Trust

Privacy is structural here, not a marketing claim.

Most apps write “your data is secure” and hope you never ask what that means. This page is the answer, including the two places your words are readable. We’d rather you hear it from us than find out on your own.

AES-256-GCM on deviceYour key never reaches our serversStored in Mumbai (asia-south1)DPDP Act 2023

The four pillars of Mann’s security

Locked behind your fingerprint

App lock uses your phone’s fingerprint or face unlock, nothing else. There is no PIN fallback, so if your device has no biometric enrolled the toggle simply won’t turn on. And it fails open on purpose: if enrollment is ever removed from the device, Mann quietly disables the lock and lets you in rather than stranding you outside your own journal. It protects casual access to the app. It is not a replacement for the on-device encryption that protects what you write.

Encryption

Entries are sealed with AES-256-GCM on your device before any network request. The key is a random 256-bit key generated the first time you use Mann and held in your phone’s secure hardware (iOS Keychain or Android Keystore). We never receive it, which means we have no way to read your entries, and no way to recover them for you.

Where it lives

Everything is stored in Google Cloud’s asia-south1 region, Mumbai. We use the smallest set of processors we can to run Mann: Firebase, Google Gemini, Google Play Billing, and the Apple App Store. Each receives only what it needs to do its one job. Razorpay is reserved for a future web checkout and receives nothing today.

Leaving is instant

Deleted immediately and permanently. Delete your account in the app or from this website. It is not queued, and there is no grace period where we quietly keep things. Once it is done, it cannot be undone, including by us.

See it, not just read it

What encryption actually looks like.

This is what happens the instant you finish writing. The plaintext above never touches our servers, only the scrambled version below does, and the key that could unscramble it stays on your phone.

What you write

Aaj bahut frustrated tha work se. Manager ne phir dismiss kar diya.

Encrypted on your device
What gets stored

The stored version is unreadable ciphertext.

AES-256-GCM, with a key generated on your phone and held in the device keychain. We never receive it, so we have no way to read your entries or move them for you.

The part other apps skip

The two places your words are readable.

Strong encryption and a useful AI are in genuine tension. Here is exactly where we’ve made that trade, and what we’re doing about it.

Exception 1

When you finish an entry

Its full text always goes to Google Gemini for a private safety check that runs on every entry so Mann can still recognize a crisis. If you’re within today’s free reflection allowance, or you have premium, it’s sent again to write your reflection and to note anything you left unresolved. The same happens when you tap Go Deeper mid-entry. On premium, viewing a finished entry Mann has already reflected on sends its full text one further time, to write a longer second reflection and label the entry with a theme; that happens on the screen you land on right after saving as well as on any later visit, once per entry. And if the safety check finds a crisis signal, your full text is sent once more, to write the helpline message itself. Every one of those is processed in flight and never kept. For daily quotes and memory nudges we send a short preview, the opening of the entry, instead.

None of your writing is sent before you say yes. Mann asks for your permission the first time it needs the AI, before you finish your very first entry.

Exception 2

Chat conversations aren’t encrypted yet

Mann needs to read your back-and-forth chat to remember it, so what you type there is stored as plain text, not ciphertext. We can read those. Journal entries are a separate store and stay encrypted.

Encrypting chat is on our roadmap. Until it ships, this page will keep saying so.

The trade-off worth knowing before you startBecause the key is generated on the device that first used Mann and never handed to us, we have no way to move it for you if you switch phones. Mann shows anything it can’t open as locked rather than hiding it, so you always know it existed. This is the cost of Mann genuinely not holding your key, and we’d rather pay it than pretend otherwise.

Full inventory

Everything we hold, in plain language.

If something we hold isn’t named here or in the privacy policy, that’s a mistake on our side. Write to us and we’ll fix it.

Encrypted, we cannot read
  • Your entry text, everything you wrote and everything Mann wrote back
  • The notes you attach to a mood
In the clear, with each entry
  • The opening of your entry (first 100 characters), for your timeline preview
  • A mood score, 1 to 5, that’s your own pick and never changed by the AI
  • First names and relationship words you mentioned, never what you said about them
  • A one-word theme, word count, tags, and the focus area you picked
On your profile
  • Email, display name, avatar emoji, language, journal style, reminder time
  • Optional: pronouns, reasons for journaling, living situation
  • Streaks, totals, timezone, push tokens, AI-consent timestamp
  • Your anonymous community handle
  • Subscription records, never card numbers
  • An internal review flag if unusual usage patterns ever trip one
What Mann remembers, and how to see itMann keeps a short list of things you left unresolved, so it doesn’t make you repeat yourself. It’s written from your entry when Mann reflects on it, holds at most ten lines, and drops anything you haven’t touched in 30 days. You can read every line and delete any of them at Profile → “What Mann remembers”.
Crisis flags never contain your wordsEvery entry is screened for signs of crisis so Mann can offer helplines instead of a reflection. What reaches our moderation queue is your account ID, the entry ID, a category, and a confidence score. Not the entry. Not the phrase that triggered it.

DPDP Act 2023

Your rights, and how to use them.

As a Data Principal under India’s Digital Personal Data Protection Act, you can do all of this, and we answer within 30 days.

Access

Everything we hold about you, on request. That includes your entry ciphertext, we can hand it over, we just can’t decrypt it for you.

Correct

Most profile fields (name, avatar, language, journal style, reminder time) are editable directly in the app. Email us for anything that isn’t.

Erase

Deleted immediately and permanently. No queue, no grace period, from the app or this website.

Withdraw consent

Stop using AI features and nothing more is sent to the model. Delete your account and everything goes.

Grievance redressal

Write to our Grievance Officer at grievance@mannjournal.app. If you’re unsatisfied with our response, you may escalate to the Data Protection Board of India.

Now you know exactly what you’re signing up for.

That was the point of this page.