1. Scope

This Policy applies to the Manyfestly website, Community Manifestation Board, account and dashboard features, manifestation practice tools, paid features, and related services that link to this Policy (collectively, the “Service”). It does not govern third-party websites or services that have their own privacy policies.

2. Information we collect

Information you provide

Depending on how you use the Service, you may provide manifestation text, categories, account email address, an optional public username, reports about community content, gratitude or visualization content, coupon codes, and communications you send to us.

If you purchase a paid feature, our payment provider processes payment and billing information. Manyfestly is designed to receive transaction and entitlement information such as the product purchased, payment status, amount, payment-provider references, subscription references, and the account or manifestation associated with the purchase. Manyfestly is not designed to store your full payment-card number.

Information created when you use the Service

We may process account identifiers, authentication events, post ownership, support interactions, reaffirmation activity, 3·6·9 practice progress, streak information, feature entitlements, reports, moderation decisions, timestamps, and similar records needed to provide the Service.

Anonymous browser identifier

You do not need an account to publish a manifestation. When you use anonymous features, Manyfestly may create a random browser identifier and store it in local browser storage. The identifier is hashed before it is associated with server-side records. We use it for abuse prevention, rate limiting, duplicate controls, support/report integrity, and—in some cases—to associate posts made from that browser with an account after you sign in.

Technical information

Our hosting, authentication, security, and infrastructure providers may process information such as IP address, browser or device information, request timestamps, referring pages, diagnostic data, and security logs when your browser communicates with the Service. We use this information to deliver pages, protect the Service, diagnose failures, prevent abuse, and maintain reliability.

3. Public information

Manifestations submitted to the Community Manifestation Board are public by design. They may be viewed, copied, screenshotted, shared, or otherwise observed by other people. A post can be anonymous on the board while still being associated internally with an account or hashed browser identifier for ownership, safety, or abuse-prevention purposes.

Do not put passwords, financial-account information, government identifiers, private contact details, medical records, or other highly sensitive personal information in a public manifestation.

4. How we use information

We use information to provide and personalize core Service functions; authenticate accounts; publish and manage manifestations; maintain ownership and practice history; calculate reaffirmation progress and streaks; process paid features; send transactional authentication or service messages; prevent fraud and abuse; enforce Community Guidelines and Terms; investigate reports; protect users and the Service; troubleshoot and improve performance; comply with law; and establish, exercise, or defend legal rights.

5. Safety screening and automated processing

Public manifestation text is subject to automated safety checks. Manyfestly uses deterministic safety rules and may send text to an artificial-intelligence moderation provider, including OpenAI, to evaluate whether content may involve sexual content, harassment, hate, violence, self-harm, illicit activity, or other material that conflicts with Community Guidelines.

Automated screening may block a submission or route a final submission for administrative review. Human administrators may review reported or uncertain content. Safety systems can make mistakes, and a moderation decision does not constitute a legal, medical, or psychological judgment about you.

6. Service providers

We use third-party service providers to operate Manyfestly. Current core providers include Supabase for authentication, database, realtime and server functions; Vercel for application hosting and delivery; Resend for authentication and transactional email; Stripe for payment processing; and OpenAI for automated content-safety screening. These providers may process information on our behalf or, in some contexts, under their own terms and privacy notices.

We may add, replace, or remove providers as the Service evolves. We seek to provide providers only the information reasonably necessary for the function they perform.

7. Payments

Payment-card information is collected and processed by Stripe or another payment provider presented at checkout. Manyfestly may retain records of a purchase, payment status, amount, subscription or checkout reference, entitlement period, and related account identifier for customer service, accounting, fraud prevention, and fulfillment.

8. Email

Manyfestly uses passwordless email authentication. When you request a sign-in link, we provide the relevant email and authentication message to our authentication and email-delivery providers. We may also send necessary service, security, billing, or policy notices. Marketing email, if introduced, will be handled separately and will include legally required choices.

9. Cookies and local storage

The Service may use cookies, local storage, session storage, or similar technologies that are necessary to maintain authentication, anonymous browser identity, security state, user preferences, and core functionality. If we introduce non-essential analytics, advertising, or cross-site tracking technologies, we will update this Policy and provide any consent or opt-out controls required by applicable law.

