Privacy Policy
Last updated: July 27, 2026
Document version: v2026-07-27.
Data controller: Esteban Pedreira, sole proprietor (entrepreneur individuel), SIREN 984 472 068, 309 rue des Tarusates, 40600 Biscarrosse, France — support contact: support@manifestwealth.io · privacy / GDPR contact: support@manifestwealth.io.
Data protection lead: no DPO designated at this stage (internal assessment); requests are handled by the privacy lead via the GDPR contact above.
Service concerned: Inner Navigation, within the Manifest Wealth ecosystem. Inner Navigation is the public service; Tracker MW is the mobile app of the service; Manifest Wealth is the ecosystem / umbrella brand.
Languages planned for the legal documents: fr, en, es, pt, de. The EN/ES/PT/DE versions must be kept aligned with this FR version before distribution in those languages.
The purposes below apply in compliance with the GDPR when you are in the European Economic Area (or where EU law applies).
1. Data processed (overview)
- •Mood and wellbeing data: scores, periods, tags, emotions, text notes, optional heart rate, data linked to entries.
- •Daily data: sleep, health, meals and food, finances, activity (including step count if you enable the pedometer), events, lifestyle, intimate life (libido, sexual activity), if you fill in those fields, illness episodes entered, environmental correlations (e.g. weather), optional demo astrological data if you use those features.
- •Journal: free-text journal entries (including text produced by voice input), timestamps, and any writing prompts used.
- •AI coach: messages you send to the coach, generated replies, technical daily quota counters.
- •Personal AI memory: distilled elements (preferences, context, goals) stored in a dedicated table (user_ai_memory) if you enable this option.
- •Programme and intentions: “Foundations 21 days” programme progress (current day, completed days, streak), analysis milestones, “if… then…” intentions (trigger, action, outcome).
- •App settings: tracking mode, interface preferences, notifications, language, consents, location and community sharing options, etc.
- •Account: email address, technical account ID, session tokens managed by the authentication provider (e.g. Supabase).
- •Technical data: app version, technical identifiers required for connected services, minimal server-side API logs if enabled by the publisher.
2. Local storage
By default, a significant portion of data is stored locally on your device (encrypted storage where the system supports it). Uninstalling the App may cause loss of local data that has not been exported.
3. Personal cloud backup (legal basis: explicit consent / performance of the requested feature)
The App works locally by default: creating an account is not, by itself, enough to enable automatic upload of your personal tracking data. If you separately enable personal cloud backup, a JSON snapshot of the main local data (mood, daily log, journal entries, programme progress, intentions, settings, illness episodes) may be sent to and stored on infrastructure configured by the publisher (e.g. Supabase project). This data remains pseudonymised within the meaning of GDPR Article 4(5): linked to an account identifier, deletable on request, but not anonymous in the legal sense.
Purpose: backup and, for Premium subscribers, restore or merge on another device. Automatic upload is rate-limited (more frequent for Premium, more spaced out for free accounts); an app-side size cap may reject an upload if the snapshot exceeds a technical limit. Refusing or withdrawing this consent does not prevent basic local use. Other processing activities (community statistics, AI, free-text notes, AI memory) rely on separate choices described in the dedicated sections.
App opens: there is no silent named tracking of app opens when personal cloud backup is not enabled. When cloud backup is enabled, a technical “one open per user per UTC day” row may be recorded in daily_app_opens for service and stability statistics, with retention limited to 90 days. Product goal: remove this named counter or anonymise it.
4. Journal (legal basis: performance of the feature / separate consents for sync and AI)
Journal entries are written freely (or dictated via voice input, see the Microphone section) and stored locally in encrypted form where the system supports it. They are synced to the cloud only if you have enabled personal cloud backup (section 3).
AI journal analyses (5 analysis modes) can be requested explicitly. Journal text is covered by the separate “free-text notes” consent (section 5): without that consent, the text content of your journal is not sent to the AI provider (except in case of a bug, in which case contact support).
5. Artificial intelligence analyses (legal basis: explicit consent, GDPR Article 9(2)(a))
Summaries or analyses may be requested via an intermediary server (Cloudflare Worker) that sends context to a language-model provider. The default provider is Google (Gemini Flash model), for the “light” tier, the only tier offered in the current version of the App. A second provider, Anthropic (Claude model), receives the analysis context in two cases: automatically, as a fallback, when the default provider is unavailable or returns an unusable response; and, should a more expensive analysis tier (“powerful”) be offered, when you use that tier. The AI providers’ secret keys are not present in the mobile app. Note: this Cloudflare Worker receives and passes through personal data (the analysis context and, subject to your separate consent, text notes); Cloudflare therefore acts here as a sub-processor processing personal data, not as a mere data-free relay (see section 17).
