Service: Raava (the "App")
Controller: Mana Cores Limited ("Mana Cores", "Raava", "we", "us"), Suite 11341, 26/27 Upper Pembroke Street, Dublin 2, D02 X361, Ireland; incorporated in Ireland
Privacy contact / Data Protection contact: legal@heyraava.com
Last updated: 6 September 2026
This Privacy Policy explains what personal data we collect, why, how we use and share it, how long we keep it, and the rights you have. Because the App processes health and other sensitive data, please read the sections on special-category data and your rights carefully.
1. A note on sensitive health data
Raava is a health and fitness tracking app. Some of the data you choose to provide is special-category / sensitive personal data under laws such as the GDPR (Article 9), including data about your health, injuries, medical clearance, supplements or medication, and - if you choose to use those features - your reproductive status, pregnancy or lactation, and menstrual cycle. We process this data only with your explicit consent and only to provide the features you have chosen. You can withdraw consent, stop using those features, export your data, or delete your account at any time.
2. The data we collect
We collect data you provide, data generated as you use the App, and a limited amount of technical data.
A. Account and identity
- Email address and authentication identifiers (via email/password, Google Sign-In, or Apple Sign-In). Apple/Google may share your name and email when you choose those sign-in methods.
- Display name, age (or age range), and sex assigned at birth.
B. Body metrics
- Weight, height, and optionally body-composition figures; derived calorie and macronutrient targets.
C. Health and medical data (sensitive - explicit consent)
- Health-screening answers (PAR-Q style: heart conditions, chest pain, dizziness or fainting, bone/joint/soft-tissue problems, blood-pressure or chronic-condition medication, pregnancy complications, and any other reason not to exercise) and the safety flags derived from them.
- Whether you have attested physician clearance to exercise.
- Injuries you report (body area, severity, notes) and muscles you choose to ease off.
- Reproductive status and, if applicable, pregnancy trimester or lactation stage, and menstrual-cycle settings (cycle length, period length, last start date).
- Supplements and medication you log (name, dose, schedule), including any items you mark as medicine. For an item marked as medicine you can also record, all optionally, whether it is a prescription, the name of the prescribing doctor, the name of your pharmacy, a refill date, and a free-text description of the condition it treats (the "Treats" field). These are among the most sensitive fields in the App: they can name a third party and state a diagnosis.
- Daily check-ins: your self-reported sleep quality, fatigue, stress, muscle soreness and mood, optional hours slept, and the readiness score and band we compute from them. (The check-in record can hold a written note, and nothing in the App asks you for one today. If we add a place to write one, this section will say so before it ships.)
D. Training and activity data
- Goals, fitness level, equipment, weekly schedule, target muscles; your weekly sport schedule; workouts, logged sets (weight, reps, perceived effort), sessions, and activity logs; AI-generated training programs and the safety decisions recorded for them (consent version, exclusions and limits applied, validator outcome).
E. Nutrition data
- Meals and food items you log (calories and macronutrients), custom foods, saved meals, and favorites. If you photograph a nutrition label or type a food to estimate, that image or text is processed to extract nutrition facts (see Section 4).
- Water, caffeine and alcohol intake you log.
- When you search for a food or scan a barcode, the search term or barcode is sent from your device to the public food and supplement databases described in Section 5. Your account identifier is never sent with it.
F. Subscription and billing data
- Subscription status, tier, trial/renewal state, and purchase events, processed through the app store and our billing provider. We do not receive or store your full payment-card details.
G. Technical, usage, and diagnostic data
- App and device information, product-analytics events about how you use features, and crash and error diagnostics. We design analytics and crash reporting not to include health data or free-text content, and they are subject to your privacy choices (Section 9).
H. Health and fitness records from your phone's health platform
- If you choose to connect it, the App can read a limited set of records from Android Health Connect or Apple Health: sleep, resting heart rate, heart rate variability, steps, active calories, body weight, and exercise sessions. We ask for your explicit consent before reading any of it, separately from anything else in this policy, because it is health data. You turn it on under Settings, then Health data sources, and you can turn it off in the same place at any time.
- We read only those categories, and only far enough back to fill in your daily record. We never write anything back to Health Connect or Apple Health.
- ⚠ As at the date of this version, no public release has this switched on, so nothing has been read from any phone's health platform yet. It is described here so the disclosure is in place before that happens rather than after it.
We do not knowingly collect precise location data, contacts, or biometric identifiers. We never ask your device for its location, and the App holds no location permission. Our analytics provider does work out an approximate location, usually the country and sometimes the region or city, from the network address your device connects with. That is an estimate drawn from the connection itself, not a reading from your phone.
