Privacy Policy
MantaForge — Forge Your Body
Last updated: 24 March 2026
MantaForge ("we", "our", "us") is a fitness and nutrition mobile application developed by Neritic Labs. We are committed to protecting your privacy and personal data. This Privacy Policy explains what information we collect, how we use it, and your rights.
1. Information We Collect
1.1 Account Information
When you create an account, we collect:
- Full name
- Email address
- Authentication credentials (password is encrypted by Firebase Authentication and never stored in plaintext)
- Profile photo (optional, stored as encrypted data)
1.2 Fitness Profile Data
During onboarding, you provide:
- Country of residence
- Fitness goal (e.g., build muscle, lose fat)
- Experience level
- Biological sex
- Weight range
- Training preferences (days per week, gym access, workout duration)
- Injuries or limitations
This data is used solely to generate personalised workout and nutrition plans.
1.3 Usage Data
We collect anonymous usage analytics including:
- Screen views and navigation patterns
- Feature usage (workout completions, meal logs)
- App crash reports and performance data
- Device type and operating system version
1.4 Community Data
If you participate in the community feed, we collect:
- Workout completion posts (automatically generated)
- Kudos (likes) given to other users
- Friend group memberships
Your identity in the community is protected by an anonymous username (e.g., "IronWolf_42") generated from your account. Your real name and email are never displayed to other users in the community feed or leaderboards.
2. How We Use Your Information
- AI-Powered Plans: Your fitness profile is sent to our AI service (Groq) to generate personalised workout and nutrition plans. Only your fitness preferences are shared — never your name, email, or identity.
- App Functionality: Account information enables login, profile management, and data sync across devices.
- Analytics: Anonymous usage data helps us improve the app experience. We use Firebase Analytics for this purpose.
- Crash Reporting: Firebase Crashlytics collects crash data to help us fix bugs and improve stability.
- Notifications: If you enable notifications, we schedule local reminders for workouts and streak alerts. These are processed on your device only — no data is sent to external servers for notifications.
3. Third-Party Services
We use the following third-party services:
- Firebase (Google): Authentication, database (Cloud Firestore), analytics, and crash reporting. Firebase Privacy Policy
- Groq: AI model provider for generating workout and nutrition plans. Only anonymised fitness profile data is sent. Groq Privacy Policy
- Google Sign-In: Optional authentication method. Google Privacy Policy
- RevenueCat: Subscription management. Processes payment information through the App Store or Google Play — we never see or store your payment card details. RevenueCat Privacy Policy
- YouTube: Exercise demonstration videos are embedded from YouTube. YouTube Privacy Policy
4. Data Storage and Security
- Your data is stored in Google Cloud Firestore, hosted in secure Google Cloud data centres.
- Passwords are encrypted using Firebase Authentication's industry-standard encryption.
- Profile photos are stored as encrypted base64 data within your Firestore profile.
- All data transmission uses HTTPS/TLS encryption.
- We do not sell, rent, or trade your personal data to third parties.
5. Data Retention
- Your account data is retained as long as your account is active.
- If you delete your account, all personal data is permanently removed from our database.
- Your email address is stored as a one-way SHA-256 hash after deletion to prevent re-registration with a deleted account. The original email cannot be recovered from this hash.
- Anonymous analytics data may be retained for up to 14 months for trend analysis.
6. Your Rights (GDPR / UK GDPR)
Under the General Data Protection Regulation and UK GDPR, you have the right to:
- Access: Request a copy of your personal data stored by MantaForge.
- Rectification: Correct inaccurate personal data via the Edit Profile screen.
- Erasure: Delete your account and all associated data permanently via Settings → Delete Account.
- Portability: Request your data in a machine-readable format.
- Object: Object to processing of your data for specific purposes.
- Withdraw Consent: Withdraw consent for data processing at any time by deleting your account.
To exercise any of these rights, contact us at support@neriticlabs.com.
7. Children's Privacy
MantaForge is not intended for children under the age of 13. We do not knowingly collect personal data from children. If you believe a child under 13 has provided us with personal data, please contact us and we will delete it promptly.
8. International Data Transfers
Your data may be processed in countries outside the UK/EEA where our third-party service providers (Google, Groq) operate. These transfers are protected by appropriate safeguards including Standard Contractual Clauses approved by the European Commission.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes through the app or by email. The "Last updated" date at the top reflects the most recent revision.
10. Contact Us
If you have questions about this Privacy Policy or your data: