MUNEN PRIVACY POLICY
Last updated: August 26, 2026
1. Data Controller
Jose Guillermo Escobar de la Rosa
Tlajomulco de Zúñiga, Jalisco, Mexico
To receive documentation and handle requests related to this policy and your ARCO rights (Access, Rectification, Cancellation, Objection), you can contact us at: privacy@munen.app.
2. Privacy approach
Munen is built on the principles of data minimization and local processing. Most of the information you generate stays exclusively on your device and is not transmitted to external services, except as described in this Policy.
3. Data we collect
3.1 Data stored locally (not transmitted)
The following data is stored on your device and is not accessible to the developer:
- Screen usage metrics (total time, app opens, nighttime use)
- Friction shield interactions: how many times you continue past a shield (bypass) or step back (decline), and the ratio between both
- Intensive sessions: occasions when you exhaust most of the bypass time window the App grants you (see §16)
- Local wellbeing algorithm output: your estimated usage zone
- Daily check-ins you report manually
- Personal journal entries, including text and your self-assessment of digital use when you write (a 1–5 digital habits scale). Due to their personal nature, these are stored encrypted in the iOS Keychain
- Configuration of apps you have selected for digital friction (technical identifiers, not app names)
- Habits data, streaks, and achievements (achievement unlocks and progress toward them)
- Focus session minutes and "time reclaimed" by ending a bypass early
- Your "why" and your "alternatives" (micro-actions), used to personalize the shield messages
- How many times you use SOS (per day and per week), used to adapt the SOS response
- Coach conversation history
- Cached results from previously generated AI analysis
3.2 Data that may be transmitted to third parties
a) Artificial intelligence — Anthropic (Claude)
Munen offers several AI features, available on both the free plan and the trial/subscription plan, subject to usage limits based on your plan. Depending on the feature, different data is sent to Anthropic, always the minimum needed to respond to you:
- Analyze with AI / Weekly Summary: the text of your journal entry and your self-assessment at the time (expressed as a zone, e.g., "balance zone (3/5)") are sent. For the weekly summary, up to 12 representative entries from the week (maximum 600 characters per entry).
- Conversational Coach: the messages you type to the Coach and a behavioral profile (recent usage metrics and journal metadata: how many reflections you wrote, their rating and what prompted them) are sent. The Coach does NOT receive the text of your journal entries — only that metadata.
- Urge SOS: the urge type you select (e.g., boredom, anxiety), your current usage zone, and how many times you've used SOS that day/week are sent, to tailor the guidance.
In all cases:
- Processing is performed by Anthropic (Claude); the result is saved locally on your device
- Requests are routed through an intermediate proxy hosted on Supabase (Edge Function), which forwards them to Anthropic without storing the content and protects the AI service access keys
- Anthropic may temporarily retain requests for operational and safety purposes and deletes them within a maximum of 30 days
- Under Anthropic's commercial terms, data sent through their API is not used to train their artificial-intelligence models
Legal basis: explicit consent when using each AI feature. For the features that send your journal text (individual analysis and weekly summary), the App shows a notice and asks for your confirmation every time, stating exactly what will be sent. No automatic transmission occurs without your action.
Anthropic's policy: https://www.anthropic.com/privacy
b) Technical diagnostics — Sentry
To maintain service stability, if an error occurs the app may automatically send:
- Technical device information (model, iOS version, memory, battery)
- Technical error trace and app version
- Anonymous installation identifier (UUID not linked to any personal identity; resets upon reinstall)
- Approximate city-level location derived from IP address
This transmission occurs automatically when a technical error happens — it requires no action from you. Journal content, personal metrics, and identifiable data are not included.
Legal basis: legitimate interest (detection of technical failures affecting the user experience). You can disable this transmission at any time from Settings → Privacy → "Share anonymous statistics" in the app; once disabled, your device stops sending error reports and analytics events.
Sentry logs are automatically deleted after 90 days.
