Get early access
On this page
The short version

Manestay keeps most of your data on your device. Your treatment logs, progress photos, streaks, and routine data are stored locally and never uploaded to any server. A few things leave your device. We use RevenueCat to operate subscriptions (the free trial, paid plans, and “restore purchase”) across the App Store and Google Play. We use Sentry to receive crash and error reports so we can fix problems and keep the app stable. And if you agree on first launch, we send anonymous usage events to PostHog so we can understand how the app is used and improve it. You can turn analytics off at any time from Settings. Inside the app there are no names, no email addresses, and no account; Manestay has no login system. The one piece of personal data we collect directly is your email address, and only if you choose to sign up for updates on the Manestay website. That’s covered in Section 15.

01

Who we are

Manestay is developed and operated by Press Get Ltd, a company registered in England and Wales. We are the data controller for any personal data processed in connection with the app and the Manestay website. You can contact us at [email protected] for any privacy-related queries or requests.

02

What data we collect and where it lives

Most of what Manestay stores never leaves your device. Here’s a full breakdown:

DataWhat it includesWhere it’s stored
Onboarding quiz answersHow long you’ve been losing hair, the areas affected, family history, what you’ve tried before, and how it’s affecting you, collected when you set up your regimenDevice only
Treatment regimenYour selected treatments, start date, and routine scheduleDevice, and treatment names to PostHog if analytics are enabled (see Section 4)
Daily logsWhich treatments you completed, skipped, or missed each dayDevice only
Progress photosPhotos you take in-app, stored as local image files with area and date metadataDevice only
Notification preferencesYour morning/evening reminder times and notification historyDevice only
Subscription statusYour current plan tier, trial dates, and whether a subscription is activeDevice and RevenueCat (see Section 6)
Article read historyWhich in-app articles you’ve openedDevice only
Milestone responsesWhether you felt your treatment was working at results-window checkpoints (overall, and per-treatment)Device, and PostHog if analytics are enabled (see Section 4)
Monthly check-in answersYour multiple-choice answers about shedding and overall impression (never free text)Device, and PostHog if analytics are enabled (see Section 4)
App rating promptsWhether the day-7/day-30 rating prompt was shown or dismissed. Your store rating goes to Apple or Google; we never see itDevice, and PostHog if analytics are enabled (see Section 4)
App UI stateSmall flags recording whether you have seen the notification primer or the photo-privacy hint, and similar first-run stateDevice only
Usage analyticsAnonymous events about how you use the app: see Section 4PostHog (remote), only if you’ve agreed to analytics
Crash diagnosticsCrash and error reports, including device and app state at the time of the errorSentry (remote): see Section 5

We do not collect your name, email address, phone number, or any account credentials. There is no account system in Manestay.

03

Progress photos

Photos you take within Manestay are saved directly to your device’s private app storage. They are never uploaded, shared, or transmitted anywhere. They are only accessible within the Manestay app. If you delete the app, your photos will be permanently deleted along with it. We recommend backing up any photos you wish to keep before uninstalling.

Camera permission. To take a progress photo, Manestay asks your device for permission to use the camera (on Android, the CAMERA permission; on iOS, camera access). We use this permission only to capture the progress photos you choose to take inside the app. We do not access your device’s photo gallery or camera roll, and we do not use the camera in the background or at any other time. You can take photos without granting the permission only by declining it, in which case the in-app photo feature is unavailable; you can change your choice at any time in your device’s system settings for Manestay.

04

Analytics (PostHog)

We use PostHog to collect anonymous analytics that help us understand how the app is used, identify problems, and improve the experience. Analytics are off until you agree to them. The first time you open the app you’ll see a short notice asking whether we can collect anonymous usage data. If you tap “No thanks”, analytics stay switched off and no events are sent. If you tap “That’s fine”, analytics start running and you can turn them off again at any time from Settings → Analytics. Turning them off stops collection immediately.

When analytics are on, PostHog receives the following:

Device information: device type, operating system version, app version, screen size, and locale. This is collected automatically by the PostHog SDK.

Usage events: actions like opening the app, logging a treatment, completing a day, saving or updating a regimen, taking or deleting a progress photo, comparing photos, viewing a screen, opening an in-app article, changing your notification times, or interacting with the paywall.

