Privacy Policy

Last updated 23 September 2026

mymomo is built so that we cannot read what you send. This page says exactly what our servers can and cannot see, in plain language. The encryption uses standard, published algorithms (X25519, XChaCha20-Poly1305), and you can verify your connection with your partner in the app: Settings → Safety number shows a code on both phones that matches only if nobody is in between.

What is end-to-end encrypted

Everything you and your partner send each other — messages, captions, photos, voice notes, stickers, status text, profile pictures, the countdown date — is encrypted on your phone with a key that only your two phones hold. Our servers relay the encrypted data and delete it as soon as your partner's phone confirms receipt. We cannot read it, and neither can anyone who compels us to hand it over: there is nothing readable to hand over.

What our servers do see

DataWhyKept
Your Apple sign-in identifierTo recognise your account. We don't ask Apple for your email or name, and our servers never see them.Until you delete your account
Your public keySo your partner's phone can derive the shared key. It cannot decrypt anything.Until you delete your account
Push notification tokenTo notify your partner's phone. Notifications say things like "Pengu sent you a sticker" — never the content.Until you sign out, delete, or it stops working
Timezone, working hours, a city you type in, and the notification sound you pickTo show your partner your local time and whether you're probably at work, and so that a message from them plays the chime you chose on your phone. All self-declared; never read from your device's location or calendar. Notifications are never held back: a message from your person arrives the moment it's sent.Until changed or deleted
The nicknames you give each otherSo notifications can say "Pengu" instead of your account name.Until changed or unpaired
Which momo you pickedSo your partner's phone can show your momo beside theirs, and so a notification can carry the right one. It is one of two characters, stored as "boy" or "girl" (the names of the two momos), and nothing else about you.Until you change it, or delete your account
Message metadata: sender, type (text / photo / sticker…), timestampsTo route delivery, and (per day, per pair, as numbers only) how many things each of you sent and of what kind (text, photo, sticker, voice note), whether each of you was active that day, whether you both sent something, whether you both added today's photo, whether your two phones were connected at once, and how long replies took (we keep the gaps between sends for up to 30 days and reduce them to a daily median). Never the content: we cannot read it.Envelope: until delivered (max 30 days). Daily counts: while paired. Reply-time detail: 30 days, then only the daily median.
Encrypted media filesHeld only until your partner's phone downloads them.Deleted on download; at most 30 days.
App usage counters (optional)Once a day the app can send counts — sessions, screens opened, stickers sent, whether notifications are allowed, how often it reconnected — so we can see what works. Counts only; nothing you wrote or sent. Settings → Privacy & data → Share usage counts turns this off.90 days
Optional profile answersIf you choose to tell us an age bracket, gender, when your relationship started, how far apart you are, or how often you meet, we use it to understand who the app is for. Every question has "prefer not to say". Your partner never sees these.Until you change or clear them, or delete your account
Whether notifications and the connection workPer day, per pair: how many notifications we sent, how many we held back because the app was already open, and how many failed (for example on a phone that uninstalled the app); how many times the app connected; and how many bytes of encrypted media passed through. It tells us when delivery is broken, which is the one thing we cannot learn from encrypted traffic. Counts only: never who sent what, never the content. A receipt id from the push service is kept for a few minutes to check a notification was accepted, then dropped.Counts: while paired. Receipt ids: minutes.

That table is the whole list. We also keep day-by-day totals across all couples, in which no pair or person appears. If we start keeping something new, it appears here before it ships.

Read receipts

Read receipts (blue ✓✓) are on and can't be turned off — mymomo is a two-person app, so 'seen' is reassurance, not pressure. A read marker is sent only while the thread is open and the app is active, and it is end-to-end encrypted: the relay sees that an encrypted marker passed, never which messages it covers.

Crash and diagnostic data

mymomo never sends crash or diagnostic data automatically. If you choose 'Share diagnostics', the app creates a content-free technical log — error types, code locations, timings, app/OS version, and non-reversible hashed identifiers only. It never contains messages, photos, voice notes, contacts, or encryption keys. Nothing is shared unless you tap Share.

What we never collect

Where your history lives

Your conversation is stored on your phone, in the app's protected storage. It is included in your iCloud Backup if you have that turned on, and is then protected the way Apple protects your backup (end-to-end only if you have enabled Advanced Data Protection). We do not keep a copy.

When you unpair or delete your account

Either partner can end the pairing alone, immediately. When that happens, everything the server holds for the pair is deleted at once, and each of you keeps only what you yourself sent. Deleting your account (Settings → Delete account) removes your account record and revokes your Apple sign-in. Reports and blocks you have filed are kept so that blocks keep working.

Safety

You can block and report from the pairing screen without pairing first. Reports contain only the reason you choose and any note you write; we cannot include message content because we cannot read it.

Who we share data with

Nobody, except the infrastructure needed to run the service: Cloudflare (servers and storage, encrypted data only), Expo and Apple (push notification delivery — token and notification text only), and Apple (sign-in). We do not sell or share data with anyone else.

Children

mymomo is for adults in a relationship. It is not directed at children under 13, and we do not knowingly collect data from them.

Changes

If this policy changes in a way that matters, the app will tell you before the change takes effect.

Contact

Questions about privacy: during the beta, send them through TestFlight (open TestFlight → mymomo → Send Beta Feedback). A contact email opens with our App Store launch.