Sentry's policy: https://sentry.io/privacy/
Error reports you send (voluntary). If you use the support screen to report a problem, the text you write plus minimal technical data (anonymous install identifier, session identifier, and App version) is sent to our support email (via Resend) and stored as a backup in Supabase in case the email fails. Only what you choose to write is included; we do not attach your journal or metrics. This is a voluntary, user-initiated action. Legal basis: your request/consent when submitting the report.
c) User account and auxiliary services — Supabase
Creating an account is not required for basic use of the App: the friction shields, usage zones, focus mode, journal, streak, achievements, and statistics work without registration, and that data stays on your device. An account is only required at the moments that need server-side identity: activating the trial period or a subscription and using the AI features (including the free plan's limited AI usage). When you create an account, the following is stored in Supabase:
- Your email address
- If you use Google Sign-In: your Google account profile name and photo (provided by Google per their privacy policy: https://policies.google.com/privacy)
- If you use Sign in with Apple: only the email address (real or private relay)
- A technical identifier (UUID) generated by Supabase, which persists while the account exists and is deleted upon account deletion
Additionally, Supabase hosts auxiliary functions (Edge Functions) that act as an intermediary for AI analysis requests described in §3.2a. These functions forward requests to Anthropic without storing the content.
Legal basis: performance of a contract (with respect to the features that require an account).
Supabase's policy: https://supabase.com/privacy
d) Payments — Apple StoreKit
Purchases are processed entirely through the Apple App Store. We do not collect or store payment information (cards, banking, or billing details). Apple sends us subscription status notifications (product purchased, price, start, renewal, or cancellation dates, and status) through opaque transaction identifiers that are not linked to your identity — we cannot associate them with your account or your person. This information is used exclusively for service accounting and aggregate metrics.
Apple's policy: https://www.apple.com/legal/privacy/
e) Transactional emails — Resend
If you create an account, verification emails (Magic Link / OTP) and account-related notifications are sent via Resend, an email infrastructure provider. Munen does not use passwords — login is done via magic link email, Sign in with Apple, or Continue with Google. Resend processes your email address solely to deliver the message and does not use your data for its own purposes.
Resend's policy: https://resend.com/legal/privacy-policy
f) Authentication — Google
If you choose to sign in with Google Sign-In, Google provides the App with your profile name, photo, and email address per the permissions you authorize. We do not access any other data in your Google account.
Google's policy: https://policies.google.com/privacy
g) Runtime security — Talsec (freeRASP)
The App integrates freeRASP (by Talsec), a security tool that detects compromised environments (jailbroken devices, app tampering, debuggers, or hooking frameworks) to protect service integrity. In its free version, freeRASP sends anonymous technical device telemetry and security events to Talsec servers (device model, OS version, app technical identifier, and detected threat signals). Journal content, personal metrics, and identifiable user data are not sent.
Legal basis: legitimate interest (fraud prevention and App integrity protection).
Talsec's policy: https://www.talsec.app/privacy-policy-talsec-eu
h) Anonymous retention analytics — Supabase
To understand, in aggregate, how many users keep using the App over time (1-, 7- and 30-day retention) and to measure the conversion funnel, the App logs anonymous events in Supabase:
- An anonymous install identifier (a UUID not linked to your identity; it resets on reinstall)
- The event name and, where applicable, technical event properties. This includes retention/funnel events (e.g., "install", "app_open", "paywall_shown", purchase) and aggregate feature-usage events — only the fact that a feature was used plus minimal technical data (e.g., that the Coach or SOS was opened, that a focus session of N minutes started/completed, that a journal entry was created, that a bypass was used). No emotional category, journal content, Coach messages, SOS reason, or identifiable data is recorded.
- The App version
These events are not associated with your account and cannot be used to reconstruct your personal activity.
Legal basis: legitimate interest (aggregate product measurement). You can disable this analytics at any time from Settings → Privacy → "Share anonymous statistics" in the app.
