Mana CoresApps worth opening
Services Our apps Studio Contact

Privacy Policy.

Privacy Policy · Terms of Service · Contact

Service: Raava (the "App")

Controller: Mana Cores Limited ("Mana Cores", "Raava", "we", "us"), Suite 11341, 26/27 Upper Pembroke Street, Dublin 2, D02 X361, Ireland; incorporated in Ireland

Privacy contact / Data Protection contact: [email protected]

Last updated: 1 September 2026

This Privacy Policy explains what personal data we collect, why, how we use and share it, how long we keep it, and the rights you have. Because the App processes health and other sensitive data, please read the sections on special-category data and your rights carefully.


1. A note on sensitive health data

Raava is a health and fitness tracking app. Some of the data you choose to provide is special-category / sensitive personal data under laws such as the GDPR (Article 9), including data about your health, injuries, medical clearance, supplements or medication, and - if you choose to use those features - your reproductive status, pregnancy or lactation, and menstrual cycle. We process this data only with your explicit consent and only to provide the features you have chosen. You can withdraw consent, stop using those features, export your data, or delete your account at any time.


2. The data we collect

We collect data you provide, data generated as you use the App, and a limited amount of technical data.

A. Account and identity

  • Email address and authentication identifiers (via email/password, Google Sign-In, or Apple Sign-In). Apple/Google may share your name and email when you choose those sign-in methods.
  • Display name, age (or age range), and sex assigned at birth.

B. Body metrics

  • Weight, height, and optionally body-composition figures; derived calorie and macronutrient targets.

C. Health and medical data (sensitive - explicit consent)

  • Health-screening answers (PAR-Q style: heart conditions, chest pain, dizziness or fainting, bone/joint/soft-tissue problems, blood-pressure or chronic-condition medication, pregnancy complications, and any other reason not to exercise) and the safety flags derived from them.
  • Whether you have attested physician clearance to exercise.
  • Injuries you report (body area, severity, notes) and muscles you choose to ease off.
  • Reproductive status and, if applicable, pregnancy trimester or lactation stage, and menstrual-cycle settings (cycle length, period length, last start date).
  • Supplements and medication you log (name, dose, schedule), including any items you mark as medicine. For an item marked as medicine you can also record, all optionally, whether it is a prescription, the name of the prescribing doctor, the name of your pharmacy, a refill date, and a free-text description of the condition it treats (the "Treats" field). These are among the most sensitive fields in the App: they can name a third party and state a diagnosis.
  • Daily check-ins: your self-reported sleep quality, fatigue, stress, muscle soreness and mood, optional hours slept, an optional free-text note for the day, and the readiness score and band we compute from them. [Counsel to confirm the Article 9 classification of readiness check-ins. The RoPA (3.3) records them as health-adjacent and unconfirmed; the DPIA (D13) treats them as explicit-consent health data. This policy follows the DPIA's position pending that confirmation.]

D. Training and activity data

  • Goals, fitness level, equipment, weekly schedule, target muscles; your weekly sport schedule; workouts, logged sets (weight, reps, perceived effort), sessions, and activity logs; AI-generated training programs and the safety decisions recorded for them (consent version, exclusions and limits applied, validator outcome).

E. Nutrition data

  • Meals and food items you log (calories and macronutrients), custom foods, saved meals, and favorites. If you photograph a nutrition label or type a food to estimate, that image or text is processed to extract nutrition facts (see Section 4).
  • Water, caffeine and alcohol intake you log. [Counsel to confirm whether alcohol intake, and dietary detail generally, should be treated as Article 9 health data rather than as ordinary nutrition data; the RoPA (3.4) and DPIA (D5) both leave this open. Nothing in this policy decides it.]
  • When you search for a food or scan a barcode, the search term or barcode is sent from your device to the public food and supplement databases described in Section 5. Your account identifier is never sent with it.

F. Subscription and billing data

  • Subscription status, tier, trial/renewal state, and purchase events, processed through the app store and our billing provider. We do not receive or store your full payment-card details.

G. Technical, usage, and diagnostic data

  • App and device information, product-analytics events about how you use features, and crash and error diagnostics. We design analytics and crash reporting not to include health data or free-text content, and they are subject to your privacy choices (Section 9).

