Privacy
Your employer owns the record. Momiji holds it for them, and does what they say with it.
Momiji is an HRIS and payroll system for Canadian employers. The company that subscribes is the custodian of its people’s information: it decides what goes in, who may see it, and how long it stays. Momiji processes that information on the employer’s instruction and for no other purpose. We do not sell it, we do not share it, and we do not use it to train anything.
Effective August 29, 2026. Momiji is operated by Greystone Strategic Partners Inc., Ontario, Canada.
What that means in practice
If you are an employee and you want to see your record, correct it, or ask why something is in it, your employer is the right place to start. They entered it and they can change it. Momiji will not hand your record to you over your employer’s head, and would not want the power to.
If you are the employer, the opposite applies: it is your data, you can read all of it, and the answers to your people’s questions are yours to give. Where the law gives an employee a right of access or correction, that right runs against you as the custodian, and Momiji’s job is to make honouring it straightforward rather than to stand in the middle of it.
Under Canadian federal privacy law, and under provincial employment standards legislation that sets what employment records must contain and how long they must be kept, that split is the normal arrangement for a payroll system. We are stating it plainly rather than leaving you to infer it.
One thing that follows from it, since it is the question every buyer asks: Momiji has no feature that lets us log in as you. There is no impersonation, no view as tenant, no support login, and no role in the system that can read another company’s records. What access we do have is set out in what we do not claim, further down, because it belongs with the honest answers rather than inside a sentence about encryption.
What we hold
Everything below is entered by your employer, or produced by Momiji from what they entered:
- People. Name, email, phone number, job and department, employment dates, province of employment, pay rate, emergency contact, and whatever documents your employer chooses to keep on file.
- Time. Punches with their timestamps, the site they were made against, and the location reading taken at that moment where the device provides one. Timesheets, approvals, and the corrections managers make.
- Leave. Requests, balances, accruals, decisions, and who decided.
- Expenses. Claims, receipt images, and what a model read off those images for a person to confirm.
- Pay. Committed pay runs, statements, year-end slips, and the calculation trail behind each figure.
- Documents. Files uploaded, files generated, and signatures with the fingerprint of the exact bytes they signed.
- Required training. Which courses and certificates a person is assigned, when each falls due and when it lapses, and the completion itself: the date, the version of the document they read, how they finished it, their answers to a knowledge check and the score, the certificate they uploaded where the training was taken elsewhere, the signature and the certificate-stamped PDF where the course was signed, the address the completion was made from, and a fingerprint over the whole record. An exemption is kept the same way, with the reason it was granted.
- Questions asked of Akiko. The question, the answer, and the count of tokens the answer cost. A conversation is readable by the person who had it and by nobody else, administrators included; what an administrator sees is the counts, per person, and never a word of the words.
- The text of your own documents. Since 29 August 2026 the words in the handbooks, policies and contracts you upload are read out of the file and stored as searchable sections, so the help assistant can answer from what a document says rather than only from its title. It is your own document, kept beside your own document, and it is readable by exactly the people who may already open that document. Replacing a document replaces its text; deleting it deletes its text.
- Who did what. An audit record of privileged actions, including who released a salary figure and when, though never the figure itself.
What we never hold
There is no Social Insurance Number column anywhere in the schema. It was removed early and never came back. A SIN is keyed in only at the moment a T4 slip is generated, appears on that slip in your own vault, and is never written to a database field.
What we hold only if you turn it on
Bank details were in the paragraph above until direct deposit, and we would rather say so than leave a sentence standing that is no longer true. Direct deposit is off for every organization by default, and while it is off Momiji holds no payment destination for anyone: net pay leaves your own bank against a printed wire sheet.
Where an account owner turns it on, each employee enters their own account on the web. The institution, transit, account number and name on the account are stored only as ciphertext, under a key held in a vault outside the database, so a copy of the database carries no key. The table has row-level security on and no policy at all, so no signed-in role can read a row from it. The only route to the numbers themselves is a call the account owner alone can make, and it writes an audit line naming who read whose account before it returns anything. The Momiji mobile app holds no grant on any of it and never shows a deposit account.
We also hold no advertising identifier, no cross-site tracking profile, and no third-party marketing data about anyone. There is no advertising or attribution software in the product or in the app.
Where it lives
Every other company involved, and exactly what each one receives.
Momiji is not the only company that touches the system. These are all of them. If a vendor is not on this list, it does not receive your data, and if we add one this table changes before the vendor does.
All of them are established providers operating under their own security and privacy terms. Momiji runs on Supabase and Vercel and keeps its document backup in Cloudflare’s eastern North America region, so the honest summary of where your records sit is North America. We do not claim Canadian data residency: no part of this stack offers it today, and our backup vendor has no Canadian jurisdiction to offer even if the database did. If residency is a requirement for you, ask us before you buy rather than after.