3. Why we use your data and our legal bases
| Purpose | Data used | GDPR legal basis |
|---|---|---|
| Provide core tracking and account features | A, B, D, E | Performance of a contract |
| Generate AI training programs and apply safety screening/limits | A-D (incl. health) | Explicit consent (Art 9) for health data; contract for the rest |
| Estimate nutrition from a label photo or food text | E (image/text) | Performance of a contract / consent |
| Reproductive, pregnancy/lactation, and cycle features | C | Explicit consent (Art 9) |
| Record supplements and medication, including prescriber, pharmacy and condition treated | C | Explicit consent (Art 9) for the health data; contract for the rest |
| Daily readiness check-ins and the recovery guidance derived from them | C | Explicit consent (Art 9) |
| Look up a food or a supplement you searched for or scanned | E | Performance of a contract |
| Keep the App secure and prevent abuse | A, G | Legitimate interests / legal obligation |
| Product analytics to improve the App | G | Consent where required, otherwise legitimate interests; controlled by your opt-out |
| Crash and error diagnostics | G | Consent where required, otherwise legitimate interests; controlled by your opt-out |
| Billing and subscriptions | A, F | Performance of a contract / legal obligation |
| Develop new products and services, and improve our existing services (under Mana Cores Limited) | Aggregated or de-identified data where possible; otherwise the categories above | Legitimate interests; explicit consent for any new use of health/sensitive data |
| Comply with law and defend legal claims | as needed | Legal obligation / legitimate interests |
We do not sell your personal data for marketing or advertising purposes, and we do not use your health data for advertising. We may use your data to develop new products and services and to improve our existing services under Mana Cores Limited, using aggregated or de-identified data wherever possible; where this would involve a new use of your health or other sensitive data, we will rely on your explicit consent. If we ever intend to use your data in a materially different way, we will tell you first and obtain your consent where the law requires it (see Section 12). We do not use your inputs to train third-party AI models (see Section 4).
4. AI processing (Google Gemini)
Two features use Google's Gemini model through Google's API:
- Nutrition-label reading: when you photograph a nutrition label, the image is sent to Gemini, which reads the panel and returns the facts for you to confirm before logging.
- Food estimation: when you type a food, the text is sent to Gemini, which returns an estimated calorie/macronutrient breakdown for you to confirm.
- Training-program generation: a structured, non-identifying description of your training parameters and a pre-vetted exercise menu are sent to Gemini, which selects exercises and writes plain-language notes. The deterministic engine, not the AI, sets all safety numbers, and a server-side validator re-checks the result.
These calls run on Google's paid API tier. Based on Google's API terms, your inputs are not used to train the model and images are not retained after processing. Gemini processing may occur on Google infrastructure outside your region (see Section 6).
5. Who we share data with (processors and recipients)
We share personal data with service providers that process it on our behalf under contract, and as required by law. We do not sell personal data.
| Recipient | Role | Data | Hosting region |
|---|---|---|---|
| Supabase | Primary backend: authentication, database, server functions | All app data you create | United Kingdom (London, eu-west-2) |
| Google (Gemini API) | AI nutrition extraction and program-copy generation | The label or supplement photo you take, the food description you type in your own words, and non-identifying program parameters | Google infrastructure (may be outside the EU; see Section 6) |
| PostHog | Product analytics | Usage events (no health readings; your email address is held on your analytics profile) | European Union |
| Sentry | Crash and error diagnostics | Error and diagnostic data, plus your account identifier (no health data by default). That identifier is the same one your records are keyed on, so it is not anonymous, it stands in for your name | European Union (Germany) |
| Cloudflare | Serves our website, including this policy and our Terms; routes email sent to our published contact addresses | Website request data including your IP address, and the content of any email you send us at those addresses | Global network; company established in the United States |
| Formspree | Delivers the contact form on our company website | Your name, email address, the enquiry category you pick and the message you write | United States |
| Google Workspace | Business email for our company addresses, including the one you would write to about your data | The content of email you send us and our reply | United States (company); European data centres available |
| Adapty | Subscription management | User ID, subscription and purchase state | ⚠ Not yet confirmed - see the note below |
| Expo / EAS | Build service only. We use it to compile the app before it is submitted to the stores | No user data. The app ships no over-the-air update channel and no remote push, so no update or device tokens are created or sent | United States (build infrastructure; no user data reaches it) |
| App stores (Apple, Google) | Payment processing for subscriptions | Purchase data | per store |
| Open Food Facts | Public food and barcode database queried from your device when you search for a food or scan a product | The search term you typed or the barcode you scanned, and your device's IP address. No account identifier, email or health data | France / EU (community-run) |
| NIH DSLD (US National Institutes of Health, Dietary Supplement Label Database) | Public supplement-label database queried from your device when a scanned supplement is not found in Open Food Facts | The scanned barcode, and your device's IP address. No account identifier, email or health data | United States |
| Resend | Intended for the launch-list email from our website. Not in use. | None. No message has ever been sent through it | Not applicable while it is unused |
⚠ Adapty's hosting region is still being confirmed. We would rather name the processing and leave the region open than state one we have not verified. It is named here so the processing itself is disclosed, the detail will be completed before this policy is relied on, and any transfer outside the EEA will be covered by the safeguards in Section 6.
