Privacy Policy

Last updated: July 22, 2026 · Effective date: July 22, 2026 · Document version: 2026-07-22

Canonical accepted document. The exact version accepted in the App is available as plain text. SHA-256: af5e69165bdf5bc46e453343cfc4b92a47ee4b84a031b570d5484b72dca02efd.

This Privacy Policy explains how The Manager ("the App," "we," "us," or "our") — an independent application developed by Jas Tandon — collects, uses, stores, shares, and protects your information when you use the App and this website (collectively, the "Service"). We are committed to a privacy-first design and to handling your data responsibly and transparently.

The short version. Your personal productivity, journal, and optional health and financial data is primarily processed on your device. If you enable automatic iCloud backup, sensitive health, fasting, and nutrition payloads are excluded. A user-directed Files export can include app-entered health information and is stored only where you choose. Account and social features use our backend. We never sell personal information, show ads, or use health data for advertising or unrelated data mining.

Contents

  1. Who we are
  2. Information we collect
  3. How we use information
  4. Legal bases (GDPR)
  5. Where your data is stored
  6. Health & fitness data
  7. Artificial intelligence features
  8. How we share information
  9. Data retention
  10. Security
  11. Your rights & choices
  12. Children's privacy
  13. International users
  14. Changes to this policy
  15. Contact us

1. Who We Are

The Manager is an independent research and development project by Jas Tandon. It is offered free of charge with no advertising and no commercial monetization. For any privacy question, you can reach us at support@themanager-app.com. For users in the EEA/UK, references to a "data controller" mean the developer identified above.

2. Information We Collect

We collect only what is needed to provide the features you use. Creating an account sets up your profile and enables the social features; the categories below otherwise depend on which features you use — for example, if you never post, message, or share, we have no posts, messages, or shared content of yours to process.

a. Account & identity information

You create an account with an email address, password, unique public username/handle, first name, and last name. Firebase Authentication stores the email, verification status, authentication record, and account identifier; we do not receive your plaintext password. First and last name support account identity and cross-device recovery and remain in local storage, a private functions-only backend account record, and, if enabled, your personal iCloud backup. Your handle is public and searchable. During account creation and when saving Edit Profile, you may provide a different public display name. The App clearly tells you that leaving that field blank uses your profile first and last name publicly on your profile, The Wall, and related social surfaces. An existing private profile name is not converted until you affirmatively save that disclosed choice. You may also choose a public profile photo, pronouns, and bio.

b. Content you create

Goals, tasks, milestones, habits, to-do lists, journals (including voice journals), calendar and focus blocks, food diary entries, and notes. Most of this stays on your device. Eligible non-health content may be included in your personal iCloud backup. It is only sent to our backend when required for an account feature or when you actively share or collaborate (see below).

c. Social & collaboration data (only if you use social features)

d. Health, fitness & nutrition data

If you use the health features, you may enter or grant access to data such as intermittent-fasting sessions, glucose and blood-pressure readings, weight, food and calorie/macro logs, and (with your explicit permission) data from Apple HealthKit such as steps, active energy, and exercise minutes. You may also optionally provide your age and biological sex to personalize fitness guidance; these are stored on your device. See Section 6 for special handling.

e. Device & technical information

f. Optional financial data

Where the optional finance feature is enabled, you may choose to connect a bank or card account through Plaid. In that case Plaid provides account and transaction information so the App can display your spending insights. We do not receive or store your bank login credentials — those are handled by Plaid. If you do not use this feature, no financial-institution data is collected.

g. Support & website information

If you email us, we receive your message and contact details. The website host may receive standard request logs such as IP address, browser, time, and requested path for security and delivery. Website fonts, scripts, images, and badges are self-hosted; links to the App Store load Apple content only after you follow them. We do not use advertising or cross-site tracking cookies.

3. How We Use Information

We do not sell your personal information, we do not serve advertising, and we do not use your health, fitness, or financial data for advertising or unrelated profiling.

Where the GDPR or UK GDPR applies, we rely on: performance of a contract to provide requested account and Service functions; consent for optional permissions and integrations where consent is the appropriate basis; legitimate interests to secure the Service, prevent abuse, maintain reliability, and operate proportionate moderation, balanced against your rights; and legal obligation where required by law. Special-category health data relies on separate explicit consent under Article 9(2)(a), which you can withdraw at any time.