We do not knowingly collect precise location data, contacts, or biometric identifiers.


3. Why we use your data and our legal bases

PurposeData usedGDPR legal basis
Provide core tracking and account featuresA, B, D, EPerformance of a contract
Generate AI training programs and apply safety screening/limitsA-D (incl. health)Explicit consent (Art 9) for health data; contract for the rest
Estimate nutrition from a label photo or food textE (image/text)Performance of a contract / consent
Reproductive, pregnancy/lactation, and cycle featuresCExplicit consent (Art 9)
Record supplements and medication, including prescriber, pharmacy and condition treatedCExplicit consent (Art 9) for the health data; contract for the rest
Daily readiness check-ins and the recovery guidance derived from themCExplicit consent (Art 9) [counsel to confirm the classification - see Section 2C]
Look up a food or a supplement you searched for or scannedEPerformance of a contract
Keep the App secure and prevent abuseA, GLegitimate interests / legal obligation
Product analytics to improve the AppGConsent where required, otherwise legitimate interests; controlled by your opt-out
Crash and error diagnosticsGConsent where required, otherwise legitimate interests; controlled by your opt-out
Billing and subscriptionsA, FPerformance of a contract / legal obligation
Develop new products and services, and improve our existing services (under Mana Cores Limited)Aggregated or de-identified data where possible; otherwise the categories aboveLegitimate interests; explicit consent for any new use of health/sensitive data
Comply with law and defend legal claimsas neededLegal obligation / legitimate interests

We do not sell your personal data for marketing or advertising purposes, and we do not use your health data for advertising. We may use your data to develop new products and services and to improve our existing services under Mana Cores Limited, using aggregated or de-identified data wherever possible; where this would involve a new use of your health or other sensitive data, we will rely on your explicit consent. If we ever intend to use your data in a materially different way, we will tell you first and obtain your consent where the law requires it (see Section 12). We do not use your inputs to train third-party AI models (see Section 4).


4. AI processing (Google Gemini)

Two features use Google's Gemini model through Google's API:

  • Nutrition-label reading: when you photograph a nutrition label, the image is sent to Gemini, which reads the panel and returns the facts for you to confirm before logging.
  • Food estimation: when you type a food, the text is sent to Gemini, which returns an estimated calorie/macronutrient breakdown for you to confirm.
  • Training-program generation: a structured, non-identifying description of your training parameters and a pre-vetted exercise menu are sent to Gemini, which selects exercises and writes plain-language notes. The deterministic engine, not the AI, sets all safety numbers, and a server-side validator re-checks the result.

These calls run on Google's paid API tier. Based on Google's API terms, your inputs are not used to train the model and images are not retained after processing. Gemini processing may occur on Google infrastructure outside your region (see Section 6). [Confirm the current Gemini API terms and the applicable data-transfer mechanism in writing.]


5. Who we share data with (processors and recipients)

We share personal data with service providers that process it on our behalf under contract, and as required by law. We do not sell personal data.

RecipientRoleDataHosting region
SupabasePrimary backend: authentication, database, server functionsAll app data you createUnited Kingdom (London, eu-west-2)
Google (Gemini API)AI nutrition extraction and program-copy generationLabel photos, food text, non-identifying program parametersGoogle infrastructure (may be outside the EU; see Section 6)
PostHogProduct analyticsUsage events (no health data; email only on the user profile)European Union
SentryCrash and error diagnosticsError/diagnostic data, opaque user ID (no health data by default)European Union (Germany)
AdaptySubscription managementUser ID, subscription and purchase state⚠ Not yet confirmed - see the note below
Expo / EASBuild service only. We use it to compile the app before it is submitted to the storesNo user data. The app ships no over-the-air update channel and no remote push, so no update or device tokens are created or sentUnited States (build infrastructure; no user data reaches it)
App stores (Apple, Google)Payment processing for subscriptionsPurchase dataper store
Open Food FactsPublic food and barcode database queried from your device when you search for a food or scan a productThe search term you typed or the barcode you scanned, and your device's IP address. No account identifier, email or health dataFrance / EU (community-run)
NIH DSLD (US National Institutes of Health, Dietary Supplement Label Database)Public supplement-label database queried from your device when a scanned supplement is not found in Open Food FactsThe scanned barcode, and your device's IP address. No account identifier, email or health dataUnited States
ResendDelivery of the launch-list email from our websiteThe email address you gave the launch list and the content of that message. No app data⚠ Not yet confirmed - see the note below

