Mana privacy

Your usage. Clear boundaries.

This policy describes Mana’s current Mac app and pre-release iPhone app, including its widgets. Mana is developed by Cristian Caroli. Contact the creator through the Mana GitHub issue tracker. Issues are public; do not post credentials or other private account data.

What leaves your iPhone

Connecting a provider and fetching usage require network requests. Mana sends credentials directly to the relevant provider over HTTPS, not through a Mana-operated server.

Providers receive these requests, including network information such as your IP address, and process them under their own policies. Browser sign-in also uses the provider’s website and its browser storage practices.

See OpenAI’s privacy policy and OpenCode’s website for provider information. Mana is not affiliated with these providers.

What your iPhone stores

Mana saves Codex access and refresh tokens, the account identifier, and token expiry, or your OpenCode Go API key, in non-synchronizing, device-only Keychain items. The app and widget extension use a shared access group. Items become accessible after the device’s first unlock.

A protected App Group cache shared by the app and widgets stores only each provider’s latest normalized quota values, reset times, fetch time, and safe freshness/error metadata. The cache is excluded from backup. Mana does not keep a usage history or persist raw provider response bodies.

Widgets can use the saved provider credentials to refresh directly with the provider and display the latest cached values. iOS controls their update schedule. Mana also stores local preferences, including your Demo choice.

The owner reports successful daily use. The TestFlight and App Store distribution builds still require separate verification.

Your controls and retention

Disconnecting a provider clears its cached usage and removes its saved credentials when the operation succeeds. Replacing a provider account clears its previous cached usage. Storage errors can prevent credential removal; check Mana’s status and retry after unlocking.

Use Disconnect before uninstalling. Keychain items can survive uninstalling an app. Revoke tokens or API keys with the provider if you also want to end provider-side access. Disconnect does not delete your provider account or its records.

Demo uses labeled synthetic quotas without reading credentials, persisting quota snapshots, or contacting providers. The current app has no Mana-operated backend, cloud sync, advertising, or analytics SDK. This does not mean that no data leaves your device: real-provider requests are described above.

Mac storage is different

The Mac app stores Codex and OpenCode Go credentials in private local plain-text files under ~/Library/Application Support/Mana/credentials, not in Keychain. The directory uses owner-only permissions (0700); credential files use owner-only permissions (0600). These permissions are not encryption.

The Mac app keeps usage snapshots in memory, not persistent storage. It sends credentials to OpenAI or OpenCode to authenticate and fetch usage. Antigravity usage comes from your signed-in agy CLI; Mana does not read or store its credentials. The CLI and its provider handle their own authentication and network activity.

Remove saved Mac provider credentials through Mana Settings. This does not revoke them at the provider.

Website and support services

This website serves static pages, scripts, fonts, and images. It does not include an analytics script or a contact form. Its hosting service receives ordinary web requests, including network information such as IP addresses. Following external links uses the destination service.

Support uses GitHub, not an in-app upload service. GitHub processes information you choose to submit under GitHub’s privacy statement. Only share redacted information needed to explain a problem.

This policy describes implementation, not a final App Store privacy label. Provider processing and Apple’s disclosure definitions must be reviewed before submission. Read the support page for current availability and limitations.