Adaptive stream

MantraStream Privacy Policy

Our privacy policy outlines the data we collect, how AI vendors process your requests, and the controls you have over your MantraStream account.

Listen now Personalize streams in seconds. Current plan and trial terms appear before Checkout.

Warm start preset

Tune MantraStream to Privacy & Trust and let the affirmations roll while you move through the day.

Open the player

We preload your goals so the first track already feels dialed in.

This privacy policy explains how MantraStream collects, uses, and protects personal data when you use personalized affirmation audio. It distinguishes account data held by the service from personal goals and cached audio that stay in your browser.

Privacy Policy Highlights

Data we collect

  • Account details: Google account subject, verified email address, display name, and avatar URL. MantraStream does not receive or store your Google password or a Google refresh token.
  • Subscription state: Stripe customer and subscription identifiers, Price identifier, subscription status, renewal or trial end, and cancellation state. Stripe handles payment-card data; MantraStream does not store full card numbers.
  • Application state: Onboarding completion and hashed application-session records in Cloudflare D1. The raw session token stays in a secure, HttpOnly cookie.
  • Usage totals: Daily counts for generation requests, generated lines, speech requests, speech characters, and failures. These counts enforce fair-use limits without retaining the underlying text.
  • Operational diagnostics: Request IDs, route outcomes, latency, and limited error events. Logs exclude goals, generated affirmations, email addresses, cookies, authentication tokens, and Stripe payloads.

Goals, emphasized topics, avoided phrases, player preferences, generated affirmation lines, and personalized audio are not stored in D1. Preferences and cached audio stay in browser storage on the device where you use MantraStream. The text needed for a request is sent to Cloudflare Workers AI while that request is processed.

How we use your information

  • Authenticate you through Google OpenID Connect and maintain a MantraStream session.
  • Ask Cloudflare Workers AI to generate the affirmation text and speech you request.
  • Maintain a continuous player queue and a device-local audio cache for limited offline continuity.
  • Process subscriptions, trials, invoices, and the customer portal through Stripe.
  • Enforce burst limits and daily fair-use ceilings and investigate service failures or abuse.

Legal bases

We process personal data to fulfill our contract with you (delivering the app), to comply with legal requirements (e.g., accounting, fraud mitigation), and with your consent when you opt into optional emails or experiments.

Data Sharing

Service providers

  • Google: Authenticates your account and returns the basic profile and verified email scopes that you approve.
  • Stripe: Processes payments, Checkout, the customer portal, invoices, and subscription events.
  • Cloudflare: Hosts the Worker and static files, stores account, session, billing, and usage data in D1, provides abuse protection and operational logs, and runs the text and speech models through Workers AI and AI Gateway.

We share only the data needed for the requested authentication, billing, infrastructure, and AI-processing functions. Each provider processes data under its own applicable terms, privacy commitments, and service configuration.

Legal disclosures

We may disclose information if compelled by law, court order, or lawful request from public authorities. If a request is overly broad, we contest it where feasible.

Data Retention and Security

Retention

  • Account and subscription state remain while the account is active and until a verified deletion request is completed, subject to financial or legal retention duties.
  • Application sessions expire after 30 days and can be revoked earlier by signing out. Expired rows are removed through the documented maintenance command.
  • Webhook event identifiers are retained to prevent duplicate billing updates. They do not contain the full Stripe payload.
  • Daily usage totals are retained for cost control and operational review. They do not contain prompt text.
  • Personalized audio remains only in the device-local cache. The cache keeps at most 160 clips and removes the least recently used entries. Clearing site data removes the local goals, settings, and audio cache.
  • Cloudflare operational-log retention follows the configured Cloudflare account policy. MantraStream does not send private prompt bodies to AI Gateway logs.

Safeguards

  • Encryption in transit via HTTPS everywhere the service is available.
  • Secrets such as API keys remain on the server; we never ship them to the browser or mobile clients.

Your Choices and Rights

Manage or delete data

  • Update goals and preferences directly inside the app.
  • Clear the site's browser data to remove device-local goals, settings, and cached audio.
  • Cancel a subscription through the Stripe customer portal.
  • Request account deletion by emailing support@mantrastream.com from the verified Google address used for the account. We verify the request before deleting user-linked D1 identity, session, subscription, and usage data that we are permitted to delete. Stripe may retain transaction records where law requires it.

Cookies and local storage

We use necessary cookies for the OAuth transaction, application session, CSRF protection, and short-lived login abuse checks. Goals and player settings use local storage. Audio uses IndexedDB. We do not run third-party advertising or social tracking scripts.

Children’s privacy

MantraStream is not directed to individuals under 16. If you believe a minor has provided personal data, contact support@mantrastream.com so we can delete it promptly.

Cross-Border Data Transfers

Google, Stripe, and Cloudflare operate internationally. Data may be processed in regions described in their service documentation and agreements. Where required, transfers rely on applicable contractual and legal safeguards.

Updates to This Policy

When this policy changes, the published page and effective date are updated. Any additional notice depends on the nature of the change and applicable law.

Effective date: October 11, 2025

For questions about this privacy policy or data practices, email support@mantrastream.com.

Personalize instantly

The preset loads affirmations tuned for Privacy & Trust so you can press play and relax into the flow.

Works anywhere

Use the responsive browser player on a phone, tablet, or computer. Goals and cached audio remain on that device.

Ready when you are

Start from this curated preset, then adjust the goals and listening controls in your browser whenever your focus changes.

Try MantraStream now

FAQs

Do you sell or rent my data?
No. We never sell or rent personal data—we only use it to operate MantraStream, deliver audio you request, and comply with legal obligations.
How can I delete my account data?
Email support@mantrastream.com from your registered Google address. We verify the request, delete the MantraStream account data that we control, and retain only records that the law requires us to keep.
Where is affirmation audio generated?
Cloudflare Workers AI generates the affirmation text and speech requested by the player. Personalized audio is cached in your browser, not in MantraStream's D1 database.