Last updated August 2, 2026

Privacy policy

This policy explains how Manifest AI handles data in the current public pilot.

Data we process

We process account details, workspace settings, saved vendor field mappings, export templates, SKU mappings, usage records, and documents submitted for extraction. Contact-form details are processed when you send an enquiry.

How documents are handled

Source PDFs are encrypted in private temporary storage while a background job runs and are deleted when the job completes, fails, or is cancelled. Generated Excel workbooks are returned to the browser and are not intentionally stored by Manifest AI.

Result retention and deletion

Extracted results and page-level evidence are stored for 90 days by default so an authenticated user can review or re-export them. A user can delete a stored result earlier from the workspace. At expiry or early deletion, extracted content, page output, document name, vendor name, invoice reference, and document fingerprints are scrubbed. Minimal usage, billing, and security audit records may remain for legitimate accounting, fraud-prevention, and legal obligations.

Why we process data

We use submitted data to authenticate users, run extraction and review workflows, create requested exports, enforce page limits, detect possible duplicate processing, support customers, protect the service, and maintain service usage records.

Service providers and locations

Manifest AI uses contracted infrastructure, identity, communications, database, and advanced document-intelligence service providers to operate the product. These providers process data only for service delivery under the operator's configured accounts and applicable data controls. Current hosting region, subprocessor information, and any required residency commitment should be confirmed before production use.

Training and product improvement

Manifest AI does not use customer documents to train its own advanced AI models. Submitted content is processed only to provide requested document services, maintain security, and meet agreed support or legal obligations.

Security

Access is tenant-scoped. Service-to-service calls are token protected, source files use AES-256-GCM encryption in temporary storage, uploads are validated and limited, and formula-like spreadsheet values are neutralized. No online service can guarantee absolute security.

Your choices

Do not upload a document unless you are authorized to process it. You may delete individual stored results in the workspace or contact us to request account access, correction, export, or deletion. Customers that require a data-processing agreement, specific residency, or a custom retention period should agree those requirements before a paid pilot.

Privacy and security contact

info@manifestai.io