Skip to content

Privacy Policy

Our commitment to your privacy and data protection.


Updated September 25, 2026

This Privacy Policy ("Policy") describes how MNFST OÜ ("Manifest", "we", "us" or "our") collects, protects and uses the personally identifiable information ("Personal Information") you ("User", "you" or "your") may provide through the Manifest website (manifestx.dev), the Manifest account dashboard (dash.manifestx.dev), the Manifest connector for AI assistants, the Manifest command-line tools, Manifest-managed hosting (including sites served on manifestx.ai and connected custom domains), and any other product, application, or service offered by Manifest (collectively, the "Service"). The Policy also describes the choices available to you regarding our use of your Personal Information and how you can access and update this information. This Policy does not apply to the practices of companies that we do not own or control, or to individuals that we do not employ or manage.

MNFST OÜ is a private limited company (osaühing) incorporated in Estonia, registry code 17606632, with its registered address at Tornimäe tn 5, Kesklinna linnaosa, Tallinn, Harju maakond, 10145, Estonia. MNFST OÜ is the data controller for the processing described in this Policy, except where this Policy states that we process data on a User's behalf. For data-protection inquiries, contact us at team@manifestx.dev.


Collection of personal information

We receive and store information you knowingly provide to us when you use the Service:

  • Account information. When you sign in to or create an account with the Service, we collect your email address, which is required to identify your account and to provide you with access to the features of the Service. You may sign in using a third-party identity provider such as Google or GitHub, in which case we receive your email from that provider through a standard OAuth 2.0 flow, or with a one-time code sent to your email address.
  • Content you publish. When you publish a project, we receive and store the site files you upload so we can host and serve them. Published sites are publicly accessible at their assigned address; do not include Personal Information in published files unless you intend it to be public.
  • Team invitations. When you invite someone to a project, we collect the invitee's email address in order to send the invitation and, once they sign in, to associate them with the project. If you provide someone else's email address, you are responsible for having their permission to do so.
  • Payment provider credentials. If you connect a payment provider to enable checkout on your own published site, we store the credentials you supply and use them solely to operate that integration on your behalf. Provide only credentials you are authorized to use, and rotate them with your provider if you disconnect.
  • Purchases. If you buy a paid plan, payment is handled by our payment processor (see "Information transfer and storage"). We receive confirmation of your subscription status and a billing reference; we do not receive or store your full card number.

Collection of non-personal information

When you visit the Service, our servers automatically record information your browser sends. This may include your IP address, browser and operating system type and version, language preferences, pages visited, time spent on those pages, and access times and dates. We use a privacy-friendly analytics provider that does not identify you individually.

We also record service telemetry for requests made to the Service by connected AI assistants: one log entry per request containing request metadata such as the tool invoked, the assistant client's name and version, response status, and hashed identifiers. Identifiers in telemetry are hashed, and header names are recorded without their values.


The Manifest connector for AI assistants

The Service can be used through an AI assistant (such as Claude) via the Manifest connector. When you use the Service this way:

  • What we receive. We receive the requests your assistant sends to the connector: the tool being called and the information included in that call, such as project names, site files being published, domain names, or invitee email addresses. We do not receive your conversation with your assistant — only the content the assistant includes in a request to us.
  • Authorization. The connector acts on your Manifest account only after you sign in and approve the connection through an OAuth 2.0 authorization flow. You can revoke a connection at any time from the assistant's settings or by contacting us.
  • Your assistant's own processing. Your conversation with the assistant, and anything the assistant does outside the connector, is governed by the assistant provider's own privacy policy, not this one.

Sites you publish and their visitors

You control the content of sites you publish through the Service. For Personal Information contained in your published content, or collected by your site from its visitors through features you add, you are the controller and we process it on your behalf as a hosting provider.

For sites hosted on the Service, we collect aggregate visitor analytics — such as page views, referrers, and country-level location — using a privacy-friendly analytics provider, and make these aggregates available to the site's owner. This analytics data does not identify individual visitors and is not used to profile them.


Google User Data

When you sign in to the Service using your Google Account, we access certain information from your Google Account through the OAuth 2.0 authorization flow.

Data accessed. We request a single Google OAuth scope, https://www.googleapis.com/auth/userinfo.email, which grants access to your Google Account email address. We do not request any other Google scopes.

Use of Google user data. Your Google email address is used solely to identify your Manifest account, to associate your session with that account, and to contact you about your account or material changes to the Service. We do not use Google user data for advertising, to train generalized AI or machine-learning models, or for any purpose unrelated to providing user-facing features of the Service.

Storage of Google user data. Your email address is stored by our authentication provider as part of your account record. We do not store your Google OAuth access or refresh tokens in our own database; session tokens are managed by our authentication provider and are scoped to your active session.

Limited Use. Manifest's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Revoking access. You may revoke Manifest's access to your Google Account at any time by visiting your Google Account permissions page.


Use and processing of collected information

We use the information we collect to identify you within the Service, provide access to its features, host and serve the content you publish, send transactional messages such as sign-in codes and project invitations, provide analytics to site owners, process payments for paid plans, communicate with you about your account or material changes, improve the Service and our documentation, secure the Service against abuse, and operate the Service. We do not sell or rent your Personal Information to any third party.


We process your Personal Information only where we have a lawful basis under applicable law. Depending on your jurisdiction and the context of the processing, that basis may be: your consent; the necessity of authenticating you and providing the Service you have requested, including performance of our contract with you; our legitimate interests in operating, securing, and improving the Service, where not overridden by your rights; or compliance with a legal obligation.