Supabase's policy: https://supabase.com/privacy
3.3 Purposes of processing
| Purpose | Type | Can you opt out? |
|---|---|---|
| Local storage of usage metrics, digital habits journal, and self-assessments | Primary (required for the service) | No, the app cannot function without it |
| Technical error detection (Sentry) | Legitimate interest (service stability) | Yes, by disabling "Share anonymous statistics" in Settings → Privacy |
| AI features (Anthropic): journal analysis, weekly summary, Coach, and SOS | Secondary (voluntary) | Yes, by not using those AI features |
| Anonymous retention analytics (Supabase) | Legitimate interest (aggregate measurement) | Yes, by disabling "Share anonymous statistics" in Settings → Privacy |
| User account (Supabase) | Secondary (needed only for trial/subscription and AI features) | Yes, by not using the features that require an account |
| Transactional emails (Resend) | Required for account management | No, if you have an active account |
| Google authentication (optional) | Secondary (voluntary) | Yes, by using another sign-in method |
| Runtime security (Talsec/freeRASP) | Required for integrity and fraud prevention | Anonymous telemetry integral to security; not separable per user |
| International data transfers | Linked to each feature that generates them | Yes, by not using the corresponding feature |
3.4 Data shared between system extensions (on-device only)
The app includes iOS extensions that operate locally and communicate through a secure on-device container. No extension has internet access or transmits data to external servers.
3.5 Screen Time permission (Screen Time / Family Controls)
Apple's Screen Time permission (the Family Controls / Screen Time framework) is essential and required to use Munen: it is the foundation on which the friction shields work. During initial setup (onboarding), when you select your apps you must grant this permission; if you do not grant it, you cannot continue or use the shield/friction features. By granting it, you authorize the App to apply the shields and to measure your usage of the apps you select.
- All of this information is processed exclusively on your device via Apple's frameworks (DeviceActivity, ManagedSettings). It never leaves your device and is not shared with third parties.
- The apps you choose are handled as Apple opaque tokens: the App does not know or transmit the names of your applications.
- You can revoke this permission at any time from iPhone Settings → Screen Time. If you revoke it, the shield/friction features stop operating.
Legal basis: consent (granting the permission) and performance of the service.
4. Nature of journal data and self-assessments
Journal entries are personal reflections about the user's digital day, written for self-observation purposes. The 1–5 scale the user selects when writing an entry is a subjective assessment of their own digital experience of the day — how they experienced their phone use — and may include observations about digital habits as well as associated mood.
Munen does not make diagnoses or infer health conditions: there is no mechanism in the app that derives clinical conclusions from the journal or the scale. The wellbeing algorithm operates exclusively on objective usage metrics: screen time, app open frequency, nighttime use, intensive sessions, and shield resistance (which combines how often you bypass and how often you respect the shield). Each signal is normalized and weighted deterministically to reflect your actual use. The algorithm is independent of journal content.
That said, we recognize that your reflections may include information about your emotional state. As a precaution, we treat the journal and self-assessments with the highest standard of protection, equivalent to what the law requires for sensitive personal data:
- They are stored encrypted in the iOS Keychain and stay on your device during ordinary app use
- The text of your entries is only transmitted to Anthropic with your express consent, requested every time through an in-app notice before using "Analyze with AI" or "Weekly Summary" — never automatically — and solely to generate self-knowledge reflections
- The Coach does not receive the text of your entries; only metadata (how many reflections you wrote, their rating and what prompted them)
- What the AI processes is used only to reply to you: Anthropic deletes it within a maximum of 30 days and does not use it to train artificial-intelligence models
- It is never shared for commercial or advertising purposes
- You can delete it at any time from Settings → Account → Delete account, or export it first from Settings → Account → Export my data
5. Data we do not collect
- Precise GPS location
- Clinical health data
- Payment or financial information
- Advertising identifiers (IDFA, IDFV)
- Biometric data
- Content of personal communications
We do not sell, rent, or share personal data with third parties for advertising purposes.
6. Trial period abuse prevention
To prevent multiple uses of the free trial period (14 days), we store the trial end date in the iOS Keychain, which persists even if you uninstall the app or delete your account within the app. By activating the trial period, you consent to this processing. This data contains no personally identifiable information and is used solely for this purpose.
