Your wishes are the most personal thing you will ever type into this app. This policy explains, in plain terms, exactly what happens to them. It describes what the app actually does — not what it might do one day.
Mesih Malik Kuru, an individual developer based in Ankara, Türkiye, is the controller of the data described here. Contact: privacy@makemanifest.app. The full trader details published on the App Store listing also identify us.
By default, everything stays on your device, in the app's private storage. That includes:
| What | Why it exists |
|---|---|
| Your wish text, its category and status | It is the app. Without it there is nothing to show you. |
| The sky snapshot stamped on a wish (moon phase, planet positions) | Computed on your device from the date; no location is used or requested. |
| Signs and check-ins | The follow-up part of the practice. |
| 3-6-9 practices: which days you kept, and how many lines you wrote | To draw your constellation. The lines you write during a session are never stored anywhere — not on the device, not on a server. Only a count. |
| Your settings: notification time, chosen ritual scene, optional sun sign | To make the app behave the way you set it. |
The app does not ask you this when you first open it, and it does not decide it for you either: a new install keeps everything on the device, and stays that way until you choose otherwise. The choice arrives when it can first make a difference — if you sign in with Apple from Settings, the app shows you what cloud sync would change and asks you to agree before Apple's own sign-in screen appears. If you close either screen, nothing is recorded and nothing leaves the device. Whichever way it is settled, the choice is honoured throughout the app:
Our database is hosted by Supabase in Frankfurt, Germany (EU). Data is encrypted in transit and at rest, and row-level security means your rows are readable only by your own account.
| Recipient | What is sent | When |
|---|---|---|
| Supabase (EU, Frankfurt) — hosting | Your wishes, signs, check-ins, practice counts, settings | Only when cloud sync is on |
| Anthropic — the model behind refining | Refining: the wish text you typed. Signs: only the wish's category (for example "well-being") — never your words | Refining: only when you tap "Refine the words" — this works whether or not cloud sync is on, because the sentence is reworded and we store none of it. Signs: when a sign is generated for a subscriber, which requires cloud sync |
| Apple — push notifications | The generated sign text and the wish's identifier, so tapping the notification opens the right wish. Never your wish text | Only if you allow notifications |
| Apple — subscriptions | Handled entirely by Apple. We never see your name, card or payment details; we receive only whether a subscription is active | If you subscribe |
The developer's own purchase-alert service (getmivvo.app) | A copy of Apple's signed purchase notification: the transaction, the product, the expiry date and the account identifier it belongs to. Never your wish text, and never anything you wrote | When you subscribe, renew or cancel — so that a one-person team notices a purchase without watching a dashboard. Forwarded only after Apple's signature has been verified |
| TelemetryDeck (EU-hosted) — usage counts | Which screens are opened and which actions occur, as counts. Never your wish text, refined text, sign text, notes or sun sign. A count can carry up to four labels and no others: the group a wish belongs to (one of seven fixed ones — love, abundance, well-being, peace, growth, career, other), the name of the ritual scene you used, whether the account is subscribed, and which screen an upgrade page was opened from. The first of those deserves a plain word: the app usually picks the group for you from a short keyword list as you type, so while no word you write is ever sent, the group is a coarse reading of what you wrote — seven buckets, not a sentence — and it is sent with the count when a wish is sent. You can change it before sending. More travels with each count than the count itself, and we would rather set it out than let the phrase "anonymous usage data" cover it: a per-install identifier; your device's model, iOS version, app version, language, region and time zone; the shape of your use — how many sessions, over how many separate days, how long they run, what hour it is; and the accessibility settings iOS reports, such as whether you use larger text, bold text or reduced motion. We neither ask for that last group nor use it — it arrives inside the standard bundle the analytics library attaches to every count — but it can say something about a person, so it is named here instead of left out. The identifier is a one-way hash of an identifier Apple gives this app for this device only, hashed again by TelemetryDeck; it is not your name, email, Apple ID or an advertising identifier, we send it nowhere else, and it never travels alongside your account id, so nothing joins it to your wishes. It exists because counting how many people come back on day 7 is impossible without something that tells one install from another | While the app is in use, including one count when the app is opened — and whichever cloud-sync choice you made |
That is the complete list. There is no advertising network, no analytics broker, no data marketplace, and no "partners".
