Legal
Privacy Policy
Last updated: August 31, 2026
What Menta is
Menta is a consumer accountability app for personal goals. People create or join challenges, submit proof or check-ins, get peer reviews, build streaks, earn Momenta rewards, customize with shop items, and stay in small private or open groups. This policy explains what data Menta collects, why, and the controls you have.
Information we collect
Account and profile: name or handle, email, login identifiers, avatar, and profile settings.
Activity in the app: challenges and groups you create or join, invite links, codes, and QR data, proof submissions (photos or text), check-ins, peer reviews, streak history, Momenta wallet balance, rewards earned, shop purchases, and inventory items.
Notifications: notification preferences and push tokens used to deliver reminders and alerts.
Purchases: subscription and purchase status (for example Pro Monthly or Pro Yearly) may be reported by the Apple App Store or Google Play and our subscription provider RevenueCat. Menta does not see or store your payment card details.
Safety and support: reports, blocks, and support messages you send us.
Device and diagnostics: device model, OS version, app version, automatic privacy-sanitised crash reports, error details, stack traces, and limited technical route or action breadcrumbs used to find and repair faults. When you are signed in, crash diagnostics can include your Menta account ID, but not your email address or username.
Product analytics: a generated app-device ID before you sign in, your Menta account ID after you sign in, and bounded product actions and categories sent to Amplitude and PostHog. Event properties exclude email, username, promise text, proof content or media, group details, notification content, advertising identifiers, and precise location.
Permissions
Camera and photos are accessed only when you choose to submit proof, change your avatar, or scan an invite QR. Push notifications require your permission and can be turned off in your device settings or in Menta. Payments are processed by the Apple App Store or Google Play; Menta does not store card information.
iOS App Tracking Transparency is requested only for Meta ad attribution. Declining it does not limit Menta or any feature in the app.
How we use your information
To run challenges, groups, proof, reviews, and streaks; to process rewards, Momenta, shop and inventory; to verify and unlock Pro features based on Apple App Store, Google Play, and RevenueCat status; to send reminders and notifications you opt into; to provide support; to prevent abuse and handle reports and blocks; to find and repair faults through privacy-sanitised diagnostics; and to meet legal obligations.
To understand activation, retention, and whether the main journeys in Menta work, through bounded product analytics that exclude the sensitive content described above.
How information is shared
Content you submit to a challenge or group (proofs, check-ins, reviews, profile basics) is visible to the relevant participants and reviewers of that challenge or group.
We use service providers that process data on our behalf under contract: Supabase for accounts, authentication, database records, storage, and server functions; Sentry for privacy-sanitised crash diagnostics and any Advanced diagnostics a person explicitly enables; RevenueCat, the Apple App Store, and Google Play for subscription and purchase status; Expo with Apple Push Notification service or Firebase Cloud Messaging, as applicable, for notification tokens and delivery; OneSignal as an optional notification delivery and interaction provider in app versions where it is enabled; Amplitude for bounded product analytics and optional masked diagnostic recording; PostHog for bounded product analytics, feature flags, experiments, and optional masked diagnostic recording; Google Mobile Ads for rewarded ad delivery; and Meta for consented app-ad attribution.
We may share information when required by law, to protect users, enforce our Terms, or respond to safety issues.
We do not sell your personal data.
Analytics, crash reports, and optional diagnostics
Ordinary Sentry crash reporting is automatic and stays separate from anything optional. Menta keeps default PII collection, screenshots, view hierarchy capture, and failed-request capture off. Diagnostic fields are filtered for credentials and user-authored promise or proof content before they are sent.
Advanced diagnostics is a separate Settings preference. It is off by default. After you explicitly opt in, Sentry, Amplitude, and PostHog may receive sampled masked diagnostic recordings. Recording uses 10 percent session sampling and conservatively masks text, inputs, images, and vectors, and it stops on authentication, proof, camera, review, journal, and payment screens. Request and response bodies, headers, logs, and enriched network details are excluded; Sentry can retain basic request metadata such as URL, method, status, and body size. While enabled, diagnostics can use extra processing, battery, and mobile data while Menta is open.
Turning the setting off stops Amplitude and PostHog recording immediately; closing and reopening Menta fully applies the Sentry change. Advanced diagnostics is used to improve reliability and performance. It is not advertising and is not used to track activity across other companies’ apps or websites. To request deletion of diagnostics already received by Sentry, email privacy@anekedigitalapps.com.
Mobile Session Replay (optional)
Mobile Session Replay is an optional part of Advanced diagnostics in the 1.9.1 release. It is off until you explicitly turn on Advanced diagnostics in Settings, and it starts only after that opt-in. Ordinary crash reports and limited performance diagnostics remain separate from replay.
For people who have opted in, replay uses 10 percent session sampling and conservatively masks text, inputs, images, and vectors. It stops on authentication, proof, camera, review, journal, and payment screens. Request and response bodies, headers, logs, and enriched network details are excluded; Sentry can retain basic request metadata such as URL, method, status, and body size. When you are signed in, Sentry can receive your Menta account ID, but not your email address or username.
Replay exists for app functionality: diagnosing faults, performance problems, and interaction failures that are hard to reproduce. It is not used for advertising and not used to track you across other companies’ apps or websites.
Turning Advanced diagnostics off prevents a new replay from starting after you close and reopen Menta. To request deletion of diagnostics already received by Sentry, email privacy@anekedigitalapps.com.