The mobile app
What the app on your phone can reach, and when.
The Momiji app asks for a small number of permissions and uses each one for a single, stated job. The most common worry is the honest one to answer first: it does not follow you around.
- At the punch, once
Location
The app takes one reading at the moment you punch, and where the site has a geofence it compares that reading against the boundary. The reading is recorded on the punch whether the site is fenced or not, which we would rather tell you than have you assume otherwise. There are no watchers, no background location permission is requested, and nothing is read between punches. A punch made offline holds its coordinates on the device until it syncs, then they are deleted.
- When you open the camera
Camera and photos
The camera scans punch and room codes and photographs receipts. Your photo library is read only for the images you pick yourself, for a receipt or a profile picture. The app has no feature that records audio, and the microphone permission is stripped out of the Android build entirely.
- If you allow them
Notifications
A push token identifies your device to the notification service, and is registered against the organization you are signed in to so another tenant's notices can never reach it. Signing out removes it. If you refuse the permission, the app falls back to notices it generates on the device from your own reads, and those name the document waiting for you where a notice we send never would.
- Handled by the operating system
Face ID and fingerprint
Unlock is the phone's own check. Momiji asks iOS or Android whether it was you and receives yes or no. No fingerprint, face or passcode data reaches the app, and none of it reaches our servers.
- On the Pay screen
Screenshots
While the Pay screen is open, Android blocks screenshots and screen recording outright, and iOS blocks recording and mirroring. iOS offers no way to block a single still screenshot, so we do not claim one.
- Inside the app sandbox
What is stored on the device
Your session, your saved logins and any queued offline punches are encrypted at rest, each under its own key held in the iOS Keychain or the Android Keystore. The read cache that lets the app work without a signal is not encrypted: it holds for 24 hours inside the app's own sandbox, protected by the operating system, and it holds only rows you were already entitled to read. Signing out deletes all of it.
- Once per launch
A check on the device itself
The app asks whether the phone has been jailbroken or rooted, and reports the answer as a handful of true or false flags with the platform name. Nothing that identifies the handset, and no fingerprint of it. On a compromised device the Pay screen and document signing are withheld with a stated reason; everything else keeps working, so a rooted phone can still record a shift.
- On your home screen
The iOS widget
If you add the widget, a small snapshot is written where the widget can read it: hours this week, days of vacation left, your next shift, how many documents are waiting, and for a leader a headcount and pending approvals. Never a pay amount, and never a confidential colleague. It is not encrypted, because a home screen is not a private place to begin with.
Two more things worth knowing. The app does not track you across other apps or websites, so it never asks permission to, and there is no advertising identifier anywhere in it. And when you open a document, the app mints a link that expires in five minutes and hands it to your phone’s own browser rather than rendering the file itself, so from that moment the document is in your browser’s hands and subject to whatever it does with downloads.
How long records are kept
Retention is mostly your employer’s call, and where it is not, the reason is either the law or a deliberate design decision we will name.
- Location readings expire. Each company sets its own window, ninety days unless it changes it, and a nightly job erases the latitude, longitude and accuracy from every punch past that window. The punch itself stays, because the hours are the record; only the coordinates go.
- Payroll records are kept, and are permanent by design. Once a pay run is committed its register cannot be edited or deleted through the product, by anyone, including your own owner account. A correction is a new reversing run that leaves both on the record. Employment and payroll records also carry statutory retention periods under federal and provincial law, and where the law requires a record to survive, the product keeps it.
- Receipts and issued T4 slips are retained on purpose. Expense and payroll records need to outlast the person who filed them. The consequence is real and worth stating: a document filed in error cannot be deleted through the product today. If you need something removed, it is a conversation with us, not a button.
- A training completion is permanent, on purpose. It is the evidence the record exists for, so it is written once and never changed: a database trigger refuses every later edit and every deletion, including from the administrator who caused it to be written. The one thing that may still be added is the employer’s own countersignature, once. Correcting a training record is a new record beside it, never an edit of the old one.
- Akiko’s conversations are deleted. A conversation nobody has touched for ninety days is removed, along with its questions and answers, by the same nightly job that erases old punch coordinates. The count of tokens each answer cost survives, because that is the billing record and it carries none of the words.
- The audit log has no eraser. There is no update path and no delete path from the application, for any role.
- Abandoned drafts are cleaned up. A receipt image left behind by a deleted draft line, a deleted draft report, or a capture abandoned before it was ever attached, is reclaimed weekly once it is at least forty-eight hours old and provably attached to nothing. Each deletion is written into that company’s own audit trail. An image that is still referenced, or whose age cannot be established, is kept.