⚠ Two hosting regions are still being confirmed (Adapty and Resend). We have not stated a region we have not verified, rather than guess at one. Both are named here so the processing itself is disclosed; the transfer detail will be completed before this policy is relied on, and any transfer outside the EEA will be covered by the safeguards described in Section 6.

Open Food Facts and NIH DSLD are public reference databases, not services we operate. The lookup is sent from your device, so those services see your device's IP address and the term or barcode, and nothing that identifies your account. We send them no health data of any kind. [Counsel to confirm whether these two are processors or independent controllers for the query they receive, as with the app-store rows above.]

We may also disclose data to comply with law, enforce our Terms, protect rights and safety, or in connection with a merger, acquisition, or asset sale (with notice where required). [Maintain executed Data Processing Agreements with each processor.]


6. International data transfers

Our primary data store (Supabase) is hosted in the United Kingdom (London, eu-west-2), not in the EEA. Our analytics and error-reporting providers (PostHog and Sentry) are hosted in the European Union. Some processing takes place outside the EEA and the UK: Google Gemini and Expo/EAS are US-based, the NIH DSLD supplement-label lookup is a US government service, and our launch-list email is delivered by Resend.

Where personal data is transferred internationally, we rely on an appropriate safeguard. Transfers of EEA personal data to the UK rely on the European Commission's adequacy decision for the United Kingdom; transfers to the US and elsewhere rely on Standard Contractual Clauses or an equivalent mechanism. [Counsel to confirm the transfer mechanism for each non-EEA processor, including Gemini, Expo/EAS, Resend and the UK adequacy reliance for Supabase, and to document the transfer impact assessment.]


7. How long we keep data

  • We keep your personal data while your account is active and as needed to provide the App.
  • Some "remove" actions in the App hide a record rather than erase it. When you remove a supplement or medication from your stack, we mark it as archived and stop showing it and its reminders; the record itself - including any prescribing doctor, pharmacy and condition-treated text you entered - remains stored for the life of your account so that your past adherence history stays intact. It is erased when you delete your account. ⚠ Those three fields can only be entered when the item is first ADDED - the App provides no way to edit or clear them afterwards. So there are exactly two ways to erase that text, and both work today: delete your account, or email us at [email protected] and we will erase those fields for you without deleting the rest of your record.
  • When you delete your account, we delete your personal data from our primary systems through a cascading deletion process, except where we must retain limited data to comply with law, resolve disputes, or enforce our agreements.
  • Backups and processor logs are deleted on a rolling basis. [Document specific retention periods per data category and per processor.]

8. Your rights and choices

Depending on where you live, you have some or all of the following rights. You can exercise many of them directly in the App, or by contacting [email protected].

Available in the App:

  • Export your data - download a copy of your data (self-service export).
  • Delete your account - permanently delete your account and associated data (cascading deletion).
  • Privacy controls - turn product analytics and crash diagnostics on or off, and manage other privacy preferences.

On request (GDPR / UK GDPR and similar laws):

  • Access, rectification, erasure, restriction of processing, data portability, and objection to processing.
  • Withdraw consent at any time (including for health features and analytics), without affecting processing done before withdrawal.
  • Lodge a complaint with your data-protection authority. EU/UK users can contact their local supervisory authority.

US state privacy rights (for example, California CCPA/CPRA):

  • Right to know, access, correct, and delete personal information, and to limit the use of sensitive personal information. We do not sell or "share" personal information for cross-context behavioral advertising. You will not be discriminated against for exercising your rights.

We respond to verified requests within the timeframes required by law.


9. Analytics and diagnostics choices

Product analytics (PostHog) and crash diagnostics (Sentry) are governed by your in-app privacy preferences and are designed to exclude health data and free-text content. Analytics events do not carry your email or other directly identifying information; your email is associated only with your profile in the analytics tool to support your account. You can opt out of analytics and crash diagnostics in the App's privacy settings.

