Privacy Policy
Your journal should be yours.
Effective 27 August 2026
1. The short version
- Your journal entries are encrypted on your device with AES-256-GCM before they reach our servers. What we store is ciphertext.
- Every entry you finish sends its full text to the AI, for a private safety check that runs even when you don't get a reflection that day. Tapping Go Deeper mid-entry sends your draft the same way, before the entry is finished. Once you finish, a full entry can send its full text more than once: for that safety check, for a reflection if you're within your allowance, to update what Mann remembers about you, and, if the check finds a crisis signal, once more to write the helpline message itself. If you're premium, once Mann has reflected on an entry its full text goes one further time, for a longer second reflection; the app asks for that as soon as you're looking at the finished entry, which is the screen you land on right after saving. Either way it is processed in flight and not kept; we'd rather you hear this from us than discover it.
- We never receive the key that unlocks your entries, so we have no way to read them. What happens if you switch phones differs by platform: see Section 4.
- Your chat conversations with Mann are not encrypted yet. We store them so Mann can remember the conversation.
- Mann asks for your consent to AI processing the first time you use any AI feature, whether that is finishing an entry, Go Deeper, chat, or the mic. Because even a plain entry gets the private safety check above, finishing an entry always needs this consent, whichever surface asked for it first. If you decline, that action does not go through: there is currently no way to use Mann's AI, including saving an entry, without it. You can withdraw this consent any time with one switch in Profile → Privacy → AI features; withdrawing pauses every AI feature, including finishing new entries, until you turn it back on. The switch is shipping in the current app update: if your app doesn't show it yet, write to us and we will action the withdrawal for you. Deleting your account (Section 8) also works.
- We never sell, rent, or trade your data. There are no advertisers.
- Mann is for adults 18 and older. We do not knowingly collect data from minors.
- You can delete every byte of your data at any time, in the app or at mannjournal.app/delete-account. Deleted immediately and permanently.
- We comply with India's Digital Personal Data Protection (DPDP) Act 2023 and the Information Technology Act 2000.
2. Who we are
"Mann" (this site, the iOS and Android apps, and the underlying service) is operated by MZEUS LABS LLP. For general questions, write to support@mannjournal.app. For DPDP related requests, put "DPDP request" in the subject line and write to our Grievance Officer at grievance@mannjournal.app. We respond within 30 days.
3. Everything we store
This is the complete list. If something we hold isn't named here, that is a mistake in this page. Write to us and we will fix it.
Encrypted, and we cannot read it
- Your entry text: everything you wrote, and everything Mann wrote back.
- The notes you attach to a mood.
Voice journaling
- Voice journaling is not available yet. Tapping the microphone does not capture or transcribe what you said at all: nothing about your actual recording is uploaded or stored. The app still makes an AI call at that point, and whatever the model invents gets appended into your entry as if you had said it. We are not describing this as a working feature until it actually transcribes your voice.
What Mann remembers between entries
- This is plaintext, the same as everything below headed “Stored in the clear”: we can read it, and it is part of what Section 5's “Comply with the law” would have to produce under a valid order.
- A short list of things you left unresolved, like “rishta meeting on Sunday” or “waiting to hear about the offer”. Mann writes these while it is reflecting on an entry, so that next time you open the app it doesn’t make you start from the beginning.
- They record something you said, never a conclusion about you. Mann keeps at most ten, drops them once they’re resolved, and forgets anything you haven’t touched in 30 days.
- You can see all of them and delete any of them in Profile → “What Mann remembers”.
Stored in the clear, with each entry
- The first 100 characters of your entry. This is what lets us show you a preview in your timeline without opening the entry.
- A mood score from 1 to 5, and the date. The mood is yours: you pick it when you finish an entry, and nothing overwrites it.
- The first names and relationship words you mentioned, like “mom”, “raj”, or “bua”. Not what you said about them. This is what powers the Cast of Characters card.
- A one-word theme for the entry, your word count, your tags, the focus area you picked, whether a reflection has been written yet, and whether the entry triggered our crisis-support response.
- Whether a free-write entry is still open, and until when.
Stored in the clear, on your profile
- Email address, display name, avatar emoji, language, your journaling style, and up to three reminder times.
- Your gender or pronouns, your reasons for journaling (work stress, family pressure, loneliness, and the rest of the options you picked at sign-up), and your living situation. These shape how Mann talks to you. They are optional at sign-up and you can leave them blank.
- Your streak, longest streak, total entries, total words, last entry date, and timezone.
- Push notification tokens, and whether you've consented to AI features.