“No training” commitment: the publisher does not train its own AI model with your data. Data sent to the AI is not used to train any general AI model of the publisher. Under the AI providers’ current commercial API terms (Anthropic and Google), data sent via the API is not used to train their models. These commitments derive from the providers’ terms, which may change; the publisher endeavours to select providers offering this guarantee and to update this policy where necessary. If training, fine-tuning, or a proprietary model were ever considered, it would be subject to a new, separate explicit consent, dedicated legal documentation, and an update of the DPIA.
Three separate choices are provided:
- •Health/wellbeing AI consent: authorises the sending of structured indicators derived from your mood, sleep, activity, meals, wellbeing, entered symptoms/illness episodes, intimate life (libido, sexual activity), if you fill in those fields, environmental signals, and other metrics needed for wellbeing trend analysis. This data includes special categories within the meaning of GDPR Article 9 (health, sex life), covered by this same explicit consent.
- •Free-text notes consent: separately authorises the inclusion of free-text notes, journal entries, comments, or written instructions. Without this separate consent, these texts must not be included in the analysis payload (except in case of a bug, in which case contact support).
- •Personal AI memory: a distinct choice allowing personal memories or preferences to be created, reused, and deleted for future analyses and conversations (see section 7). Personal AI memory is not general model training.
5 bis. Purpose, recipients, and safeguards of AI analyses
Purpose: generating wellbeing trend analysis, summaries, and non-medical food for thought. Recipients: the publisher, the Cloudflare intermediary server or equivalent, and the configured AI provider (Google by default; Anthropic in the two cases described in section 5). Countries: processing in the EEA where the infrastructure allows, and possible transfers to the United States or other processing countries of the providers, with appropriate safeguards (see section 18). Duration: the payload is processed to answer the request; any stored analysis history follows the AI retention period configured in the App or until deletion/withdrawal where applicable.
Each AI analysis must be considered automatically generated, possibly incorrect, and does not constitute medical advice, diagnosis, medical prevention, triage, or a therapeutic recommendation.
You can easily withdraw these consents in the settings. The App keeps the date and version of the consent or withdrawal to document the choice, without affecting the lawfulness of processing carried out before withdrawal.
6. Conversational AI coach (legal basis: explicit consent; quotas: legitimate interest)
The AI coach is a conversational messaging feature. Your messages pass through the same intermediary server (Cloudflare Worker) to the configured AI provider (Google’s Gemini Flash by default). The transmitted content respects the consents in section 5: wellbeing indicators, free-text notes, or memory elements are only included in the conversation context if the corresponding consents are active.
Server-enforced quotas: a free taster limited to 1 message per day for non-subscribed accounts, then access reserved for the Premium subscription up to an anti-abuse cap of 20 messages per day. Technical daily counters (one row per device token per UTC day) are kept briefly to enforce these quotas.
Coach replies are generated automatically, may be inaccurate, and do not constitute medical advice. Any conversation history stored on the intermediary server is purged when the account is deleted (technical ai_chat entries), and otherwise follows the configured retention period.
7. Personal AI memory (legal basis: dedicated consent)
If you enable this distinct choice, the service may asynchronously distil useful elements (preferences, context, goals) from your conversations with the coach and your analyses, and store them in a dedicated table (user_ai_memory) linked to your account. This data is pseudonymised within the meaning of the GDPR: linked to your account identifier, it is not anonymous in the legal sense.
These elements are reused to personalise coach replies and future analyses. You can view and delete them in the App. Withdrawing the consent stops the distillation; deleting the account triggers cascading erasure of the memory. Personal AI memory is not general model training.
8. “Foundations 21 days” programme and intentions (legal basis: performance of the feature / consent for sync)
Programme progress (current day, completed days, streak) and analysis milestones are stored locally and, if you are signed in with cloud backup enabled, synced to the publisher’s infrastructure. A server-side anti-replay mechanism ensures that analysis milestones (day 7 free; days 14 and 21 reserved for Premium) can only be used once. Milestone analyses use the AI analysis pipeline and the consents in section 5.
