Privacy Policy
Last updated: 2026-08-11 · v1.5
1. WHO WE ARE
Momentum is published by Adrian Gratar, an independent developer ("we", "us", "our"). Contact: the.real.momentum.app@gmail.com. As an EU-based controller (Romania), Article 27 GDPR does not require appointment of a separate EU representative.
2. WHAT WE COLLECT — AND WHAT WE DON'T
We do not collect personal information. We do not require sign-up, and we never ask for your name, email address, phone number, location, contacts, camera, photos, or device advertising identifier.
Everything you enter into Momentum — tasks, stash items, emotional check-ins, session records, task notes, and target dates — is stored only on your device using Apple's on-device database (SwiftData / SQLite), isolated within the app's iOS sandbox. Emotional check-in data (anxiety, energy, focus, and motivation scores) is stored exclusively on your device and is never transmitted to us or any third party. As this data does not leave your device, it is not subject to GDPR Article 6 lawful basis requirements for off-device processing, nor to CPRA sensitive personal information rules.
If, in a future update, you opt in to iCloud sync, your data will replicate via your personal iCloud account using Apple's CloudKit. We never have access to that data; only your Apple ID can read it. iCloud sync is not yet available.
The only data we hold on our infrastructure relates to AI-feature fraud prevention. This is described in detail in Sections 3 and 4 below. It is pseudonymous (no name, email, Apple ID, or content), it is held only on Cloudflare-hosted servers we control, and it can be reset by you any time from Settings → Reset AI session.
3. AI FEATURES — WHAT GETS SENT AND TO WHOM
Three optional features send text to an external AI service when you explicitly activate them: the "I can't start" step breakdown, the "this feels scary" reframe, and the AI Sort in Stash.
What is sent: only the specific text you are acting on — a single task title, an avoidance reason you selected, or your list of stash items. Nothing else is included: no name, email, location, check-in data, or session history.
What gets attached to the request for fraud prevention: an Apple App Attest assertion. Apple App Attest is an Apple framework that proves the request was made by an unmodified copy of Momentum running on a real Apple device. It produces a per-install device key identifier ("key ID") that is pseudonymous — it is not linked to your Apple ID, your name, your phone number, or anything you have entered into the app. The App Attest key ID and an associated counter of AI calls (number of calls today, this week, this month, plus input and output token totals) are stored on our Cloudflare-hosted proxy server for up to 180 days, then automatically deleted. We use these counters solely to enforce per-user usage limits, prevent abuse, and protect ourselves from runaway costs caused by automated scraping of the AI features.
Content safety classifier: before forwarding your text to the AI provider, our proxy runs a quick automated classifier over the text. The classifier looks for content the app is not built to help with — for example self-harm crises, requests to make weapons or synthesize drugs, requests to write programming code, requests to manipulate the AI's instructions, and content unrelated to starting personal tasks. When the classifier flags such content, the AI request is refused without being sent to Google, and the app shows a contextual response on-screen (for example, a list of crisis hotlines for self-harm content). The classifier itself is a short call to Google Gemini that processes only the text you are currently submitting; it produces a category label and is not retained.
How the request is routed: requests pass through a lightweight proxy server we operate, hosted on Cloudflare Workers (Cloudflare, Inc., USA). The proxy verifies the App Attest assertion, runs the content classifier, enforces per-device rate limits, and — if accepted — forwards the text to Google LLC's Gemini API. The proxy does not log the content of your prompt. The proxy retains, per device, only: (a) the App Attest key ID, (b) daily / weekly / monthly call and token counters, (c) timestamps of recent calls for burst detection, (d) a cooldown timestamp if you exceeded a limit, (e) a signature counter used to detect replayed requests, and (f) a per-day count of AI requests refused by the content classifier, used solely to apply the temporary cooldown described in the Terms of Use (Section 8). Standard Cloudflare infrastructure logs (IP address, timestamp, request size) may be retained by Cloudflare per their data retention policy, which is typically 14 days for free-tier traffic. Separately, to stop automated abuse of the device-reset flow described in Section 8 (Right to erasure), the proxy itself keeps a short-lived counter of how many times a given IP address has used Settings → Reset AI session in a day; this is the only IP-address data we deliberately store ourselves, as distinct from Cloudflare's own standard infrastructure logs described above.
Google LLC processes the text using the Gemini model and returns a response. Google's processing is governed by Google's Privacy Policy and its Generative AI Additional Terms. Google is a certified participant in the EU–US Data Privacy Framework and provides a Data Processing Addendum covering EU personal data.
Cloudflare is also an EU–US Data Privacy Framework participant. Both transfers therefore have an adequacy mechanism under GDPR Chapter V.
