Legal
Privacy Policy
Effective date: 29 August 2026
Mandrake is published by Arcturus Digital Consulting Ltd. We are the controller for personal data processed through the app. Contact us at info@arcturusdc.com.
The short version
- No name, email or password—just a random app identifier.
- Urge entries are stored securely in the cloud under that identifier.
- Screening answers and custom text remain on your device.
- There are no ads or analytics SDKs in the current Android app.
- You can reset app data in Settings and can request cloud deletion by email.
1. Information Mandrake processes
Anonymous app identity
On first use, Firebase Authentication assigns the app a random user identifier (UID). Mandrake does not ask you for a name, email address or password. The UID keeps cloud records separated between app installations. Although it is pseudonymous rather than a name, we still protect it as personal data.
Urge events stored in Firestore
When you save an urge event, the current app uploads the following fields:
- the time of the event and whether the urge was bypassed or acted on;
- the selected urge category, intensity, mood and trigger;
- the selected tactic; and
- whether the wave timer was used and its duration.
These records can reveal information about health, substance use or behaviour and are treated as sensitive. They are stored under the anonymous UID in Google Cloud Firestore. Custom tactic text and custom urge-category text are not included in the current cloud upload.
Information stored only on your device
- the local copy of your urge events, including any custom text;
- optional screening responses, scores and risk bands;
- loops, milestones, rewards and progress; and
- settings such as support region and reminder preferences.
Purchases
A one-time unlock is sold by Google Play and checked by RevenueCat. Google handles the payment details. RevenueCat processes the identifiers and transaction information needed to validate and restore the purchase; it does not receive your urge log from Mandrake.
Support and platform diagnostics
If you email us, we process the information you choose to send so we can answer. Google Play or your device platform may also provide diagnostic or crash information under its own settings. Mandrake does not currently include Firebase Analytics or Crashlytics.
2. What Mandrake does not collect
- No advertising identifiers, advertising or cross-app tracking.
- No location, contacts, photos, camera or microphone data.
- No sale or rental of data.
- No use of urge data to train AI or to build commercial profiles.
The app requests notification permission for reminders you choose and vibration access for haptic feedback.
3. Why we process information
We process the minimum information needed to:
- save and show your history, patterns, milestones and rewards;
- provide optional screening and support signposting;
- validate and restore a purchase; and
- answer support requests and maintain the security and reliability of the app.
4. Legal basis in the UK and EEA
We process app data because it is necessary to provide the Mandrake service you request. Where urge records reveal special-category information, including health information, the relevant additional condition is explicit consent. The current Android release does not yet present a separate explicit-consent control before the first cloud upload; this is an app-side compliance gap, and this policy does not treat ordinary app use as a substitute for that control. You may stop further processing by no longer recording events and may request deletion as described below. We use legitimate interests to answer support requests and protect the service, where those interests are not overridden by your rights.
5. Storage, processors and international transfers
Google Firebase provides authentication and Firestore storage. Google Play processes the purchase, and RevenueCat checks purchase entitlement. These providers act under their own terms and applicable data-processing safeguards. Their processing may take place outside the UK; where required, recognised transfer safeguards apply.
6. Retention and deletion
Local records remain until you reset app data, clear the app's storage or uninstall it. Firestore urge events remain until the in-app cloud deletion succeeds or we fulfil a deletion request. Purchase and support records may be retained where reasonably needed for accounting, fraud prevention, legal claims or support history.
Android backup is enabled for the current app, so Google may retain or restore an encrypted device backup according to your Android backup settings and Google's retention rules.
The Reset action deletes Firestore urge events first. Only after that succeeds does it clear the local database and app preferences. If cloud deletion fails, the app leaves the local data in place and asks you to try again. Reset does not delete the Firebase anonymous authentication record. See the Data Deletion page for the exact process.
7. Your rights
Depending on where you live, you may have rights to access, correct, erase, restrict, object to or receive a copy of your personal data. Because Mandrake does not collect your name or email address, we need the anonymous UID to locate cloud records. You can copy it from the Account section in Mandrake Settings.
Contact info@arcturusdc.com. You may also complain to the UK Information Commissioner's Office at ico.org.uk.
8. Security
Data is encrypted in transit and at rest by our cloud provider, and access to production systems is restricted. No service is completely secure, so keep your device and app up to date and use a device passcode.
9. Age
Mandrake is for people aged 16 and over. If you believe someone under 16 has provided data, contact us so we can take appropriate action.
10. Changes and contact
We may update this policy when the app or legal requirements change. We will publish the new date here and flag material changes where appropriate.
Arcturus Digital Consulting Ltd
info@arcturusdc.com