Moun - Privacy & Security Policy
Last updated: 08/14/2026
This Privacy & Security Policy explains how Zima LLC (“Zima,” “we,” “us,” or “our”) collects, uses, shares, and protects your information when you use the Moun mobile application and the website at https://moun.app (the “Service”). It also describes the security measures we apply and the choices you have.
By using Moun, you agree to the practices described in this Policy. If you do not agree, please do not use the Service.
1. Who we are
Moun is a personal memory and reminder app. You can talk or type to capture things you do not want to keep in your head; set time-based and location-based reminders; save Memory Cards (short items with optional photo, address, or link); chat with an AI assistant about your own saved content; and, if you choose, connect a calendar.
The Service is operated by Zima LLC.
2. Information we collect
We collect the following categories of information.
a) Account information. When you create an account — with Sign in with Apple, Sign in with Google, or email and password — we receive your email address, a display name if you provide one, and identifiers needed to create and secure your account. We do not receive the password you use with Apple or Google.
b) Content you create (“User Content”). This includes:
messages you send in chat (text and photos);
reminders and their details (title, time, place, notes);
Memory Cards (title, details, optional photo, address, and link);
saved places (for example “Home” or “Work”);
onboarding answers you give when you set up the app.
c) Voice audio and transcripts. If you use voice, we receive the audio you record so we can turn it into text. Transcription is performed by a speech-to-text provider (currently Groq and/or Deepgram) through our backend. We keep the resulting text as part of your User Content. We do not use your voice to advertise to you.
d) AI-derived data. To search your Memory Cards and to let the assistant answer you, we generate:
embeddings (numerical vectors) of your content;
a lexical “blind index” (HMAC tokens derived from your text, not the readable text itself);
short classifications or extracted details the assistant needs to do what you asked (for example a date or a place).
This data is derived from User Content and stored with your account.
e) Chat history. We store conversations with the assistant so the thread can continue and so you can review past messages. You can delete chat history from the app.
f) Location. If you allow location access, we use it for location-based reminders and to help you save a place. We store:
saved locations you register, which stay until you delete them;
temporary locations for one-off reminders (for example “remind me when I get there”), which we delete automatically 48 hours after they are used.
You control location through your device permissions.
g) Calendar (optional). If you connect Google Calendar, we access calendars and events using the Google permissions you grant, so we can show and sync them in Moun. Event titles, descriptions, and locations are stored encrypted (see Section 8). If you connect your device calendar on iOS, we read and write events on the device using the permissions you grant. See Section 6 for Google user data.
h) Device, usage, and diagnostics. We collect limited technical data such as device type, operating system, app version, and language, plus product-usage events and crash/performance logs, so we can operate, secure, and improve the Service.
i) Payments and trial. Subscriptions are billed by the Apple App Store or Google Play. Those stores handle your payment details. We receive subscription status (for example active, expired, or trial), not your full card number. We may also store when a free trial started so we can show remaining time in the app. Paywalls are presented with Superwall.
j) Onboarding draft. If you leave setup unfinished, we may keep a local draft on your device so you can continue where you left off.
3. How we use your information
We use your information to:
create, authenticate, and secure your account;
store and show your reminders, Memory Cards, photos, and chat;
transcribe voice and understand photos you attach;
search Memory Cards (semantic search via embeddings, and lexical search via the blind index);
let the assistant answer using your own content, reminders, and — if connected — calendar;
fire time-based and location-based reminders, including alarms on the device;
sync calendars you chose to connect;
run onboarding, subscriptions, and the trial;
provide support;
understand how the Service is used, in aggregate, so we can improve it;
keep the Service secure, prevent abuse, and meet legal duties.
We do not sell your personal information. We do not use your private content to serve third-party ads. We do not track you across other companies’ apps or websites for advertising.
4. Voice, photos, and AI
Moun is built around voice, photos, and an assistant. To do that, some content must be processed by our servers and by trusted processors (Section 5).
Voice recordings are sent to our backend and transcribed by our speech-to-text provider. We send the audio reasonably needed for that transcription.
Chat text and images may be sent to our AI provider (Anthropic) so the assistant can answer, create reminders or Memory Cards, and understand a photo.
Memory Card text is decrypted in our backend only as needed to embed it for search, to let the assistant recall it, or to return it to you.
We route these requests through our backend. API keys are not shipped in the app.
Our AI and speech providers process your content to perform the feature you requested. They are not permitted to use that content to train generalized public models under our contracts with them.
AI output can be wrong. Do not treat it as medical, legal, or financial advice.
5. Processors (sub-processors)
We use these providers to run Moun. They process data only to provide their service to us:
ProviderPurpose
Supabase
Database, authentication, file storage, and backend functions
Google Cloud KMS
Wrapping (encrypting) each user’s data key
Anthropic (Claude)
Assistant reasoning, image understanding, and answers about your content
Groq / Deepgram
Speech-to-text for voice capture
PostHog
Product analytics, diagnostics, and errors
Google (Sign-In, Calendar, Maps/Places)
Sign-in, optional calendar sync, optional place search
Superwall
Paywalls and subscription presentation
Apple App Store / Google Play
Distribution and billing
Apple (Sign in with Apple, device calendar, notifications, Keychain)
Sign-in, optional device calendar, alerts, on-device key storage
We may change providers as the Service evolves and will update this Policy when we do.
