← Back to Inner Horizon

Privacy Policy

Inner Horizon · Legal

Privacy Policy

Effective date: 24 July 2026

🔒 Data stored in Europe (Ireland) · GDPR compliant

1. Introduction

The Inner Horizon application is committed to protecting the privacy of its users. This policy details how we process your personal data in the context of using our wealth simulator.

Data controller: Esteban Pedreira, sole proprietor (entrepreneur individuel), SIREN 984 472 068, 309 rue des Tarusates, 40600 Biscarrosse, France — support@manifestwealth.io. The app is published within the Manifest Wealth ecosystem (umbrella brand).

2. Data Collected

We collect the following information:

  • Identity: display name provided when creating a profile.
  • Account: when you create or recover an account via email one-time code (OTP) or account recovery, we receive at least an account identifier and the email address linked to that account. There is no sign-in via a third-party identity provider (Google, Apple, etc.).
  • Location: approximate position to adapt simulations (currencies, local real estate markets) — Premium feature only.
  • Simulation data: fictional assets and settings entered in the app (real estate, portfolios, fictional accounts).
  • Analytics: product usage events via PostHog (analytics provider, EU hosting by default, e.g. eu.posthog.com), tied to a user identifier only if you enable the “Audience measurement” setting; on iOS, Apple's App Tracking Transparency (ATT) prompt appears before any collection — you can decline and no tracking will occur.
  • Asset logos: the app displays listed-company logos as colored initials (on-device fallback). An optional Supabase Edge logo-proxy endpoint (Ireland), if still called by an older client build, returns Gone (410) and does not fetch or transfer logos from any third-party logo service. No personal data is sent to third-party logo providers.
  • Push notifications: if you enable notifications, a push token (device identifier) is stored and transmitted to Apple (APNs) and Google (FCM) notification services via Expo, to send you reminders.
  • Technical logs may also be kept for service reliability.
  • Crash reports: if the app crashes, a technical report (error trace, device model, OS and app version) is sent to our provider Sentry (Functional Software, Inc.), hosted in the European Union, so we can fix bugs. Reports are scrubbed before sending (emails, identifiers and addresses redacted), contain neither your IP address nor your account identifier, and are automatically deleted after 90 days. Legal basis: our legitimate interest in keeping the app reliable (Art. 6.1.f GDPR).
  • Payment data: handled exclusively by Apple App Store / Google Play via RevenueCat. We do not have access to your real banking details.

3. Artificial intelligence

We use our AI to produce personalised content from your profile and simulation data (local pack: names, assets, events, fortune narrative, notifications, heritage letters). These processes may involve secure transmission of data to our AI provider (Google Gemini). Google does not use this data (prompts and responses) to train or improve its models (paid Gemini API). Items useful for service continuity (cache, preferences, generation results) may be stored on our servers (Supabase, Ireland). These processes are not used to profile you for commercial purposes. Legal basis: your consent (Art. 6.1.a GDPR), given when using the relevant features. You may withdraw this consent by deleting your data from your profile.

Data about third parties (relatives, children, heirs): if you enter information about people close to you (first names, relationship, context), this data is processed strictly within the personal/family context of your use of the application. You are responsible for informing those persons about the processing and, where applicable, for obtaining their consent. For minors, the consent of the legal guardian is required. We recommend avoiding sensitive data (health, religion, opinions) about such third parties.

4. Storage & Security

Your data is stored securely on Supabase servers located in Ireland (Western Europe), in compliance with GDPR standards. Local data is also stored on your device (AsyncStorage / SQLite). When you enable automatic location during onboarding, your coordinates may be sent to the Nominatim service (OpenStreetMap Foundation) to resolve city, region, and country — solely to contextualise the simulation, not for ad targeting on our part. When you use AI features, certain profile and simulation data may be transmitted to Google Gemini (Google LLC, United States) for processing. This transfer is governed by the European Commission's standard contractual clauses. Likewise, crash reports are processed by Sentry (Functional Software, Inc.) on servers located in the European Union; any residual access from the United States is covered by GDPR-compliant safeguards (standard contractual clauses and/or the EU–US Data Privacy Framework).

Indicative retention periods:

  • Account and profile data: kept as long as your account is active; deleted within 30 days of your erasure request (or after the documented 7-day grace period in settings).
  • Simulation data: kept as long as your profile uses it; deleted with the profile.
  • Technical logs and audience events: kept for at most 13 months (CNIL guideline for audience measurement), then anonymised or deleted.
  • Crash reports (Sentry): automatically deleted after 90 days.
  • Account backups: kept for 12 months after the last update, unless an earlier erasure request is made.
  • Billing data managed by the stores: retained according to Apple/Google's own legal obligations (up to 10 years for accounting records).

