1. Information we collect
Manifest collects the account name, email address, password hash, session records, plan and billing status, and support communications you provide. We do not store your plaintext password.
2. App Store Connect data
When you connect Apple, Manifest stores your key ID, issuer ID, and encrypted private key, plus the applications and analytics reports your credentials can access. Private keys are encrypted with AES-256-GCM and decrypted only when Manifest communicates with Apple.
3. Billing and technical data
Stripe processes payments and supplies customer, subscription, and payment-status identifiers. Manifest does not store full payment-card numbers. We may also process IP addresses, request metadata, error logs, and security events needed to authenticate users, prevent abuse, and operate the service.
4. How we use information
We use information to authenticate accounts, collect and preserve authorized analytics, calculate trends, enforce plans, process billing, send service and recovery messages, provide support, secure Manifest, and comply with law.
5. Service providers
We disclose information only as needed to operate Manifest, including to Apple for App Store Connect requests, Stripe for billing, Render for hosting and database infrastructure, and Resend for transactional email. These providers process information under their own terms and privacy practices. We may also disclose information when required by law or to protect rights and security.
6. Retention
Manifest is designed to keep collected analytics beyond Apple’s short API window. Plan limits can restrict what history is visible without immediately deleting the underlying record. You may delete your hosted account from Account settings after confirming your password; active Stripe billing is canceled first and the tenant’s stored data is removed. You must separately revoke the App Store Connect key in Apple. We may retain narrowly scoped records where needed to resolve disputes, meet legal obligations, or maintain security.
7. Security
We use tenant-scoped database queries, hashed passwords and sessions, encrypted App Store Connect private keys, signed Stripe webhooks, and access controls intended to protect information. No system is completely secure, so keep your account and Apple credentials protected and contact us about suspected compromise.
8. Your choices
You can update App Store Connect credentials and billing details through Manifest and Stripe. Depending on applicable law, you may request access, correction, export, or deletion of personal information by contacting us. We may need to verify the request.
9. Children
Manifest is a business analytics service and is not directed to children under thirteen. We do not knowingly collect personal information from children.
10. Changes
We may update this policy as the service or legal requirements change. The effective date above identifies the latest version.
11. Contact
Privacy questions and requests can be sent to randyventures06@gmail.com.