Back to Login

🔒 Privacy & Data Safety

Last updated: June 2026

ManoDweep is a mental wellness platform. Because you share deeply personal information with us (journal entries, mood logs, therapy notes), we take data protection seriously. This page explains what we collect, how it is protected, and what rights you have.

What We Collect

We collect only what is needed to provide the service:

  • Account information: name, email address, date of birth, gender, and (optionally) phone number, provided during registration.
  • Mental health content: journal letters, mood entries, lighthouse reflections, therapy session notes, trigger logs, and garden entries that you write inside the app.
  • Usage data: which areas of the app you visit and for how long, used only to award coins and improve the experience. No external analytics.

We do not sell your data. We do not run ads. We do not share your mental health content with third parties.

How Your Data Is Protected

Encryption in transit. All communication between your device and ManoDweep uses HTTPS/TLS. Strict-Transport-Security headers are enforced on every response.

Encryption at rest. Sensitive fields (journal letters, therapy notes, lighthouse reflections, trigger logs, and pre/post session notes) are encrypted in the database using AES-256-GCM before storage. The encryption key is never stored alongside your data.

Passwords. Your password is hashed with bcrypt (cost factor 12) and never stored in plaintext. We never have access to your raw password.

Session security. Authentication tokens are short-lived (7 days), stored in httpOnly cookies that JavaScript cannot read, and sent only over HTTPS in production.

Access control. Your content is only accessible to you. API endpoints enforce authentication on every request and validate that the requesting user owns the data. Admin access is restricted to a named whitelist.

Rate limiting. Login, registration, and OTP endpoints are rate-limited to protect against brute-force attacks.

Data Retention

Your data is retained for as long as your account is active. You may request deletion at any time by contacting us, see below. Upon account deletion, all personally identifiable information and mental health content is removed from our database within 30 days.

Third-Party Services

We use a small number of trusted third-party services to operate the platform:

  • Neon (PostgreSQL): database hosting. Data is stored in the EU/US region with encryption at rest by default.
  • Vercel: application hosting and blob storage for media files.
  • Redis (Upstash): used only for temporary rate-limiting counters. No personal content is stored in Redis.
  • Google OAuth: optional login method. If you sign in with Google, we receive only your name and email from Google.
  • Google Gemini / Groq AI: used to generate the daily island story. No personally identifiable data is sent to AI providers.

Age Requirement

ManoDweep requires users to be 18 years or older. Date of birth is verified at registration. If we discover an account belongs to someone under 18, the account will be closed and all data deleted.

Your Rights

  • Access: you can view all your content within the app at any time.
  • Correction: you can update your profile and data from your profile page.
  • Deletion: contact us to request full account and data deletion.
  • Portability: data export is on our roadmap. Until then, contact us to request a copy of your data.

Contact Us

If you have questions about this policy, want to exercise your rights, or want to report a security concern, please email us at privacy@manobandhu.com.

ManoDweep · Island of the Mind · This policy may be updated from time to time. Continued use of the platform after changes constitutes acceptance.