Privacy policy

Last updated October 8, 2026

themanifold is run by Terry Hughes, referred to here as the operator. This policy covers themanifold.app and the apps at addresses ending in .themanifold.app. It says what themanifold collects, why, who it is shared with, how long it is kept, and what you can do about it. Questions and requests go to privacy@themanifold.app.

What themanifold collects

  • Your account: your email address, name and profile photo; your password, stored only as a secure hash; and your two-factor settings.
  • What you add: contacts, labels, notes, workspaces, the people you invite and share with, and your preferences. Each record keeps a history of its changes.
  • Google data you choose to connect: described below.
  • Sign-in records: for each device you sign in on, its browser, operating system, IP address and last activity, so you can see them under Account, Devices and sign them out.
  • Error reports and speed measurements: when something breaks, a report of the error with personal data removed and IP addresses not stored; and page speed measurements, collected without cookies.

Google user data

Signing in with Google gives themanifold your Google account's name, email address and profile photo, used only to sign you in and fill in your profile. No Google token is kept for sign-in.

Connecting Google Contacts asks Google for permission to see, edit and delete your contacts. With it, themanifold:

  • reads your Google contacts and keeps a copy, so you can see, search and label them beside your other contacts;
  • saves to Google the changes you make to those contacts in themanifold, including deletes you confirm, and nothing else;
  • checks Google every few minutes for changes, so the copy stays current.

Google's "Other contacts" (addresses Google saves automatically) are not read. The permission Google gives themanifold is stored encrypted and is used only by the service that keeps your contacts in step with Google.

Your Google data is used only to provide these features to you. It is not sold, not used for advertising, not used to train AI models, and not shared except as described under "Who your data is shared with". People do not read it, unless you ask for help with a specific problem and agree, it is needed for security or to investigate abuse, or the law requires it.

themanifold's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Disconnecting: in Account, Connections, or at your Google Account's permissions page. The permission is withdrawn at once and your Google contacts disappear from themanifold. Their copies, with any labels you added, are kept for 30 days so that reconnecting the same account restores them, and are then permanently deleted. To have them deleted sooner, write to privacy@themanifold.app.

How your data is used

  • To provide themanifold: to show, search and save your data.
  • To keep your account safe: for example, to alert you to a sign-in on a new device.
  • To send you email you need or have chosen: sign-in codes, invitations, security alerts and the notifications you turn on.
  • To find and fix errors.

Your data is never sold, never used for advertising, and never used to build a profile of you.

Who your data is shared with

  • People you choose: members of your team workspaces see that workspace's records, and people you share a record with see that record, at the level you give them. Your connected Google account itself is never shared.
  • Service providers that run parts of themanifold, each only for that purpose and under its own data protection terms: Supabase (database, sign-in and file storage), Vercel (hosting the website), Railway (background services), Resend (sending email), Sentry (error reports) and Better Stack (checking that the site is up; it sees no personal data).
  • AI assistants you connect: if you connect your own assistant, such as Claude, it can read and change what you ask it to, as you. What it receives is then handled under your agreement with its provider.
  • When the law requires it, or to protect the safety of people or of themanifold.

Cookies

themanifold uses only the cookies it needs: to keep you signed in, and to remember your theme, time zone and layout on each device. There are no advertising or tracking cookies.

How long data is kept

  • Your account and data: until you delete them.
  • Deleted records: in Trash for 30 days, where you can restore them, then permanently deleted.
  • Deleting your account: it is hidden at once and can be restored for 30 days; then the account and your personal workspace are permanently deleted. Records you added to a team workspace stay with that team.
  • Disconnected Google data: 30 days, as described above.
  • Backups, error reports and email delivery records are kept for a limited time by the providers above and then deleted.

Your choices and rights

  • See and correct your data in themanifold at any time.
  • Export your contacts as vCard or CSV.
  • Disconnect Google at any time.
  • Delete your account in Account, Delete account.

You can also ask for a copy of your data, or for anything to be corrected or deleted, by writing to privacy@themanifold.app. Requests are answered within 30 days.

Security

Data is encrypted in transit and at rest. Who can see each record is enforced by the database itself, not only by the app. Google permissions are stored encrypted and only the syncing service can use them. You can protect your account with two-factor authentication.

Where data is stored

Your data is stored and processed in the United States.

Children

themanifold is not for children under 13, and does not knowingly collect their personal information. If you believe a child under 13 has an account, write to privacy@themanifold.app and it will be deleted.

Changes to this policy

The date at the top changes whenever this policy does. If a change affects how your data is used, you will be told by email or in themanifold before it takes effect.

Contact

Terry Hughes, the operator of themanifold: privacy@themanifold.app.

Back to themanifold