“If… then…” intentions (trigger, action, outcome) are stored locally, synced under the same conditions, and may trigger local notification reminders (see section 14).
9. Guided sessions
The three guided sessions (5-5 heart coherence, somatic reset, visualisation) run entirely on the device, are free of charge, and involve no transmission of session data to the servers.
10. Community statistics — levels of identifiability (legal basis: separate consent)
Contributing to community statistics is separate from personal cloud backup: accepting one does not automatically enable the other. Important GDPR distinction. When you enable “collective sharing”, two levels coexist and must be distinguished so as not to mislead you:
(a) Data stored on our servers: pseudonymised (GDPR Article 4(5)). Your data is linked to your account by a technical identifier. We can technically retrieve it and delete it on your request. It is therefore not anonymous in the legal sense: it remains personal data subject to the GDPR. Free-text notes and journal entries are never included in the community flow; only structured indicators (rounded scores, tags from a closed list, day and 4-hour slot, coarse geographic area) are concerned.
(b) Statistics published to the community: aggregated with k-anonymity (k ≥ 10) and statistical noise. Before publication, indicators are aggregated by geographic cell (~110 km wide) and by time window. A cell is published only if at least 10 distinct contributors are present (k-anonymity), with deterministic ±0.3 noise added to the means. At this output level, and absent cross-referencing with other databases, the published statistics do not, in practice, allow tracing back to an individual.
No sharing with external partners (research or otherwise) is currently offered or carried out: neither the pseudonymised data (a) nor the aggregated statistics (b) are transmitted to third parties for research purposes. If such sharing — limited to the aggregated statistics (b) — were to be offered in the future, it would require a separate explicit consent, distinct from collective sharing, and a prior update of this policy.
11. Location (legal basis: consent via system permissions / consent for community features)
Location may be used for weather, air quality, pollen, and environmental charts (pollen coverage mainly Europe); coordinates may be rounded on device before storage.
For community features, a separate option may associate k-anonymous aggregates (k ≥ 10) with a very coarse area (e.g. short geohash) without mandatory transmission of precise coordinates to the community server.
12. Microphone and speech recognition (legal basis: consent)
Some voice input features — notably dictating journal entries — may use the microphone and the system’s or manufacturer’s speech recognition services. Audio is processed according to platform rules (Apple/Google); the transcribed text is then treated as a free-text note (sections 4 and 5).
13. Physical activity (legal basis: consent)
Step counting may use the device’s activity sensors after permission is granted.
14. Notifications (legal basis: consent / legitimate interest for service messages if applicable)
Notification preferences are managed in system and App settings. Intention and programme reminders are scheduled locally on the device.
15. Payments, subscription, and credits (legal basis: contract)
In-app purchases (monthly/yearly Premium subscription, credit packs of 3, 10, or 30 units) are processed by Apple or Google. We do not receive your card number. One purchased credit is worth one analysis unit; the purchased credit balance is separate from the weekly quota included in the subscription (see Terms, section 8).
To apply your entitlements (Premium status, credit balance), transaction identifiers and a credit balance may be kept server-side, linked to a technical device token or to your account, for as long as needed to provide the service and meet accounting obligations.
16. Retention periods (indicative)
- •On-device data: while the App is installed and you do not erase it (some retention options, e.g. astro data, may be configurable in the app).
- •Account and cloud backup (snapshot on the infrastructure configured by the publisher): only if you have enabled personal cloud backup; kept for the life of the account and as long as needed to provide the service (backup; restore reserved for Premium). When the account is deleted, data linked to that account is deleted via the technical mechanisms in place (including cascading erasure of associated rows). For an erasure or export request outside these automatic mechanisms, contact the data controller.
- •Free vs Premium account: the same type of snapshot may be stored; automatic sync frequency and access to cloud restore/merge differ by plan, as indicated in the App.
- •AI history (analyses, coach conversations): follows the retention period configured in the App; technical entries on the intermediary server (ai_analysis, ai_chat) are purged when the account is deleted.
- •Personal AI memory (user_ai_memory): until you delete it, withdraw the dedicated consent, or delete the account (cascading erasure).
- •Programme progress and intentions: for the life of the account (cascading erasure on deletion).
- •App opens (daily_app_opens): where present under cloud consent, maximum retention 90 days.
- •Environmental context data (environment_snapshots — public weather, air quality, pollen, seismic activity, and space weather data correlated with your account, where location is enabled for the local layers): where present under cloud consent, maximum retention 730 days (2 years), then automatic purge.
