Manda

Privacy Policy

Last updated: 11 July 2026. This Policy explains how Manda handles your information.

1. Introduction and scope

This Privacy Policy explains how Manda ("Manda", the "Service", "we", "us", or "our") handles information in connection with your use of our offline-first Chinese learning application. Manda is available as a web application accessible through a browser (the "Web Service") and as downloadable native desktop applications for macOS and Windows (the "Desktop Application"). Unless the context requires otherwise, references to the Service cover all of these forms.

This Policy should be read together with our Terms and Conditions. It describes what information is stored on your own device, what limited information reaches us or our service providers when you choose to use certain optional features, why, and what choices and rights you have. By using Manda, you acknowledge that you have read and understood this Policy.

Manda is a small, independent, hobby-scale project. We have deliberately designed it to collect as little personal information as possible, and to keep the great majority of your data on your own device rather than on our servers.

2. Who we are and how to contact us

Manda is operated by an individual developer. For the purposes of applicable data-protection law, the operator of Manda is the "data controller" for the limited personal information described in this Policy.

If you have any questions about this Policy, or wish to exercise any of your rights, you can reach us through the Contact page on the Service.

3. Our offline-first approach: data stored on your device

Manda is offline-first. By default, the great majority of your data is stored locally on your own device and is never transmitted to us. This includes your study list, known words, review schedule and spaced-repetition data, learning-path progress and lesson stars, saved texts, reading history, word notes, study statistics, records of texts and news you have read, your settings and theme preference, dashboard layout, onboarding state, and (for the Desktop Application) your license key and update-check state.

On the Web Service this data is held in your browser’s local storage (primarily IndexedDB, with a small amount in localStorage); in the Desktop Application it is held in the application’s own local storage. This information stays on your device, under your control. We do not have access to it, we cannot read it remotely, and it is not sent to us unless you actively choose to use the optional account and cloud-sync features described below.

Because this data lives on your device, it can be lost if you clear your browser or app data, use private or incognito mode, switch devices or browsers, or uninstall the application. You can view, export, and clear this locally stored data at any time using the Import/Export tools within the Service. A detailed technical listing of every storage key is available at the /localdata page.

4. Information we collect when you use optional features

You can use Manda’s core learning features without creating an account and without actively giving us any personal information (though limited usage analytics are collected automatically, as described in Section 5). Some optional features, however, do involve sending a limited amount of information off your device. These are:

(a) Account creation and sign-in. Creating an account is optional and is only needed for features such as cloud sync. To create an account you provide an email address and choose a password. Authentication is handled by our infrastructure provider (Supabase); your password is stored by that provider in hashed form and is not visible to us.

(b) Cloud sync. If you choose to sync, a copy of your learning data (the same set of data used for file backups, for example your study list, known words, review schedule, learning progress, saved texts, notes, and statistics) is uploaded to our database and associated with your account so that you can restore it on another device. You control when this happens, and you can stop using cloud sync at any time.

(c) Display name and profile. If you set a public display name (for example to post community comments), that name and your account identifier are stored in your profile.

(d) Community comments. If you post comments on dictionary words, the comment text, your chosen display name, and your account identifier are stored and are publicly visible to other users. Please do not include sensitive personal information in comments.

(e) Bug reports and feature suggestions. If you submit a bug report or feature suggestion, the content you write, and (if you are signed in) your display name and account identifier, are stored so that we can review and act on it.

(f) Contact form. If you use the Contact page, the name, email address, and message you enter are transmitted so that we can receive and reply to your message. To help prevent spam and abuse, we also collect basic technical information about the request, such as your browser’s user-agent string, and use an anti-bot verification service (see Section 6), which processes your IP address for that purpose.

We do not ask for, and you should not send us, special-category data (such as information about your health, race, religion, or political views) or other sensitive personal information. We do not knowingly collect any personal information beyond what is described in this Policy.

5. Analytics and cookies

We use PostHog, a third-party product-analytics service, to understand how Manda is used so that we can fix problems and improve the Service. When you use Manda, PostHog collects usage information on our behalf, such as: events reflecting the features you use (for example, adding a word to your study list, starting or completing a study session, completing a lesson, exporting your data, registering, or signing in); the pages and screens you view within the app; and technical information such as your device and browser type, general diagnostic data, and an approximate, coarse location derived from your IP address.

If you are signed in, these analytics events are associated with your account identifier so that your activity can be recognised across sessions and devices. If you are not signed in, PostHog instead uses a randomly generated identifier stored on your device. PostHog may set cookies or use similar local-storage technologies to function. We use this information only to analyse and improve Manda.

We do not use advertising networks, ad-targeting, or cross-site advertising trackers, we do not sell your information, and we do not build advertising profiles about you. You can limit or block analytics collection using your browser’s privacy settings (for example, by blocking cookies or scripts, or using tracking-protection features).

Separately from analytics, the Service uses your browser’s local storage technologies (IndexedDB and localStorage) to make the application work, for example to remember your study data, settings, and, if you have signed in, your login session. These are essential to the functioning of the Service.

6. Third-party service providers

To provide the optional features above, we rely on a small number of reputable third-party service providers ("processors"), who process information on our behalf or provide functionality you have chosen to use. Depending on which features you use, these may include:

(a) Supabase: our infrastructure provider, used for account authentication, database storage (including cloud-sync data, profiles, community comments, bug reports, feature suggestions, and contact messages), and serverless functions.

