Manifast AI – Privacy Policy
Effective Date: January 1, 2026
This Privacy Policy describes how Manifast AI LLC ("Manifast," "we," "us," or "our") collects, uses, discloses, and protects information when you use the Manifast AI platform (the "Service"), visit our website, or interact with us. This Policy applies to Authorized Users of our business customers and to visitors of our marketing site.
By using the Service, you acknowledge the practices described here. If you do not agree, do not use the Service.
Context: Manifast is a business-to-business SaaS platform. Our direct customers are organizations (e.g., apparel brands) that purchase subscriptions for their personnel. Those organizations ("Customers") act as the controller of the data their users submit; Manifast processes that data on the Customer's instructions and for the purposes described below.
1. Information We Collect
1.1 Information You Provide
- Account Information: name, email address, job title, company, phone number, profile photo (if provided).
- Authentication Information: passwords (hashed), SSO tokens, multi-factor authentication settings.
- Billing Information: billing contact, billing address, and payment method details handled by our payment processor (we do not store full payment card numbers).
- Customer Content: text prompts, reference images, brand assets, sketches, technical specifications, color palettes, material references, product metadata, and any other materials you upload or input into the Service.
- Communications: messages you send to support, feedback, and survey responses.
1.2 Information Collected Automatically
- Usage and Activity Data: prompts submitted, workflows selected (e.g., Product Generator, Restyler Pro, Vector Lab), generation counts, session duration, click paths, feature interactions, timestamps, and error events.
- Generated Output: images, vectors, patterns, and other artifacts produced by the Service in response to your inputs.
- Device and Technical Data: IP address, browser type and version, operating system, device identifiers, language preferences, referring URLs.
- Log Data: server logs, API call logs, and diagnostic information stored in our database infrastructure (Supabase).
- Cookies and Similar Technologies: see Section 9.
1.3 Information from Third Parties
- SSO and Identity Providers: if you sign in via Google, Microsoft, or another SSO, we receive basic profile information.
- Payment Processors: transaction status and tokenized payment identifiers.
- Customer Administrators: information provided when your organization provisions your seat.
2. How We Use Information
We use the information we collect for the following purposes:
2.1 Service Delivery
- Creating and managing Accounts and seats
- Processing prompts, generating outputs, and routing requests to third-party AI providers
- Storing Customer Content and Generated Output
- Providing customer support
- Processing payments and managing subscriptions
2.2 Platform Operation and Security
- Monitoring uptime, performance, and error rates
- Detecting, preventing, and responding to fraud, abuse, and security incidents
- Enforcing our Terms of Service and acceptable use policies
- Complying with legal obligations
2.3 Administrator Access for Support and Operations
Manifast personnel with administrator privileges may view and access Customer Content, Generated Output, prompts, session activity, and usage data for the following purposes:
- Responding to support requests and troubleshooting issues
- Diagnosing errors and workflow failures
- Investigating suspected misuse or Terms violations
- Quality assurance and output review
- Internal reporting and operational dashboards
Administrator access is logged and limited to personnel with a legitimate need. We do not read Customer Content for purposes unrelated to the operation, improvement, and security of the Service.
2.4 Service Improvement and Analytics
- Analyzing aggregated usage patterns to improve features, prompts, workflows, and models
- Identifying UX friction, feature adoption, and common use cases
- Building internal evaluation datasets and test suites using aggregated or de-identified Customer Content and Generated Output
- Refining internal prompt templates, workflow logic, and model-routing heuristics
- Generating internal business intelligence, usage reports, and performance metrics
We use aggregated or de-identified data for these purposes where reasonably practicable.
2.5 Communications
- Sending transactional messages (account notices, billing, security alerts, service updates)
- Responding to inquiries
- Sending product updates, newsletters, and marketing communications (you may opt out of marketing communications at any time; transactional messages will continue)
2.6 Marketing and Promotional Use
We may use certain information to promote the Service as follows:
- Without additional consent: aggregated and de-identified statistics, anonymized case studies where the customer and individuals cannot reasonably be identified, and Customer names and logos in customer lists on our website and investor materials (Customers may opt out by written request).
- With prior written consent: identifiable Customer Content, Generated Output, Customer names, user names, and images in case studies, social media posts, public galleries, press releases, sales collateral, conference presentations, and similar materials.
2.7 Legal and Compliance
- Complying with applicable laws, regulations, subpoenas, and lawful requests
- Establishing, exercising, or defending legal claims
- Enforcing our agreements and protecting our rights and those of our users
3. How We Share Information
We share information only as described below. We do not sell personal information for money.