- •Aggregated community statistics (k ≥ 10, ±0.3 noise): kept without a predefined retention period in the absence of individual identifiers once published. The pseudonymised data used to produce them remains subject to the account retention periods (above).
17. Recipients and sub-processors
The publisher uses the following sub-processors, each governed by a data processing agreement (DPA) and, for transfers outside the EEA, by the European Commission’s standard contractual clauses (SCCs) supplemented by technical measures (encryption in transit and at rest):
- •Supabase — database hosting, authentication, and optional cloud backup. Region: EEA (eu-west-1, Dublin, Ireland). Data: account, backup snapshot if you enable it, AI memory, programme progress, intentions, consents, pseudonymised community data if you contribute.
- •Cloudflare — intermediary server (Worker) for AI analyses, the conversational coach, and in-app purchase (IAP) validation. This Worker receives and passes through personal data (analysis context, coach messages, any notes subject to consent, transaction identifiers). Cloudflare is therefore a sub-processor of personal data, not a mere “data-free” relay.
- •Google (Gemini) — default AI model provider for the “light” tier (Gemini Flash, coach and analyses), the only tier offered in the current version of the App; recipient of the context when you use AI features. Processing may take place outside the EEA (notably the United States). Under its current commercial API terms, data sent is not used to train its models.
- •Anthropic (Claude) — second AI model provider, recipient of the analysis context in two cases: automatically, as a fallback, when the default provider (Google) is unavailable or returns an unusable response; and, should a more expensive analysis tier (“powerful”) be offered, when you use that tier. Conversational coach messages, analysed journal entries, and AI memory items are not sent to it. Processing may take place outside the EEA (notably the United States). Under its current commercial API terms, data sent is not used to train its models.
- •Apple (App Store) and Google (Google Play) — processing of in-app purchases (payment, subscriptions, credits). We do not receive your card number.
- •Sentry — crash and stability telemetry, only if enabled by the publisher. Configured not to collect raw personal data (no notes, no AI prompts, no health data); IP addresses are masked and payloads are scrubbed (see section 21). Processing may take place outside the EEA.
17 bis. Sub-processor update policy
The list above may change. The publisher maintains an up-to-date internal register of sub-processors and their safeguards. The current list may be obtained on request from the contact at the top. If a sub-processor is added or replaced with a significant impact on your data, the publisher updates this policy (date and version at the top) and, for a substantial change, may inform you in the App.
18. Transfers outside the EU
Some sub-processors (notably the AI providers Google and Anthropic, Cloudflare, and, where applicable, Sentry) may process data outside the EEA, notably in the United States. In that case, the publisher relies on the appropriate safeguards provided by the GDPR: the European Commission’s standard contractual clauses (SCCs) and, where relevant, applicable adequacy mechanisms (e.g. the EU-US Data Privacy Framework for certified providers), supplemented by technical measures (encryption, minimisation of transmitted data). A data protection impact assessment (DPIA) has been carried out for high-risk processing (health/wellbeing data, external AI, location, trend profiling, public forum).
19. Your rights
You have rights of access, rectification, erasure, restriction, portability (for data provided and processed by contract/automation), and objection, under legal conditions. Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of prior processing.
You may lodge a complaint with the CNIL (www.cnil.fr) or your local supervisory authority.
20. Minors
The App is not directed at people under 15 (the age of digital consent in France under Article 7-1 of the French Data Protection Act implementing Article 8 GDPR). If you believe a minor has provided data without parental authorisation, contact the data controller.
21. Cookies, trackers, and telemetry
The mobile App uses no advertising cookies or marketing trackers. The only necessary technical mechanisms are the authentication provider’s session tokens (Supabase), strictly required for sign-in and sync. No non-essential audience analytics tool is used without your prior consent. If such a tool were added later, it would only be activated after prior consent is collected (banner or choice screen).
Crash telemetry: to improve stability, the publisher may enable a crash telemetry tool (Sentry). When enabled, it is configured never to send raw personal data: no text notes, no AI prompts or replies, no health/wellbeing data. IP addresses are masked, payloads are scrubbed, and only minimal technical information (error type, version, non-identifying technical ID) is kept, for a limited time. The associated website applies its own cookie policy stated on that site.
22. Contact
For any question about this policy or your rights: support@manifestwealth.io. For general assistance: support@manifestwealth.io.