THE MANAGER PRIVACY POLICY Effective date: July 22, 2026 Document version: 2026-07-22 This Privacy Policy explains how The Manager, an independent application developed by Jas Tandon ("The Manager," the "App," "we," "us," or "our"), collects, uses, stores, discloses, and deletes information when you use the App and themanager-app.com (the "Service"). The developer is the data controller where applicable. Contact: support@themanager-app.com. 1. Account and identity information The App requires an account. You provide an email address, password, unique public username or handle, first name, and last name. Firebase Authentication stores the email, authentication record, verification status, and account identifier; we do not receive your plaintext password. First and last name support account identity and cross-device recovery. They are stored in the App’s local account storage, a private functions-only backend account record available only to the authenticated account and authorized service operations, and, if enabled, your personal iCloud backup. Your handle is public and searchable. During account creation and when saving Edit Profile, you may provide a different public display name. The App clearly tells you that if the public-name field is blank, saving uses your profile first and last name as the public display name shown on your profile, The Wall, and related social surfaces. An existing private profile name is not converted until you affirmatively save that disclosed choice. You may also choose a public profile photo, pronouns, and bio. 2. Productivity and user content The App can store goals, tasks, milestones, habits, lists, journals, voice journals, photos, files, calendar and focus blocks, reminders, completion history, behavior logs, templates, and achievements. Most personal productivity content is local to your device. Eligible non-health content may be included in your personal iCloud backup. Content is sent to our backend when required for an account feature or when you choose to post, message, collaborate, publish a template, join a challenge, submit a report, or otherwise share it. 3. Social, messaging, and collaboration information Creating an account enables profiles and social functions. We process your public handle/profile fields, followers and following, follow requests, blocks, posts, feed events, reactions, comments, direct messages and read status, collaboration and accountability records, challenges, shared templates, and moderation reports when you use those functions. People search matches public handles only. Your public display name—either the different name you enter or the disclosed profile-name fallback—plus other optional public profile fields may be shown after a handle match, on The Wall, in notifications, or when another user opens your profile. Privacy settings control account visibility, list visibility, messaging, progress statistics, and shared wins. 4. Sensitive health, fitness, and nutrition information Health functions are optional and require a separate explicit in-app consent. Depending on the functions you use, the App may process HealthKit data you authorize and information you enter, including steps, exercise, energy, sleep, heart rate, weight, height, body-mass index, cardio fitness, fasting, food and nutrient entries, water, glucose, blood pressure, mood, age, and biological sex. Health information is processed on your device for the health, dashboard, analytics, and coaching functions you request. It is not placed in automatic iCloud backups, public profiles, social search, advertising, or tracking. An explicit user-directed Files export may include app-entered health information; you choose the export destination and control the resulting file. Health context is sent to a cloud AI provider only if you separately enable app-context sharing and make a relevant request. You can withdraw consent in Settings, disable Health integration, revoke HealthKit permissions in iOS, and delete stored information or the account. Withdrawal stops further health processing but does not automatically erase existing local records unless you delete them. For EEA/UK users, where health information is special-category data, we rely on your explicit consent under Article 9(2)(a) in addition to the applicable Article 6 basis. You may withdraw that consent at any time without affecting processing that occurred before withdrawal. 5. Optional financial information Where finance functions are enabled and you connect an institution through Plaid, Plaid provides Item, institution, account, balance, transaction, merchant, category, and recurring-payment information. Plaid handles bank credentials; we do not receive them. Long-lived Plaid access tokens are stored only in a restricted server-side location. Disconnecting an Item or deleting the account revokes Plaid access before stored tokens are removed. Financial data is used only to provide the requested finance functions and optional AI context you separately enable. 6. Artificial intelligence The App can use Apple on-device models and cloud providers including OpenAI, Google Gemini, and Anthropic. A cloud request includes your prompt, settings needed to complete it, and only the App context you explicitly select or enable. The "Share app context" control defaults on for new installations, but no private app context is sent until you affirmatively accept the onboarding disclosure for the signed-in account. If you decline or turn it off, private app, health, finance, calendar, email, journal, and social context is withheld from model tools and execution. If you supply your own provider key, your request may go directly from the device to that provider under its terms. Shared-key OpenAI and Gemini requests pass through authenticated, App Check-protected developer proxies with request limits. 7. Device, permissions, and technical data We may process APNs/FCM push tokens and routing identifiers; App Attest/App Check signals; limited rate-limit counters; a hashed per-installation/device identifier and coarse iPhone/iPad label for a short-lived active-device session lease; app version and platform in legal-acceptance records; calendar, location, motion, microphone, speech, HealthKit, notification, photo, and file access only after the relevant system or in-app choice; and limited security/reliability logs. Routine server logs pseudonymize account identifiers. Firebase Analytics collection is disabled. Apple may separately provide crash and performance diagnostics according to your device settings. 8. Website and support information If you email support, we receive your message and contact information. The website host may receive standard request logs such as IP address, browser, time, and requested path for security and delivery. The site does not use advertising or cross-site behavioral tracking. Website fonts, scripts, images, and badges are self-hosted or loaded from the disclosed App Store destination; no unversioned third-party script is required. 9. How we use information We use information to authenticate and verify accounts; restore private account identity; enforce one active app device at a time; provide local, backup, social, messaging, collaboration, moderation, notification, finance, AI, and support functions; maintain security and prevent abuse; honor privacy controls and legal rights; debug failures; and comply with law. We do not sell personal information, show behavioral advertising, use HealthKit data for advertising or data mining, or use personal information for cross-context behavioral advertising. 