- A device identifier, written when you sign in. On Android this is the Android ID. On iOS it is the vendor identifier, or a random ID the app creates and keeps in the Keychain when the vendor identifier is unavailable. We keep it so that a suspension applies to the device, not only to the account. It is never shared with anyone, and never used for ads or analytics.
- A review flag, set automatically if your usage crosses our abuse limits.
- A review flag, set automatically if an automated check finds an attempt to manipulate the AI. With it we store the time, which check fired, and where in the app it happened. Never the text you wrote.
Stored in the clear, elsewhere
- Weekly summaries built from the above: daily word counts, mood counts, which days you wrote, recurring themes, and the AI-written headline for your week.
- Your habits and completions, and your progress through any programs.
- Your notifications, and the cached daily quote and memory nudge.
- Your community posts, which carry your account ID and your handle. See Section 7. Also the list of community members you have blocked, visible only to you.
- Daily and weekly counters of how many reflections, chat messages, and other AI features you have used against your plan, so we can enforce fair-use limits.
- If you are on iOS, an index entry mapping your purchase token back to your account, so a renewal notification can find its owner. Server-only, deleted with your account.
- Subscription and payment records: plan, dates, and identifiers from whichever store processed the purchase. Never card numbers.
- If our safety filter detects a crisis signal, a flag in our moderation queue containing your account ID, the entry ID, and how confident the filter was. It never contains your words: not the entry, not the phrase that triggered it.
- If an automated check finds an attempt to manipulate the AI, a flag in the same moderation queue with your account ID, the entry or chat session ID, which check fired, and where in the app it happened. Never the text.
- When you delete your account, an anonymous record that a deletion happened, with deliberately coarse ranges instead of exact numbers so it cannot be traced back to you.
Aggregate counts, not linked to you
- Which screens get used, feature engagement, retention, AI cost telemetry, and daily totals across all users.
- Device model, OS version, and app version, used for crash reports.
4. What we cannot read
The text of your journal entries and your mood notes. These are encrypted on your device with AES-256-GCM before any network request. The key is generated on your device the first time you use Mann and stored in your phone's secure hardware: iOS Keychain or Android Keystore. We never receive it or hold a copy, so we have no way to read this content, and no way to recover it for you.
What happens if you switch phones is different on each platform. On Android, the key is bound to that device: reinstalling Mann or moving to a new phone means previous entries can no longer be opened. On iOS, the key is held in your device's Keychain, which Apple can include in an encrypted device backup; restoring that backup onto a new iPhone can carry the key with it, so entries may stay readable there. Either way, we never see or move the key ourselves. Mann shows any entry it can't open as locked rather than hiding it, so you always know it existed.
Three things this does not cover, stated plainly. Your chat conversations with Mann are stored unencrypted so Mann can remember them, and we can read those. Every entry you finish, even one that gets no reflection, is sent in readable form for a private safety check, and tapping Go Deeper sends your draft the same way before the entry is even finished. And a finished entry can be read by the AI more than once: for that check, for a reflection if you ask for one, to update what Mann remembers about you, and, if the check finds a crisis signal, once more to write the helpline message itself. See Section 5 for the full list.
We are working on encrypting chat. Key portability across devices is not a feature we have built: on Android it does not happen; on iOS it can happen today as a side effect of Apple's own device-backup system, which is not something we control or guarantee will keep working. This page will keep tracking both as they change.
5. How we use your data
- Run the app. Authenticate you, store your entries, deliver push notifications, charge subscriptions. Whether your entries can be opened on a second device depends on your platform; see Section 4.
- Only after you consent. The first time you use any AI feature, whether that is finishing an entry, Go Deeper, chat, or the mic, the app asks for your explicit consent and records when you gave it. Nothing you write is sent to the AI before that. Because every entry you finish afterward gets at least the private safety check described below, there is no in-app way to keep journaling while opting out of AI entirely once you have said yes. But saying yes is not permanent: the switch in Profile → Privacy → AI features withdraws consent as easily as you gave it. While it is off, nothing you write is sent to the AI, not even the safety check, and finishing new entries pauses. Turn it back on any time.
- Screen every entry for safety. The full text of every entry you finish is sent to Google Gemini, for a private check that runs even on an entry that gets no reflection that day (a free account past its daily allowance, for example). The same check also runs on your draft the moment you tap Go Deeper, before the entry is finished. This is the one AI step that always runs; see “Keep you safe” below for what happens if it finds something.