- Two things simply accumulate. An invitation that expires is marked expired rather than deleted, and the nightly document backup has no expiry on old copies. Neither is a leak, and both are records living longer than they need to, which is a different thing from a policy.
Your rights, and where to take them
If you are employed by a company that uses Momiji, ask your employer first. They are the custodian: access, correction, and questions about why something is on file are theirs to answer, and they can act on them the same day. Your own pay statements, slips and signed documents are already in your account for you to read and download whenever you want, one at a time. There is no single button that packages your whole record and none that erases it: both are requests we handle by hand today, and we would rather tell you that than imply a control that does not exist.
Deleting your account and your data
Your employer is the custodian of your record, so a deletion request starts with them, and they can close your account the same day. For anything Momiji holds beyond what your employer controls, write to hello@mymomiji.com from the address on your account and we handle it by hand. There is no single button that erases a whole record today, and payroll records your employer is required to keep are retained for the period the law sets, as described above.
Anything about Momiji itself is ours to answer, and you do not need to go through your employer for it: how the system processes information, what a subprocessor in the table above receives, how a control works, or a complaint about us. Write to hello@mymomiji.com and a real person will answer. If you are running a formal security or privacy review, ask for the migration, policy or test behind any line on this page and you will get it. Where the honest answer is that something is not built, that is the answer you will get; our security page lists what we do not claim, on purpose.
If we cannot resolve something with you, the Office of the Privacy Commissioner of Canada takes complaints about organizations subject to federal privacy law.
This website, separately
The page you are reading is the marketing site, and it holds nobody’s employee records. It uses PostHog to see how it is read: pages visited, clicks, and recordings of these public pages. Visitors are anonymous, there is no sign-in and no identify call in the code, and the identifier is a random value in a cookie. Query strings are stripped before anything is sent, which matters because the Stripe session id on the checkout success page could otherwise be exchanged for a buyer’s name. Two disclosures we would rather make than leave you to find: these recordings capture text and mouse movement on the public pages, and this site does not honour Do Not Track.
None of that analytics software is in the web app at app.mymomiji.com, and it never will be. In the app a captured URL would carry an employee’s identifier and a recorded screen would be a salary leak played back frame by frame, which is why usage measurement there is built server side, inside the same tenancy rules as everything else.
Starting a subscription hands you to Stripe, which collects your name, email and payment method. We receive a confirmation and the email you used, so we can reach you to begin onboarding. Terms covers the agreement itself.
What we do not claim
Our security page ends with the gaps rather than the strengths, and this page keeps the same habit, because the fastest way to lose your trust is to have you discover one of these yourself.
- Not everything on your phone is encrypted. The session, your saved logins and queued punches are. The 24-hour cache that lets the app work without a signal is not, and it can hold figures you have looked at, the coordinates on your own punches, and names from your directory. It sits inside the app sandbox under the operating system’s protection, which is real but is not the same as a key of ours.
- iOS declares permissions the app does not use. Building on Expo brings default purpose strings for always-on location, motion and the microphone. The app has no code that uses any of them and never asks for them, and on Android the microphone permission is removed from the build outright. On iOS the strings still ship, which is untidy rather than harmful, and it is on the list to fix.
- Analytics infers roughly where you are. We send PostHog no location at all, but it resolves the network address an event arrives from to an approximate city and country at its end. We do not use the result. It is derived, and we are not going to write a sentence that implies otherwise.
- Crash reports are scrubbed by rule, not by proof. Identity is an allowlist, and money, coordinates and query strings are removed by pattern and by field name. A name quoted inside an error message would be truncated rather than caught. The breadcrumbs that would realistically carry one, console output and what you typed and tapped, are dropped entirely.
- We hold no external audit. Momiji has no SOC 2 report and has not had an outside penetration test. Our reviews are internal, and we would rather say so than let a phrase imply otherwise.
- We can technically read your data. There is no impersonation feature and no support login, but the keys that run the nightly backups, the retention sweep and the scheduled jobs bypass every tenancy rule by design, and the people who hold those keys are us. That is the ordinary position for hosted software and it belongs in daylight rather than in a footnote.
Changes
This page changes when the system changes, in the same release, not on an annual review cycle. The effective date at the top moves with it, and subscribing organizations are told by email when a change is material rather than editorial.
Contact
Momiji is operated by Greystone Strategic Partners Inc. of Ontario, Canada. Privacy questions, access requests about Momiji itself, and security reviews all go to hello@mymomiji.com. This policy is governed by the laws of the Province of Ontario and the federal laws of Canada that apply there.