Notifications
With your permission, Menta uses a device-specific Expo push token delivered through the applicable platform service — Apple Push Notification service on Apple devices or Firebase Cloud Messaging on Android — to deliver reminders, approvals, group activity, and important account information. You can turn notifications off in Menta or in your device settings. Signing out, revoking permission, or deleting your account stops further use of the token as applicable.
Menta can use OneSignal for push notification delivery, notification interaction, and in-app messages such as the optional reminder-permission explanation. OneSignal receives only bounded notification and lifecycle fields: a device or app subscription identifier, a push token, push-permission state, an opaque Menta account identifier used as an external alias after you sign in, delivery and open state, allowlisted actions needed to route a notification, and non-sensitive tags or events such as your notification permission, whether you have an active promise, your Pro status, and whether optional marketing email consent is on. OneSignal does not receive promise text, proof content or media, group details, your Momenta balance, your username, or free text for targeting.
If you explicitly turn on Menta product-news emails in the app, Menta links your account email to the same OneSignal user only for that consented email channel. Your email is not used as the external account alias and is not sent without that explicit email consent. You can turn product-news emails off in Menta or use the unsubscribe link in every marketing email. Account, security, and proof notifications do not depend on marketing consent.
Signing out removes the account alias from the device, while the device subscription can remain associated with the app. Signing back in may bind the same subscription again without intentionally creating a second account identity. Deleting your Menta account also requests deletion of the matching OneSignal user and its push and email subscriptions.
OneSignal is not enabled in every installed version of Menta. Existing Expo delivery can remain active while Menta tests a limited OneSignal canary.
Advertising
Menta uses Google AdMob to show ads in the free version of the app. You can choose to watch a rewarded ad to earn Momenta. Free accounts may also see a short ad after leaving every second newly submitted proof receipt. An ad never changes whether proof was sent, accepted or saved, and an automatic ad break does not award or remove Momenta. Menta Pro accounts do not receive these ad breaks.
Menta asks Google for non-personalised ads. These ads are not selected from your past activity across apps or websites. Google may still process data such as your IP address, general location derived from it, app and device identifiers, ad views and interactions, and diagnostic or performance data to deliver ads, limit how often an ad appears, measure aggregated results, and prevent fraud. Google says its Mobile Ads SDK encrypts this data in transit.
Menta does not add your email address, username, promise text, proof photo, proof video, proof text, group details or Momenta balance to an AdMob ad request. Google and participating advertising providers process ad data under their own privacy terms.
Where required, Menta uses Google’s User Messaging Platform to show advertising privacy choices before requesting an ad. If the consent system cannot confirm that an ad request is allowed, Menta does not request the ad. You can reopen Google’s advertising privacy choices from Menta’s settings when Google reports that the option is required for you. Declining an ad choice, an unavailable ad, or an advertising error does not block proof submission, proof receipts or navigation in Menta.
The automatic proof-receipt ad break applies only after Menta releases the feature for your installed app version.
Menta also uses Meta App Events for consented ad attribution. Meta SDK auto-initialisation, advertiser-ID collection, and automatic Meta events stay off on iOS until you grant App Tracking Transparency. After you grant it, Menta sends only four conversion event types — sign up, create group, create promise, and invite friend — without account ID, email, invite code, or user-authored content. If you decline App Tracking Transparency, Menta does not send those conversion events to Meta and all app features remain available. Meta may use the advertising identifier and SKAdNetwork only within that consented attribution path. The consent description above applies to iOS; Menta will not enable Meta attribution on Android until an Android-specific consent and legal-basis control is implemented and this policy is updated. Google’s User Messaging Platform consent does not authorise Meta attribution.
Your controls
Edit your profile and settings, manage notification preferences, including the optional product-email toggle in Notification Settings, use in-app Report and Block on proof, challenges, groups, and users to keep your space safe, restore purchases in Menta where available or manage them through your Apple App Store or Google Play account, and delete your account from inside the app at Profile or Settings, then Delete account. In Settings → Ad measurement you can see the ad measurement explanation and system prompt; in Settings → Advanced diagnostics you can turn optional diagnostics on or off. App Tracking Transparency can also be changed in iOS Settings. You can also email hello@menta.quest for help.
Account deletion and retention
Deleting your account removes or de-identifies your account data where possible. Confirmed account deletion also removes the linked OneSignal messaging profile as part of provider cleanup. Some limited information may be retained where required for safety, legal, or payment record-keeping reasons (for example fraud prevention or store-mandated subscription records). Backups are purged on a rolling basis.
Children
Menta is intended for people aged 16 and over and is not directed at children.
Android interest requests
If you submit the Android interest form on menta.quest, we store the email address you provide and, if you choose to add them, your country, Android version or device, and your answer to “What would you use Menta for?”. We also record whether you ticked the update box and when the request was made.
This is an earlier and current interest form used to understand interest in an Android version and, if you ticked the update box, to optionally contact you about Android testing or release updates. If you did not tick the box, we do not treat it as marketing consent and will not email you updates. If you did tick it, you can unsubscribe at any time. Submitting the form does not guarantee tester access or a release date.
These requests are not readable by other visitors. To have your request deleted, email hello@menta.quest.
Changes
We may update this policy as the app evolves. Material changes will be communicated in-app or by email.
Contact
Questions about privacy? Email hello@menta.quest.