Privacy Policy
Last updated: 10 July 2026
Privacy is the starting point of this service, not a setting. You can take the check-in and reach crisis resources with no account, no name, and no payment. This policy explains, in plain language, what we process, why, who we share it with, and the rights you have over it.
1. Who we are (the data controller)
The Mansio (“we”, “us”) operates themansio.com. The controller responsible for your personal data is Maksym Postoliuk, Warsaw, Poland. You can reach us about privacy at [email protected].
2. Our privacy-by-design choices
- Private by design. Crisis resources always work without an account or any identifier. The check-in asks only for what it needs — your answers and an email to deliver your result.
- No advertising trackers; analytics fenced to public pages. We set no advertising cookies and run no advertising pixels in your browser. Usage analytics (Microsoft Clarity, cookie-free — no cookies, nothing stored on your device; opt out anytime via our Cookie Policy) runs only on public marketing pages and never on the check-in, your result, your private space, or the crisis page. When you arrive from one of our ads, conversion results are reported to the ad platform from our server as a hashed identifier — never health information.
- We never sell or rent your data, and we do not use your health information to target advertising.
- Data minimisation. Safety events are recorded as a category and outcome only — never the words you wrote.
- Self-hosted database. Your records are stored in our own database on our server, not in a third-party marketing platform.
3. What we process and why
| Data | Purpose | Lawful basis (GDPR) |
|---|---|---|
| Check-in answers and your computed result (health-related) | To give you a screening result and a next-step plan | Explicit consent — Art. 9(2)(a); Art. 6(1)(a) |
| Consent records (version, time, purposes, and the IP address / browser identifier at the moment of consent) | To prove and manage your consent | Legal obligation / legitimate interest — Art. 6(1)(c)/(f) |
| Daily check-ins and weekly pulses (health-related) | To track your progress over time, re-screen safety each week, and adjust your plan | Explicit consent — Art. 9(2)(a); Art. 6(1)(a) |
| In-app tool entries you choose to log — tagged thoughts, chosen values, urge-tool outcomes, and rituals (all picked from preset options, never free text; health-related) | To power the Tools features you use — the set-aside box, your values, your own progress receipts, and your trigger rituals | Explicit consent — Art. 9(2)(a); Art. 6(1)(a) |
| Safety events (category + outcome only) | To route you to crisis/medical help and audit that safety always works | Vital interests / consent — Art. 9(2)(c)/(a) |
| Account email | To sign you in (magic link, or a password if you chose to set one) and run your subscription | Contract — Art. 6(1)(b) |
| Email you choose to give us (to receive your result and supportive tips) | To email your result and occasional follow-ups; you can unsubscribe at any time | Consent — Art. 6(1)(a) |
| Payment data | Handled by our Merchant of Record; we receive only a subscription status, not card numbers | Contract — Art. 6(1)(b) |
| Minimal technical/log data (e.g. IP, device, processed by our network provider) | Security, abuse prevention, keeping the service available | Legitimate interest — Art. 6(1)(f) |
| Anonymous funnel-progress events (how far in the check-in you got — never your answers, never your identity) | First-party measurement to see where the free check-in can be improved | Legitimate interest — Art. 6(1)(f) |
| Where a visit came from (UTM tags and ad-click identifiers like fbclid/gclid, if present in the link you clicked) | First-party measurement of which channel brought a check-in or purchase. If you arrived from a Meta ad, we may report the conversion back to Meta server-side — a hashed (unreadable) email, the ad-click identifier, and the purchase amount only. Never your answers, never your focus area, never any health information; no advertising cookies or pixels run in your browser | Legitimate interest — Art. 6(1)(f) |
| Email delivery events (sent / delivered / bounced, and opens or clicks reported by our email provider) | To stop sending to broken mailboxes and see whether follow-ups are wanted; unsubscribe ends all marketing email | Legitimate interest — Art. 6(1)(f) |
| Browser push subscription (a device push endpoint, only if you tap “Enable” and grant permission) | To send one neutral daily reminder that never names what you’re working on; disable it any time in your browser or account | Consent — Art. 6(1)(a) |
| Notification preference (the “Discreet” toggle) | Discreet by default — notifications and email previews never reveal why you’re here; turning Discreet off only allows the product name in subjects, never the topic | Consent — Art. 6(1)(a) |
| Buddy link (a nickname you choose plus an unguessable link id, only if you create one) | To show one person you invite which days you showed up — never your answers, never your focus area; delete the link any time and it stops working instantly | Consent — Art. 6(1)(a) |
4. Special-category (health) data
Information about gambling, alcohol, drugs, or eating concerns is “special category” data under GDPR Article 9. We process it only with your explicit consent, which you give before the check-in stores anything, and only for the purposes above. You can withdraw consent at any time (Section 8); withdrawal does not affect processing already carried out, and never affects your access to free crisis resources.