6. Google user data and Limited Use
When you sign in with Google or connect Google Calendar, Moun accesses Google user data only with the scopes you grant, and only to provide the features you asked for.
Moun’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
In particular:
We request only the Google scopes needed for the features you use.
We use Google user data solely to provide and improve those user-facing features.
We do not sell Google user data. We do not use it for advertising or for any purpose unrelated to the Service.
We do not use Google user data to train generalized AI or machine-learning models.
If you ask the assistant about your schedule, calendar event data (such as titles, times, and descriptions) may be sent to Anthropic to produce the answer. Anthropic processes that data to provide the feature and, under our arrangement, not to train general models.
Humans do not read your Google user data except (a) with your consent, (b) when needed for security (for example investigating abuse), or (c) to comply with law.
Refresh tokens used to keep Google Calendar connected are stored encrypted. You can disconnect Google Calendar in Moun or revoke access in your Google Account.
7. How we share information
We share information only:
with the processors in Section 5, to operate the Service;
if we reasonably believe disclosure is required by law, legal process, or a lawful government request, or to protect users, the public, or Zima;
in a merger, acquisition, or sale of assets, in which case the recipient must honor this Policy or we will notify you as required by law.
We do not sell your personal information.
8. Security and encryption
We use technical and organizational measures that are reasonable for a consumer app of this kind.
In transit. Traffic between the app and our backend uses HTTPS/TLS.
At rest — Memory Cards, reminders, and synced calendar text. Titles, bodies, addresses, links, and similar fields are encrypted with a per-user data key (AES). That data key is wrapped with Google Cloud KMS and unwrapped only by our authenticated backend when the app or a server feature needs it. On the device, the unwrapped key is kept in the platform secure store (Keychain / Keystore) when available.
Search. Because encrypted text cannot be searched as plain SQL text, we store HMAC tokens (a blind index) and embeddings. Those let us find your Memory Cards without keeping a second readable copy of the body for search.
Chat. Assistant conversations are stored so history works. Chat is processed in readable form by the AI provider. Do not put secrets in chat if you would not send them to an AI service.
Files. Photos and other files live in our storage provider and are encrypted at rest by that provider.
Access control. Database row-level security is configured so one account cannot read another account’s rows.
What this is not. Moun is not a zero-knowledge or end-to-end encrypted vault. Our systems can unwrap your data key to provide search, sync, the assistant, and support. Authorized personnel could access data if required for security, abuse, or law. If you need a product where even the operator cannot read your data, Moun is not that product.
Do not store passwords, government ID numbers, or full financial account numbers in Moun.
No system is perfectly secure. We cannot promise that data will never be lost or accessed without authorization.
9. Retention
We keep information while your account is active and as needed to provide the Service.
Temporary one-off reminder locations are deleted 48 hours after use.
If you delete a Memory Card, reminder, chat, or photo, we remove it from your active account.
If you delete your account, we delete or de-identify personal information and User Content within a commercially reasonable time, except where we must keep something for law, disputes, or enforcement. Encrypted backups may hold copies for a short period until they rotate.
10. Your rights and choices
Depending on where you live, you may have the right to access, correct, delete, or export your information, to withdraw consent for optional processing (location, calendar, notifications), and to object to or restrict certain processing.
You can do many of these in the app: edit or delete content, disconnect Google or device calendar, turn off permissions, or delete your account. You can also email us (Section 15). We will respond in the time applicable law requires.
If you are in the EEA, the UK, or a similar jurisdiction, we process data to perform our contract with you, with your consent, for legitimate interests in running and securing the Service, and to comply with law.
11. Account deletion
You can delete your account in the app or by emailing privacy@moun.app. Deletion removes your Memory Cards, reminders, chat history, AI-derived indexes, photos we store, and calendar authorization tokens from your active account, subject to Section 9. Instructions: https://moun.app/delete-account.
12. Children
Moun is not directed at children under 13 (or the higher digital-consent age in your country). You must be at least 13 to use Moun. If you believe a child has given us personal information, contact us and we will delete it.
13. International transfers
We and our processors may process data in countries other than yours, including the United States. Where required, we use appropriate transfer safeguards. By using Moun you understand that your information may be processed in those places.
14. Changes
We may update this Policy. For material changes we will update the date above and, where appropriate, notify you in the app or by email. Continued use after the change means you accept the updated Policy.
15. Contact
Zima LLC
Email: legal@moun.app (legal) · privacy@moun.app (privacy requests)
Website: https://moun.app
If a translation of this Policy conflicts with the English version, the English version governs.
© 2026 Zima LLC. All rights reserved.