PRIVACY POLICY

Your life. Your data.

Last updated: 28 May 2026

RONAR is operated by the publisher of ronar.ai. This policy explains what we collect, why, where it lives, and how to get it out (or wipe it) when you ask. It applies to the web app at app.ronar.ai and any future mobile builds. If a line conflicts with applicable law in your jurisdiction, that law wins.

1. What we collect

Account. Email + a Supabase-managed password hash. We never see your raw password.

Profile. Name, date of birth, locale, currency, theme, time-zone, and any optional fields you enter during onboarding (income, goals, weight target).

Money. Transactions you log manually or import via CSV. Bank auto-sync via Plaid or PSD2 providers is planned for a future release; when it ships and you opt in, we'll receive the access token plus periodic balance + transaction syncs. Account numbers are never displayed to us — the aggregator holds those.

Net worth. Daily aggregated balance snapshots from connected banks + any manual assets / liabilities you enter (real estate, crypto, loans).

Health. If you connect WHOOP, Oura, Fitbit, Strava, Apple Health, or Android Health Connect (each opt-in), we receive the metrics you authorize: sleep hours, HRV, recovery, steps, active kcal.

Meds & supplements. The list of items you track and which doses you marked taken / skipped.

Sleep. Bedtime / wake reflections you log and pre-bed wind-down session history.

Diet. Logged meals + photos (if you use the photo recognition tab), water intake, weight check-ins.

Daniel voice. Pre-synthesized MP3s of your daily motivation message and any proactive nudge (e.g. "You crossed a net-worth milestone") are stored in Supabase Storage so playback is instant. The audio references you by name and may reference figures derived from your data.

Push subscription. If you allow notifications, the browser's Web Push endpoint + crypto keys are stored so we can deliver alerts.

Device. User-agent string + the page you submitted feedback from (for triage only).

Location. Approximate coordinates are computed in your browser only — used to pick the right sunrise/sunset for the time-of-day theme. The coordinates never leave your device.

2. What we never do

We don't sell your data. We don't run third-party ads or behavioral trackers inside the app. We don't share your financial, health, or diet data with anyone for marketing. We don't profile you across other websites. We don't read your inbox, your calendar, or your contacts.

3. Lawful basis (GDPR Art. 6)

Contract. Most processing — storing your transactions, syncing your bank, generating your insights — is necessary to perform the service you signed up for.

Consent. Optional connections (bank, health, push notifications) and any audio recording playback that uses your name require your explicit toggle. You can revoke from Settings → Connect at any time.

Legitimate interest. Aggregate, de-identified product analytics (which features are used, where errors happen). We never sell or share these and you can opt out by emailing domanado.r@gmail.com.

4. Where it lives

All structured data is stored in Supabase (Postgres) in the EU-West region under Row Level Security — your rows can only be read by your own account. Plaid access tokens are encrypted at rest with AES-256-GCM (when bank sync is enabled; key held only in our edge function secrets, never in the database). Voice MP3s live in a private Supabase Storage bucket and are served via expiring signed URLs (one-year TTL) tied to your account, not via public links. Everything is encrypted in transit (TLS 1.2+) and at rest (Supabase + AWS disk encryption). Web push delivery hits the user's browser vendor (Apple, Google, Mozilla) directly — we don't see the payload after sending it.

5. Subprocessors

RONAR uses the following data processors. Each has its own privacy practices linked below.

6. International transfers

Some subprocessors (Plaid, OpenAI, ElevenLabs, Vercel CDN edges) operate from the United States. EU-to-US transfers rely on each provider's Standard Contractual Clauses and, where applicable, Data Privacy Framework certification.

7. Data retention

We keep your data while your account is active. If you delete the account, the auth row + every linked table (transactions, profile, decisions, weekly_reports, health_snapshots, bank_connections, net_worth_snapshots, manual_assets, manual_liabilities, med_items, med_events, proactive_nudges, morning_reflections, wind_down_messages, diet_logs, daniel_motivations, push_subscriptions, and every other user-keyed table) is removed within 30 days, along with all voice MP3s under your user ID in storage. Bug-report and feedback rows are anonymized (your user ID is nulled) rather than deleted, so we can still triage them. Supabase nightly database backups expire after 7 days under the Pro tier; old backups containing your data therefore age out within that window.

8. Your rights

Access & portability. Settings → Data → Export → Download my complete data. Returns a JSON document with every row in every table you own (cryptographic secrets redacted).

Erasure. Settings → Delete account. Or email domanado.r@gmail.com if you can't sign in.

Rectification. Edit your profile fields in-app at any time. For corrections we can't surface (e.g. a wrong field type in a synced bank transaction), email us.

Withdraw consent. Settings → Connect → disconnect any provider. Settings → Notifications → turn off push.

Object & restrict. Email us; we'll comply or explain why we can't.

Lodge a complaint. If you're in the EU/EEA, you can complain to your national supervisory authority. In the UK, the ICO. In California, the Attorney General's office.

9. Children

RONAR is not directed at children under 16, and we don't knowingly collect data from them. If you believe a child has signed up, email us and we'll delete the account immediately.

10. Cookies + local storage

RONAR uses no first-party cookies. Supabase stores your session token in browser localStorage; your locale preference is also in localStorage. Vercel may use a single load-balancer cookie for routing; it carries no personal data.

11. Changes to this policy

When we materially change what we collect or who we share it with, we'll update the "Last updated" date above and notify you in-app on next open. Continued use after notice means you accept the change.

12. Contact

Questions, requests, complaints, or to exercise any of the rights above: domanado.r@gmail.com. We respond within 30 days (GDPR statutory window).

RONAR is provided as-is. We're a read-only personal finance + life-mastery tool — not a money mover, not a lender, not a regulated investment advisor. See our Terms of Service for the full scope.