Manifesting is run by one person, Mesih Malik Kuru, who lives and works in Türkiye. If you are in Europe, that is worth stating plainly at the top rather than burying in a table: the person who decides what this app does with your data is outside the EU, and he reaches it from there.
Your wishes themselves are stored in the European Union (Frankfurt) and the usage counts are held by an EU-hosted service. Some of the recipients listed above are nonetheless outside the EU and the UK, so your data crosses a border:
| Who | Where |
|---|---|
| Supabase — the database holding synced wishes | European Union (Frankfurt, Germany) |
| Supabase — the server code that handles a refining request | Served from Supabase's global edge network, so this particular request may be handled outside the EU. It stores nothing |
| TelemetryDeck — usage counts | European Union |
| Anthropic — the model behind refining | United States |
| Apple — subscriptions, push notifications, Sign in with Apple | United States and Apple's global infrastructure |
The developer's own purchase-alert service (getmivvo.app) | Outside the EU. It never receives anything you wrote |
The European Commission has adopted an adequacy decision for the United States, the EU–US Data Privacy Framework, but it covers only recipients that certify to it. Unless a recipient is so certified, its transfers rest on the data protection terms it publishes — including the EU Standard Contractual Clauses where it offers them — together with the technical measures described in this policy: encryption in transit and at rest, row-level isolation, redacted logging, and the rule that your wish text travels on exactly one path and only when you ask it to.
If you would rather nothing crossed a border at all, keep cloud sync off and do not use refining. The ritual, the journal, the moon data, the practice and the widgets all work with no network at all.
The app creates an anonymous account on first launch, so that it never has to interrupt you for a sign-up. Nothing you write is uploaded to it until you turn cloud sync on — and the app only ever offers that as part of signing in with Apple, so an account that is still anonymous normally holds nothing you wrote. Two exceptions. If you agreed to cloud sync in the app's older onboarding and never signed in, your wishes are on the server under an anonymous account — Settings → Privacy center turns sync off, and "Delete account & data" removes them. And if the app ever has to start a fresh session because your sign-in stops being valid, anything synced before that stays under your previous account, where a fresh session cannot reach it — write to privacy@makemanifest.app and we will delete it for you. You may optionally link the account to your Apple ID with Sign in with Apple — the moment described above, where cloud sync is explained and agreed to first. When you do, we ask Apple for nothing but an opaque identifier — no email address and no name, because the app has no use for either. If you granted this app your email address in the past, Apple may still include it; it is stored with your account, used for nothing, and you can withdraw it in your Apple ID settings.
Because we serve users in the European Union, you have the rights granted by the GDPR: access, rectification, erasure, restriction, objection, and portability. Two of them are built into the app and need no correspondence with us:
Where we rely on your consent — cloud storage of wish content — the legal basis is your explicit consent under Article 9(2)(a), and you may withdraw it at any time in Settings without losing the use of the app. Withdrawing consent does not affect processing that already happened.
For anything else, or to complain, write to privacy@makemanifest.app. You also have the right to lodge a complaint with your local data protection authority.
Some US states — California among them — give you the right to know what is collected, to have it deleted, to correct it, and to opt out of its sale or of its sharing for advertising. The first three are the same rights described above and are exercised the same way: the export and delete buttons in Settings → Privacy center, or an email to us.
The fourth needs no button, because there is nothing to opt out of. We do not sell your personal information and we do not share it for cross-context behavioural advertising — not for money, not for anything else. We have never done so, including with the personal information of anyone we know to be under 16. There is no advertising in this app, no advertising identifier is collected, and no advertising network receives anything. We will not treat you differently for exercising any of these rights; there is no discount, loyalty tier or feature that depends on giving up your privacy.
On your device: until you delete the wish or the app. On our server, if sync is on: until you delete your account, at which point the records are removed. Usage counts are held separately by TelemetryDeck and are keyed to the per-install identifier described above, never to your account — deleting your account therefore removes your wishes but does not reach counts that carry no link to them. Removing the app ends the collection. Apple resets that identifier only once every app from the same developer has been removed from the device, so if this is the only one of ours you have, reinstalling starts a new one.
The app is rated 13+ and is not directed at children under 13. We do not knowingly collect data from children under 13. In some EU countries the age at which a person can consent to data processing on their own is higher than 13; where that applies, a parent or guardian should give that consent.
If this policy changes in a way that affects you, we will update the date at the top and, for
material changes, tell you in the app. The current version always lives at
makemanifest.app/privacy.