7. Notifications
If you grant permission, the app may send you local notifications (generated on your device, without external services). Notification types include:
- Journal reminders: inviting you to write a journal entry
- Friction nudges: alerts related to your digital habits and configured shields
- Recalibrations: requesting you to update your perception of your phone use
- Achievements: notifying you when you unlock a badge or reach a milestone
All notifications are generated and scheduled locally. No external push notification service is used. You can disable them at any time from iPhone Settings → Munen → Notifications.
8. Data retention
| Data | Location | Retention |
|---|---|---|
| Metrics, journal, achievements, check-ins | Local (device) | Until you use "Delete account" |
| AI analysis cache | Local (device) | Until you use "Delete account" |
| Account data (email, UUID, profile) | Supabase | Until account deletion |
| Error logs | Sentry | 90 days |
| Trial end date | iOS Keychain | Persists after uninstall and after "Delete account" (see §6) |
8.1 Data deletion
- Delete account (Settings → Account → Delete account): permanently and irreversibly deletes all metrics, journal entries, achievements, streaks, and AI analysis cache stored locally on your device, and also deletes your account and associated data in Supabase (email, profile, UUID).
- Before deleting, you can keep a copy of your information via Settings → Account → Export my data (HTML report).
The trial end date in the Keychain is not deleted when the account is deleted (see §6).
9. Data export and portability
All users can export their data (usage metrics, zone history, journal entries, streak, focus minutes, and achievements) as an HTML report from Settings → Account → Export my data. The file is generated locally and you decide where to share it. This portability right is free and not conditioned on any subscription.
10. User rights and consent withdrawal
You may write to privacy@munen.app to exercise your rights.
We will respond within a maximum of 20 business days.
| Right | How to exercise it |
|---|---|
| Access | Request your Supabase account data. Local data you export directly from Settings. |
| Rectification | Applies to data in Supabase (email, name). Local data is under your exclusive control. |
| Erasure | Use "Delete account" in Settings to delete local data and your Supabase account. |
| Objection / Restriction | Write to us to evaluate the options available for the applicable data type. |
Consent withdrawal: You may withdraw consent for specific processing at any time by writing to support@munen.app, stating the processing you wish to withdraw. For secondary purposes (AI analysis, user account), withdrawal takes effect by stopping use of the corresponding feature or deleting your account. Withdrawal does not have retroactive effect on processing already carried out.
11. International data transfers
Some providers (Anthropic, Sentry, Supabase, Resend, Google, Talsec) operate infrastructure outside Mexico, including the United States and the European Union. Transfers are necessary for the functions described in §3.2 and occur only when you activate those functions or when a technical error occurs (in the case of Sentry). You may object to transfers associated with voluntary functions by not using those functions, in which case your data stays exclusively on your device. By using a function that involves international transfer, you provide explicit consent for that specific transfer. Each provider operates under its own data protection framework, linked in §3.2.
11.1 List of providers and subprocessors
| Provider | Function | Data it may receive | Primary location |
|---|---|---|---|
| Anthropic | AI feature processing | Journal text (only with your per-use consent), Coach messages, SOS urge type, usage zone | USA |
| Supabase (on AWS) | User account, AI proxy, anonymous analytics, support report backup | Email, account UUID, anonymous events, text of reports you submit | USA (us-east-1) |
| Sentry | Error diagnostics | Technical device data, error trace, anonymous install identifier | USA |
| Apple | Payments and distribution (App Store) | Payment information (handled by Apple; we do not receive it). Apple notifies us of subscription status through opaque identifiers not linked to your identity (see §3.2d) | USA |
| Resend | Transactional account emails | Email address | USA |
| Optional authentication (Google Sign-In) | Profile name, photo, and email (only if you choose this method) | USA | |
| Talsec | Runtime security (freeRASP) | Anonymous technical telemetry and security events | EU |
| Netlify | Hosting of the munen.app website and updates form | Standard technical website logs (not app data). If you subscribe to updates on munen.app, your email address, used only to send you Munen news; you can unsubscribe at any time by writing to privacy@munen.app | USA |
We will update this list whenever we add or replace a provider (see §17).