5. Where Your Data Is Stored

Your personal content is stored locally on your device. If you enable backup, eligible non-health content is stored in your own iCloud account (we do not host your backups). You can also export a copy of the data stored on your device to the Files app at any time; server-hosted social content — your messages, public profile, and posts shared to others' feeds — is not included in that export (deleting your account removes it everywhere instead). Private account-recovery fields, active-device lease metadata, and data required for social, messaging, collaboration, and account features are processed and stored on our cloud backend (Google Firebase / Cloud Firestore), which may operate on servers in the United States.

6. Health & Fitness Data — Special Handling

Consistent with Apple's requirements, we never use data gathered from HealthKit or the App's health, fasting, and nutrition features for advertising, marketing, or use-based data mining, and we do not disclose it to third parties for those purposes. Health data is used only to provide the insights and coaching you request.

Optional health processing requires a separate explicit in-App consent as well as any applicable HealthKit permission. You can withdraw consent in the App and revoke HealthKit access in iOS Settings. Health and nutrition entries remain on your device and are excluded from automatic iCloud backups. A user-directed Files export can include app-entered health information; you choose and control its destination. Health information is not placed in public profiles or people search.

7. Artificial Intelligence Features

The App includes an assistant and a fitness coach using Apple on-device models and optional cloud providers including OpenAI, Google Gemini, and Anthropic. The "Share app context" control defaults on for new installations, but no private app context is sent until you affirmatively accept the onboarding disclosure for the signed-in account. If you decline or turn it off, private app, health, finance, calendar, email, journal, and social context is withheld from model tools and execution. When enabled and consented, only context relevant to your request is sent to the selected provider. If you supply your own API key, requests may go directly to that provider under its terms. AI responses can be inaccurate and are not professional advice.

8. How We Share Information

We share information only as needed to run the Service:

We do not sell or "share" (as defined by the CCPA/CPRA) your personal information, and we do not disclose it for cross-context behavioral advertising.

9. Data Retention

We keep account, private account-recovery, and social data while the account is active. Active-device lease metadata is released on logout where connectivity permits, becomes available for takeover after seven days without renewal, and is deleted with the account. On-device and personal iCloud data persists until you delete it, remove the backup, delete the account, or remove the App, subject to operating-system behavior. Account deletion removes legal-acceptance records unless a documented legal hold or law requires a specific record. A minimal moderation category, disposition, expiry, and pseudonymous marker may remain for up to 180 days to prevent repeat abuse and ban evasion; raw deleted-account identifiers, names, and reporter free text are removed. Provider-generated operational logs follow the provider account's configured retention and applicable terms.

10. Security

We use industry-standard safeguards, including encryption in transit, authenticated access controls, server-side validation, app-attestation (App Check), and rate limiting to protect against abuse. On-device data is protected by your device's security features (passcode, Face ID / Touch ID). No method of transmission or storage is 100% secure, but we work to protect your information and to respond promptly to any issue.

11. Your Rights & Choices

Depending on where you live, you may have some or all of the following rights. We honor these requests regardless of location wherever practicable:

To exercise a right that you cannot complete in the App, email support@themanager-app.com. EEA/UK users also have the right to lodge a complaint with their local data protection authority.

12. Children's Privacy

The Service is not directed to children and requires users to be at least 13 years old. We do not knowingly permit accounts for children under 13. If you believe a child created an account, contact us so we can investigate and delete it.

13. International Users & Transfers

We are based in, and Firebase/Google Cloud and other providers may process data in, the United States and other countries. Where EEA/UK data is transferred to a country without an adequacy decision, we rely as applicable on the EU Standard Contractual Clauses, the UK International Data Transfer Addendum or Agreement, provider Data Privacy Framework certification where valid, and supplementary technical and organizational safeguards.

14. Changes to This Policy

We may update this Privacy Policy. Material changes receive a new version and SHA-256 fingerprint, and the App requires acceptance of the new exact document set before access to gated functions. Older clients cannot bypass the current backend acceptance requirement.

15. Contact Us

Questions, requests, or concerns about this Privacy Policy or your data? Email us at support@themanager-app.com.