Treatment names: the treatments in your regimen (for example minoxidil or finasteride) are included as properties on analytics events: when you save or edit your regimen, when you skip a treatment, and when you open a page in the treatment library. This tells us which routines people build and stick to. Your daily log history itself is never uploaded, only the events described here.

Monthly check-in answers: your multiple-choice answers about shedding and overall impression are included on the corresponding event. We never record free-text answers.

Photo-comparison verdicts: when you compare two progress photos, whether you judged them better, the same, or not sure is included on the event, along with the scalp area and how many weeks apart the two photos were taken. The photos themselves are never uploaded.

Milestone reflections: at weeks 6, 12, and 24 the app shows a short prompt asking whether you feel your treatment is working. Your answer (“yes” or “not yet”) and which milestone it relates to are included on the corresponding event. For per-treatment checkpoints, the event also identifies which treatment the answer concerns; we do not record free-text responses.

App rating prompts: when the day-7 or day-30 rating prompt appears, the event records only whether it was shown, dismissed, or that the system rating dialog was requested. No rating value and no text is ever sent to PostHog; your store rating goes directly to Apple or Google, and we never see it. There is no feedback email flow.

Your IP address: received with each event, because any network request includes it. We use it only to derive an approximate location (country and region), and we have PostHog configured to discard the IP once that location is derived; it is not stored against your events.

A persistent device identifier: a randomly generated ID created on first launch and stored on your device. This is used to associate analytics events across sessions. It is not linked to your name, email address, or any other personal information.

We do not send your name, email, photos, daily log content, onboarding quiz answers, or any feedback text you write to PostHog. PostHog processes data on servers in the United States: see International data transfers (Section 10). You can read PostHog’s own privacy policy at posthog.com/privacy.

05

Crash reporting (Sentry)

When the app hits an error or crashes, we use Sentry to receive a diagnostic report so we can find and fix the problem. Sentry runs for everyone (it is not tied to the analytics toggle in Section 4) because we need stability data to keep the app working, including for people who’ve turned analytics off. Our lawful basis for this is our legitimate interest in keeping Manestay stable and secure.

A crash report can include the type of error and where it happened in the app, your device model and operating system version, the app version, and the app’s state at the moment of the crash.

We do not use Sentry’s session replay or in-app feedback widget. Sentry never receives screen recordings of your session or free-text bug reports you type. We have also turned off Sentry’s default IP collection and added filters so your IP address and other identifying information cannot be attached to a crash report.

We do not use crash reports to identify you, and we keep treatment and health information out of crash payloads. Sentry processes data on servers in the United States: see International data transfers (Section 10). You can read Sentry’s privacy policy at sentry.io/privacy.

06

Subscriptions (RevenueCat)

Manestay offers a free trial and paid monthly and annual plans. We use RevenueCat to handle this because it manages App Store and Google Play in-app purchase receipts, restore-purchase flows, and subscription status in one place. RevenueCat runs every time the app is launched, not only when you open the paywall. The app needs to know on every screen whether you have an active subscription, and RevenueCat is how it finds out. This means RevenueCat operates outside the analytics notice; it is part of the subscription feature itself, not an analytics tool. If you never open the paywall and never subscribe, RevenueCat still confirms to the app that you have no active purchase.

When the app talks to RevenueCat, RevenueCat receives:

  • An anonymous user identifier that RevenueCat generates for your installation. It is not linked to your Apple ID, Google account, name, or email.
  • Device information: device model, operating system version, app version, and locale.
  • Your IP address, which is unavoidable whenever any app makes a network request.
  • If you purchase or restore a subscription, the associated App Store or Google Play receipt (which the relevant store validates) and the product identifier of the plan you chose.

RevenueCat processes this data on servers in the United States: see International data transfers (Section 10). You can read RevenueCat’s own privacy policy at revenuecat.com/privacy. Our lawful basis under UK GDPR is performance of a contract: if you start a free trial or a paid plan, we need RevenueCat to operate that subscription on your behalf. For users who never subscribe, the processing is limited to the handshake required to confirm that no subscription exists, and our lawful basis is our legitimate interest in operating the free trial and paywall. To stop this processing, uninstall the app. Because there is no account, there is nothing to “log out” of.

