random ID that is the same only across apps from the same developer), the device model, iOS version, language, country, app version and network type, the time of the install and each app session, and the IP address your phone connects from.
- Your advertising identifier (IDFA) only if you allow tracking when iOS asks. If you decline, or iOS restricts tracking, the identifier isn't available and isn't sent.
- A few app events: that you finished onboarding, that you created a Momstash account, and that you bought Momstash Pro, with the product, the store transaction ID, the price and the currency. Singular uses Apple's SKAdNetwork too, which reports installs to ad networks without identifying you.
What it never receives: anything you save or import (no titles, links, notes, places, screenshots or searches), your username, your Momstash account ID, your profile or your onboarding answers.
When it starts. On first launch Momstash waits until onboarding has shown you the tracking step. If you tap Allow tracking, iOS asks you and Singular starts after you've answered. If you decline in iOS, or skip our tracking step so iOS never asks, Singular still starts after onboarding, but without the advertising identifier; it then receives the device information and events above and relies on SKAdNetwork. Declining tracking doesn't change what you can do in Momstash.
Singular may pass the result (for example "this install came from that campaign") back to the ad network that ran the ad, so it can count its results. You can change your answer at any time in iOS Settings → Privacy & Security → Tracking.
4. Why we use it, and our legal basis
| Why | What we use | Legal basis (GDPR Art. 6) |
|---|---|---|
| Creating and securing your account, signing you in | Username, password hash, account ID, sign-in events | Contract |
| Importing and organizing what you save | Links, screenshots, the public content they point to, your library | Contract |
| Backing up your library and restoring it on a new phone | Your library, profile, settings, onboarding answers | Contract |
| Social features: posts, replies, likes and follows | Your posts and the author details you choose to show | Contract |
| Free access period, daily limits and Momstash Pro | Account creation date, import counts, subscription status | Contract |
| Preventing abuse, fraud and runaway costs, and keeping the service secure | IP address (briefly), request logs, import cost counters | Legitimate interests (keeping Momstash safe and affordable to run) |
| Processing public information about the creators and commenters of posts you save | Names, handles, captions and comments that are already public | Legitimate interests (giving you a useful copy of what you chose to save) |
| Answering you | Support emails | Contract, or legitimate interests |
| Keeping accounting records of purchases | Transaction records | Legal obligation |
| Measuring which of our ads and links bring people to Momstash (section 3.5) | Advertising identifier | Your permission, given in the iOS tracking prompt, which you can withdraw in iOS Settings |
| The same, without the advertising identifier | Device and install information, the onboarding, account-created and purchase events | Legitimate interests (knowing which of our own marketing works) |
| Showing your location on your map (on your phone only) | Device location | Your permission in iOS, which you can withdraw in Settings at any time |
Where we rely on legitimate interests you can object (section 13). We don't use your data for automated decisions that have legal or similarly significant effects on you, and we don't profile you for advertising.
5. How an import works, and who helps
When you share a link or a screenshot to Momstash, this is what happens:
Your phone sends the link (or the image) to our server, together with your account ID.
Our server fetches the public post. Depending on the site, we fetch it ourselves (using open-source tools that talk directly to the site) or ask a provider to fetch it for us:
- Apify (Apify Technologies s.r.o., Czech Republic), a web data platform, for sites like Instagram, TikTok, Reddit, Facebook, Threads and Pinterest.
- The platforms' own official APIs where available: Google (YouTube Data API), X, Pinterest and Meta (Threads).
- Instantane, our own capture service, which stores a snapshot of the public post and its media so we don't have to fetch the same post twice. It holds public posts only. It doesn't know who saved them.
These providers receive the link you shared, not your name, username or account ID.
AI reads it. We download the media, turn speech into text and take a handful of still frames from videos. We then send the text, the transcript and up to twelve images to OpenAI (United States), which transcribes audio and extracts the useful things: ingredients and steps, places, products, films and so on. For a screenshot, OpenAI receives the screenshot itself. We send OpenAI the link, the post's title, author and text, the transcript and the images. We don't send your account ID, username or anything else about you. We ask OpenAI not to store the request (
store: false), and under OpenAI's API policy it isn't used to train their models. OpenAI may keep API data for up to 30 days for abuse monitoring, or longer where the law requires.We look up details. To fill in a place's address, hours and photos we send the place's name to Google Places. To find a product's listing we search Amazon for its name through Apify. To find posters and details for films, shows and games we look up the title in a film and game catalogue service (Cinéphile, operated by, built on TMDB and RAWG data). Only the thing's name goes out, never anything about you.
