Manifst Manifst Back to Home
Legal Document

Privacy Policy

Last updated: August 1, 2026  ·  Version 1.1

Manifst is fully GDPR compliant. Your data is hosted and stored in France, never sold to third parties, and you can exercise your rights at any time by contacting privacy@manifst.net.

Table of Contents

  1. Data Controller
  2. Data Collected and Purposes
  3. Data Retention Periods
  4. Data Hosting and Sovereignty
  5. Data Security
  6. Your GDPR Rights
  7. Cookies and Trackers
  8. Contact Information

Art. 1 Data Controller

The data controller responsible for processing your personal data is Adrien Savelli (Manifst), 6 Allée des Restanques, 13016 Marseille, France (SIREN: 797 513 470, contact: privacy@manifst.net).

Art. 2 Data Collected and Purposes

We collect and process personal data necessary to provide the Manifst platform:

Category Data Types Purpose & Legal Basis
Account Data First name, last name, email address, password hash Account creation, authentication, communication (Contractual necessity)
Project Data Backlog items, tasks, story points, time logs, risk logs Service provision, metrics calculation (Contractual necessity)
Billing Data Billing address, transaction receipts, payment status Subscription billing, tax compliance (Legal obligation)
Technical Logs IP address, browser type, connection timestamps Security monitoring, fraud prevention (Legitimate interest)

Art. 3 Data Retention Periods

Personal data is retained only for as long as necessary for the purposes for which it was collected:

  • Active Account: Retained for the entire duration of active subscription / account use.
  • Closed Account: Deleted permanently within 30 days after account deletion.
  • Invoices & Billing: Retained for 10 years in accordance with French commercial tax regulations.

Art. 4 Data Hosting and Sovereignty

All database records and file attachments managed by Manifst are hosted exclusively on secure infrastructure located in France. Data is stored strictly within the European Union.

Art. 5 Data Security

Manifst implements industry-standard technical and organizational security measures, including TLS/HTTPS transport encryption, salted password hashing, role-based access control, and daily offsite backups.

Art. 6 Your GDPR Rights

Under the GDPR, you hold the following rights regarding your personal data:

Right of Access

Obtain a copy of all personal data held about you.

Right to Rectification

Request correction of inaccurate or incomplete data.

Right to Erasure

Request permanent deletion of your personal data.

Right to Data Portability

Export your project and backlog data in structured formats.

To exercise any of these rights, email us at privacy@manifst.net.

Art. 7 Cookies and Trackers

Manifst uses essential functional session cookies strictly necessary to maintain authentication state. Analytics trackers (Google Analytics / GTM) are loaded with IP anonymization enabled.

Art. 8 Contact Information

For any privacy inquiries or to reach our Data Protection Officer, please contact privacy@manifst.net.

Art. 9 Google Workspace Data & Artificial Intelligence

When connecting your Google account to Manifst's Google Meet Connector, the application accesses, with your explicit consent, the following data:

Google DataScopePurpose
Account Email Addressopenid, emailIdentify connected account
Meeting Titles & Datescalendar.events.readonlyName and timestamp analyzed meeting
Meet Meeting Transcriptsmeetings.space.readonlyGenerate agile backlog (epics / user stories)

AI Processing & Third Parties

To generate backlog items, meeting transcript text is transmitted to our AI processor Mistral AI (a French company operating strictly within European Union data centers). Mistral AI processes this data exclusively to produce requested backlog output, does not use your data to train AI models, and never shares it with third parties.

Google Data Protection & Security

Data retrieved from Google APIs (transcripts, meeting titles, account email) is transmitted over encrypted channels (HTTPS/TLS), stored on secure servers in France, and accessible solely to authorized personnel. Your Google data is never sold, rented, or used for advertising purposes.

Retention & Deletion of Google Data

Cached meeting transcripts are retained for the duration of the associated project to allow backlog generation and refinement. They are automatically deleted upon project deletion, and can be deleted at any time upon request to privacy@manifst.net. Disconnecting the connector halts all further access to Google APIs.

Compliance with Google API Services User Data Policy

Manifst's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Revocation of Access

You can disconnect the Google Meet connector at any time in project settings, or revoke access directly from your Google Account Permissions page.

Manifst Manifst
  • Terms of Sale
  • Terms of Service
  • Privacy Policy

© 2026 Manifst. All rights reserved.