Privacy
Effective October 4, 2026
Mantis is built to need as little data as possible. This policy describes what the current version of the Mantis iPhone app and mantis.hurstsystems.com collect. You can read stories as a guest without an account. The app contains no advertising or tracking code, and its usage analytics go only to our own server.
Reading stories
Reading stories needs no personal information. The app downloads stories from our server, which, like most web servers, records each request's IP address, time, address requested, and app or browser version. We use these logs only to keep the service secure and working, and delete them after 14 days.
Your account
Alerts, following stories, choosing topics, asking about stories and reporting problems need a free account. You can sign in with Apple, with Google, or with an email and password. Our server stores:
- a random account ID, and the name and email you or your sign-in provider share with us (Sign in with Apple lets you hide your email behind an Apple relay address);
- for Apple and Google, the provider's ID for your account, so it can recognize you next time. We never see or store your Apple or Google password;
- for email sign-in, your email and a salted, one-way scrypt hash of your password. Your password itself is never stored or logged. To confirm your address or reset your password we email you a six-digit code through our email provider; we store only a one-way hash of it, and it expires after 15 minutes;
- the topics you follow, the stories you follow or mute, any alert filters you write, and whether you finished setting up;
- if you turn on the digest, that choice, how often you want it, your time zone, and when the last digest was sent. We email it to your account's address through our email provider, and you can turn it off in Settings or from the link in any digest;
- problems you report with a story: which story and version, the reason you pick, any note you write, and when;
- questions you ask about stories, with their answers and the sources the answers cite;
- if you subscribe to Mantis Plus or Pro: the plan, the App Store's ID for your subscription, when it was bought and when it renews or ends, and whether it was a test purchase. Apple handles payment; we never see your payment details. When you subscribe, the app gives Apple your random account ID, so Apple's notifications about renewals and refunds reach the right account;
- for each signed-in device, a one-way hash of a random session token (the token itself stays in your iPhone's Keychain), and when it was created and last used.
We use this only to sign you in, to send you alerts for the topics you follow, to answer your questions, to keep your plan, and to fix stories you report; reports reach the Mantis team by email without your name or email. We keep it until you delete your account. We do not sell it or share it with anyone else, except with the services described next and under "Services we use".
When you ask about a story, we send your question, your earlier questions and answers on that story, and the story's own material to OpenAI, which writes the answer and may search the web to do it. Nothing that identifies you is sent, and we ask OpenAI not to keep it.
Alert filters are optional instructions, in your own words, for which alerts you want. To check an alert against them, we send your filters and the alert's text, and nothing that identifies you, to TypeSafe, the AI service behind Mantis AI. We send them only for that check, and to show you how your filters would have handled your recent alerts.
Monitors are optional, too: a name and a description, in your own words, of news you want gathered and alerted on your way. To sort markets into a monitor, we send its name and description and each market's title, and nothing that identifies you, to TypeSafe. Deleting a monitor or your account erases them from our server. When you search for a market to add to a monitor, your search words, and nothing that identifies you, go to Polymarket's public search.
If you send your monitor alerts to Slack, Discord, a webhook or your email, we send each alert's text to the address you gave, and keep that address until you remove it. API keys you make are stored only as a hash.
Alerts
If you turn alerts on, the app registers your iPhone with our server, which stores:
- a random installation ID created by the app;
- a one-way hash of a random secret that proves requests come from your installation (the ID and secret stay in your iPhone's Keychain);
- the push token Apple issues for Mantis on your iPhone, and whether it is for Apple's development or production push service;
- whether alerts are on, and when the registration was created and last changed;
- for each alert, which story it was for, whether it was delivered, and when.
We use this only to send you Mantis alerts. Alerts are delivered through the Apple Push Notification service, so Apple receives your push token and the alert's text. While you are signed in, your installation is linked to your account so alerts follow your topics; signing out removes the link. We do not sell this data or share it with anyone else.
Usage analytics
To learn which parts of Mantis are useful, the app records what you do in it, such as screens you view, stories and sources you open, alerts you tap, and whether setup and sign-in succeeded, with your app and iOS versions. Each event is stored on our server under a random ID the app creates for itself, not your device's identifiers, and is linked to your account while you are signed in. Events never include your name, email, search text or alert filter wording. We use them only to improve Mantis; they are not sent to any analytics or advertising company, and are not used to track you across other apps or websites.
Deleting your data
- Deleting your account in Mantis (Settings, then Delete Account) erases your account, sign-in details, topics, followed and muted stories, alert filters, monitors and their alerts, delivery destinations, API keys, questions and answers, subscription records, sessions, and the usage events linked to your account from our server immediately, and the app starts a new random analytics ID. Problems you reported with stories are kept, no longer linked to you. If alerts were on, your iPhone keeps getting general alerts as a guest until you turn them off. Deleting your account doesn't cancel an App Store subscription; manage that in your iPhone's Settings.
- Signing out ends that device's session on our server.
- If you signed in with Apple, deleting your account also tells Apple to end Mantis's access to your Apple ID.
- Turning alerts off in Mantis deletes your installation, push token, and alert history from our server immediately.
- If Apple tells us your push token is no longer valid (for example, after you delete the app), we delete the token.
- Database backups, kept for 14 days, can hold a copy until they expire.
Services we use
These companies process data for Mantis, only as described above:
- Amazon Web Services runs our server and database, in the United States;
- our email provider sends sign-in codes, digests and alerts you choose to get by email;
- Apple delivers alerts, runs Sign in with Apple, and handles App Store purchases;
- Google runs Sign in with Google, if you use it;
- OpenAI writes stories and answers your questions about them;
- TypeSafe checks alert filters and sorts markets into monitors;
- Polymarket answers market searches.
Where stories come from
Stories are written from public Polymarket market data and public news reporting, using OpenAI's models. None of your data is sent to Polymarket, OpenAI, or any other service to write them.
Children
Mantis is not directed at children under 13, and we do not knowingly collect data from them.
Changes
Mantis will change as it grows. Before a change to what data Mantis collects or how it is used takes effect, we will post the updated policy here with a new effective date, and tell you in the app when the change is significant.
Contact
Questions or requests: josh@hurstsystems.com.