We save the result to your library, including copies of the post's images and media so your save keeps working if the original disappears.
"Ask Momstash" questions about a save are answered on your phone from what was already extracted. Your question isn't sent anywhere.
AI can be wrong. Always double-check quantities, allergens, opening hours, prices and anything important. See the Terms of Use.
6. What other people can see
Your library is private. Your saves, collections, plans, notes, reviews and profile details are not visible to other users. Sharing a collection uses your phone's share sheet to send a plain-text list to whoever you choose. Nothing is published.
The Social tab is the exception, and you pick who sees each post:
- Only you: nobody else.
- Followers only: people who follow you.
- Anyone on Momstash: every signed-in Momstash user.
Posts show the author details linked to your account. Replies and likes are visible to people who can see the post. You can delete your own posts at any time.
7. Notifications
If you allow notifications, iOS gives the app a device token. In the current version we don't send push notifications from our servers and we don't store that token. Notices you see in the app (like "your import finished") are created on your phone.
8. Purchases
Momstash Pro is sold through the App Store. Apple is the merchant and handles your payment details under Apple's own privacy policy. RevenueCat (RevenueCat, Inc., United States) checks your purchase with Apple and tells the app and our server whether Pro is active. RevenueCat receives your Momstash account ID and your purchase records from Apple.
9. Who handles your data for us
We don't sell your personal data or share it for cross-context behavioural advertising. We use these service providers (processors), each only for the purpose described:
| Who | What for | Where |
|---|---|---|
| DigitalOcean, LLC | Hosting our API, workers, databases (your library, imports, posts, account records) and our sign-in service | Frankfurt, Germany (EU) |
| Appwrite (open-source software we run ourselves on DigitalOcean) | Storing your uploaded screenshots and copies of media from your saves | Same as above |
| Logto (open-source software we run ourselves on DigitalOcean) | Accounts and sign-in | Same as above |
| OpenAI, L.L.C. | Transcribing audio and extracting saves from posts and screenshots (section 5) | United States |
| Apify Technologies s.r.o. | Fetching public posts and product listings for the link you shared | Czech Republic (EU); its cloud providers may process data outside the EEA |
| Google LLC | YouTube Data API and Google Places API lookups | United States |
| X Corp., Pinterest, Inc., Meta Platforms (Threads) | Official APIs for fetching a public post you shared from their platform | United States / Ireland |
| Cloudflare, Inc. | Storage for Instantane's snapshots of public posts; DNS | Global network |
| Cinéphile (api.cinephile.unifiedsense.com) | Film, TV and game catalogue lookups by title (only the title is sent) | May be outside the EEA |
| RevenueCat, Inc. | Subscription status | United States |
| Singular Labs, Inc. | Ad attribution: which ad or link brought an install, and the onboarding, account-created and purchase events described in section 3.5. The advertising identifier only with your iOS tracking permission. | United States |
| Apple | App distribution, payments and notifications. An independent controller under its own policy. | Global |
When you tap a link on a save (for example a recipe's original post or a product page), it opens in Safari inside the app. That website then sees your visit under its own privacy policy, not ours.
If we add a provider, this list changes before any data goes to them.
10. International transfers
Our servers are in the European Union. Some providers above (OpenAI, Google, RevenueCat, Singular and, depending on the request, Apify, Cloudflare, X, Pinterest and Meta) may process data in the United States or elsewhere outside the EEA. Where they do, we rely on the European Commission's adequacy decision for the EU–US Data Privacy Framework (where the provider is certified) or on the Standard Contractual Clauses, together with the providers' additional safeguards. You can ask us for more detail at [email protected].