On devices running iOS 26 or later with Apple Intelligence available and enabled, all three AI features process entirely on-device using Apple's FoundationModels framework — nothing is sent to any server. When on-device AI is unavailable (older OS, Apple Intelligence not enabled, or model not downloaded), the app falls back to a rule-based offline path that requires no network connection. The App Attest fraud-prevention flow only runs when the request actually leaves your device.
4. IN-APP PURCHASES AND PREMIUM VERIFICATION
In-app purchases are processed by Apple through the App Store using Apple's native StoreKit 2 framework. No third-party in-app-purchase SDK is involved.
Server-side verification: when you purchase or restore Premium, your device sends Apple's signed transaction (a StoreKit 2 JSON Web Signature, which we verify against Apple's certificate chain) to our Cloudflare proxy so the proxy can verify your Premium status independently of the on-device flag. The proxy then stores a small binding record for your device: the product identifier you purchased, the original transaction identifier (a value assigned by Apple), the expiration timestamp, and the time the binding was made. This record is kept until your subscription expires plus a 7-day grace period, then automatically deleted. The binding is not linked to your Apple ID — it is keyed by the same pseudonymous App Attest key ID described above.
The purpose of the binding is solely to make sure that AI usage attributed to Premium quotas comes from a device that has genuinely paid for Premium. It is not used for marketing or analytics.
5. CALENDAR INTEGRATION (PREMIUM)
The optional Calendar feature (available to Premium subscribers) reads your calendar events on-device using Apple's EventKit framework to estimate your daily meeting load and warn about session conflicts. Calendar data is never transmitted off your device.
6. NOTIFICATIONS
All notifications are scheduled locally on your device by iOS. We do not operate a push notification server and no notification content passes through our infrastructure.
7. NO ANALYTICS, TRACKING, OR ADVERTISING
Momentum contains no analytics SDKs (no Firebase, no Google Analytics, no Mixpanel, no Amplitude), no crash-reporting libraries, no advertising libraries, and no tracking pixels of any kind. The App Store provides aggregated, anonymous install statistics to all developers; we have no control over that data and do not enrich it.
The app uses Apple's on-device MetricKit framework. MetricKit delivers aggregated performance and crash diagnostic data to the app locally. The app logs byte counts to the device system log and keeps the most recent diagnostic files (at most five per type) inside the app's private container on your device so crashes can be investigated; these files never leave your device, are not transmitted to us or anyone else, and are removed when you delete the app. Apple may separately collect diagnostic data per Apple's Privacy Policy (apple.com/legal/privacy).
8. YOUR RIGHTS
Because all personal data lives on your device, you can exercise most rights directly in the app.
Right of access: your data is visible directly within the app at any time. The fraud-prevention records we hold (App Attest key ID, AI usage counters, Premium binding) can be summarized on request via the email address in Section 14.
Right to rectification: edit or delete any item inside the app.
Right to erasure: use Settings → Clear all activity to erase your tasks, sessions, and check-ins (your saved preferences are kept); to remove absolutely everything on-device, delete the app. To erase the fraud-prevention records on our proxy, tap Settings → Reset AI session — this revokes the App Attest key and tells the proxy to delete the associated counters and Premium binding within seconds.
Right to data portability: Settings → Export everything produces two files — a PDF you can read, print, or keep, and a JSON file containing the same tasks, sessions, check-ins, and preferences in a structured, commonly used, machine-readable format that you can import into other software. This right is available to all users, free of charge.
Right to restriction of processing and right to object: the AI fraud-prevention processing on our proxy is the minimum necessary to prevent abuse; you can stop it entirely by not using the AI features, which is the trigger for any data leaving your device.
Withdrawal of consent: you can stop using AI features at any time — they are always opt-in, triggered only when you tap the relevant button. You can disable notifications in iOS Settings. You can cancel your subscription at any time in iOS Settings → Apple ID → Subscriptions.
For users in the EU / UK (GDPR / UK GDPR): where we act as a data controller — specifically when you voluntarily trigger an AI feature and text plus the pseudonymous App Attest key ID is transmitted to our proxy — our lawful basis is Article 6(1)(f) (legitimate interests: preventing fraud against our AI service and providing the assistance you explicitly requested) and, where applicable, Article 6(1)(a) (consent, given by the voluntary act of tapping the feature). You have the right to lodge a complaint with your national supervisory authority (in Romania: ANSPDCP, anspdcp.ro; in the EU generally: your country's data protection authority; in the UK: the ICO, ico.org.uk).
For users in California (CCPA / CPRA): we do not "sell" or "share" personal information as those terms are defined by California law. The pseudonymous App Attest key ID and the associated AI usage counters constitute personal information under California's broad definition, even though they are not linked to your name or contact info. We retain that information only for fraud prevention and Premium verification, as described in Sections 3 and 4.
