Scope and album input
This policy applies to the MomenThumb iOS app and website, plus their Firebase and Google Cloud backend.
The app and website accept a public photos.app.goo.gl or Google Photos share URL as album input. “Public” means anyone who receives that Google link may be able to see the album; it does not mean the photos are non-sensitive. Only submit an album you are authorized to process.
Google controls the album page, access permissions, and archive download. MomenThumb automatically retries temporary transfer failures, but it does not bypass Google login, reauthentication, CAPTCHA, permission, quota, or native download restrictions. After repeated blocked attempts, the job pauses until the owner confirms the album is still public and tries again.
Data MomenThumb handles
Account and job data
- A Firebase Authentication anonymous user identifier. The app and website do not require your name or email address.
- The Google Photos share URL, album title when available, job status, timestamps, progress, error details, and analysis preferences.
- Share records, expiration times, and revocation state for galleries created from the app or website.
Photo and analysis data
- The private source archive downloaded from the album.
- Inventories, ranking scores, recommendations, and other derived analysis needed to build the result.
- Sanitized thumbnails, browsing previews, and higher-quality display derivatives used by the gallery. Source metadata is removed from published copies.
- If you explicitly opt in to people grouping, face-detection and similarity data used to form recurring-person clusters.
Google Cloud and Firebase may also generate operational logs needed to run, secure, and diagnose the service.
How data is used and processed
MomenThumb uses submitted data only to acquire the requested album, analyze and rank its photos, build your result, publish galleries you ask to share, prevent abuse, secure the service, and troubleshoot failures.
Private archives and owner records are stored in Firebase services. Analysis and publication run in Firebase and Google Cloud services, including Cloud Storage, Firestore, Cloud Functions, and Cloud Run. Google acts as the infrastructure provider processing data on behalf of the service.
MomenThumb does not sell personal data, run advertisements, or use album content or product activity for behavioral or cross-app tracking. This site does not load advertising pixels or third-party analytics scripts.
Optional people grouping
People grouping is off by default. It runs only when the job owner explicitly opts in. The feature groups visually similar faces across the submitted album; it is not intended to identify a person by name.
When enabled, a published gallery automatically includes anonymous Browse by person filters, rank-to-group membership, and a generated representative thumbnail for each group. Embeddings, confidence metrics, source filenames, and private review artifacts are not published.
Photos of people and face-derived data are particularly sensitive. Enable the feature only when you have an appropriate reason and permission to process everyone shown. If you do not opt in, the base ranking flow does not run people grouping.
Retention, revocation, and deletion
MomenThumb temporarily keeps the private source archive for up to seven days so interrupted analysis can recover without another Google Photos transfer. Analysis output, derived photo assets, and job records remain available so the owner can revisit a result and manage its shares. An expired or revoked share is disabled, but the stored result is not automatically deleted merely because sharing ended.
The iOS app provides permanent deletion in Settings → Delete My Account and All Data. After a destructive confirmation, MomenThumb first disables and removes the account's public gallery capabilities, then deletes the anonymous Firebase Authentication account, private archives, analysis records, rankings, optional people-grouping data, generated photo assets, and local job history.
Most deletion finishes during the request. If a cloud analysis was already running, a deletion fence blocks new access and automated cleanup continues for up to 25 hours so delayed worker output is also removed. Limited provider recovery copies and security logs may persist for their ordinary retention periods where required for infrastructure reliability, abuse prevention, or law.
Your choices
- Do not submit an album unless you are comfortable processing it in Google Cloud and Firebase.
- Leave people grouping off; it is optional and disabled by default.
- During development, submitting an album automatically creates an expiring shared gallery. Share its capability URL only with intended recipients.
- Revoke an active gallery from the app to prevent future capability access.
- Delete the anonymous account and all associated data directly from Settings in the iOS app.
The current Firebase account is anonymous and local to the app installation or browser profile. Reinstalling the app, clearing browser site data, or losing local authentication state may remove your ability to access existing owner records. It should not be treated as a durable cross-device account.
Questions and policy changes
For privacy questions or requests, use the project's GitHub Issues following the privacy precautions on the support page. No support email address is currently published.
This policy may change as MomenThumb evolves. Material changes will be reflected by updating the effective date on this page.