Privacy Policy

This policy explains what personal data we process when you use manare — across the website, the iPhone and Apple Watch apps, and related services — and the rights you have over that data.

Last updated

Responsible Party (Controller)

The party responsible for processing your personal data within the meaning of the General Data Protection Regulation (GDPR) is:

PEP ökotec Consult GmbH
Hildastraße 10, 69469 Weinheim (Bergstraße), Germany
Email: info@pep-oekotec.de

Further details about the operator can be found in our Imprint.

What Data We Process

We process the following categories of personal data:

  • Account data — your name, email address, and authentication details when you create an account or sign in (including via Sign in with Apple).
  • Content you create — the contacts, notes, reminders, interactions, and other relationship data you store in manare. This is your private data and is protected by row-level security so that only you (and people you explicitly share a team with) can access it.
  • Usage and device data — information such as your IP address, browser or device type, and pages or features used, generated automatically when you use our website or apps.
  • Subscription data — your subscription status and entitlements for the manare Pro plan. Payments are handled by the Apple App Store; we do not receive or store your payment card details.
  • Communications — the contents of any message you send us for support or other inquiries.

Legal Bases for Processing

We process personal data on the following legal bases:

  • Performance of a contract (Art. 6(1)(b) GDPR) — to provide your account, store your contacts, and deliver the features you request.
  • Consent (Art. 6(1)(a) GDPR) — for analytics cookies and push notifications. You can withdraw consent at any time with effect for the future.
  • Legitimate interests (Art. 6(1)(f) GDPR) — to keep the service secure, prevent abuse, and understand and improve how manare is used.
  • Legal obligation (Art. 6(1)(c) GDPR) — where we are required to retain data, for example to meet tax or accounting requirements.

Service Providers We Work With

We use carefully selected service providers who process data on our behalf as processors under Art. 28 GDPR, bound by data processing agreements. The key providers are:

Hosting & infrastructure

  • Vercel Inc. — hosting and delivery of the manare website, including server logs and IP addresses.
  • Supabase, Inc. — our backend database, authentication, and file storage. Your account data and the contacts you store are held here under row-level security.

Analytics

  • Google Analytics 4 (Google Ireland Ltd.) — to measure website traffic and usage. Loaded only after you consent to analytics cookies.
  • PostHog — product analytics to understand how features are used. Loaded only after you consent to analytics cookies.

App services

  • OneSignal (OneSignal, Inc.) — to deliver push notifications and reminders, where you have enabled them.
  • RevenueCat, Inc. — to manage manare Pro subscriptions and entitlements.
  • Apple — for Sign in with Apple and for App Store purchases. Apple processes payment data directly; we never see your card details.
  • Sentry (Functional Software, Inc.) — error and crash reporting, to diagnose and fix problems.

International Data Transfers

Some of the providers listed above are based in, or process data in, countries outside the European Economic Area — in particular the United States. Where this is the case, the transfer is safeguarded by the European Commission’s Standard Contractual Clauses and, where applicable, the provider’s certification under the EU–U.S. Data Privacy Framework, together with additional technical and organisational measures.

Cookies and Tracking

Our website uses cookies and similar technologies. Strictly necessary cookies are always active; analytics cookies are set only with your consent, which you manage through our cookie banner and the “Cookie Settings” link in the footer. For full details of each cookie we use, see our Cookie Policy.

Security

We use appropriate technical and organisational measures to protect your data, including encryption in transit (TLS), encryption at rest, and row-level security so that your contacts are only accessible to you and those you choose to share a team with. No method of transmission or storage is completely secure, but we continually review and improve our safeguards.

Data Retention

We keep your personal data only for as long as necessary for the purposes described above. Account data and the contacts you store are retained while your account is active. When you delete your account, your data is deleted without undue delay, except where we are required to retain certain records to comply with legal obligations. Residual copies in encrypted backups are removed in the ordinary course of our backup rotation.

Your Rights

Under the GDPR, you have the right to:

  • access the personal data we hold about you (Art. 15);
  • request correction of inaccurate data (Art. 16);
  • request erasure of your data (Art. 17);
  • request restriction of processing (Art. 18);
  • receive your data in a portable format (Art. 20);
  • object to processing based on our legitimate interests (Art. 21); and
  • withdraw consent at any time, with effect for the future (Art. 7(3)).

To exercise any of these rights, contact us at info@pep-oekotec.de. You also have the right to lodge a complaint with the competent data protection supervisory authority.

Changes to This Policy

We may update this privacy policy from time to time to reflect changes to our services or legal requirements. The current version is always available on this page, with the revision date shown above.