Privacy Policy
Effective date: 2026-01-01 · Last updated: 2026-01-01
This Privacy Policy explains what personal information we collect when you use Manifold (the "Service"), how we use it, who we share it with, and the rights you have. It applies to the hosted Service at manifold.app and any related applications operated by us. If you self-host Manifold under its open-source license, you are the data controller for that deployment and this policy does not apply to it.
1. Who we are
Manifold is operated by the team at hello@manifold.app. For privacy-specific questions, write to privacy@manifold.app. References to "we," "us," and "our" mean Manifold; references to "you" mean a registered user, a teammate added by a user, or a visitor to manifold.app.
2. Information we collect
2.1 Account information
When you create an account we collect your name, email address, and a hashed password. If a workspace administrator invites you to a brand, your role and site assignments are stored alongside your account.
2.2 Workspace content
Posts, drafts, per-platform variants, scheduled times, media files you upload, and analytics that we fetch back from connected platforms. You own this content; we process it on your behalf so we can publish, schedule, and store it.
2.3 Connected-platform credentials
OAuth access tokens, refresh tokens, and configuration values for LinkedIn, X, Instagram, Facebook, Reddit, Pinterest, WordPress, YouTube, Imgur, and OpenAI when you connect them. These are stored in our database in encrypted form and used only to publish content on your instruction.
2.4 Usage and device information
Server logs (IP address, user agent, requested URL, response code, timestamp) are kept for 30 days for security and debugging. We use Sentry for application error reporting; stack traces may include the file and line number where an error occurred but personal data is stripped before transmission.
2.5 Marketing-site submissions
If you fill out the contact form, we receive your name, email, subject, message, IP address, and user agent. This is stored in our database until we respond and is not used for marketing.
2.6 Cookies
We use one session cookie (HttpOnly, Secure, SameSite=Lax) to keep you signed in. No third-party analytics, advertising, or social cookies are set by the Service.
3. How we use information
- To provide the Service — authenticate you, render the panel, schedule and publish your posts to the platforms you've connected.
- To operate and secure the Service — rate-limit abuse, investigate incidents, comply with legal obligations.
- To communicate with you — service notifications, account or billing emails, and replies to support requests. We do not send marketing email unless you explicitly opt in.
- To improve the Service — aggregated, de-identified usage patterns help us decide what to build.
4. Legal basis for processing (EU/UK)
We rely on (a) performance of a contract — we need to process your data to provide the Service you signed up for; (b) legitimate interests — to operate, secure, and improve the Service; and (c) consent — for any optional processing that requires it, such as marketing emails. Where legitimate interests is the basis, you can object using the contacts below.
5. How we share information
We do not sell personal information. We share data in these limited cases:
5.1 Subprocessors
We use vendors to run the Service. The current list:
- Fly.io — application hosting (United States).
- Neon — managed Postgres (United States).
- Cloudflare R2 — object storage for media (global edge).
- Sentry — application error monitoring (United States, PII-scrubbed events).
- Google Fonts— Inter typeface served via Google's CDN. Loading a page makes a request to Google; we do not pass account data.
5.2 Connected platforms
When you instruct Manifold to publish a post, we transmit that post (and any media you attached) to the platform you selected — LinkedIn, X, Instagram, etc. — using the credentials you provided. Their privacy policies govern what they do with it after that.
5.3 Legal disclosures
We may disclose data if required by law, court order, or to enforce our Terms or protect the Service and its users. We will challenge overbroad or improper requests where lawful.
6. Retention
Account, workspace content, and connected-platform credentials are kept while your account is active and for up to 90 days after deletion to allow recovery. Server access logs are kept 30 days. Sentry error events are kept 30 days. Contact-form submissions are kept up to 24 months. You can request earlier deletion via the contacts below.
7. International transfers
Our infrastructure is hosted in the United States and at Cloudflare's global edge. If you're in the EU, UK, or another region with cross-border transfer requirements, we rely on Standard Contractual Clauses with our subprocessors where applicable.
8. Your rights
Depending on your jurisdiction, you may have the right to access, correct, export, delete, or restrict the processing of your personal data, and to object to certain processing or withdraw consent. EU/UK residents have these rights under GDPR; California residents have analogous rights under the CCPA/CPRA, including the right to know what we collect and the right to opt out of "sale" (we do not sell). To exercise any right, email privacy@manifold.app. We will respond within 30 days.
9. Security
Connections are HTTPS-only with HSTS. Passwords are bcrypt-hashed. OAuth tokens and other sensitive credentials are encrypted at rest. Session cookies are HttpOnly, Secure, and SameSite-restricted. Application errors are scrubbed of PII before transmission to Sentry. See /security for the full breakdown.
10. Children
The Service is not directed at children under 16. We do not knowingly collect personal data from anyone under 16. If you believe we have, write to privacy@manifold.app and we will delete it.
11. Changes to this policy
We may revise this policy as the Service or applicable law changes. Material changes will be announced in-product and emailed to account holders at least 14 days before they take effect. The "Last updated" date at the top always reflects the current version.
12. Contact
Privacy questions, data-subject requests, and complaints: privacy@manifold.app. General support: hello@manifold.app.
Note for operators: This policy is written to industry-standard SaaS conventions but is not a substitute for legal advice. Before public launch, have qualified counsel in your jurisdiction(s) review it against your actual data flows, subprocessor list, and regulatory exposure (GDPR, CCPA, sector-specific rules).