Privacy Policy
Last updated: October 8, 2026
This Privacy Policy explains how Ananda Manifest & Affirmation ("we", "us", or "our") collects, uses, shares and protects information when you use the Ananda Manifest & Affirmation mobile app for iOS and Android (the "App"), and when you visit our website and blog at ananda-app-web.pages.dev (the "Website"). The App has no sign-up, and neither the App nor the Website uses advertising or analytics tools. This Policy describes exactly what we do collect, and why.
Contents
- Summary
- Information We Collect
- How Your Answers Are Used to Write Affirmations
- Our Website
- How We Use Your Information
- Service Providers & Sharing
- Purchases, Adapty & Refund Requests
- Data Retention
- Deleting Your Data
- Data Security
- Your Rights & Choices
- International Data Transfers
- Children's Privacy
- Changes to This Policy
- Contact Us
1. Summary
- No sign-up. The App creates an anonymous account the first time you save your details in Settings. We never ask for your email address, phone number or a password.
- AI, only with your permission. Nothing is sent to OpenAI until you tap "I Accept" on the App's "Your Data & AI" screen. After that, your first name, the focus you choose, your language and your two answers about your life are sent to OpenAI to write your affirmations. Your last name, account ID, IP address and device identifiers are not. You can change your choice at any time in Settings → Privacy & Safety.
- Android reinstalls. On Android, we store a one-way hash of your device's Android ID so your account and free-tier limits carry over if you reinstall the App on the same device.
- No ads or tracking. We don't sell your data, show ads, track you across other apps or websites, or collect advertising identifiers. The Website sets no cookies and has no analytics.
- Deletion. Settings → Delete My Data erases your name, answers, affirmations and favorites. Section 9 explains what remains and how to remove it too.
2. Information We Collect
2.1 Information stored only on your device
The App keeps some information on your device so it opens quickly and works offline. It is not sent to us, except as described elsewhere in this Policy:
- a copy of your profile, your current affirmations, your favorites, your daily streak and your App language;
- edits in Settings that you haven't saved yet, kept as a draft until you save or delete them;
- your reminder and Home Screen widget settings. Daily reminders are scheduled by your device itself, and we don't collect push-notification tokens;
- your answer on the "Your Data & AI" screen (accepted or declined) and when you gave it;
- the times of any problem reports you've sent in the last 24 hours, so the App can limit reports to two a day per device; and
- your sign-in session, kept in secure storage backed by the iOS Keychain or the Android Keystore.
Some features run entirely on your device. Reading an affirmation aloud uses your device's built-in text-to-speech. Sharing an affirmation creates the image on your device and passes it to the app you choose in the share sheet. The Home Screen widget shows affirmations from the copy stored on your device. We don't receive the audio, the shared image, or who you share it with. The App may also run security checks on your device (for example, to detect an emulator, a rooted or jailbroken device, or a modified copy of the App). These checks run on your device, and their results are not sent to us.
Uninstalling the App deletes this information from your device. The one exception is that iOS may keep your sign-in in the Keychain (see 2.2).
2.2 Your anonymous account
The first time you tap "Save Changes & Calibrate AI" in Settings, the App creates an anonymous account with our backend provider, Supabase. The account is identified by a randomly generated ID, not by your name, email address or phone number. We also assign a second random ID that links your account to your purchases in Adapty (see Section 7).
- iOS: your sign-in is kept in the iOS Keychain, which iOS may keep after the App is deleted. Reinstalling the App on the same device can therefore reconnect your account. We do not collect a device identifier on iOS.
- Android: Android erases the sign-in when the App is uninstalled. So that a reinstall on the same device can reconnect your account, the App sends us a one-way, salted SHA-256 hash of your device's Android ID (the "hashed device ID"). We never receive the Android ID itself. The Android ID is specific to this App on your device, and it changes only after a factory reset. We use the hashed device ID only to restore your account and to apply free-tier limits per device. We never use it for advertising or to track you across other apps.
2.3 Your personalization ("Personal Essence")
When you save Settings, we store the following with your account:
- your first name (required) and last name (optional);
- your affirmation mode: Daily Affirmation, Goals, Job Loss, Divorce, Family Issue or Manifestation;
- your language, one of 70 supported languages; and
- your two answers, "past milestones & anchors" and "current challenges & daily motivation", of 20–300 characters each.
Your mode and answers may reveal personal circumstances, such as a divorce or a job loss. We use them only to write your affirmations.
2.4 Affirmations, favorites and usage
- Your current set of affirmations (the latest 7), so they can be restored if you reinstall the App.
- Favorites. These are always stored on your device. If you have an active subscription, we also store a copy on our servers so you can restore them on a new install.