Resend is listed because we set it up, not because it is running. No sending domain of ours has been verified with it, our launch list is switched off in the website's own code, and no message has ever been sent. We name it so the list is complete. If we start using it, this row and Section 6 change first.
Open Food Facts and NIH DSLD are public reference databases, not services we operate. The lookup is sent from your device, so those services see your device's IP address and the term or barcode, and nothing that identifies your account. We send them no health data of any kind.
We may also disclose data to comply with law, enforce our Terms, protect rights and safety, or in connection with a merger, acquisition, or asset sale (with notice where required).
6. International data transfers
We are established in Ireland, so we sit under the EU rules, and our primary data store
(Supabase) is hosted in the United Kingdom (London, eu-west-2), not in the EEA. That
is a cross-border transfer on every write, and it is covered by the adequacy decision
described below. Our analytics and error-reporting providers (PostHog and Sentry) are
hosted in the European Union.
Some processing takes place outside the EEA and the UK. Google Gemini and Expo/EAS are US-based, the NIH DSLD supplement-label lookup is a US government service, Formspree handles our website contact form from the United States, and Google Workspace carries our business email. Cloudflare serves our website, including this policy, and routes email to our published addresses across a global network from a company established in the United States. Resend is set up but not in use, so nothing is transferred to it today.
Where personal data is transferred internationally, we rely on an appropriate safeguard. Transfers of EEA personal data to the UK rely on the European Commission's adequacy decision for the United Kingdom; transfers to the US and elsewhere rely on Standard Contractual Clauses or an equivalent mechanism.
7. How long we keep data
- We keep your personal data while your account is active and as needed to provide the App.
- Some "remove" actions in the App hide a record rather than erase it. When you remove a supplement or medication from your stack, we mark it as archived and stop showing it and its reminders; the record itself - including any prescribing doctor, pharmacy and condition-treated text you entered - remains stored for the life of your account so that your past adherence history stays intact. It is erased when you delete your account. ⚠ Those three fields can only be entered when the item is first ADDED - the App provides no way to edit or clear them afterwards. So there are exactly two ways to erase that text, and both work today: delete your account, or email us at legal@heyraava.com and we will erase those fields for you without deleting the rest of your record.
- When you delete your account, we delete your personal data from our primary systems through a cascading deletion process, except where we must retain limited data to comply with law, resolve disputes, or enforce our agreements.
- Backups and processor logs are deleted on a rolling basis.
8. Your rights and choices
Depending on where you live, you have some or all of the following rights. You can exercise many of them directly in the App, or by contacting legal@heyraava.com.
Available in the App:
- Export your data - download a copy of your data (self-service export).
- Delete your account - permanently delete your account and associated data (cascading deletion).
- Privacy controls - turn product analytics and crash diagnostics on or off, and manage other privacy preferences.
On request (GDPR / UK GDPR and similar laws):
- Access, rectification, erasure, restriction of processing, data portability, and objection to processing.
- Withdraw consent at any time (including for health features and analytics), without affecting processing done before withdrawal.
- Lodge a complaint with your data-protection authority. Our lead supervisory authority is Ireland's Data Protection Commission (dataprotection.ie). EU/UK users can also contact their own local supervisory authority.
US state privacy rights (for example, California CCPA/CPRA):
- Right to know, access, correct, and delete personal information, and to limit the use of sensitive personal information. We do not sell or "share" personal information for cross-context behavioral advertising. You will not be discriminated against for exercising your rights.
We respond to verified requests within the timeframes required by law.
9. Analytics and diagnostics choices
Product analytics (PostHog) and crash diagnostics (Sentry) are governed by your in-app privacy preferences and are designed to exclude health data and free-text content. Analytics events do not carry your email or other directly identifying information; your email is associated only with your profile in the analytics tool to support your account. You can opt out of analytics and crash diagnostics in the App's privacy settings.