07

Telehealth referral links

Manestay may in future show a link, in a small number of places, inviting you to speak to a regulated UK telehealth provider about your hair-loss treatment options: for example, if you tell the app you are not yet on any treatment, while you are browsing the treatment library, when you add a new treatment to your regimen, or in an occasional check-in card. If we introduce this link, it would only appear where your own actions in the app suggest you might want it, it would never name a prescription-only medicine, and every surface that carries it would tell you, in plain sight, that we may earn a commission.

The affiliate network. If we introduce this link and you tap it, your tap would be routed through an affiliate network (we expect this to be a network such as Awin or Impact; we will name the specific network here once it is confirmed) on its way to the telehealth provider’s own website. That network, and the telehealth provider, would receive the fact that a click occurred, a timestamp, and a referral or click identifier that lets them attribute the referral back to Manestay, so that we can be paid a commission if you go on to become a patient. They would not receive your treatment logs, regimen, photos, or any other data held on your device, only the fact that a Manestay user followed the link.

Lawful basis. If we introduce this link, our lawful basis for passing this attribution identifier would be our legitimate interest in operating our affiliate referral arrangement, balanced against your interests: the identifier would only ever serve referral attribution, would not be linked to your name or to any health information we hold, and you would be able to avoid it entirely by not tapping the link. If the network or provider ever needs your consent for part of this (for example, to set a tracking cookie that goes beyond simple attribution), we will ask for it before the link is shown, and you will be able to decline without losing access to any other part of Manestay. Where the affiliate network processes data outside the UK, that transfer would be covered by International data transfers (Section 10).

Third-party links generally. Tapping this link, if introduced, or any other external link inside Manestay or on this website, takes you to a third party’s own site or service. From that point, the third party’s own privacy policy governs how they handle your data, not this one. We are not responsible for the privacy practices, content, or services of any third party we link to, including the telehealth provider. We recommend reading their privacy policy before giving them any information.

We will update this section with the confirmed partner’s name and a link to their privacy policy once the partnership is live.

08

Health data

Manestay does not connect to any health platform. On iOS it does not connect to Apple Health and does not read from or write to HealthKit. On Android it does not connect to Health Connect, Google Fit, or any equivalent health service. The treatments you log within Manestay (such as minoxidil or finasteride) are stored only on your device and treated as private personal data. As noted above, treatment names may appear in anonymous analytics events; this does not include your personal log history. We do not sell your health or treatment data, and we do not use it for advertising or any purpose unrelated to operating the app for you. Manestay is not a medical device and does not diagnose, treat, cure, or prevent any medical condition. The app is a routine and consistency tool only. Always consult a qualified healthcare professional before starting, stopping, or changing any treatment.

09

Your rights

Under UK GDPR and the Data Protection Act 2018, you have the right to:

Access: request a copy of any personal data we hold about you.

Erasure (data deletion). Manestay has no account system, so there is no account to delete. Because your data is stored on your device, you can delete all of it at any time using the Delete all my data option in the app’s Settings screen, by clearing the app’s data in your device settings, or by uninstalling the app. For the limited data held off-device by our processors (analytics data held by PostHog, crash-report data held by Sentry, or subscription data held by RevenueCat), email us at [email protected] and we will submit a deletion request on your behalf. This is also the route to request deletion of any data without using the app itself.

Portability: request your data in a portable format.

Objection: object to analytics processing. You can turn analytics off yourself at any time from Settings → Analytics; this stops collection immediately. If you also want the events PostHog has already received from your device to be deleted, contact us and we will submit a deletion request on the anonymous device identifier associated with your installation.

To exercise any of these rights, email [email protected]. We will respond within 30 days.

10

International data transfers

Some of our processors are based in, or host data in, the United States: PostHog (analytics), RevenueCat (subscriptions), Sentry (crash reporting), and Kit (website mailing list). Whenever your personal data is transferred outside the UK, we rely on a lawful transfer mechanism. PostHog, Sentry, and Kit are certified under the UK Extension to the EU–US Data Privacy Framework, so those transfers are covered by that framework. RevenueCat relies on the UK International Data Transfer Agreement / the EU Standard Contractual Clauses with the UK Addendum. The applicable mechanism is set out in each provider’s data processing agreement.