5. Who we share data with (sub-processors)
We use a small number of vetted providers strictly to run the service. They process data on our instructions only.
| Provider | Role | Region |
|---|---|---|
| LemonSqueezy (Merchant of Record) | Checkout, payment processing, tax/VAT | United States / EU |
| Resend | Transactional and account emails | EU (Ireland) |
| Anthropic (Claude, AI text generation) | Phrases the wording of your plan text and supportive weekly notes. Receives your concern area and progress trend under a random identifier — never your name, email, or anything you typed. Safety and crisis content is never AI-generated. | United States |
| Voyage AI (semantic search) | Indexes fragments of our published content library so the right passage can be found. Receives no personal data. | United States |
| Microsoft (Clarity) | Cookie-free usage analytics on public marketing pages only — never on your check-in, result, private space, or the crisis page. No cookies, nothing stored on your device; opt out any time via the Cookie Policy | United States / EU |
| Meta Platforms | Server-side conversion reporting when you arrive from one of our ads: a hashed (unreadable) email, the ad-click identifier, and the purchase amount only — never your answers, never any health information. No Meta cookies or pixels run in your browser | United States / EU |
| Cloudflare | DNS, inbound email routing, and a security/CDN proxy (DDoS protection and faster delivery); processes only network traffic and metadata, never your check-in content | Global |
| Our hosting provider (Hetzner) | The server that runs the app and our database | EU (Germany/Finland) |
We do not share your data with anyone else, and we never sell it. We may disclose data if required by law or to protect someone’s safety.
6. International transfers
Some providers above are located in the United States, so your data may be transferred outside the EEA/UK. Where that happens we rely on appropriate safeguards — principally the European Commission’s Standard Contractual Clauses (and the UK Addendum) — to protect your data to an equivalent standard. You can request a copy of the relevant safeguards from [email protected].
7. How long we keep it
- Anonymous check-in sessions: funnel progress is purged after 180 days; one-time sign-in and claim tokens after 30 days.
- Email leads that never became an account: deleted no later than 18 months after capture (sooner on unsubscribe).
- Account data: kept while your account exists; deleted immediately and completely when you use “Delete my account”, or on request to [email protected].
- Consent and safety-audit records: kept as needed to evidence compliance.
- Check-ins, pulses and progress: kept while your account is active so you can see your trend; deleted with your account.
8. Your rights
Subject to applicable law, you can (most of these work self-serve in your account: “Export my data”, “Delete my account”, and “Pause data processing” live under Account → Your data & privacy):
- Access the personal data we hold about you, and get a copy (portability).
- Correct inaccurate data, or ask us to complete incomplete data.
- Erase your data (“right to be forgotten”) — for accounts, this deletes your record and cascades to related data.
- Restrict or object to processing, including processing based on legitimate interests.
- Withdraw consent at any time, without affecting prior processing.
- Lodge a complaint with your data protection authority.
To exercise any right, email [email protected]. We respond within the time limits the law requires (generally one month).
9. Children
This service is for adults (18+). It is not directed at children, and we do not knowingly process the data of anyone under 18. If you are under 18, please use a service made for young people — there is guidance and a youth helpline linked from the site.
10. Security
We use technical and organizational measures appropriate to the sensitivity of the data, including access controls, encryption in transit, security headers, and a minimized data footprint. No system is perfectly secure, but we work to protect your information and to limit what we collect in the first place.
11. Your region
- EEA / UK / Switzerland: the GDPR / UK GDPR rights above apply; you may complain to your national authority.
- Canada: we handle personal information consistently with PIPEDA principles, including consent and access rights.
- United States (incl. California): we do not sell or “share” personal information for cross-context behavioral advertising; California residents may exercise access and deletion rights under the CCPA/CPRA.
- Australia: we handle personal information consistently with the Australian Privacy Principles.
12. Changes
We may update this policy. We will change the “last updated” date above and, for material changes affecting accounts, notify you. Continued use after an update means you accept the revised policy.
The Mansio is private recovery support and education, alongside professional care, never instead of it. This is not medical advice, diagnosis, or treatment. In a crisis, contact your local emergency number.
Questions about this document: [email protected].