One limit worth stating plainly: turning "Crash & diagnostics" off stops the App from sending error reports, but it does not stop reports generated when the App itself crashes at the operating-system level. Those are produced by the crash-reporting component before the App's own settings can be read. They contain a technical stack trace and an opaque user identifier - no health data, no email. We accept this limit because the alternative is to delay crash reporting at every start-up, which would mean losing exactly the crashes that happen while the App is opening.
10. Security
We use technical and organizational measures to protect personal data, including
authentication, access controls, encryption in transit, row-level access restrictions, and
UK-hosted primary storage (London, eu-west-2), with analytics and error reporting hosted
in the EU. No method of transmission or storage is completely secure, and
we cannot guarantee absolute security. Please keep your credentials safe and notify us of
any suspected compromise.
11. Children and young people
The App is not directed to children under 16. We do not knowingly collect personal data from anyone under that age. If you believe a child has provided us data without appropriate consent, contact legal@heyraava.com and we will take appropriate steps. We do not operate a permitted 14-17 band. You must be at least 16 to use the App, or older where your country sets a higher age of digital consent. An age below 16 is rejected at sign-up, in Settings, and by the database.
That is a check rather than a complete gate, and we would rather say so plainly. Entering an age is optional, so an account can be created without one, and we operate no verifiable parental consent route for anyone below the applicable age. Accounts created before this minimum was introduced were not re-checked. Closing these gaps is an open item in our age gate remediation record.
12. Changes to this policy
We may update this Privacy Policy. If we make material changes, we will tell you at least 14 days before they take effect (for example, in-app or by email) and, where required by law, obtain your consent. The "Last updated" date shows the current version, and the version history at the end of this policy records what changed in each one.
13. Contact us
Questions or requests about your privacy: legal@heyraava.com
Mana Cores Limited, Suite 11341, 26/27 Upper Pembroke Street, Dublin 2, D02 X361, Ireland.
No Data Protection Officer has been appointed, and no EU or UK representative has been designated. Mana Cores Limited is established in Ireland, so no Article 27 representative is required for the EU.
Version history
Kept because the "Last updated" date alone tells a reader that something changed, not what. A published policy that names a controller, an erasure route and a set of processors should be able to show how each of those has moved.
| Date | Version | What changed |
|---|---|---|
| 6 September 2026 | 2.1 | What we disclose about who receives your data, and about your phone's health platform. Three recipients were missing and are now listed: Cloudflare, which serves this page and routes email to our published addresses; Formspree, which delivers our website contact form; and Google Workspace, which carries our business email. A new part H describes reading sleep, heart rate, heart rate variability, steps, active calories, weight and exercise from Android Health Connect or Apple Health, with your explicit consent and nothing written back; no public release has it switched on yet. We now say plainly that our analytics provider estimates an approximate location from your network address, even though the App never asks your device where it is. The Resend row changed from an unconfirmed region to what is actually true, that it is set up and has never sent anything. The Gemini row now says the food description is the text you type in your own words rather than a parameter. The Sentry row no longer calls your identifier opaque, because it is the same identifier your records are keyed on. Section 6 now names every recipient outside the EEA and states that our Irish establishment plus a UK database means a cross-border transfer on every write. And a daily check-in note was described as something you could write when nothing in the App asks you for one. |
| 5 September 2026 | 2.0.1 | Notes addressed to our lawyers were removed from the published text of this policy and the Terms; they were never meant to be part of either document and are now kept separately. In the Terms, the warranty disclaimer and the limitation of liability still disclaimed on behalf of MANA and were corrected to RAAVA. ⚠ Recorded here on 6 September. These changes went live on 5 September without a version-history entry and without the "Last updated" date moving, which is the thing this table exists to prevent. |
| 1 September 2026 | 2.0 | The product was renamed from Mana Unlimited to Raava. Trademark clearance found the MANA name unavailable across the classes covering software, training and nutrition. The controller is unchanged: Mana Cores Limited, same registration, same registered office. Contact addresses moved from @manacores.com to @heyraava.com. Separately: the Expo / EAS entry was corrected - it disclosed over-the-air updates and push notifications, neither of which the app has, so no update or device tokens exist to be processed. The minimum age is now stated as 16 rather than left blank. Section 11 states plainly that this is a check and not a complete gate, because entering an age is optional, the database CHECK was never validated against pre-existing rows, and there is no verifiable parental consent route; an earlier draft of this revision claimed the minimum was enforced in the app and in the database, which overstated it. The position on a Data Protection Officer is stated explicitly rather than left as an editorial note. |
| 6 August 2026 | 1.0 | First published version. |