Privacy policy
Last updated 3 August 2026
MyNextLevel is operated by MB HorseHat, a company registered in Lithuania. We are the data controller for the personal data described here. You can reach us at horsehat.it@gmail.com.
The short version
We do not run analytics, advertising or tracking of any kind. The things you write — your goals, tasks and reflections — are encrypted in your browser before they reach us, using a key derived from a passphrase we never receive. We cannot read them, and neither can anyone who obtains our database.
What we hold
| Account | Your name, email address and profile picture, received from Google when you sign in. We never see your Google password. |
|---|---|
| Your entries | Goal titles and reasons, task titles, routine titles and all reflection text are stored encrypted. We hold only ciphertext. |
| Activity metadata | Dates, completion flags, goal status, progress and category, ordering, recurrence schedules, and the 1–5 mood score are stored unencrypted, because the app needs them to build your lists, streaks and charts. This means we can see when you were active and how you rated a day — but not a word of what you wrote. |
| Subscription | Trial end date, subscription status, renewal date, and identifiers issued by Stripe. We never see or store your card details. |
| Technical | Our hosting provider keeps standard server logs, which include IP addresses and browser user agents, for security and troubleshooting. |
What we deliberately do not have
- Your encryption passphrase or recovery code — these never leave your device.
- Any means of decrypting your entries, including under legal compulsion.
- Analytics, advertising identifiers, or third-party tracking cookies.
Why we process it, and on what basis
- To provide the service — performance of our contract with you (Art. 6(1)(b) GDPR).
- To take payment — performance of that contract, and compliance with tax and accounting obligations (Art. 6(1)(b) and 6(1)(c)).
- To keep the service secure and working — our legitimate interests in preventing abuse and diagnosing faults (Art. 6(1)(f)).
Who else processes it
We use a small number of providers, each acting on our instructions. Some are based outside the European Economic Area; those transfers rely on the European Commission's adequacy decisions or on Standard Contractual Clauses.
| Sign-in. Receives the fact that you authenticated; provides your name and email. | |
| MongoDB Atlas | Database hosting. Holds encrypted entries and the metadata described above. |
| Railway | Application hosting and server logs. |
| Stripe | Payments. Receives your name, email and payment details directly. Stripe never receives anything you write in the app. |
Cookies
We set one cookie: the session cookie that keeps you signed in. It is strictly necessary for the service to function, so it does not require consent. We do not use any other cookies.
How long we keep it
Your account and its contents are kept while your account exists. If you ask us to delete it, we remove your account, entries and settings within 30 days. Records of payments are kept for as long as Lithuanian accounting and tax law requires, independently of account deletion.
Your rights
Under the GDPR you may request access to your data, correction of it, erasure of it, restriction of or objection to our processing, and a portable copy of it. You may also withdraw consent where processing relies on consent.
The app does not yet have self-service buttons for these, so please email horsehat.it@gmail.com from the address on your account and we will act within one month.
An important limit: because your entries are encrypted with a key we do not hold, a copy we export for you will be ciphertext unless you decrypt it in the app yourself. For the same reason, if you lose both your passphrase and your recovery code, your entries cannot be recovered by anyone, including us.
If you believe we have handled your data improperly, you can complain to the Lithuanian State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija), vdai.lrv.lt, or to the supervisory authority where you live.
Children
MyNextLevel is not intended for children under 16, and we do not knowingly collect their data.
Changes
If we change this policy materially we will say so in the app before the change takes effect. The date at the top always reflects the current version.