- Write reflections, and remember what matters. When you finish an entry and Mann writes back, that entry's full text is sent to Google Gemini again, twice in parallel: once to write the reflection, and once to pull out anything worth adding to what Mann remembers between entries (Section 3). Viewing a finished entry Mann has already reflected on is a separate trigger: if you are premium, that sends the entry's full text one further time, as a single call, to write a longer second reflection and label the entry with a theme. This happens on the screen you land on right after saving as well as on any later visit, and it happens once per entry. That one does not update what Mann remembers. Go Deeper is different again: tapping it sends your draft to Google Gemini twice in parallel too, but only for the safety check and the reply itself, before the entry is even finished; it never touches what Mann remembers either. None of these calls are stored by Google or used to train any model. Chat, daily quotes, memory nudges, Insights patterns, weekly reports, and the mic also carry a profile snapshot, described in Section 6, so responses feel like they know you; Go Deeper, reflections, and the safety check itself do not receive it. Daily quotes use only a short entry preview; nudges, patterns, and weekly reports may also include mood scores, timestamps, or your open threads (Section 3).
- Voice journaling. This is not a working feature right now. Tapping the microphone does not capture or transcribe what you said, but it does still make an AI call, and whatever the model invents is appended into your entry as if you had said it. We are not describing this as a working feature until it actually transcribes your voice.
- Keep you safe. If the safety check above finds a crisis signal, your full entry text is sent to Google Gemini once more, to write the helpline message itself; if that call fails, we show a fixed fallback message with the same numbers instead. A flag goes to our moderation queue; your words do not.
- Review misuse. Our servers check the text they already receive (the entry preview, a Go Deeper draft, a finished entry, a chat message) for attempts to override the AI's instructions. A match creates a flag in our moderation queue with the check name, the time, and the place in the app. A person reviews every flag before any action; the flagged text itself is never stored with the flag. After review we may suspend the account. A suspension stores the time, which team member applied it, and a short reason. A suspension also applies to the device: we keep a one-way hash of the device identifier in a server-only list, and a new account created from that device is suspended automatically. Lifting the suspension removes the hash. The app shows that the account is suspended; it does not state the reason. If your account is suspended, write to support@mannjournal.app to contest it or to have your data deleted.
- Improve the product. Aggregated usage metrics, never linked to entry content.
- Comply with the law. If we receive a valid Indian legal order, we can produce account metadata and everything listed as stored in the clear in Section 3. We cannot produce your entry text, because we cannot read it.
6. Third-party services
We use the smallest set of third parties needed to run Mann. Each one receives only what's listed below.
| Service | Purpose | What they receive |
|---|---|---|
| Google Firebase | Auth, Firestore, Cloud Functions, Storage, FCM (asia-south1, Mumbai) | Email, encrypted entry ciphertext, the plaintext metadata listed in Section 3 (previews, moods, names mentioned, profile fields), and push notification tokens. Everything is stored in the Mumbai region. |
| Google Gemini API | Safety screening, reflections, Go Deeper, chat, weekly insights, nudges, quotes, opening prompts | The full text of an entry every time you finish one, for a private safety check that runs even when no reflection is granted that day, and again on your draft the moment you tap Go Deeper, before the entry is finished. Once finished, the same full text can go again, in parallel, for a reflection: once to write the response, once more to update what Mann remembers between entries. Viewing an already reflected entry on premium, including the screen right after you save, sends the full text one further time, as a single call that writes a longer second reflection and labels the entry with a theme; that call does not update what Mann remembers. If the check ever finds a crisis signal, your full text is sent once more to write the helpline message, with a fixed fallback message if that call fails. Beyond full-text sends: your chat messages; your open threads, a recall hint, your focus area, time of day, a short mood summary, and your display name, to write the prompt that opens a new entry; and, on chat, daily quotes, memory nudges, Insights patterns, weekly reports, and the mic, a profile snapshot (first name, pronouns, language, your journaling style, why you journal, your living situation, habit names, streak, lifetime totals, current program, and 7-day mood average and trend) plus entry previews and moods, whose amount and detail vary by feature: a short preview of your last few entries for chat and quotes, previews and moods for up to your last 50 entries for Insights patterns, and every entry's preview, mood, and timestamp for the current week for weekly reports. Processed in flight, not retained by Google, not used for training. Nothing is sent before you give AI consent in the app. |
| Razorpay | Reserved for a future web checkout | Nothing today. The code that would create a Razorpay order exists, but no page on this site or in the app calls it yet; every live subscription runs through Google Play Billing below. If that changes, this row changes with it. |
| Google Play Billing | In-app subscriptions (Android) | Your account ID (attached to the purchase) and the plan you chose. Payment details stay with Google. We never see them. |
| Apple App Store | In-app subscriptions (iOS) | A UUID derived from your account ID (the purchase's account token) and the plan you chose. Payment details stay with Apple. We never see them. |
| Firebase Crashlytics | Crash reports (mobile) | App version, device model, stack traces. No personal content. |
| Firebase Analytics | Product analytics | Screen and feature events, device and app metadata. Never entry content. |
| Apple & Google | Sign-in and push delivery | An account identifier, for users who sign in with Apple or Google. |
7. Community posts are pseudonymous, not anonymous
Other members see only your handle: never your name, never your email. But the post is stored with your account ID attached, so Mann can link a community post to your account. We use this to action reports and enforce our community rules.
