Privacy policy

Last updated 3 August 2026

MyNextLevel is operated by MB HorseHat, a company registered in Lithuania. We are the data controller for the personal data described here. You can reach us at horsehat.it@gmail.com.

The short version

We do not run analytics, advertising or tracking of any kind. The things you write — your goals, tasks and reflections — are encrypted in your browser before they reach us, using a key derived from a passphrase we never receive. We cannot read them, and neither can anyone who obtains our database.

What we hold

AccountYour name, email address and profile picture, received from Google when you sign in. We never see your Google password.
Your entriesGoal titles and reasons, task titles, routine titles and all reflection text are stored encrypted. We hold only ciphertext.
Activity metadataDates, completion flags, goal status, progress and category, ordering, recurrence schedules, and the 1–5 mood score are stored unencrypted, because the app needs them to build your lists, streaks and charts. This means we can see when you were active and how you rated a day — but not a word of what you wrote.
SubscriptionTrial end date, subscription status, renewal date, and identifiers issued by Stripe. We never see or store your card details.
TechnicalOur hosting provider keeps standard server logs, which include IP addresses and browser user agents, for security and troubleshooting.

What we deliberately do not have

Why we process it, and on what basis

Who else processes it

We use a small number of providers, each acting on our instructions. Some are based outside the European Economic Area; those transfers rely on the European Commission's adequacy decisions or on Standard Contractual Clauses.

GoogleSign-in. Receives the fact that you authenticated; provides your name and email.
MongoDB AtlasDatabase hosting. Holds encrypted entries and the metadata described above.
RailwayApplication hosting and server logs.
StripePayments. Receives your name, email and payment details directly. Stripe never receives anything you write in the app.

Cookies

We set one cookie: the session cookie that keeps you signed in. It is strictly necessary for the service to function, so it does not require consent. We do not use any other cookies.

How long we keep it

Your account and its contents are kept while your account exists. If you ask us to delete it, we remove your account, entries and settings within 30 days. Records of payments are kept for as long as Lithuanian accounting and tax law requires, independently of account deletion.

Your rights

Under the GDPR you may request access to your data, correction of it, erasure of it, restriction of or objection to our processing, and a portable copy of it. You may also withdraw consent where processing relies on consent.

The app does not yet have self-service buttons for these, so please email horsehat.it@gmail.com from the address on your account and we will act within one month.

An important limit: because your entries are encrypted with a key we do not hold, a copy we export for you will be ciphertext unless you decrypt it in the app yourself. For the same reason, if you lose both your passphrase and your recovery code, your entries cannot be recovered by anyone, including us.

If you believe we have handled your data improperly, you can complain to the Lithuanian State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija), vdai.lrv.lt, or to the supervisory authority where you live.

Children

MyNextLevel is not intended for children under 16, and we do not knowingly collect their data.

Changes

If we change this policy materially we will say so in the app before the change takes effect. The date at the top always reflects the current version.

MB HorseHat · Lithuania · horsehat.it@gmail.com