Skip to main content
←Back to Home

Privacy Policy

Last updated: September 2026

1. Our Architecture: Privacy by Structure

Mana is built on a simple architecture: Circles are the only audience primitive.

  • Private Circles: Every member receives their own Private Circle. Notes, drafts, and private reminders saved here cannot be viewed by household owners, guardians, or administrators.
  • Home & Extended Circles: Items shared with a Home or specific Circle (e.g. sitters, grandparents, carpools) are visible only to active members of that Circle.
  • Provider-Managed Encryption: Data is encrypted in transit via modern TLS (TLS 1.3) and at rest using provider-managed AES-256 encryption on Google Cloud and Firebase. We do not claim universal client-to-client end-to-end encryption, because features like background reminders, search indexing, and authorized assistant retrieval require trusted server computation.

2. Information We Collect

We collect only what is necessary to coordinate your household:

  • Account Information: Name, email address, and profile photo when you sign in via Google Sign-In, Apple Sign-In, or email verification code. For guardian-managed accounts (e.g. children or dependents), an account is created with a display name and avatar without requiring an email address or third-party auth identity.
  • Household Content: Tasks, calendar events, shopping lists, recipes, notes, meal plans, and circle messages you create.
  • Attachments & Media: Photos or documents you upload (such as recipe photos or note attachments), stored in Google Cloud Storage with strict audience access rules.
  • Push Notification Tokens: Device tokens (Firebase Cloud Messaging / Apple Push Notification service) used exclusively for operational reminders and circle updates.
  • Operational Telemetry: Aggregated, privacy-preserving performance metrics (command response times, error rates, quota utilization) with all private content, entity names, and user identifiers stripped.
  • Marketing Website Analytics: Google Analytics 4 (GA4) on our public marketing website (ourmana.app) to understand aggregate traffic. You can opt out at any time by loading any page with ?no-analytics=1.

* Mana does not collect precise GPS tracking, health sensor data, browsing history, or biometric data, and we never sell personal data to advertisers.

3. AI & Model Processing

Mana includes an assistant powered by Google Gemini models:

  • Strict Audience Boundaries: When you ask Mana a question, context retrieval queries only the active Circle and your Private Circle. Untrusted user context is escaped to protect against prompt injection.
  • No Model Training: Your household conversations, schedules, notes, recipes, and private items are never used to train third-party foundation AI models.
  • Confirmed Actions: For consequential operations (such as deleting items or changing permissions), Mana asks for your explicit confirmation before executing.

4. Integrations & Model Context Protocol (MCP)

Mana supports external AI clients (like Claude, ChatGPT, or Cursor) through the open Model Context Protocol (MCP):

  • Scoped Permissions: Connected MCP agents are granted read and add permissions only. They cannot delete content or send unprompted messages.
  • Server-Only Secrets: External OAuth refresh tokens and credentials are encrypted and stored in server-only secure storage, never exposed to client applications.
  • Revocable Anytime: You can review or revoke any connected integration at any time in Settings → Agent access.

5. Data Retention & Lifecycle

  • Active Data: Retained for as long as your account and household remain active.
  • Soft-Delete & Undo: Deleted objects enter a 30-day soft-delete retention window before permanent hard purge, allowing immediate Undo and recovery from accidental deletions.
  • Activity Logs: Transient activity feed entries have a 90-day retention time-to-live (TTL), after which they are automatically purged.

6. Data Exports & Account Deletion

You maintain complete ownership of your family data:

  • Full Data Export: You can download a complete, machine-readable JSON export of your personal and household data at any time via Settings → Export My Data.
  • Account Deletion: You can delete your account inside the app (Settings → Delete Account) or via our web deletion portal. Upon deletion, your authentication record, personal profile, push tokens, and Private Circle data are permanently purged. Shared household items stay with the household so remaining members aren't left with broken schedules.

7. Children & Managed Accounts

Mana is designed for real households, including young children and dependents. Guardians can create managed accounts without requiring an email address. Guardians maintain oversight over these accounts, and any circle invitations or outward sharing must be approved by a guardian.

8. Subscriptions & Billing

Paid subscriptions (such as Mana Plus) are processed directly by platform app stores (Apple App Store, Google Play) or Stripe. Payment card details are handled directly by the payment processor and are never stored on Mana servers. Subscription entitlements are managed server-side and are independent of circle roles.

9. Service Providers & Infrastructure

We use trusted cloud infrastructure to deliver Mana:

  • Google Cloud Platform & Firebase: Hosting, database (Cloud Firestore), Cloud Storage, and Cloud Functions.
  • Google Gemini API: AI inference processing.
  • Apple & Google: Push notifications and in-app purchase processing.

10. Contact Us

If you have questions regarding this Privacy Policy or your data, reach us at: hello@ourmana.app