Privacy policy

Moment: Run of Show privacy policy

Last updated: September 25, 2026

Moment is a free event app for iPhone and iPad made by All Things AI, Inc. Organizers use it to run events, communities (a chapter, club or school group) use it to keep their members in one place, and guests use it to join them. This policy explains exactly what Moment collects, who can see it, what never leaves your phone, and how long we keep things. It covers the app and the Moment pages on allthingsn.com (the web demo, invite links and the report form).

The short version

  • We collect what it takes to run an event or a community: your name, your email, your account ID from Apple or Google, what you do in the events and communities you join, and any optional profile details you choose to give a community.
  • For payments we only store the status (paid, amount, time, ticket type). Moment never processes payments and never sees card, bank, Venmo, PayPal or Cash App details.
  • Photo wall photos go directly from phone to phone and never reach our servers.
  • No ads, no tracking, no selling or sharing of your data, no AI, no third-party analytics.
  • Contact Us opens your own email app. Moment doesn't carry or keep messages between members and a community.
  • You can delete your account in the app at any time.

What we collect

Your account

When you sign in, we receive your name, email address and an account ID from Apple or Google.

  • Sign in with Apple: if you choose "Hide My Email", we only get Apple's private relay address. Apple may not share your name after the first sign-in, and you can change your display name in the app.
  • Google: Moment signs you in through allthingsn.com's own Google sign-in. Google shares your name, email address and Google account ID with allthingsn.com, which creates (or reuses) an allthingsn.com account for you. That account is covered by our company privacy policy. The site then passes a one-time, five-minute sign-in token to the app.

Events you join or run

  • The events you join or run, your role in each (organizer, co-admin, check-in staff or attendee), and when you joined.
  • Your check-in time and how you were checked in (pass scan, from the list, or self check-in).
  • Your answers to polls and questions the organizer asks in the event.
  • Which announcements you've opened, so organizers can see how many people read an update.
  • The short payment code Moment shows you, which lets an organizer's Zeffy form match your payment to you.

Communities you join

  • The communities you belong to, your role (member, admin or super admin), your membership status (for example waiting for approval) and when you joined, after you enter the community's registration code.
  • Optional member profile details the community asks for and you choose to fill in, such as a phone number, city, or the names of family members who attend with you.
  • Extra email addresses you confirm so registrations made with them reach your account (useful if you use Sign in with Apple's "Hide My Email"). We email a 6-digit code to each address; unconfirmed addresses are deleted after 7 days.
  • Event registrations: when an organizer's connected Zeffy form lists an email as a participant (the buyer or a ticket holder), we record the name and email as entered, the event, and the payment it came from, and show the event in that person's My Events once they have a Moment account with that confirmed email.
  • Community notifications you receive, and whether you've read them, so admins can see how many members read an update.
  • If you allow notifications, your device's push notification token, used only to deliver community and event notifications. It's removed when you delete your account or the token stops working.

Contact Us opens your own email app addressed to the email the community's admins chose. Moment doesn't send, read or store those messages. An event's shared photo album, if the host adds one, is a link to the host's own Google Drive or Google Photos album; what you add there is handled by Google under their terms, not by Moment.

Payment status, never payment details

Moment does not process payments. When you pay, you pay the organizer directly through a link (Venmo, PayPal, Cash App or another site) or through the organizer's Zeffy page. Payment pages open in Safari or the provider's app, and what you do there is covered by that provider's privacy policy. What Moment stores is the status of a payment for an event: whether it was paid, the amount and currency, when it was paid, any refund, and the ticket type. That status comes from one of three places:

  • The organizer's Zeffy account, only if the organizer connected it. We receive payment records for the campaigns they linked, including the payer name and email as entered on the Zeffy form, and match them to attendees.
  • The organizer, who can mark you as paid.
  • You, if you tap "I've paid" (with an optional note) so the organizer can confirm it.

We never see or store card numbers, bank details, or Venmo, PayPal or Cash App credentials. Payment status is informational only and never unlocks anything in the app.

What organizers upload

Event details (title, description, venue, schedule, links, FAQs, hosts), logos, banners, and the photos and videos attached to announcements, and payment link QR images are stored on our servers so attendees can see them. Organizers can add co-admins and check-in staff by email address. If an organizer connects Zeffy, their Zeffy API key and webhook secret are stored encrypted and are never shown back, not even to them.

Safety reports

If you report something, we store what you reported (for example an announcement, a person or an event), your reason and details, and your email address if you give it. If you report a photo from the photo wall, that one photo is sent to us so we can review it. That's the only way a photo wall photo ever reaches us.

Server logs

Like any web service, our servers record technical request logs (IP address, time, the request made and the result) to keep the service secure, stop abuse and fix errors. They are kept only as long as needed for that and are not used to profile you.

