Monk ModeThe 45-day challenge
Back to Monk Mode

Privacy Policy

Last updated 22 September 2026

Who We Are

Monk Mode is the 45-day challenge run by Consulting.com, based in Dubai, United Arab Emirates. We decide what is collected here and why, which makes us the controller of your personal data under the UAE Personal Data Protection Law, the EU and UK GDPR, and the equivalent laws where you live.

Write to support@consulting.com with any question about this notice, or to exercise any of the rights set out below. A person reads that address.

What This Policy Covers

This notice covers the Monk Mode app: your account, your daily check-ins, anything you upload, and what you choose to show the cohort. It is about this app alone.

You reach Monk Mode through Whop, and Whop runs your membership and your payment. What Whop collects when you buy, sign in or browse there is governed by Whop’s own privacy policy, not this one.

What We Collect

Everything below either comes from you as you use the challenge, or from Whop when you sign in. We do not buy personal data, and we do not collect anything from you outside this app.

  • Account and sign-in. Your name, email address, profile picture and Whop user ID, passed to us by Whop when you sign in, along with whether your membership is still active. We keep a session record so you stay signed in: its expiry, and the IP address and browser that opened it.
  • Your challenge record. The timezone you confirmed, the day you joined, the version of the rules you accepted, every check-in with its date and whether it was reported late, any caption you wrote with it, your XP, streak, complete days and badges.
  • What you upload. Photographs and documents you attach to a task as proof, and the before and after photographs and the written reflection in your transformation submission. We store the file, its name, type, size and a checksum, and — once the team reads it — whether it was accepted and any note left with it.
  • What you show the cohort. Check-ins you publish to the feed, the comments you write, the upvotes you give, and any content you report to the team.
  • Reminders. If you turn them on, the local hour you picked and whether the last reminder was delivered. Reminders are sent as Whop notifications.
  • Technical and usage data. The ordinary records our hosting and backend keep — IP address, device and browser, timestamps, error and security logs — and a count of which screens get used, held without your name, your email, file contents or anything you wrote. We also note when you were last active.

Why We Use It, and on What Basis

Where the EU or UK GDPR applies, the law asks us to name a basis for each purpose. These are ours.

  • To run the challenge. Creating your account, counting your days, scoring your work, reading your submission and publishing results. We need this to give you what you signed up for — performance of our contract with you.
  • To keep the app safe and working. Preventing abuse and fraud, reviewing content reported by members, fixing faults, and understanding which parts of the app get used so we can improve them. Our legitimate interest in a service that works and a cohort that behaves.
  • To send you things you asked for. Daily reminders, and nothing else. You turn these on, and you can turn them off at any time in Settings — your consent.
  • To show your work to the cohort. Publishing a check-in, and sending its photographs with it, happens only when you choose it — your consent, withdrawn by taking the post down.
  • To meet legal obligations. Responding to lawful requests, keeping records we are required to keep, and defending legal claims.

What We Do Not Do

Your data is here to run your 45 days. It is not a product we trade on.

  • We do not sell your personal information, and we do not share it for cross-context behavioural advertising, as those terms are used in California and other US state privacy laws. We have not done so in the last twelve months.
  • We do not advertise to you or let anyone else advertise to you through this app. There are no advertising trackers or third-party analytics scripts in it.
  • We do not train AI on your work. Monk Mode has no AI feature. Your check-ins, reflections and photographs are not used to train any model, ours or anyone else’s.
  • We do not read your uploads for anything but review. The team opens evidence to judge whether a task was kept, and reads finalists’ submissions before results are published. That is all.
  • We do not profile you automatically. Nothing here decides anything about you on its own. Winners are chosen by people reading the work.

What Others See Is Your Choice

Files you upload as proof are private by default. Only you and the review team can open them.

Publishing a check-in to the feed is a separate decision from keeping the task, and it sends that check-in’s photographs with it. Taking the post down makes them private again. Existing uploads and your transformation photographs are never published by us.

Two switches in Settings control the rest: whether your badges appear beside your name, and whether other members can open your profile. Neither changes your score or what the review team reads. Your name and picture stay on the check-ins you have published either way.

Who We Share It With

We share your data with the companies that run the app for us. They may only use it on our instructions, and each is bound by a contract that says so.

  • Whop. Sign-in, membership and access, payments, and delivery of the reminders you opted into.
  • Convex. The backend and database that hold your challenge record, and the storage that holds your files.
  • Vercel. Hosting and delivery of the app itself.
  • Slack. Used internally by our review team. When a member reports a post or a comment, a notification with that content reaches the team there.

Beyond those, we disclose personal data only where the law requires it, where it is needed to establish or defend a legal claim or to protect someone’s safety, or — if the business is ever sold or merged — to the buyer, who would remain bound by this notice until you are told otherwise.

Where Your Data Is Processed

We are in the United Arab Emirates and our members are spread across the Americas, Europe and Asia, so your data crosses borders. Our providers process it primarily in the United States and the European Union.

Where a transfer leaves the EEA, the UK, or another country whose law restricts it, we rely on the safeguards that law provides — the European Commission’s standard contractual clauses and the UK addendum, or an adequacy decision where one covers the destination. Ask us at support@consulting.com and we will tell you which applies to a given provider.

How Long We Keep It

Your account and challenge record are kept while your account is open and for as long as we need them to run and settle the cohort you joined — including reviewing work, publishing results and awarding prizes.

Once a cohort’s results are published we keep a small final record of it: your display name, days kept and score. It is what lets us settle any question about a result later, and it is why coming back for a later round starts a clean record rather than overwriting the old one.

Session and security logs are short-lived. If you ask us to delete your data, we do so within 30 days, except where we are required to keep something longer — and we will tell you if that is the case.

How We Protect It

Everything travels over encrypted connections and is stored on managed infrastructure with encryption at rest. Uploads are private by default and served only through authorised requests. Administrative access is limited to the review team, and corrections they make to your record are logged with a reason.

Your Rights

Wherever you live, you can ask us to do the following, and we will answer within 30 days:

  • Access. Get a copy of the personal data we hold about you, and an explanation of what we do with it.
  • Correction. Fix anything inaccurate or incomplete.
  • Deletion. Delete your account and the personal data attached to it.
  • Portability. Receive your data in a machine-readable file, or have us send it elsewhere where that is technically feasible.
  • Objection and restriction. Object to processing we base on our legitimate interests, or ask us to pause processing while a dispute is resolved.
  • Withdrawing consent. Turn off reminders, or take a published post down, at any time. That does not undo what was done while consent was in place.

Some of this is immediate and in your hands: reminders and visibility live in Settings, and any published check-in can be taken down from the feed. For the rest, write to support@consulting.com from the address on your account. We will not charge you, and we will not treat you differently for asking.

Cookies and Local Storage

We use no advertising or analytics cookies. The only cookies we set are the ones that sign you in and keep you signed in, and a few short-lived ones that remember a sign-in attempt or that you signed out.

Your browser also stores a little on your device so the app behaves: your light or dark theme, which account was last active, and a local copy of a reflection you are part-way through writing, so it survives a closed tab. That draft stays on your device, and is cleared when you sign out.

Children

Monk Mode is for adults. It is not directed at anyone under 18, and we do not knowingly collect their data. If you believe a child has an account here, write to us and we will remove it.

Changes to This Policy

We will update this notice as the app changes. The date at the top always says when. If a change materially affects how we use your data, we will tell you in the app or by email before it takes effect, and ask for your consent where the law requires it.

Contact Us

Consulting.com, Dubai, United Arab Emirates.

Privacy questions and requests: support@consulting.com