Privacy Policy
Last updated: 7 September 2026
This is a draft, not legal advice. It’s written to reflect exactly what this app does, who it’s operated by, and which third parties it uses, but a qualified lawyer should still review it before it governs real users’ data or a real subscription.
1. What this covers
This Privacy Policy explains what personal data Meyer Utvikling Frilans Tjenester (org. no. 931 370 898, Norway) (“Manifesto-it”, “we”, “us”) collects through the Manifesto-it website and app (the “Service”), why we collect it, who we share it with, and the choices you have. If a term isn’t defined here, it has the meaning given in our Terms of Service.
2. What we collect
- Account data: your name and email address, and your subscription/billing status.
- Content you create: your goal, life area, dream description, timeframe, journal entries, vision board images/text, and 30-day-challenge progress.
- Photos you choose to upload: for the optional Future Self feature — a “today” photo and the stylised image we generate from it. Uploading a photo is entirely optional.
- Usage data: streaks, completed actions, achievements, and basic app interaction data needed to run the product.
- Device data: if you enable notifications, a push subscription token tied to your browser/device.
- Payment status: whether you’re subscribed and to which plan — full card details are handled entirely by Stripe and never reach our servers.
3. Why we collect it
- To provide the Service — save your goal, generate your daily sessions, run your vision board and challenge, track streaks.
- To personalise content — your goal and journal text may be used (see Section 4) to generate your future vision, daily manifestation, challenge, and timeline.
- To process payments and manage your subscription.
- To send you the notifications you explicitly opt into.
- To maintain security, prevent abuse, and comply with legal obligations.
We do not sell your personal data, and we do not use your content to train third-party AI models.
4. Who we share it with
We use a small number of third-party processors, each only for the specific purpose below:
- Supabase — hosts our database, authentication, and file storage (your account data, content, and uploaded photos).
- Anthropic (Claude API) — if you’re on a Premium plan and AI generation is enabled, the relevant goal/journal text is sent to Anthropic solely to generate that piece of content for you. Free-plan content, and Premium content when AI isn’t configured, is generated entirely on our own servers using a template engine — nothing is sent anywhere.
- Stripe — processes subscription payments. We receive your subscription status, never your full card number.
- Web push services (e.g. Apple, Google, or Mozilla’s push relay, depending on your browser) — deliver notifications you’ve opted into.
We don’t share your data with anyone else, except where required by law, to protect our legal rights, or with your explicit consent.
5. International transfers
Some of the processors above are based in, or process data in, the United States. Where we transfer personal data internationally, we rely on appropriate safeguards (such as Standard Contractual Clauses) as required under UK/EU data protection law.
6. Cookies and local storage
We use essential cookies for authentication (set by Supabase) and browser local storage for non-sensitive convenience data — e.g. remembering an in-progress onboarding draft on your own device, or whether you’ve dismissed the install prompt. We don’t use advertising or third-party tracking cookies.
7. Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you;
- Correct inaccurate data;
- Request deletion of your account and associated data;
- Export your data in a portable format;
- Object to or restrict certain processing.
To exercise any of these, contact us via our contact page or hello@manifesto-it.com. We’ll respond within the timeframe required by applicable law.
8. Data retention
We keep your data for as long as your account is active. If you delete your account, we delete your personal data and content within 30 days, except where we’re required to retain limited records (e.g. billing history) for legal or accounting purposes.
9. Security
We use industry-standard measures to protect your data, including encryption in transit and Row Level Security at the database level, so your content is only ever accessible to your own account. No method of storage or transmission is 100% secure, and we can’t guarantee absolute security.
10. Children
The Service is not directed at children under 18, and we don’t knowingly collect data from them.
11. Changes to this policy
If we make material changes to this Policy, we’ll notify you in the app or by email before they take effect.
12. Contact
For any privacy question or request, reach us via our contact page or at hello@manifesto-it.com.