As a California resident, you have the following rights under the CCPA:
- Right to know: You may request disclosure of the categories and specific pieces of personal information we have collected about you, the purposes for collection, and the third parties we share it with.
- Right to delete: You may request deletion of personal information we have collected. Use "Clear all activity" in Settings (or delete the app to remove everything, including preferences), or email the.real.momentum.app@gmail.com.
- Right to opt out of sale: We do not sell your personal information. No opt-out is required.
- Right to non-discrimination: Exercising any of these rights will not result in discriminatory treatment.
To submit a CCPA rights request, email: the.real.momentum.app@gmail.com with the subject line "CCPA Request". We will respond within 45 days.
For users in Australia (Privacy Act 1988): the personal information handling described in this policy aligns with the Australian Privacy Principles. Contact us at the address below for any privacy-related requests.
9. CHILDREN
Momentum is not directed at children. In the United States, we do not knowingly collect personal information from children under 13 (COPPA threshold). In the EU and UK, we do not knowingly collect personal information from children under 16 (GDPR threshold; some EU member states set this at 13). Because we collect no name, email, or contact information at all, there is nothing personally-identifying to remove, but if you are a parent or guardian with a concern, contacting us or tapping Settings → Reset AI session then deleting the app fully removes all on-device data and the pseudonymous fraud-prevention records.
10. DATA RETENTION
On-device data persists until you delete it or uninstall the app. We do not retain that content on our servers because we do not collect it.
For data on our Cloudflare proxy:
- App Attest key ID and associated AI call / token counters: kept for up to 180 days from the most recent AI call, then automatically expired by Cloudflare's storage TTL.
- Premium binding record: kept until your subscription expires plus a 7-day grace period, then deleted.
- Short-lived authentication challenges (nonces): retained for at most 5 minutes.
- Revocation tombstones (after you tap Reset AI session, to block replay attacks): kept for 90 days.
- Per-day counters of AI requests refused by the content classifier: kept for 30 days.
- Minimal audit records of AI-session resets and subscription revocations (timestamp and one or more truncated key identifiers only — no content): kept for 90 days.
- Daily aggregate spend ledger (anonymous, for the global usage kill-switch): kept for 3 days.
- Per-IP-address counter limiting how often Reset AI session can be used from the same network connection (abuse prevention): kept for about 2 days.
Text transiently routed through our proxy to the AI provider is not stored by us beyond the time needed to complete the request (typically under 2 seconds). Cloudflare's standard infrastructure logs are retained per Cloudflare's own retention policy.
11. SECURITY
On-device data is protected by iOS sandboxing, the app's data container, and the device passcode, Face ID, or Touch ID you have configured. Security-relevant flags (the App Attest key identifier, the cached AI usage snapshot, and the Premium binding state) are stored in the iOS Keychain with the most restrictive accessibility flag we can use ("after first unlock, this device only") so they are not synced via iCloud Keychain and are not readable from a backup that has been moved to a different Apple ID.
All network communications (proxy requests, App Store) use HTTPS with TLS 1.2 or higher. Our proxy authenticates every AI request using Apple App Attest, a cryptographic challenge-response protocol provided by Apple's operating system that proves the request came from an unmodified copy of this app on a real Apple device. Apple subscription receipts are independently verified server-side against Apple's published certificate chain before any Premium quota is granted.
The proxy enforces per-device daily, weekly, and monthly call and token ceilings, a burst-rate cooldown, and a global daily spend ceiling that automatically falls back to offline mode if exceeded. These measures protect both the service and your data from being exploited by automated abuse.
We do not operate user-account databases, persistent application servers, or any storage that ties an identity to your usage.
12. INTERNATIONAL DATA TRANSFERS
When you voluntarily trigger an AI feature, your text is routed through Cloudflare Workers infrastructure (global edge network, primarily processed at the Cloudflare data center closest to you) to Google's Gemini API (data centers in the United States and potentially other locations). Both Cloudflare and Google participate in the EU–US Data Privacy Framework. For transfers from the UK, Standard Contractual Clauses are available from both providers. The pseudonymous App Attest key ID and Premium binding records are stored in Cloudflare KV and Durable Objects, which run on Cloudflare's global edge network with the same legal-transfer safeguards.
13. CHANGES TO THIS POLICY
If we make material changes, we will note them in the app's release notes and update the "Last updated" date at the top of this policy. Continued use of the app after a change constitutes acceptance of the updated policy.
14. CONTACT
Privacy questions, data requests, or concerns: the.real.momentum.app@gmail.com
We aim to respond to privacy-related inquiries within 30 days.