Privacy Policy
mantus
Effective Date: 2026-01-27
Last Updated: 2026-04-26
1. Who We Are
mantus is a personal flashcard and spaced repetition learning app. This policy describes what data we collect, how we use it, and your rights regarding that data.
Developer: mantus.ai
Contact: info@mantus.ai
2. Account Deletion
You can delete your account and all associated data directly in the mantus app:
- Open the mantus app
- Go to Settings
- Tap Delete Account
- Confirm deletion in the two-step confirmation dialog
When you delete your account, the following data is permanently and immediately deleted:
- Your profile and account information
- All decks and cards in your library
- All review history and learning progress
- Scheduling data and streak records
- Device tokens and notification preferences
There is no retention period — all data is removed as part of the deletion process. This action cannot be undone.
If you are unable to access the app, you can request account deletion by emailing info@mantus.ai with the email address associated with your account.
3. What Data We Collect
2.1 Account Data
When you sign in with Google or Apple, we receive:
- Data
- Email address
- Source
- Google/Apple
- Purpose
- Account identification and login
- Data
- Name (optional)
- Source
- Apple (if provided)
- Purpose
- Display purposes (if provided)
- Data
- Provider user ID
- Source
- Google/Apple
- Purpose
- Link authentication to your account
We do not request access to your contacts, calendar, photos, or other Google/Apple services.
2.2 Learning Data
mantus provides curated decks that you add to your library. We store which decks you have added and your review progress:
- Data
- Review ratings (1-4)
- Purpose
- Calculate spaced repetition intervals
- Data
- Review timestamps
- Purpose
- Track learning progress
- Data
- Due dates and intervals
- Purpose
- Schedule your next reviews
2.3 User Preferences
- Data
- Daily reminder time
- Purpose
- When to send reminders
- Data
- Timezone
- Purpose
- Ensure reminders arrive at correct local time
- Data
- Language preference
- Purpose
- Display language
- Data
- Theme preference
- Purpose
- Light/Dark/System (stored locally only)
- Data
- Notifications enabled
- Purpose
- Your opt-in preference
2.4 Device Data (for Notifications)
- Data
- Push token (Expo)
- Purpose
- Deliver push notifications
- Data
- Platform (iOS/Android)
- Purpose
- Platform-specific notification handling
Push tokens are device identifiers used to route notifications. They are linked to your account only for delivering reminders.
2.5 Diagnostic Data
We use Sentry for crash and error reporting. Sentry receives error messages, stack traces, and basic device information (device type, OS version, app version) when a crash or error occurs. Authentication headers, tokens, and request bodies are redacted before any data is sent. No user identity is included in crash reports.
We do not use analytics or advertising SDKs. If we add analytics in the future, we will update this policy and our App Store privacy disclosures.
4. How We Use Your Data
We use your data to:
- Provide app functionality (decks, reviews, progress tracking)
- Store and sync your learning progress across sessions and devices
- Send push notification reminders (only if you enable notifications)
- Maintain account security and prevent abuse
We do not use your data for:
- Advertising or marketing targeting
- Selling data to third parties
- Training AI models
5. Third-Party Services
We use the following services to operate the app:
5.1 Supabase (Database & Authentication)
- Purpose: Authentication and storage of your app data
- Data processed: Account data, deck selections, preferences, review history
- Provider policy: https://supabase.com/privacy
- Hosting region: Europe (Stockholm)
5.2 Expo Push Notifications
- Purpose: Deliver push notifications
- Data processed: Push token and notification payload (title/body)
- Provider policy: https://expo.dev/privacy
5.3 Google (Sign-In)
- Purpose: Authentication only
- Data received: Email and basic profile information
- We do not access: Gmail, Drive, Calendar, Contacts
- Provider policy: https://policies.google.com/privacy
5.4 Apple (Sign-In)
- Purpose: Authentication only
- Data received: Email (may be private relay) and name (if provided)
- Provider policy: https://www.apple.com/legal/privacy/
5.5 Sentry (Crash Reporting)
- Purpose: Crash and error reporting to improve app stability
- Data processed: Error messages, stack traces, device type, OS version, and app version. Authentication headers, tokens, and request bodies are redacted before sending. No user identity is included.
- Provider policy: https://sentry.io/privacy/
6. Data Retention
We retain data for as long as needed to provide the service:
- Data Type
- Account data
- Retention
- Until you delete your account
- Data Type
- Deck selections and review data
- Retention
- Until you delete your account
- Data Type
- Review history
- Retention
- Until you delete your account
- Data Type
- Push tokens
- Retention
- Until you sign out or delete your account
When you delete your account, we delete or de-identify associated app data within our systems as part of the deletion process.
7. Data Security
We use standard security practices, including:
- Encryption in transit (HTTPS/TLS)
- Access controls and database security rules (e.g., row-level access controls where applicable)
- OAuth-based authentication (Google/Apple)
Session tokens may be stored locally on your device. If your device is compromised (e.g., jailbroken/rooted), an attacker could potentially access locally stored session data.
8. Your Rights
8.1 Access and Control
You can view your decks and learning progress in the app.
8.2 Delete Your Account
You can delete your account in the app via Settings > Delete Account. This removes your account and associated learning data from our systems.
8.3 Manage Your Preferences
You can update your preferences and notification settings at any time.
8.4 Data Portability
If you want a copy of your data, contact us at info@mantus.ai and we will help you.
8.5 Withdraw Consent for Notifications
You can disable notifications at any time in the app settings or your device settings.
9. Children's Privacy
mantus is not directed to children under 13. We do not knowingly collect personal data from children under 13. If you believe a child has provided data, contact us for removal.
10. International Data Transfers
Our service providers may process data in different countries depending on their infrastructure and the configuration of our project. Supabase for this project is hosted in Europe (Stockholm). If you have questions about where your data is processed, contact us at info@mantus.ai.
11. Changes to This Policy
We may update this policy from time to time. We will update the "Last Updated" date above. Continued use of the app after changes means you accept the updated policy.
12. Contact
For privacy questions or requests:
Email: info@mantus.ai