Privacy Policy
Last updated: February 2025
1. Introduction
Manifold Studio ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you use our desktop application and related services.
2. Information We Collect
2.1 Account Information
When you create an account, we collect:
- Email address
- Password (stored securely hashed)
- Payment information (processed by Stripe, not stored by us)
2.2 License Information
For license validation, we collect:
- Hardware ID (anonymized device identifier)
- License key
- Activation timestamps
2.3 Local Data
The following data is stored locally on your device and is NOT transmitted to our servers:
- Workflows you create
- Projects and file references
- Platform configurations and credentials
- Browser session data and cookies
- Application settings
2.4 Community Workshop
When you use the Community Workshop, we collect:
- Workflows you choose to share publicly
- Ratings and reports you submit
- Download history
3. How We Use Your Information
We use the information we collect to:
- Provide and maintain the Software
- Process payments and manage subscriptions
- Validate licenses and prevent unauthorized use
- Send important notifications about your account
- Improve and develop new features
- Respond to support requests
- Enforce our Terms of Service
4. Data Storage and Security
We implement appropriate security measures to protect your data:
- Passwords are hashed using bcrypt
- All API communications use HTTPS encryption
- Database access is restricted with Row Level Security (RLS)
- Payment processing is handled by Stripe (PCI compliant)
Sensitive data like platform credentials is stored locally on your device using encrypted storage and is never transmitted to our servers.
5. Third-Party Services
We use the following third-party services:
- Stripe: Payment processing (Stripe Privacy Policy)
- Supabase: Database hosting (Supabase Privacy Policy)
- Resend: Email delivery (Resend Privacy Policy)
- Cloudflare: CDN and hosting (Cloudflare Privacy Policy)
6. Data Retention
We retain your account data for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except where retention is required by law or for legitimate business purposes (e.g., fraud prevention).
7. Your Rights
You have the right to:
- Access: Request a copy of your personal data
- Correction: Update inaccurate information
- Deletion: Request deletion of your account and data
- Portability: Export your data in a machine-readable format
- Objection: Opt-out of certain data processing
To exercise these rights, contact us at [email protected].
8. Cookies
Our website uses essential cookies for authentication and functionality. We do not use tracking cookies or third-party advertising cookies. The desktop application does not use cookies for tracking purposes.
9. Children's Privacy
Manifold Studio is not intended for use by children under 13 years of age. We do not knowingly collect personal information from children under 13. If we discover such information has been collected, we will delete it immediately.
10. International Data Transfers
Your data may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place for such transfers in compliance with applicable data protection laws.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by email or through the application. Continued use of the Software after changes constitutes acceptance of the updated policy.
12. Contact Us
If you have any questions about this Privacy Policy, please contact us at:
- Email: [email protected]
GDPR Compliance (EU Users)
If you are located in the European Economic Area (EEA), you have additional rights under the General Data Protection Regulation (GDPR):
- Right to be informed about data collection
- Right of access to your personal data
- Right to rectification of inaccurate data
- Right to erasure ("right to be forgotten")
- Right to restrict processing
- Right to data portability
- Right to object to processing
- Right to lodge a complaint with a supervisory authority
Our legal basis for processing your data includes: contract performance, legitimate interests, and consent where applicable.