- Usage and limits: whether you have used your free affirmation generation, the time of your latest generation, how many free profile saves you have used, your daily streak, and when your account was created and last updated.
2.5 Technical, security and log data
- IP address. Our server uses the IP address of each request to limit how many free generations and account-recovery requests can come from one network, to prevent abuse. These counters are deleted after about 25 hours.
- Server logs. Each request to our backend is logged with the feature used, the result, how long it took, your IP address and your anonymous account ID. Failed requests also log your device's user-agent string, which contains basic device and software information. Our hosting provider keeps these logs for a short time, currently about one day.
- Security and audit events. Certain events are recorded with the IP address and account ID and kept for 90 days. Examples are an exceeded rate limit, a failed authentication, a data deletion, a change in subscription status, or a server error.
Our logs never contain your name, your answers, your affirmations or your favorites.
2.6 Problem reports you send
If you use Report a problem (Settings → Privacy & Safety) to tell us about an affirmation that seems offensive, harmful or inappropriate, we receive:
- the reason you choose and any message you write (up to 1,000 characters);
- if you choose to include them, the affirmations you were shown, so we can see exactly what you're reporting;
- your App language, affirmation mode, platform (iOS or Android) and App version;
- your anonymous account ID, if you have an account; and
- your IP address, used only to limit each network to 10 reports a day.
We use reports only to review and improve the affirmations the App writes and to meet the App Store's and Google Play's rules on AI-generated content. Reports are not sent to OpenAI or to anyone else. Please don't include personal details in your message.
2.7 Purchase information
If you buy a subscription or another in-app purchase, purchase information is processed as described in Section 7.
We do not collect your email address (unless you email us), phone number, contacts, photos, location or advertising identifiers, and the App doesn't contain third-party analytics or advertising SDKs.
3. How Your Answers Are Used to Write Affirmations
3.1 We ask for your permission first
Before anything is sent to our AI provider, the App shows a "Your Data & AI" screen that explains what is shared, what is never shared and why, and asks for your permission. It appears the first time you open Settings, or when you first tap "Generate Positivity" if you haven't answered yet.
- If you tap I Accept, your details are sent to OpenAI each time you generate affirmations, as described below.
- If you tap I Decline, nothing is sent to OpenAI, and the App can't write new affirmations for you. You can still read the affirmations and favorites you already have.
- You can change your answer at any time in Settings → Privacy & Safety. Withdrawing permission stops future sharing. It doesn't affect information already sent.
Your answer is stored only on your device, so if you reinstall the App, it asks you again.
3.2 What is sent
When you tap "Generate Positivity" after giving permission, our server sends the following toOpenAI, our AI provider: your first name, affirmation mode, language and yourtwo answers. We do not send your last name, account IDs, hashed device ID, IP address or purchase information. OpenAI returns the text of your affirmations, which we save to your account and send to your device.
Under OpenAI's API data policy, data sent through its API is not used to train OpenAI's models. OpenAI may keep it for up to 30 days to monitor for abuse, unless the law requires longer. OpenAI may process this data in the United States (see Section 12). We do not use your answers or affirmations to train any AI model.
Saving your details in Settings sends them only to our own backend (Supabase), not to OpenAI.
4. Our Website
The Website, including the blog, is a static site. It has no accounts, forms, comments, cookies, analytics, advertising or social-media trackers, and it doesn't load fonts, scripts or other content from third parties.
- Hosting. The Website is hosted on GitHub Pages, a service of GitHub, Inc. Like any web host, GitHub receives your IP address and basic request information, such as your browser type and the page requested, when you visit, and it logs visitors' IP addresses for security purposes. We don't receive these logs or use them to identify you. SeeGitHub's Privacy Statement.
- Offline reading. The Website can be installed and read offline. To do this, your browser keeps copies of the site's files and the pages you open in its own storage on your device. This stays on your device and is never sent to us. You can remove it by clearing this site's data in your browser settings.
- Links to other sites. Links to the App Store, Google Play, research sources and other websites are governed by those sites' own privacy policies.
- Emails. If you email us, we receive your email address and whatever you include, and use them only to reply and to keep a record of your request.
