Your trust is our most precious thing

Privacy at Mymantra

Your data belongs to you. We do not sell it. Not voluntarily, not for money, not for reach. Here you can read transparently how we handle what you entrust to us.

EU Hosting

Servers in the EU, connection encrypted.

No Selling

We do not share your data. Ever.

No Tracking

No ad pixels, no behavioural analysis.

1.Controller

The controller for data processing on this website and in the Mymantra App is:

WORQ BOUTIQUE UG (haftungsbeschränkt)
Schloßstraße 40, 14059 Berlin, Deutschland
Represented by: Falco Adnan Max-Georg Schneider
E-Mail: worqboutique@gmail.com
Phone: 0160 4077626

2.What Data We Process

Account data: When you register, we store your e-mail address and an encrypted password hash. When logging in via Google, we receive the name and e-mail of the linked account.

Content you create: Your personal mantras, favourites, onboarding answers about your topics (stress, sleep, self-worth, etc.) and your ritual history.

Usage data: Anonymous server logs (IP address, timestamp, page accessed) for a maximum of 30 days for security and error analysis.

Payment data: Processed exclusively by our payment service provider Stripe. We do not store any credit card or bank account data.

3.Purposes & Legal Bases

We process your data on the following legal bases under Art. 6 GDPR:

  • Performance of contract (Art. 6(1)(b)): Providing your personal space, storing your mantras, processing your payment.
  • Legitimate interests (Art. 6(1)(f)): Technical operation, security, abuse prevention.
  • Consent (Art. 6(1)(a)): For optional features such as e-mail reminders, if you activate them.

4.Recipients & Processors

We work with carefully selected service providers with whom we have concluded data processing agreements pursuant to Art. 28 GDPR:

  • Supabase (database hosting and authentication, EU region) — stores your account and your mantras.
  • Stripe Payments Europe Ltd. (Dublin, Ireland) — processes your payments.
  • Cloudflare — CDN and edge hosting of the website.
  • Lovable AI Gateway — processes your inputs for mantra generation and the Amaya chat. Data is not used for model training and is not permanently stored by the AI provider.

5.Retention Periods

  • Account and content data: until you delete them or delete your account.
  • Payment records: statutory retention periods (10 years, § 147 AO / applicable tax law).
  • Server logs: maximum 30 days, then automatically deleted.

6.Your Rights

Under GDPR, you have the following rights against us at any time:

  • Access to your stored data (Art. 15)
  • Rectification of inaccurate data (Art. 16)
  • Erasure ("right to be forgotten", Art. 17)
  • Restriction of processing (Art. 18)
  • Data portability (Art. 20)
  • Objection to processing (Art. 21)
  • Withdrawal of granted consents (Art. 7(3))

A brief e-mail to worqboutique@gmail.com is sufficient. You also have the right to lodge a complaint with the competent supervisory authority — for us: Berliner Beauftragte für Datenschutz und Informationsfreiheit, Friedrichstraße 219, 10969 Berlin.

7.Cookies & Tracking

We use only technically necessary cookies — for example, to maintain your login session. We use no Google Analytics, no advertising pixels, no social media trackers, and no behavioural profiling.

8.AI Processing (Amaya & Mantra Generator)

To generate your personal mantras and for the chat with Amaya, we send your inputs to our AI service provider (Lovable AI Gateway, which in turn uses large language models). The providers have contractually undertaken not to use your data to train their models and not to store it permanently.

Note on the EU AI Act (Regulation (EU) 2024/1689): Mymantra is a Deployer of an AI system within the meaning of the Regulation. It is not classified as a high-risk AI system under Annex III. The AI generates inspirational texts (mantras, impulses) — it does not make legally relevant or medical decisions about you. You are transparently informed that you are interacting with an AI system (Art. 50 EU AI Act). Questions can be directed to worqboutique@gmail.com.

9.International Data Transfers

We prefer providers with EU-based hosting. Where data is transferred to third countries (e.g. the USA), this is done on the basis of EU Standard Contractual Clauses (SCCs) and supplementary technical safeguards.

10.Data Security

All connections are encrypted with TLS. Passwords are stored exclusively as cryptographic hashes. At the database level, all content is protected via Row-Level Security so that only you yourself can access your mantras and account data.

11.Changes to This Policy

We update this policy when our services or the legal situation change. Material changes will be announced by e-mail. As of: June 2026.

Want to know more about our promise?

Read why your trust matters more to us than any advertising budget.

Read our Data Promise