SecurityHow we protect your data
Your journey, kept yours.
A short summary of how Manifestory stores, protects and deletes your data. The Privacy Policy is the full description; if this page and the policy ever differ, the policy governs.
Last updated October 5, 2026
Where your data lives
Manifestory is operated from the United States by VedaStack LLC and is available on the App Store in the United States and Canada. Your account and journey data are stored by our database provider, Supabase, in its US East (Northern Virginia) region. If you use Manifestory from Canada, your data is stored and processed in the United States.
A few providers that receive limited data from us may process it in other countries under their own safeguards. Section 9 of the Privacy Policy explains.
Encryption
- In transit
- The app, this website and the assistant API at
https://api.manifestory.appuse TLS (HTTPS). The API refuses plain HTTP, so a token is never accepted unencrypted. - At rest
- Supabase encrypts all stored customer data with AES-256 (Supabase security).
- Passwords
- Stored only as a password hash, never in plain text.
Access to your data
Row-level security is switched on for every table that holds app data, so users can only access their own data. The rules are enforced by the database itself, not just by the app.
Signing in
You can sign in with Apple, Google or email. With Apple or Google, your password and any two-step verification stay with Apple or Google; we never see that password. When you create an email account, the app requires a password of at least 8 characters with upper- and lower-case letters and a number.
AI providers
We never use your data to train AI models. Our AI providers receive your data solely to generate content for you in the app.
Anthropic, whose Claude models write your statement, daily actions, card reflection and coaching insights, does not use data sent through its API to train its models, and deletes API inputs and outputs within 30 days, except content flagged for a usage-policy review, which it may keep longer. We don’t send Anthropic your email address or account ID.
Section 4.1 of the Privacy Policy lists every service provider and exactly what it receives.
AI assistant connections
Connecting an assistant such as Meta Muse or Claude is optional and off until you create a connection in Settings › AI assistants. Read how connecting works.
- Access level
- You choose Read only or Read & check in. An assistant can never read your journal notes or your answers to coaching questions.
- Tokens
- Each connection uses a personal access token, shown once when you create it. We store only a one-way (SHA-256) hash of it, never the token itself.
- Scope
- Requests run as you, with row-level security enforced, so a connection reaches your own journey and nothing else.
- Limits
- 30 operations per minute per connection, and up to 5 active connections per account.
- Expiry
- A connection stops working after 60 days without use. You can revoke one at any time in Settings › AI assistants, and access stops right away.
- Logs
- Request logs record a short internal connection ID, never the token.
- Retention
- When you revoke a connection, or it stops working after 60 days without use, we delete its record 12 months later, or sooner if you delete your account.
Data an assistant has already received is kept by that assistant’s provider under its own privacy policy. Section 15 of the Privacy Policy covers connected assistants in full.
Deleting your data
- Delete Account in Settings deletes your account and personal data, including your manifestations, daily logs, reflections, evidence and AI assistant connections. It’s a two-step confirmation that takes effect immediately, and your data is removed from our active databases within 30 days. You can also ask us to delete it.
- When a journey ends, its detailed data is permanently deleted after an automatic cleanup period. Before that, we extract fully anonymized benchmark data that can’t be linked back to you.
- For each deletion we keep an audit record of your user ID, the type of deletion and a count of records deleted, without any of your content.
Monitoring and incidents
An automated check tests the AI assistant connection end to end, through to the database, every hour, and alerts us by email if it fails.
If we become aware of a security breach that affects your personal data, we will notify affected users within 72 hours of discovering it, by email to the address on the account. We will describe what happened, the categories of data affected and the approximate number of users impacted; the measures we are taking; and steps you can take to protect yourself. We report breaches to regulators as the law requires.
Reporting a vulnerability
If you think you’ve found a security problem, send us a message with the steps to reproduce it, choosing Something else as the topic. Please don’t access other people’s data or disrupt the service while looking into it. We’ll reply by email.
Security reports
Message us