11. How long we keep it
| What | How long |
|---|---|
| Your library, profile, settings, onboarding answers, posts, follows, likes, uploaded screenshots and media copies | Until you reset your data or delete your account in the app |
| Import records and daily usage counters | 90 days after the import finishes |
| Backups of our databases | Up to 7 days (daily backups, kept for a rolling week) |
| Your account (username, password hash, account ID, creation date) | Until you delete your account in the app (Settings → Account & sync → Delete account). "Reset everything" deletes your data but keeps the account itself, including the date your free access started. |
| A minimal deletion record (your random account ID and the fact it was deleted) | Kept after deletion so an old signed-in phone can't accidentally recreate your data |
| Sign-in event records | A limited period for security and troubleshooting, then deleted |
| Server logs | A limited period for security and troubleshooting, then deleted |
| Instantane snapshots of public posts (not linked to you) | Only as long as needed to serve imports, then deleted |
| Data sent to OpenAI | Not stored by us beyond your save. OpenAI may keep it up to 30 days for abuse monitoring. |
| Support emails | As long as needed to help you, then deleted |
| Purchase and transaction records | As long as tax and accounting law requires |
| Ad attribution data at Singular (device and install information, advertising identifier if you allowed tracking, the events in section 3.5) | 25 months, then kept only in aggregated form |
| Data on your phone | Until you reset it or delete the app |
12. Your choices and how to delete your data
In the app
- Export everything: Settings → Storage & data → Export everything creates a file with every save, collection, plan, grocery list, setting and profile field.
- Reset everything: Settings → Storage & data → Reset everything deletes your library, import history, posts, uploads and media copies from our servers and wipes this phone. This can't be undone, so export first if you're not sure.
- Delete a single save or post from its own screen.
- Location, photos and notifications can be switched off at any time in iOS Settings → Momstash.
- Tracking (the advertising identifier Singular may use, section 3.5) can be switched off at any time in iOS Settings → Privacy & Security → Tracking.
- Sign out from Settings → Account & sync.
Delete your account completely. In the app, go to Settings → Account & sync → Delete account and confirm. This deletes your account itself (your username, password and sign-in record), your library, import history, posts, uploads and media copies from our servers, and your customer record at RevenueCat, then wipes this phone and signs you out. It happens straight away and can't be undone, so export first if you're not sure. Only the minimal deletion record described in section 11 remains, and copies in our database backups expire within 7 days. If something goes wrong part-way, the app tells you and you can try again. If you can't sign in any more, email [email protected] with your Momstash username and we'll delete it for you within 30 days.
Deleting your account or data doesn't cancel Momstash Pro. Apple bills the subscription, so cancel it in iOS Settings → your name → Subscriptions. Otherwise it keeps renewing.
13. Your rights
If you are in the EEA, the UK or Switzerland, you have the right to access your data, correct it, delete it, restrict or object to how we use it, receive it in a portable format, and withdraw any permission you gave (this doesn't affect what we did before). You can also complain to a data protection authority. In Slovenia that's the Information Commissioner (Informacijski pooblaščenec, www.ip-rs.si), and you can also go to the authority where you live.
If you are in California or another US state with a privacy law, you have the right to know what we collect and why (this policy), to get a copy, to correct it, to delete it, and not to be treated differently for asking. We do not sell personal information. Measuring our own ads through Singular (section 3.5) may count as "sharing" for cross-context behavioural advertising under some state laws. To opt out, decline tracking when iOS asks, or turn it off in iOS Settings → Privacy & Security → Tracking; the advertising identifier is then never used. We don't use or disclose sensitive personal information for anything beyond providing the service.
Wherever you live, write to [email protected]. We'll answer within one month (or the time your law requires), may need to confirm it's really your account (for example by asking you to write from inside the app or confirm details only the account holder would know), and will explain if we can't do something and why. You can appeal a refusal by replying to our answer.
14. Security
Everything between the app and our servers is encrypted with HTTPS. Every request is checked against your sign-in token, and every database query is scoped to your account, so one person's library can't be read by another. Uploaded files and media copies can only be opened by their owner. Server secrets never ship inside the app. No system is perfectly secure, but if something ever goes wrong in a way that affects you, we'll tell you and the authorities as the law requires.
15. The website
momstashapp.com is an information site. It has no accounts. It is hosted by DigitalOcean in Frankfurt, sets no cookies, has no analytics or tracking, and loads no third-party scripts or fonts. The hosting provider sees your IP address when you load a page, as with any website.
16. Changes
If we change how Momstash handles your data, we'll update this page and the date at the top. If the change matters, for example a new kind of data or a new provider, we'll tell you in the app before it takes effect.
17. Contact
Mimi Studio d.o.o.
Trubarjeva cesta 79
1000 Ljubljana, Slovenia
[email protected]