3.1 Service Providers and Subprocessors
We share information with third-party vendors who help us operate the Service, including:
| Provider | Purpose | Data Shared |
|---|---|---|
| Google (Gemini API) | AI image generation | Prompts, reference images, workflow parameters |
| Google (Veo API) | AI video generation | Prompts, reference media |
| Anthropic (Claude API) | Text generation, reasoning | Prompts, text inputs |
| OpenRouter | AI model routing | Prompts, model-routing metadata |
| Fal.ai | AI model inference | Prompts, reference images |
| Supabase | Database, auth, storage | Account data, Customer Content, logs |
| n8n | Workflow orchestration | Prompts, workflow parameters |
| Stripe | Billing and payments | Billing contact, tokenized payment info |
These providers are contractually required to safeguard information and process it only for the purposes we specify.
Note on AI provider training: We configure third-party AI providers, where contractually available, to not use Customer Content or Generated Output to train their foundation models.
3.2 Customer and Authorized User Access
Information submitted within a Customer's workspace is accessible to that Customer's Administrators and to other Authorized Users as permitted by the Customer's configuration.
3.3 Business Transfers
In connection with a merger, acquisition, financing, reorganization, or sale of assets, information may be transferred to the successor entity, subject to confidentiality protections.
3.4 Legal Requirements
We may disclose information if required by law, regulation, legal process, or governmental request.
3.5 With Consent
We share information for any other purpose disclosed to you with your consent.
4. Data Retention
We retain information for as long as necessary to provide the Service and for legitimate business purposes, including:
- Customer Content and Generated Output: retained during the subscription term and for up to ninety (90) days after termination, unless Customer requests earlier deletion or we are required to retain it by law.
- Logs and Telemetry: typically retained for twelve (12) to twenty-four (24) months.
- Account and Billing Records: retained as required by applicable tax, accounting, and legal requirements.
- Aggregated or De-Identified Data: may be retained indefinitely.
5. Security
We implement reasonable administrative, technical, and physical safeguards designed to protect information, including encryption in transit, access controls, authentication requirements, logging, and vendor security reviews. No system is perfectly secure; we cannot guarantee absolute security.
6. Your Rights and Choices
6.1 U.S. State Privacy Rights
If you are a resident of a U.S. state with applicable privacy laws, you may have the right to:
- Know / Access: request confirmation of whether we process your personal information and receive a copy.
- Correct: request correction of inaccurate information.
- Delete: request deletion of personal information, subject to legal exceptions.
- Portability: receive your information in a portable format.
- Opt Out of Sale or Sharing: Manifast does not sell personal information for money or share it for cross-context behavioral advertising.
- Non-Discrimination: we will not discriminate against you for exercising your rights.
To exercise these rights, contact us at privacy@manifast.ai.
6.2 GDPR / UK GDPR
If EU/UK data protection law applies, you have the rights of access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with a supervisory authority.
6.3 Marketing Opt-Out
You may opt out of marketing emails by following the unsubscribe link in any message or contacting us.
7. International Data Transfers
Manifast is based in the United States. If you access the Service from outside the U.S., your information will be transferred to and processed in the U.S. and other countries that may have different data protection laws.
8. Children's Privacy
The Service is intended for business use by adults. We do not knowingly collect personal information from children under sixteen (16).
9. Cookies and Tracking Technologies
We use cookies and similar technologies to operate the Service, maintain sessions, remember preferences, and understand usage:
- Strictly Necessary: required for authentication and basic functionality.
- Functional: remember preferences.
- Analytics: help us understand feature usage.
- Marketing: on our marketing website only, where applicable.
10. Changes to This Policy
We may update this Policy from time to time. When we make material changes, we will provide notice by posting the updated Policy and, where appropriate, by email or in-product notice.
11. Contact Us
Manifast AI LLC
Brooklyn, NY
Email: privacy@manifast.ai
Legal: legal@manifast.ai
Appendix A – Quick Reference: Administrator and Marketing Data Rights
| Right | Scope | Consent Required? |
|---|---|---|
| View Customer Content, prompts, outputs, session activity | Support, debugging, abuse detection, quality review | No |
| Use aggregated/de-identified data for improvement | Internal analytics | No |
| Use Customer name & logo in customer lists | Marketing | No (opt-out available) |
| Use identifiable Customer Content in case studies, social media | External marketing | Yes – prior written consent |
| Share Customer Content with third-party AI providers for training | N/A | Not permitted |