Cookies and local storage

We use cookies and browser local storage for authentication, session management, preferences, and anonymized analytics. Strictly necessary entries support authentication and sessions and cannot be disabled without breaking core functionality. Optional cookies, such as analytics, are set only with your consent where required by law. You can manage cookies in your browser settings.


Information transfer and storage

We use the following processors to operate the Service:

  • Appwrite (appwrite.io) provides authentication, sessions, account storage, and the delivery of transactional email such as sign-in codes and project invitations.
  • Cloudflare (cloudflare.com) provides hosting, content delivery, storage, and supporting infrastructure for the Service and for published sites, and operates the privacy-friendly analytics described in this Policy.
  • Polar (polar.sh) processes payments and manages billing for paid plans. Card details are provided directly to the payment processor and are not stored by us.

Each provider has its own privacy policy and processes data under contractual obligations consistent with this Policy. Data is encrypted in transit using TLS 1.2 or higher and at rest by our providers in accordance with their security practices.


International data transfers

Manifest operates globally, and your Personal Information may be processed in countries whose data protection laws differ from your own. Our providers operate infrastructure in jurisdictions including the United States, the European Union, and Asia-Pacific.

Where Personal Information of Users in the European Economic Area, the United Kingdom, or Switzerland is transferred outside those jurisdictions, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses, the United Kingdom International Data Transfer Addendum, and the EU–US, UK Extension, and Swiss–US Data Privacy Frameworks where applicable. You may request a copy of the transfer mechanism we rely on at team@manifestx.dev.


Data retention

We retain your Personal Information for as long as your account is active or as needed to provide the Service. Published site files are retained while their project exists so the site can be served and restored. Service telemetry is retained for a limited period for security and operations. When you delete your account or request erasure, we remove your Personal Information from active systems within thirty (30) days. Backup and archival copies are overwritten on a rolling basis and fully retired within ninety (90) days. We may retain limited information longer where required to comply with legal obligations, resolve disputes, or enforce our agreements, and billing records as required by accounting law.


The rights of users

Subject to the privacy law applicable to you, you have the right to (i) access the Personal Information we hold about you; (ii) request correction of inaccurate or incomplete information; (iii) request deletion or erasure of your Personal Information; (iv) restrict, or object to, certain processing; (v) withdraw consent where processing is based on consent; (vi) receive your Personal Information in a portable, commonly used, machine-readable format and, where technically feasible, have it transmitted to another controller; (vii) limit the use and disclosure of Sensitive Personal Information; (viii) opt out of the sale or sharing of Personal Information; (ix) not be discriminated against for exercising these rights; and (x) lodge a complaint with a competent supervisory authority.

To exercise any right you believe you hold, or to request account deletion, contact us at team@manifestx.dev. Requests are handled free of charge and within one month, except where applicable law permits longer. You may designate an authorized agent, subject to verification of your identity and the agent's authority.


Jurisdiction-specific notices

This Policy is intended to satisfy the substantive requirements of applicable privacy laws globally, including the General Data Protection Regulation, the UK GDPR, the California Consumer Privacy Act as amended by the California Privacy Rights Act, the Personal Information Protection and Electronic Documents Act, and equivalent state, provincial, and national legislation. Our lead supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon).

Categories of Personal Information collected. In the preceding twelve (12) months, we have collected only the categories of Personal Information described in this Policy: identifiers (such as your email address and the email addresses of people you invite), content you choose to publish, credentials you supply for integrations, commercial information (subscription status), and internet or other electronic network activity information (such as anonymized browsing data and service telemetry).

No sale or sharing. We do not sell or share Personal Information as those terms are defined under any applicable privacy law, and have not done so in the preceding twelve (12) months. We do not knowingly process the Personal Information of children, and we do not collect or process Sensitive Personal Information to infer characteristics about you.

Complaints. If your jurisdiction provides for it, you may lodge a complaint with your local data protection or supervisory authority. We encourage you to contact us first so we can address your concern directly.


Privacy of children

The Service is not directed to children under sixteen (16), and we do not knowingly collect Personal Information from them. If we become aware that we have collected such information without verifiable parental consent, we will delete it promptly. If you believe we may have collected information from a child under sixteen (16), contact us at team@manifestx.dev.


Information security

We maintain reasonable administrative, technical, and physical safeguards to protect Personal Information against unauthorized access, use, modification, and disclosure. No method of internet transmission or electronic storage is fully secure, and we cannot guarantee absolute security.


Data breach notification

In the event of a personal data breach affecting your Personal Information, we will notify affected Users and the relevant supervisory authorities where required by applicable law, without undue delay and in any event within seventy-two (72) hours of becoming aware of the breach where law requires.


The Service may contain links to websites we do not operate, including those of identity providers and our service providers, and sites published by Users. We have no control over, and assume no responsibility for, their content or privacy practices. We encourage you to review the privacy policy of every site you visit.


Changes and amendments

We may update this Policy from time to time. We will revise the date at the top of this page and communicate material changes through the Service or by email.


Acceptance of this Policy

By using the Service, you accept this Policy. If you do not agree, please do not use the Service. Continued use after changes to this Policy constitutes acceptance of those changes.


Contacting us

For any questions about this Policy or our privacy practices, contact us at team@manifestx.dev. See also our Terms of Service.