10. Sale, sharing, and advertising

Manyfestly does not currently sell personal information for money. We also do not currently use personal information for cross-context behavioral advertising. We disclose information to service providers and other parties as described in this Policy, including where necessary to operate the Service, complete a transaction, protect the Service, or comply with law.

11. When information may be disclosed

We may disclose information to service providers acting for us; payment and transaction providers; professional advisers; authorities or other parties when reasonably necessary to comply with law or valid legal process; parties involved in investigating fraud, abuse, security threats, or violations; and a successor or potential successor in connection with a merger, financing, acquisition, reorganization, sale of assets, or similar business transaction, subject to appropriate safeguards.

12. Retention

We retain information for as long as reasonably necessary for the purposes described in this Policy, including maintaining an account, providing public posts and practice history, securing the Service, preventing abuse, honoring legal obligations, resolving disputes, and maintaining financial records. Retention periods vary by record type. Public posts may remain available until removed by the user where supported, removed through moderation, deleted with an account where applicable, or otherwise no longer needed. Financial and security records may be retained longer where reasonably necessary or legally required.

Content placed into a moderation review queue may be retained long enough to investigate the safety decision, improve enforcement consistency, document administrative action, and protect the Service. We aim not to retain rejected-content review records longer than reasonably necessary for those purposes.

13. Security

We use technical and organizational measures intended to protect information, including restricted server credentials, authenticated administrative actions, access controls, database security policies, hashed browser identifiers, rate limits, content moderation, provider security controls, and encrypted network transport where supported. No online system can guarantee absolute security.

14. Your choices and controls

You may choose to post anonymously, choose not to create an account, sign out, decide whether to use a public Premium username, and choose whether to purchase optional paid features. Where account controls support it, you may update profile information or request deletion. You may also request access, correction, deletion, or another privacy action by contacting privacy@manyfestly.com. We may need to verify your identity before acting on a request.

15. U.S. state privacy rights

Depending on where you live and whether a particular law applies to Manyfestly, you may have rights to know or access personal information, correct inaccurate information, delete information, obtain a portable copy, opt out of certain sales, sharing, profiling, or targeted advertising, limit certain uses of sensitive personal information, and receive non-discriminatory treatment for exercising privacy rights. Manyfestly does not currently sell personal information or use it for cross-context behavioral advertising.

California residents may have rights under the California Consumer Privacy Act, as amended, if its applicability thresholds and other requirements are met. You may submit a request using the privacy contact above. We will not discriminate against you for exercising a privacy right protected by applicable law.

16. European Economic Area, United Kingdom, and similar jurisdictions

Where data-protection laws such as the GDPR apply, our legal bases may include performance of a contract or steps requested before entering one; our legitimate interests in operating, securing, improving, and moderating the Service; compliance with legal obligations; and consent where consent is legally required. Depending on applicable law, you may have rights of access, rectification, erasure, restriction, objection, portability, withdrawal of consent, and complaint to a supervisory authority.

Manyfestly and its providers may process information in the United States and other countries. Where required, providers may rely on contractual clauses, adequacy decisions, recognized data-transfer frameworks, or other lawful transfer mechanisms.

17. Children

Manyfestly is intended for adults age 18 and older and is not directed to children. If we learn that personal information was collected from a person under 18 in violation of this Policy, we may remove the information and close the associated account.

18. Sensitive information

Manifestation content can sometimes reveal information about health, relationships, finances, religion, or other personal matters. Do not post information publicly that you would not want other people to see. We do not require you to provide sensitive personal information to use the public board.

19. Third-party links

The Service may link to third-party sites, payment pages, or resources. Their privacy practices are governed by their own policies, not this Policy.

20. Changes to this Policy

We may update this Policy as Manyfestly changes. We will update the effective date when we make changes and may provide additional notice when a change is material or when required by law. Continued use after an update is subject to the revised Policy to the extent permitted by law.

21. Contact

Privacy questions and requests may be sent to privacy@manyfestly.com.