Privacy Policy
Last updated 4 October 2026
Deus is a personal app for tracking habits, reflections, finances and learning. It is run by Samman Thapa, an individual based in Nepal (“I”, “me”). This page explains what the app collects, why, who else handles it, and what you can ask me to do. It is written to be read, not skimmed past.
What the app collects
- Your account. Your email address. If you sign up with a password, the password is kept only as a salted hash by the sign-in provider (Supabase); I cannot read it. If you choose Sign in with Google, Google gives the app your email address, your name and your profile picture, and nothing else. The app asks Google for exactly three things:
openid,emailandprofile. - What you put in it. Habits, lifestyles and the commitments you track; daily and periodic reflections and plans; avoidance (“via negativa”) entries and the notes you write when you break one; finances such as budgets and transactions; learning cards and your review history; water and food logs; writings; your preferences; and any profile details you choose to fill in (a bio, a phone number, a target date, life events).
- Files you upload, such as a profile picture or images inside a writing.
- Technical data. Like any website, the hosting providers keep standard server logs (IP address, browser, the pages requested) for security and operation. The app sets a cookie to keep you signed in (see “Cookies and local storage”).
- Usage analytics. The app uses Google Analytics 4 to count page views and a small number of in-app actions (for example, which suggestion on the home screen was opened). These events carry labels such as a page title or a status, never the text of your entries, and no user ID is sent.
What I use it for
To run the app and show you your own data; to sign you in and keep your account secure; to send you password-reset emails; to understand roughly how the app is used; and to run the optional features described below when you choose to use them. I do not sell your data, I do not show advertising, and I do not build profiles of you for anyone else.
Who else handles your data
These services process data on my behalf, each under its own terms and privacy policy. Your data may be processed in countries other than yours, wherever they run their servers.
- Supabase — the database and the sign-in system.
- Vercel — hosts the website and its server code.
- Cloudflare — stores uploaded images (R2 object storage).
- Google — Sign in with Google (only if you use it), Google Analytics, and the Gemini AI service described next.
- Resend — delivers password-reset and account emails.
The AI weekly review
The app has a weekly review that you start yourself with a button. When you do, it sends a structured summary of your last week to Google’s Gemini API and shows you the reply. The summary contains your habit names and streaks, your lifestyles and quarts, your avoidance commitments including the short notes you wrote about breaking them, challenges, daily water totals against your goal, and your learning review queue (card titles, short key points and tags, and how recent reviews went). It never contains your reflections, your daily or periodic planning answers, or your writings. The reply is shown to you and is not stored.
The app currently uses Gemini on Google’s free tier. Under Google’s terms for that tier, content sent to it may be used to improve Google’s products and may be read by human reviewers. Because the summary can include notes you wrote about your own lapses, only use the weekly review if you are comfortable with that. If this changes, I will update this page.
Agent access (optional)
In Settings you can create an access token for an AI assistant you choose. With the permissions you tick, that assistant can read a summary of your habits and today’s status, log water, mark a habit complete, and leave you notes. It cannot read your reflections or writings. Every request it makes is logged where you can see it, and you can revoke the token at any time. What the assistant’s own provider does with what it reads is governed by that provider, not by me.
Cookies and local storage
- A sign-in cookie called
__sessionand the sign-in session your browser keeps (Supabase’ssb-…-auth-token). These are necessary: without them you cannot stay signed in. - Preferences, unsent drafts and small bits of interface state (such as the theme or a dismissed hint) stored in your browser.
- Google Analytics cookies (
_gaand_ga_…). You can block these in your browser; the app works without them.
Who can see your entries
Your entries are private to your account. The database enforces this with row-level security, so one account cannot read another’s. As the administrator I can technically reach the database; I do not browse people’s entries, and I would only look at yours to fix a problem you have asked me about, or if the law required it.
How long I keep it, and deleting it
I keep your data while your account exists. To delete your account and everything under it, write to contact@sammanthapa.com.np. I will delete the account, all of the data in it and the files stored for you. A copy may remain in a backup I keep for disaster recovery until that backup is replaced. If you used Google to sign in, you can also remove the app’s access at myaccount.google.com/permissions.
Your choices
You can change your profile, email and password in Settings. You can ask me for a copy of your data, to correct it, or to delete it, by writing to contact@sammanthapa.com.np. Depending on where you live, the law may give you further rights; I will honour them.
Security
Everything travels over HTTPS, passwords are hashed, and access to data is limited by row-level security. No system is perfectly secure, and I cannot promise that nothing will ever go wrong.
Children
Deus is not for children under 13, and I do not knowingly collect their data. If you believe a child has signed up, write to contact@sammanthapa.com.np and I will delete the account.
Google user data
Deus’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. The app uses your Google name, email address and picture only to create and sign in to your account.
Changes to this policy
If I change this policy in a way that matters, I will update the date at the top and, for significant changes, say so inside the app.
Contact
Questions or requests about your data: contact@sammanthapa.com.np.