5. Geolocation

Geolocation is an optional Premium-only feature used to contextualise local asset simulations (real estate, regional businesses, currencies). During automatic location onboarding, coordinates may be sent to the Nominatim service to resolve city and region (see section 4); we do not use this for targeted advertising. Your precise location is not kept on our servers for advertising purposes.

6. Your Rights (GDPR)

Under the GDPR (Articles 15 to 22), you have the following rights over your personal data:

  • Right of access (Art. 15): obtain a copy of the data we hold about you.
  • Right of rectification (Art. 16): correct inaccurate data; your display name and email can be edited directly in Profile › Account backup.
  • Right to erasure (Art. 17): delete your data via the "Delete my data" feature in settings — this is irreversible.
  • Right to restriction of processing (Art. 18): suspend certain processing operations.
  • Right to data portability (Art. 20): retrieve your data in a structured, machine-readable format (JSON) via the "Export my data" feature in settings.
  • Right to object (Art. 21): object to processing based on legitimate interest or for profiling purposes.
  • Right to withdraw consent at any time for consent-based processing (in particular AI and analytics).

To exercise these rights, use the dedicated features in settings or contact us at the address below. We respond within a maximum of one month (Art. 12.3 GDPR).

You also have the right to lodge a complaint with the competent supervisory authority. In France this is the CNIL (Commission Nationale de l'Informatique et des Libertés), 3 place de Fontenoy, 75007 Paris — cnil.fr. Users in other EU Member States may contact their own national authority.

Scope of the export: the in-app export ("Export my data") covers data we store directly. Some data held by our processors is provided or handled separately: PostHog analytics events (anonymised, deleted when your account is deleted), transient operational logs from Supabase Edge functions (not part of the export, auto-expired), Sentry crash reports (technical data without user identifiers, auto-deleted after 90 days), and purchase/subscription data held by RevenueCat and the App Store / Google Play (kept by those third parties — you can request it directly from them).

7. Policy Changes

We reserve the right to modify this policy at any time. Significant changes will be communicated in the App and/or via the store update notes. Where a change requires a new consent under applicable law (for example for optional analytics), we will ask for that consent again — continued use alone is not treated as consent for those purposes.

8. Your regional rights (outside the EU)

Inner Horizon is operated from the European Union and applies the GDPR to all of its users. Depending on where you live, you may have additional rights.

United States — California (CCPA/CPRA): we do not sell or share your personal information, and have not done so in the past 12 months. We do not 'share' it for cross-context behavioral advertising. You have the right to know, access, correct and delete your data, and not to be discriminated against for exercising these rights. Categories of data involved: identifiers (UUID, email), commercial information (subscription status), approximate geolocation (Premium), usage activity (analytics, with consent). To exercise these rights, use 'Export my data' / 'Delete my data' or contact us.

Brazil (LGPD — Lei nº 13.709/2018): you have the rights set out in Article 18 (confirmation of processing, access, correction, anonymization/blocking/deletion, portability, information on sharing, withdrawal of consent). The legal basis is consent (Art. 7, X) for AI and analytics, and legitimate interest (Art. 7, IX) for reliability and security. Data Protection Officer (Encarregado): support@manifestwealth.io. Authority: ANPD (gov.br/anpd). Processing of children's and adolescents' data follows Art. 14 (consent of a parent or guardian).

United Kingdom (UK GDPR): your rights arise under the UK GDPR and the Data Protection Act 2018. Supervisory authority: ICO (ico.org.uk).

Other countries (Switzerland, Canada, Australia, etc.): you may have rights under your local data-protection law (Switzerland: FDPIC — edoeb.admin.ch; Canada: PIPEDA — priv.gc.ca; Australia: OAIC — oaic.gov.au). Contact us to exercise them.

International transfers: wherever you live, your data is processed in the European Union (Supabase, Ireland) and, for AI features only, in the United States (Google), under appropriate safeguards (Standard Contractual Clauses).

Data controller: Esteban Pedreira, sole proprietor (entrepreneur individuel), SIREN 984 472 068, 309 rue des Tarusates, 40600 Biscarrosse, France. Contact: support@manifestwealth.io