5. How We Use Your Information
The "legal basis" column applies if you are in the European Economic Area (EEA) or the United Kingdom.
| Purpose | Information used | Legal basis |
|---|---|---|
| Create your anonymous account and restore it after a reinstall | Account IDs; hashed device ID (Android) | Performance of our contract with you |
| Write and show your affirmations, including sending your details to OpenAI | Personal Essence; generated affirmations | Your consent, given on the "Your Data & AI" screen; performance of our contract with you |
| Run streaks, favorites backup and the Home Screen widget | Usage information; favorites | Performance of our contract with you |
| Apply free-tier limits and unlock what you've paid for | Usage and limit information; hashed device ID; subscription status | Performance of our contract with you; our legitimate interest in preventing abuse of free features |
| Keep the App secure, prevent abuse and fix problems | IP address; server logs; security and audit events | Our legitimate interest in a secure, working service |
| Answer information requests from Apple about refund requests | See Section 7.3 | Our legitimate interest in handling refund requests fairly, and your consent where Apple requires it |
| Review problem reports about AI-written affirmations | See Section 2.6 | Our legitimate interest in keeping the App's content safe, and app store rules on AI-generated content |
| Reply to messages you send us | What you send us | Our legitimate interest in supporting users |
| Meet legal obligations | As required | Legal obligation |
Daily reminders rely on your device's notification permission, which you can withdraw at any time in your device settings. We do not use your information for advertising or profiling, and we don't make decisions about you that have legal or similarly significant effects based solely on automated processing.
6. Service Providers & Sharing
We share information only with the following service providers, and only so they can run the App for us:
| Provider | Purpose | Information shared |
|---|---|---|
| Supabase | Hosting, database, anonymous sign-in and server functions | The information described in Sections 2.2–2.5, and favorites if you subscribe |
| OpenAI | Writing your affirmations | First name, affirmation mode, language and your two answers (see Section 3) |
| Adapty | Subscriptions and in-app purchases, and answering Apple's refund information requests | See Section 7 |
| Apple App Store / Google Play | App distribution and payments | Apple and Google process your payment under their own privacy policies. We never receive your card or bank details. |
Each provider may use the information only to provide its service to us, and is bound by its terms with us to protect it to the same or an equal standard as this Policy. You can read their own policies here:Supabase,OpenAI andAdapty.
We do not otherwise share your information with anyone, except: (a) with your consent; (b) to comply with a legal obligation, court order or valid government request; (c) to protect the rights, property or safety of our users, the public or us; or (d) as part of a merger, acquisition or sale of assets, in which case we will tell you before your information becomes subject to a different privacy policy.
7. Purchases, Adapty & Refund Requests
7.1 Payments
Purchases are paid for through Apple's App Store or Google Play. We never receive your card or bank details.
7.2 Adapty
The App uses Adapty's software to show the subscription screen, process purchases and restores through the App Store or Google Play, and tell our server whether your subscription is active. Adapty receives:
- your Adapty customer ID, the random ID described in 2.2 (not your name);
- your purchase and subscription history: products, purchase and renewal dates, trials, cancellations, refunds and expiry dates;
- store transaction identifiers and receipts; and
- technical information that Adapty's software collects, such as a device or installation identifier and basic device and App information. Like any server, Adapty also receives your IP address when the App contacts it.
We set up Adapty so that it does not collect advertising identifiers (Apple's IDFA or Google's Advertising ID). Adapty tells our server only whether your premium access is active and when it ends.
7.3 Refund requests ("Refund Saver")
App Store. When you ask Apple for a refund of a purchase made in the App, Apple may ask us for information about how the purchase was used before it decides. We use Adapty's Refund Saverfeature to answer these requests automatically. The answer can include: the time since you installed the App, your total time using the App, an anonymous account identifier, how much of the purchase was used, whether it included a free trial, the total amount you've spent in the App and the total refunded to you, and our preference on whether the refund should be granted. Apple makes the final decision. We share this information only to answer that refund request, and never for advertising.
Apple requires your consent for this sharing. If you don't want this information sent to Apple, email us atPLACEHOLDER_SUPPORT_EMAIL@example.com with your App Store order ID (shown in your purchase receipt from Apple) so we can find your purchase. We will then record that you do not consent, and Refund Saver will stop sharing it. Opting out does not affect your right to ask Apple for a refund.
Google Play. Google Play does not ask us for usage information about refund requests. If you ask your bank to reverse a Google Play payment (a chargeback), Adapty may respond to Google's chargeback review for us. No personal information is shared with Google in that response.
8. Data Retention
- Personal Essence, current affirmations and favorites backup: until you use Delete My Data or ask us to delete your account.
- Remaining account record (account and Adapty IDs, hashed device ID on Android, free-tier usage, time of your latest generation and subscription status): for as long as the account exists. This record stays after Delete My Data, so that deleting your data doesn't reset free-tier limits or interrupt a subscription you've paid for. You can ask us to delete it (see Section 9).
- Problem reports: deleted automatically once they are 30 days old, by a cleanup that runs once a month, so each report is kept for between 30 and about 60 days. Reports are kept separately from your account, so Delete My Data doesn't remove them. You can ask us to delete a report sooner (see Section 9).
- IP-based rate-limit counters: about 25 hours.
- Server logs: about one day, set by our hosting provider.
- Security and audit events: 90 days.