Who can see what

Who can see your information in Moment
WhoWhat they see
Organizer and co-admins of an event you joinedYour name, email address, when you joined, your check-in status and time, your payment status for that event (including the payer name and email from Zeffy, and any "I've paid" note), your poll and question answers, and whether you opened their announcements. Only for their own event. They can export their own event's attendee list.
Admins of a community you joinedYour name, sign-in email, any extra emails you confirmed, your role and membership status, the optional profile details you gave that community, your registrations for its events, and read counts for its notifications. Only for their own community. They can export their community's member list and an event's guest list (including registrations waiting for a matching account).
Check-in staff for that eventThe attendee list for that event: names, emails, check-in status and payment status, so they can run the door.
Other attendeesYour display name when you're on the photo wall together, and the photos you choose to share with them. Poll results are shown as totals, never who voted for what. If the organizer turns it on, attendees see how many people have joined, not who.
Attendees, about organizersThe event details, the organizer's name on announcements, and any hosts the organizer lists.
Everyone elseNothing. Event details are only shown to people who signed in and joined with the code. Invite links and the code check reveal no event details.

What never leaves your device

  • Photo wall photos. They go directly from phone to phone over Bluetooth and Wi-Fi between people at the same event, and are never uploaded to our servers. The one exception is a photo you choose to report.
  • Your photo library. Moment only gets the photos you pick to share, and those go to nearby guests, not to us. Saving a photo from the wall to your library happens on your phone.
  • Location metadata. Moment strips location and other EXIF metadata from every photo before it is shared. We don't collect your location.
  • Your camera. Scanning check-in passes happens on your device. Moment doesn't access your contacts.

To find nearby guests, the photo wall asks for Local Network access. Moment uses it only to connect to other Moment users at the same event.

Service providers

  • Our own infrastructure. Moment's API runs on a server we operate and rent from Amazon Web Services in the United States. Its database — accounts, events, attendance, check-ins, payment status and announcements — runs on hardware we own and operate in the United States. Organizer-uploaded logos, banners, announcement photos and videos, and payment QR images are stored encrypted in a private Amazon S3 bucket (US) used only by Moment. No outside company reads, analyzes or processes the data for its own purposes.
  • Apple for Sign in with Apple and for delivering the app through TestFlight and the App Store.
  • Google for Google sign-in, through allthingsn.com.
  • Amazon Simple Email Service (SES) to send the one-time codes that confirm an email address.
  • Apple Push Notification service to deliver notifications you've allowed.
  • Zeffy, only when an organizer connects their own Zeffy account to an event. We fetch that organizer's payment records for the campaigns they linked and receive Zeffy's signed payment notifications. We don't send Zeffy anything about you.

That's the full list. Moment has no advertising, no third-party analytics or tracking SDKs, and no AI. We don't sell your data or share it for advertising, and we don't track you across other companies' apps or websites.

How long we keep it

  • Your account, community memberships, profile details and confirmed emails: until you delete your account or leave the community. Unconfirmed extra emails: 7 days.
  • Community notifications: as long as the community exists; admins can delete them sooner.
  • Event data (attendance, check-ins, answers, payment status, announcements and organizer media): 12 months after the event ends, then deleted. If the organizer deletes the event sooner, it's deleted then.
  • Raw payment records received from Zeffy: 90 days. After that we keep only the payment status described above, for as long as the event data is kept.
  • Safety reports: 1 year, or longer when the law requires us to preserve them (for example, material reported to the National Center for Missing & Exploited Children).
  • Web demo sandbox: demo accounts and demo events are deleted after 24 hours.

Your choices and rights

  • Delete your account in the app: Settings → Delete account. This deletes your account, your community memberships and profile details, your confirmed emails, your push tokens, your event registrations, and the events you own along with their media, and signs you out of Moment on every device. Deletion happens immediately. To also remove Moment from the list of apps connected to your Apple ID or Google account, visit Settings → Apple ID → Sign in with Apple, or myaccount.google.com → Security → Third-party connections. Material we are legally required to preserve (see safety reports above) is the only exception.
  • Leave an event or community: you're removed from its attendee or member list.
  • Notifications: turn them off anytime in iOS Settings → Moment.
  • Hide your email with Sign in with Apple.
  • Ask us for a copy of your data, a correction, or deletion without using the app by emailing support@allthingsn.com. We answer within 30 days. Depending on where you live (for example California or the EU), you may have additional rights, and we honor them for everyone.

Reporting and takedowns

You can report any photo, announcement, person or event from inside the app, or without an account using our report form. We act on reports within 48 hours. That includes requests to remove non-consensual intimate images under the TAKE IT DOWN Act. Reports involving the safety of a child are escalated to the National Center for Missing & Exploited Children (NCMEC), as US law requires.

Age requirement

Moment is for people 13 and older and is not directed at children. If we learn that an account belongs to a child under 13, we delete it. If you think that has happened, email support@allthingsn.com.

Security

All traffic between the app and our servers is encrypted in transit. Sign-in sessions expire, integration secrets are encrypted at rest, and access to production data is limited to the people who run the service. No system is perfectly secure. If we ever have a breach that affects you, we will tell you.

Moment pages on allthingsn.com

The web demo keeps its sandbox sign-in in your browser's session storage, which is cleared when you close the tab. It talks to the same Moment service as the app. allthingsn.com itself, including these pages, is covered by our company privacy policy and cookie notice.

Changes and contact

If we change what Moment collects or how it's used, we'll update this page and the date at the top, and tell you in the app before a material change takes effect. Questions, requests or complaints: support@allthingsn.com, subject "Moment privacy", or use the support page.

Your use of Moment is also governed by our Terms of Use and Apple's Standard License Agreement (EULA).

All Things AI, Inc · Los Gatos, California, USA