10. Legal bases for EEA/UK processing We rely on performance of a contract to provide account and Service functions you request; consent for optional HealthKit and sensitive-health processing, app-context sharing, notifications, location, calendar, microphone, speech, and Plaid linking where consent is the appropriate basis; legitimate interests to secure the Service, prevent fraud and abuse, maintain reliability, and operate proportionate moderation, balanced against your rights; and legal obligation where processing is required by law. Special-category health data relies on explicit consent as described in Section 4. 11. Service providers and disclosures We disclose information only as needed to provide a requested function or comply with law: Apple for App Store delivery, iCloud, HealthKit, APNs, and platform services; Google Firebase/Google Cloud for authentication, Firestore, Cloud Functions, messaging, App Check, and operational infrastructure; Plaid for connected financial accounts; OpenAI, Google Gemini, Anthropic, or Apple for the AI function you select; website hosting and email providers for site delivery and support; other users for content and profile fields you choose to share; and authorities or advisers when legally required or reasonably necessary to address imminent safety, fraud, abuse, or legal claims. We contractually or technically require processors acting on our behalf to handle data consistently with this Policy and applicable law. A provider acting under its independent terms may also be an independent controller for data you intentionally submit, particularly when you use your own API key. Review the selected provider’s policy before sending sensitive information. 12. Storage locations and international transfers Local content is stored on your device. Automatic backups, if enabled, are stored in your personal iCloud container and exclude health, fitness, fasting, nutrition, glucose, blood-pressure, water, and related sensitive-health payloads. Private account-recovery fields, active-device lease metadata, and social/account data are stored in Firebase/Google Cloud and may be processed in the United States. Providers may process data in other countries. Where EEA/UK data is transferred to a country without an adequacy decision, we rely as applicable on the EU Standard Contractual Clauses, the UK International Data Transfer Addendum or Agreement, provider Data Privacy Framework certification where valid, and supplementary technical and organizational safeguards. 13. Retention - Account, private account-recovery, public profile, social, messaging, and collaboration records: while the account is active, then deleted through the in-app deletion workflow. - Active-device lease metadata: released on logout where connectivity permits, replaced when a new active device is allowed, becomes available for takeover after seven days without renewal, and is deleted with the account. - Device data and automatic iCloud backups: until you delete the data, disable/remove the backup, delete the account, or remove the App, subject to the operating system’s behavior. - Plaid access and connected financial records: until you disconnect the Item or delete the account; access revocation occurs before token deletion. - Push tokens: until logout, replacement, invalidation, or account deletion. - Legal acceptance evidence: retained in the account record and its acceptance subcollection while the account is active. The account-deletion workflow deletes those records. A specific record may be preserved only when a documented legal hold or applicable law requires it. - De-identified moderation category/disposition records: up to 180 days after deletion to prevent repeat abuse and ban evasion. Raw deleted-account UIDs, names, and reporter free text are removed. A longer hold occurs only when legally required for a specific investigation or claim. - Rate-limit counters and routine operational logs: retained only for the short operational periods configured by the applicable infrastructure provider for security, abuse prevention, and debugging. Raw account identifiers are not intentionally placed in routine application logs. Provider-generated request and security logs follow the provider account’s configured retention and applicable provider terms. - Support email: until the request is resolved and for a reasonable period needed for follow-up, legal obligations, or claims. 14. Security Safeguards include TLS in transit, iOS data protection, Keychain storage, authenticated and owner/participant-scoped access, default-deny Firestore rules, App Check/App Attest, verified email, server-side validation and moderation, rate and cost limits, restricted secrets, pseudonymized routine logs, and retryable fail-closed deletion. No system is perfectly secure. Contact support@themanager-app.com if you believe your account or data is at risk. 15. Your choices and rights You can edit optional profile fields and privacy settings; block and report users; disconnect permissions, Plaid, AI context, and Health consent; export a copy of on-device data to Files; request server-held access or portability by email; correct information; object or restrict processing where applicable; withdraw consent; and delete your account in the App. Server-hosted messages, feed content, public profile, and collaboration records are not included in the local Files export but are removed through account deletion or can be requested through support. Depending on your location, you may have rights to know/access, correct, delete, receive a portable copy, object, restrict, withdraw consent, appeal, and complain to a regulator. We do not sell or share personal information for cross-context behavioral advertising. We do not discriminate for exercising privacy rights. 16. Account deletion The in-app deletion workflow first verifies and removes the App’s personal iCloud backup directory using a cross-device existence marker, then removes cloud social/account data and revokes Plaid access, then removes local account files and preferences, and finally deletes Firebase Authentication. It does not report success if a required step cannot be confirmed. A minimal de-identified moderation record may remain for up to 180 days as described above. A specific legal record may be preserved only when a documented legal hold or applicable law requires it. 17. Children The Service is not directed to children and requires users to be at least 16. We do not knowingly permit accounts for children under 16. If you believe a child created an account, contact support@themanager-app.com so we can investigate and delete it. 18. Changes Material changes receive a new version, SHA-256 fingerprint, and in-app acceptance prompt before access to gated functions. Older clients cannot use gated backend functions without accepting the current exact document set. 19. Contact and complaints Email support@themanager-app.com for privacy questions or rights requests. EEA/UK users may complain to their local data-protection authority; other users may contact the regulator or attorney general responsible for their location.