12. Security
Data stored locally on the device benefits from the file protection provided by the iOS operating system. Journal entries are stored encrypted in the iOS Keychain. All data transmission to external services uses encrypted HTTPS/TLS connections. Supabase implements access controls and encryption on its servers per its own security standards.
No system is completely secure; we cannot guarantee absolute security in third-party systems.
If you discover a vulnerability, contact us at support@munen.app.
13. Security incidents
In the event of a breach that significantly affects your personal data, we will make our best effort to notify you within 72 hours of becoming aware of the incident, by email (if we have it) and within the app.
14. California and US users (CCPA / state privacy laws)
If you reside in California or another U.S. state with applicable privacy legislation, you have the following rights:
- Right to know: what personal data we collect, the categories of sources, and the purposes of processing (described in §3)
- Right to delete: you may request deletion of your data by writing to support@munen.app or using "Delete account" in Settings
- Right to portability: you may export your data as an HTML report from Settings (see §9), available to all users at no cost
- Right to non-discrimination: we do not offer different prices or service levels based on the exercise of your privacy rights. Premium features differ based on product capabilities, not the exercise of rights
- We do not sell personal data: we do not sell, share, or disclose personal data to third parties for advertising or profiling purposes
AI features and purchases are restricted to persons 18 years of age and older (see §15). We do not knowingly collect data from minors. If you believe a minor has created an account, write to us at support@munen.app to have their information deleted.
To exercise any of these rights, write to support@munen.app. We will respond within the legally established timeframes.
15. Minors
The App's free tier may be used in accordance with the age rating published on the App Store. The AI features and purchases (trial period and subscriptions) are restricted to persons 18 years of age and older: when creating an account — a requirement for those features — you must declare that you are 18 or older. We do not knowingly collect data from minors. If you believe a minor has created an account or is using AI features, write to us at support@munen.app to have their account deleted.
16. Artificial intelligence and wellbeing algorithm
Your usage zone is estimated by a transparent wellbeing algorithm that operates exclusively on your device and does not transmit data. It is a deterministic and explainable algorithm. It does not "learn" or train on your data, uses no learned weights, and does not adapt individually over time. It analyzes five behavioral signals measured on the device: screen time, app open frequency, nighttime use, intensive sessions, and shield resistance (which combines bypass frequency and how often you respect the shield). Each signal is normalized (0–1), weighted, and summed into a "load" (0–1) that maps to a usage zone from 1 to 5. The result is a transparent estimate, not a clinical measurement.
The only artificial intelligence in the App is the generative features (journal analysis, weekly summary, conversational Coach, and urge SOS), processed by Anthropic (Claude) with your consent. Data sent to Anthropic's API is not used to train their models.
An intensive session is not defined by a fixed minute threshold, but relative to the bypass time window the App grants you (which varies based on your estimated usage zone): it is recorded when you exhaust most of that window. This design avoids disproportionately penalizing users with better habits, who receive wider windows.
Additionally, the estimated usage zone adjusts based on your shield behavior: how often you bypass and how often you respect the shield rather than bypassing it. This adjustment is calculated solely from data already recorded locally on your device and involves no additional transmission.
AI features (Claude by Anthropic) — journal analysis, weekly summary, Coach, and urge SOS — are strictly informational and supportive, do not constitute medical, psychological, or therapeutic advice or diagnoses, and are activated when you use those features (available on the free plan and the trial/subscription plan, subject to usage limits based on your plan). Data sent to Anthropic's API is not used to train their models.
Munen is not a medical device.
17. Changes to this policy
We will update the date at the top of this document when we modify this Policy. For changes that expand the type of data processed or introduce new purposes, we will make our best effort to notify you within the app or by email and, where appropriate, will request your consent again. Continued use of the app after notification implies acceptance of non-material changes.