Manifest is in private alpha - native signed builds for macOS, Windows & Linux.

Privacy Policy

Last updated: August 27, 2026

Manifest is built so that your code stays on your machine. This policy describes the limited data Vector One does collect through the website, the desktop app, and Manifest Cloud, and how we look after it.

1.Who we are

Vector One, Inc. ("Vector One", "we", "us"), a Delaware corporation in the United States, is the data controller for personal data processed through the Manifest website at manifestgit.com (the "Site"), the Manifest desktop application for macOS, Windows, and Linux (the "App"), and the optional Manifest Cloud account service (together, the "Service").

This policy explains what we collect, why, on what legal basis, how long we keep it, who we share it with, and the rights you have. It applies to the Service only; GitHub and any assistant clients you connect through the MCP bridge have their own privacy policies.

Privacy questions and requests can be sent to legal@wearevectorone.com.

2.What we collect

Access requests. When you request access to the private alpha, we collect the information you enter in the form: your name, email address, and, if you choose to provide them, your company, the number of GitHub identities you use, how you ship (your workflow or use case), how you heard about Manifest, and the operating system you would install on. We also record the time of the request and the status of your application.

Download links. When we approve a request, we generate a personal download token. We record when the link was used, how many times, whether it expired, and whether it was revoked.

Manifest Cloud accounts. If you sign in to Manifest Cloud (for example with Google), we receive your name, email address, and profile picture from the identity provider and store them with your account, together with your subscription tier, session tokens, and any MCP API keys you create.

App telemetry. The App sends a small set of operational events to Manifest Cloud: app opened, session started and ended, and, if crash reports are enabled, a crash class. With the telemetry toggle switched on in Settings, it also sends product-usage events such as which view was opened, or that a commit, push, or clone happened, together with an outcome, a duration, and coarse counts. Each event carries the App version, your platform, a random session identifier, and, when you are signed in, your Manifest Cloud user. Property names are allow-listed per event so that file paths, repository or branch names, remotes, commit messages, search text, tokens, and email addresses are never included.

What the App does not send. The App does not transmit your repository contents, diffs, commit history, file paths, GitHub access tokens, SSH keys, or other credentials to Vector One. Git and GitHub operations run directly between your device and the Git host you use. Credentials are stored on your device, encrypted with AES-256-GCM.

Site analytics. When Google Analytics 4 is enabled on the Site and you have accepted analytics cookies, Google collects usage information such as pages viewed, approximate location derived from a truncated IP address, device and browser type, and referrer. See our Cookie Policy for details.

Support and correspondence. If you email us or report a bug, we keep the correspondence and any information you include in it.

Server logs. Our hosting infrastructure records standard request logs (IP address, user agent, timestamp, requested resource) for security and reliability.

3.How we use your data

  • reviewing access requests and operating the private alpha, including sending download links;
  • creating and securing Manifest Cloud accounts, sessions, and MCP tokens;
  • providing paid plans, invoicing, and managing subscriptions;
  • understanding how the App is used, so that we can fix crashes and prioritise features;
  • measuring Site traffic and the effectiveness of our pages;
  • responding to support requests and feedback;
  • sending product updates about the alpha and, with your consent where required, marketing emails, each with an unsubscribe link;
  • detecting abuse, protecting the security of the Service, and enforcing our Terms;
  • complying with legal obligations, such as tax and accounting rules.

5.How long we keep data

  • Access requests are kept while the alpha program runs and for up to 12 months after it ends, or until you ask us to delete them, unless you have become a Manifest Cloud user.
  • Download-link records are kept for 12 months after the link expires.
  • Manifest Cloud account data is kept for as long as your account exists and for 30 days after deletion to allow recovery from accidental deletion, after which it is erased or anonymised. Session tokens expire automatically.
  • App telemetry is kept in identifiable form for up to 14 months, then aggregated or deleted.
  • Billing records are kept for the period required by US federal and state tax and commercial law (generally 7 years).
  • Server logs are kept for up to 90 days.
  • Support correspondence is kept for up to 3 years after the matter is closed.

6.Who we share data with

We do not sell personal data. We share it only with:

  • GitHub. The App talks to the GitHub API directly from your device using the identities you connect. GitHub receives the requests you initiate under its own privacy policy. We do not receive your GitHub tokens.
  • Identity providers. If you sign in to Manifest Cloud with Google, Google processes the sign-in under its own policy and tells us your name, email, and avatar.
  • Hosting and infrastructure providers that run the Site, Manifest Cloud, our database, email delivery, and backups, acting as processors under contract.
  • Google Analytics (Google Ireland Limited / Google LLC) for Site analytics, when enabled and consented to.
  • Payment providers that process subscription payments. We do not store full card numbers.
  • Professional advisers and authorities where required by law, to protect our rights, or in connection with a merger, acquisition, or sale of assets, in which case we will notify you of any change of controller.

Assistant clients that you connect through the MCP bridge (for example a desktop or editor-based coding assistant) receive the data you allow them to read through the permissions you configure. That data flows from your device to the client; it does not pass through Vector One.

7.International transfers

Vector One is based in the United States. Our infrastructure and some processors are located in the United States and the European Union, so your data may be transferred outside your country.

For transfers from the EEA and the UK, we rely on adequacy decisions where available and otherwise on the European Commission's Standard Contractual Clauses (and the UK Addendum) with supplementary measures, and we participate in the EU-US Data Privacy Framework where applicable. You can request a copy of the relevant safeguards by contacting us.

8.Your rights

Depending on where you live, you may have the right to:

  • access the personal data we hold about you and receive a copy;
  • have inaccurate data corrected and incomplete data completed;
  • have your data erased, including by deleting your Manifest Cloud account;
  • restrict or object to processing based on legitimate interests;
  • receive your data in a portable, machine-readable format;
  • withdraw consent at any time, for example by turning off telemetry in the App or rejecting cookies;
  • if you are a California resident, exercise your rights under the CCPA/CPRA to know, delete, and correct personal information and to opt out of "sales" or "sharing" (we do not sell personal information or share it for cross-context behavioural advertising), without discrimination for exercising those rights;
  • lodge a complaint with a supervisory authority, such as your EU data protection authority, the UK ICO, or your US state attorney general.

To exercise a right, email legal@wearevectorone.com from the address associated with your request or account. We respond within 30 days (or the shorter period required by law) and may ask you to verify your identity first.

9.Security

We apply technical and organisational measures appropriate to the risk, including encryption in transit (TLS) for all traffic between the App, the Site, and Manifest Cloud, encrypted storage of credentials on your device with AES-256-GCM, short-lived and revocable session tokens, access controls and least-privilege for our staff, and monitoring of our infrastructure.

The App also includes a commit-time secrets guardrail that blocks common credential files from being committed unless you explicitly allow it, and a pre-push identity check. These help protect you but do not replace your own security practices. No system is completely secure; if we become aware of a breach affecting your data, we will notify you and the relevant authorities as required by law.

10.Children

The Service is not directed at children and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.

11.Changes to this policy

We may update this policy as the Service evolves or the law changes. We will post the new version on the Site with an updated "Last updated" date and, for material changes, notify you by email or in the App before they take effect.

12.Contact

For any privacy-related question or request, contact the data controller:

Vector One, Inc.
Delaware, United States
legal@wearevectorone.com
wearevectorone.com