- Emails you send us: as long as needed to handle your request, and no longer than two years.
- Records of subscription updates from Adapty (event ID, event type and Adapty customer ID): 30 days.
- OpenAI: up to 30 days, under OpenAI's API data policy (see Section 3).
- Adapty: purchase records are kept under Adapty's policies and as needed for accounting, tax and fraud prevention. When you ask us to delete your account, we also ask Adapty to delete its profile for you, except where the law requires those records to be kept. Apple and Google keep their own purchase records under their policies.
- Data on your device: until you use Delete My Data or uninstall the App. On iOS, your sign-in may remain in the Keychain after you uninstall.
9. Deleting Your Data
9.1 In the App
Open Settings, tap Delete My Data, then confirm. This immediately deletes the following from our servers: your name, affirmation mode, language, your two answers, your current affirmations, your favorites backup and your streak. It also clears the copy of this data stored on your device.
It keeps the anonymous account record described in Section 8: your account and Adapty IDs, your hashed device ID (Android), whether you have used your free generation and free saves, the time of your latest generation, and your subscription status. This record is no longer linked to your name or anything you wrote. Problem reports you have sent are also kept, for about 30 to 60 days (see Section 8).
Deleting your data does not cancel a subscription. To stop future charges, cancel in your Apple ID subscription settings or in Google Play's Subscriptions page.
9.2 Deleting your whole account
To have the remaining account record deleted as well, emailPLACEHOLDER_SUPPORT_EMAIL@example.com with the subject "Delete my account". Your account is anonymous, so we need a way to find it. If you have made a purchase, include its App Store or Google Play order ID. If you have never made a purchase, the remaining record contains only the random IDs, usage information and (on Android) the hashed device ID described above, and we can't match it to an email request.
We will act on your request within 30 days. We may keep the minimum information we need to meet legal obligations (such as tax records) or to prevent abuse of free features, such as the hashed device ID and a record that the free generation was used.
To have a problem report deleted sooner, email us with roughly when you sent it and what it said, so we can find it.
10. Data Security
- All communication between the App and our servers, and between your browser and the Website, is encrypted in transit with HTTPS/TLS.
- Our database host, Supabase, encrypts stored data at rest (AES-256).
- The App never accesses our database directly. Every request goes through our server functions, which check your sign-in first. Row-level security is enabled on every table, and our secret keys stay on our servers.
- Your sign-in session is kept in Keychain- or Keystore-backed secure storage on your device.
- We store only a hash of your Android ID, never the ID itself, and our logs exclude your personal content.
No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
11. Your Rights & Choices
- See and correct your information: view and edit your name, mode, language and answers at any time in Settings.
- Delete your information: see Section 9.
- AI sharing: allow or stop sharing your details with our AI provider at any time in Settings → Privacy & Safety (see Section 3).
- Get a copy of your information, or object to or ask us to restrict how we use it: email us (see Contact Us). We reply within 30 days, or sooner if the law requires.
- Notifications: turn daily reminders off in Settings or in your device settings.
- Refund information sharing: opt out as described in Section 7.3.
EEA and UK: under the GDPR and UK GDPR you have the right to access, correct, erase, restrict and port your personal data, to object to processing based on legitimate interests, and to withdraw consent at any time. You can also complain to your local data protection authority.
United States: if you live in a state with a comprehensive privacy law (such as California, Colorado, Connecticut, Virginia or Utah), you may have the right to know, access, correct and delete your personal information. We do not sell personal information or share it for cross-context behavioral advertising. We use sensitive personal information only to provide the App's features, and we will not discriminate against you for exercising your rights.
Other countries: laws such as India's Digital Personal Data Protection Act, 2023 and Brazil's LGPD give you similar rights. Contact us to exercise them.
12. International Data Transfers
Our database and server functions are hosted by Supabase in the European Union (Frankfurt, Germany). OpenAI may process the information sent for affirmation writing in the United States. Adapty is a US company and may process purchase information in the United States and other countries. The Website is hosted by GitHub, which may process visitors' request information in the United States. Where the law requires it, these transfers are protected by appropriate safeguards, such as the European Commission's Standard Contractual Clauses in our providers' data processing terms.
13. Children's Privacy
The App is not directed to children under 13, or under the higher minimum age that applies in your country (for example, 16 in some EEA countries). We do not knowingly collect personal information from children under that age. If you believe a child has given us personal information, contact us and we will delete it.
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will change the "Last updated" date above and, for material changes, tell you in the App or on this page before they take effect. If you keep using the App after a change takes effect, the updated Policy applies.
15. Contact Us
For questions about this Privacy Policy, or to exercise any of your rights, contact:
Ananda Manifest & Affirmation
Email: PLACEHOLDER_SUPPORT_EMAIL@example.com