When you delete your account we remove that link permanently. The post text stays, because it is part of conversations other people are still having. If you want a specific post gone, delete it before deleting your account, or write to us.
8. Data retention and deletion
We keep your data only as long as your account is active. There are two ways to delete: tap Delete account in the Profile tab of the app, or sign in at mannjournal.app/delete-account if you no longer have the app installed. Either way, once you confirm we run a cascading deletion across:
- Your user profile, encrypted entries, mood logs, chat sessions, habits
- Everything Mann remembered between entries (the open-thread list in Section 3)
- Your weekly reports, notifications, cached AI nudges
- Your subscription record
- Your Firebase Auth account
Community posts are the one exception. The post text stays up, since it is part of other people's conversation too, but your account ID, your handle, and your reactions are stripped from it, so nothing connects it to you.
Deleted immediately and permanently. It is not queued, and there is no grace period during which we secretly keep things. Your sign-in stops working the moment it finishes. Residual copies in system backups are purged within 30 days. Once it's done, it cannot be undone. We keep an anonymous record that a deletion happened, with coarse ranges instead of exact numbers, so it cannot be traced back to you. Payment records our payment processor must retain under Indian tax law stay with them for the mandated period.
9. If something goes wrong: data breaches
If a breach of personal data ever affects you, we will tell you. We commit to notifying affected users without undue delay, in plain language: what happened, what data was involved, what we have done about it, and what you can do. We will also notify the Data Protection Board of India in the manner and timelines the DPDP Rules prescribe. Two structural facts limit what a breach of our systems can expose: your entry text is ciphertext to us (the key never leaves your device), and we hold no card numbers or payment credentials at all.
10. Children: Mann is 18+
Mann is intended for users aged 18 and older. We display an age-gate during sign-up and ask you to confirm. We do not knowingly collect personal data from anyone under 18. If you believe a minor has created an account, write to grievance@mannjournal.app and we will remove the account. Once we run it, deletion is immediate and permanent.
11. Your rights under DPDP Act 2023
As a Data Principal under the DPDP Act, you have the right to:
- Access the personal data we hold about you (account fields, metadata; entry ciphertext can be exported but not decrypted by us).
- Correct inaccurate data: most fields can be edited in the app directly.
- Erase all your data. See Section 8.
- Withdraw consent at any time. The lawful basis for processing is your consent given at sign-up, plus the separate AI consent the app asks for the first time you use any AI feature. Because every entry gets at least a private safety check, there is no in-app way to keep journaling while opting out of AI entirely; the only ways to withdraw are to delete your account (Section 8) or write to us.
- Nominate a person to exercise these rights on your behalf if you die or become incapacitated. Write to our Grievance Officer with “DPDP nomination” in the subject to record or change a nominee.
- Grievance redressal: write to our Grievance Officer at grievance@mannjournal.app. We respond within 30 days. If you are unsatisfied with our response, you may complain to the Data Protection Board of India through the Board's complaint mechanism under the DPDP Rules; we will link the Board's portal here once it is operational.
When you write to us with a DPDP request, we verify it came from you by replying to your registered email address before acting on it.
12. Crisis resources (always free)
Mann is a journaling tool, not a medical service. If you need to talk to a human right now:
- iCall 9152987821 · Mon to Sat, 8am to 10pm
- Vandrevala Foundation 1860-2662-345 · 24/7
- NIMHANS 080-46110007 · 24/7, toll-free
13. Medical disclaimer
Mann does not provide medical advice, diagnosis, or treatment. AI reflections are reflective prompts, not clinical guidance. Nothing Mann says should substitute professional mental health care. Always consult a licensed therapist or psychiatrist for medical concerns.
14. Changes to this policy
If we make material changes, we'll notify you via email and an in-app banner at least 30 days before they take effect. Minor edits (clarifications, typos) are published silently. The "Effective" date at the top tells you the latest version.
Questions? Write to support@mannjournal.app. We answer.