Manifest — Privacy Policy
Last updated: September 25, 2026
Manifest is a personal lists app — weekly to-dos, groceries, trips, recipes, and notes. This policy explains, in plain language, what data Manifest collects, how it's used, and the choices you have.
Who runs Manifest
Manifest is an independent app operated by Jaylon Rodriguez. Questions about this policy or your data: [email protected].
What we collect
- Your email address — used to sign you in. Manifest uses a one-time emailed code or sign-in link; there is no password. We also use it to send you app-related messages you request.
- The content you create — your lists, items, notes, recipes, grocery items, trips, and any photos you attach. This is the data the app exists to store for you.
- A notification token — only if you turn on reminders, so we can deliver the notifications you've enabled. You can turn this off at any time.
- Basic technical data — standard server logs (such as IP address, timestamps, and error diagnostics) generated by our hosting infrastructure to keep the service running and secure.
We do not run advertising, we do not track you across other apps or websites, and we do not sell your data.
How we use your data
Only to run the app for you: to store and sync your content, sign you in, deliver reminders you enable, and diagnose errors or prevent abuse. That's it.
Who can access it
Your content is private to your account. Other users cannot see it — the database enforces per-account isolation at the row level.
Manifest relies on a few standard infrastructure providers to operate, which process data only to provide their service to Manifest:
- Supabase — database, file storage, and authentication.
- Vercel — application hosting.
- Apple (APNs) — delivering push notifications, if you enable them.
- An email delivery provider — sending your sign-in codes and links.
We don't share your data with anyone for their own purposes.
Photos
Photos you attach are stored in a private storage bucket accessible only to your account.
The browser extension (optional)
The Manifest extension for Chrome and Brave shows Manifest in the browser's side panel. To offer Clip page, it reads the address and title of the tab you're looking at (the browser describes this permission as "Read your browsing history"). It uses them in two ways only: it shows the site's name next to the Clip button, and when you clip a page, it passes that one address and title to Manifest in the panel, where you choose a list and save it as a row in your account. Nothing else leaves your browser. The extension never reads what is on a page, keeps no history of the pages you visit, and has no access to any website's data. Everything you clip is ordinary Manifest content, covered by the rest of this policy.
Exporting to your own device (optional)
Manifest has an optional archiver that a user can run on their own computer to save copies of their completed lists and notes as files in their own Obsidian vault. That export runs on your device, under your control, scoped to your own account — it does not share your data with anyone else.
Keeping and deleting data
- Deleted items go to a Recently Deleted area for 30 days, then are permanently removed.
- You can delete your content anytime in the app. To delete your entire account and all associated data, email [email protected] and we'll remove it.
Your choices
You can access, edit, export (via the archiver), and delete your data. Contact us if you'd like a copy of your data or have any request.
Children
Manifest is not directed at children under 13, and we do not knowingly collect data from them.
Changes
If this policy changes, we'll update the date above and post the new version here.