11

Security

Most of your data stays on your device, protected by your device’s own security. For the limited data we process off-device, we use providers that maintain recognised security practices, restrict access to your data, and protect it in transit and at rest. No system is perfectly secure, but we take reasonable steps to protect your information.

12

Data retention

All on-device data is retained until you delete the app or clear its storage. We have no ability to delete on-device data remotely. Analytics data held by PostHog is retained for up to 12 months, after which it is automatically deleted. Crash-report data held by Sentry is retained for up to 90 days (Sentry’s standard error-event retention), after which it is automatically deleted. Subscription data held by RevenueCat is retained according to RevenueCat’s own retention policy, which covers the lifetime of your subscription record plus any period needed to support App Store and Google Play receipt validation and billing-dispute handling. See revenuecat.com/privacy for their current terms.

13

Age

Manestay is for adults. It is intended only for people aged 18 or over, and is not directed at anyone under 18. We do not knowingly collect personal data from anyone under 18. If you believe someone under 18 has provided personal data through the app, please contact us and we will take steps to delete it.

14

Changes to this policy

We may update this policy from time to time: for example, when we introduce new features such as cloud backup or account creation. When we do, we will update the date at the top of this page and, where the changes are significant, notify you within the app. We recommend checking this page periodically if you want to stay informed.

15

The Manestay website

This section covers the Manestay website, not the app. Everything above describes data inside the app, where we collect no email address and there is no account. Two things are different on the website: we use privacy-friendly analytics to understand traffic, and (if you choose to sign up for our updates) we collect your email address.

Website analytics. We use Cloudflare Web Analytics to understand how this website is used: for example, which pages are viewed, how many visitors we get, and roughly where they come from. It is privacy-first: it does not use cookies, does not fingerprint your device or browser, and does not track you across other websites. The measurement is aggregate only and does not collect personal data or identify you, so there is nothing for you to consent to or opt out of. You can read more in Cloudflare’s privacy policy at cloudflare.com/privacypolicy.

The mailing list. If you sign up for our updates, you give us your email address.

What we collect. Your email address, and nothing else you aren’t asked for. When we send you emails, Kit (our email provider, described below) also records standard delivery and engagement information (such as whether an email was delivered, opened, or a link was clicked, along with technical details like your IP address), which helps us understand whether our emails are working. We may also record basic details of the signup itself, such as the date you subscribed and whether you have confirmed your email.

Why we collect it. To send you occasional updates about Manestay: new features, announcements, and chances to give feedback. We will only ever email you about Manestay. We do not sell or rent your email address, and we do not use it for unrelated advertising.

Our lawful basis. Consent. You opt in by entering your email and signing up, and you can withdraw that consent at any time. Where we use a confirmation step (“double opt-in”), you also confirm your email before we add you to the list.

Who processes it. We use Kit (formerly ConvertKit) to store your email address and send our emails, acting as our data processor. Kit processes data on servers in the United States; that transfer relies on the safeguards described in International data transfers (Section 10) above. You can read Kit’s privacy policy at kit.com/privacy.

How long we keep it. Until you unsubscribe or ask us to delete it. If you unsubscribe, we keep only the minimal record needed to honour your choice not to be contacted.

Your choices and rights. Every email we send includes an unsubscribe link; one click withdraws your consent and stops further emails. You can also email us at [email protected] to be removed, to access the email data we hold about you, or to have it deleted. You also have the right to complain to the Information Commissioner’s Office (ICO) at ico.org.uk.

16

Contact

For any questions about this privacy policy or how we handle your data, please contact:

Press Get Ltd
71–75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom
Registered in England and Wales No. 17111297
Email: [email protected]

If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk.

This is educational information, not medical advice. Manestay is not a medical device and does not diagnose, treat, cure, or prevent any medical condition. Always consult your dermatologist or another qualified healthcare professional before starting, stopping, or changing any treatment.