(b) PostHog: the product-analytics service described in Section 5, used to collect usage and diagnostic information so that we can understand and improve how Manda is used.

(c) Cloudflare Turnstile: an anti-bot verification service used to protect forms such as the Contact page from automated abuse. When you complete a verification challenge, your IP address and related technical signals are processed by Cloudflare.

(d) Resend: an email delivery service used to notify us when you send a message through the Contact page, so that we receive your message and can reply.

(e) Translation providers: when you use the in-app translation feature, the specific Chinese text you ask to translate is sent to third-party translation services (currently Lingva and MyMemory) in order to return a translation. You should avoid selecting text that contains personal or sensitive information for translation, as that text will be transmitted to, and processed by, those external services under their own terms and privacy policies.

(f) GitHub: the Desktop Application checks for updates by contacting GitHub’s release API. This request may transmit basic technical information such as your current app version and platform.

These providers operate under their own privacy policies. We share information with them only to the extent needed to provide the relevant feature, and we do not sell your personal information to anyone.

7. How we use information

We use the limited information described above only to operate, understand, and improve the Service. Specifically, we use it to: provide account authentication and keep you signed in; store and restore your learning data when you use cloud sync; display your chosen name and community contributions; receive, review, and respond to contact messages, bug reports, and feature suggestions; analyse usage to understand how Manda is used and to improve it; protect the Service against spam, abuse, and security threats; and comply with our legal obligations.

We do not use your information for advertising, and we do not sell, rent, or trade it.

8. Legal bases for processing

Where data-protection law such as the GDPR applies, we rely on the following legal bases to process personal information: performance of a contract with you (for example, to provide account and cloud-sync features you have requested); your consent (for example, where you choose to submit a contact message, post a comment, or use the translation feature, which you may withdraw at any time by ceasing to use the relevant feature); and our legitimate interests (for example, keeping the Service secure, preventing abuse, analysing usage to understand and improve Manda, and reviewing feedback), balanced against your rights and interests.

9. Data sharing and disclosure

We do not sell your personal information, and we do not share it with third parties except: with the service providers listed in Section 6, acting on our behalf to provide the Service; where content is inherently public (such as community comments you choose to post); and where we are required to do so by law, or where disclosure is reasonably necessary to protect our rights, your safety or the safety of others, or to investigate fraud or abuse.

10. International transfers

Our service providers may store and process information on servers located outside your country of residence. Where information is transferred internationally, it is done in reliance on the safeguards and terms offered by those providers. By using the optional features that involve these providers, you understand that your information may be processed in other countries.

11. Data retention

Data stored locally on your device remains until you delete it (for example, by clearing your browser or app data, or using the in-app Import/Export tools), and is not subject to any retention period set by us.

For information held by us or our providers: account and cloud-sync data is retained for as long as your account exists; if you delete your account, associated data is deleted or disassociated as described in Section 13. Community comments remain until you or we remove them. Contact messages, bug reports, and feature suggestions are retained for as long as reasonably necessary to handle and follow up on them, and for our records. We may retain limited information for longer where required for legal, security, or abuse-prevention reasons.

12. Security

We take reasonable measures, and rely on the security features of our service providers, to protect information. However, as also explained in our Terms and Conditions, no method of transmission or storage is completely secure, and we cannot guarantee absolute security. You use the Service, and store data with it, at your own risk.

You are responsible for your own account security. In particular, you should choose a strong, unique password used only for Manda, never re-use a password from another service, and keep your credentials confidential. Please notify us promptly if you believe your account has been compromised.

13. Your rights and choices

Subject to applicable law, you may have the right to: access the personal information we hold about you; request correction of inaccurate information; request deletion of your information; object to or restrict certain processing; and request a copy of certain information in a portable format. Because most of your data already lives on your own device, you can directly view, export, and delete much of it yourself using the Import/Export tools and the /localdata page.

You can update your email or password, and delete your account, from the account settings within the Service. Deleting your account removes your account and associated server-side data through our provider. You can also stop using cloud sync, community, translation, or contact features at any time.

To exercise any right that you cannot action yourself within the app, please contact us via the Contact page. We may need to verify your identity before responding. Depending on where you live, you may also have the right to lodge a complaint with your local data-protection supervisory authority if you are unhappy with how we have handled your information.

14. Children’s privacy

Manda is not directed at children under 13 (or the minimum age of digital consent in your country, if higher), and you must meet the age requirement set out in our Terms and Conditions to create an account or use the Service. We do not knowingly collect personal information from children below that age. If you believe a child has provided us with personal information, please contact us so that we can take appropriate steps.

15. The Desktop Application

The Desktop Application is a paid product that stores your learning data locally on your device in the same offline-first manner as the Web Service. Your license key is stored locally on the device on which it is activated. As described in Section 6, the Desktop Application may contact GitHub to check for updates, which can transmit basic technical information such as your app version and platform, and may check a published list of revoked keys to confirm that your license key is still valid. Purchases and refunds are handled by the third-party seller through which you bought your licence, under that seller’s own terms and privacy policy.

16. Changes to this Policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page. Your continued use of the Service after any change constitutes your acceptance of the revised Policy. We recommend that you review this page periodically.

For more about your use of Manda, please also review our Terms & Conditions and FAQ, or get in touch through the Contact page.