One limit worth stating plainly: turning "Crash & diagnostics" off stops the App from sending error reports, but it does not stop reports generated when the App itself crashes at the operating-system level. Those are produced by the crash-reporting component before the App's own settings can be read. They contain a technical stack trace and an opaque user identifier - no health data, no email. We accept this limit because the alternative is to delay crash reporting at every start-up, which would mean losing exactly the crashes that happen while the App is opening.


10. Security

We use technical and organizational measures to protect personal data, including authentication, access controls, encryption in transit, row-level access restrictions, and UK-hosted primary storage (London, eu-west-2), with analytics and error reporting hosted in the EU. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Please keep your credentials safe and notify us of any suspected compromise.


11. Children and young people

The App is not directed to children under 16. We do not knowingly collect personal data from anyone under that age. If you believe a child has provided us data without appropriate consent, contact [email protected] and we will take appropriate steps. We do not operate a permitted 14-17 band. You must be at least 16 to use the App, or older where your country sets a higher age of digital consent. An age below 16 is rejected at sign-up, in Settings, and by the database.

That is a check rather than a complete gate, and we would rather say so plainly. Entering an age is optional, so an account can be created without one, and we operate no verifiable parental consent route for anyone below the applicable age. Accounts created before this minimum was introduced were not re-checked. Closing these gaps is an open item in our age gate remediation record and sits with counsel. If counsel directs a different minimum under R2, this section and the enforcement move together.


12. Changes to this policy

We may update this Privacy Policy. If we make material changes, we will provide notice (for example, in-app or by email) and, where required by law, obtain your consent. The "Last updated" date shows the current version, and the version history at the end of this policy records what changed in each one.


13. Contact us

Questions or requests about your privacy: [email protected]

Mana Cores Limited, Suite 11341, 26/27 Upper Pembroke Street, Dublin 2, D02 X361, Ireland.

⚠ This address is not a preference, it is the one already published. lib/site.ts in the website repo defines a single legalEmail, and the live privacy, terms, support and cookies pages all route to it. An earlier draft of this section left a placeholder suggesting [email protected] and asked someone to "pick one and make both say it" - which is how a policy ends up naming an erasure route that no mailbox answers. Matching the published page was the only option that did not create the mismatch the placeholder warned about. If a dedicated privacy mailbox is ever preferred, change site.legalEmail and this line in the same commit. No Data Protection Officer has been appointed, and no EU or UK representative has been designated. Mana Cores Limited is established in Ireland, so no Article 27 representative is required for the EU. ⚠ Whether Article 37 requires a DPO given large-scale special-category processing is an open question for counsel; if one is appointed, their contact details belong here.


Version history

Kept because the "Last updated" date alone tells a reader that something changed, not what. A published policy that names a controller, an erasure route and a set of processors should be able to show how each of those has moved.

DateVersionWhat changed
1 September 20262.0The product was renamed from Mana Unlimited to Raava. Trademark clearance found the MANA name unavailable across the classes covering software, training and nutrition. The controller is unchanged: Mana Cores Limited, same registration, same registered office. Contact addresses moved from @manacores.com to @heyraava.com. Separately: the Expo / EAS entry was corrected - it disclosed over-the-air updates and push notifications, neither of which the app has, so no update or device tokens exist to be processed. The minimum age is now stated as 16 rather than left blank. Section 11 states plainly that this is a check and not a complete gate, because entering an age is optional, the database CHECK was never validated against pre-existing rows, and there is no verifiable parental consent route; an earlier draft of this revision claimed the minimum was enforced in the app and in the database, which overstated it. The position on a Data Protection Officer is stated explicitly rather than left as an editorial note.
6 August 20261.0First published version.
Mana Cores Limited · Registered in Ireland, Company Number 820239
Suite 11341, 26/27 Upper Pembroke Street, Dublin 2, D02 X361, Ireland
© 2026 Mana Cores. All rights reserved.
Privacy Terms
Made with ❤ in Dublin · manacores.com