Manifest Privacy Policy
Effective date: 23 September 2026 (version 5, closed test)
Manifest is operated by Novee Consultants, a registered Malaysian business (SSM business registration no. CA0324687-D), based in Kuantan, Pahang, Malaysia. In this policy, "we", "us" and "our" mean Novee Consultants; "the app" means the Manifest mobile app.
This policy describes what the app actually does with data, section by section. Every claim here is written from the app's code, and the policy changes whenever the code's behavior changes.
The short version
Manifest is a local-first app. Your playlists, saved quotes, play history, likes, preferences and voice recordings live on your device, not on our servers. You do not need an account to browse the app, listen to anything, or use your own playlists. You only create an account — with your email address — if you choose to share a quote to the community or vote on community quotes. A small number of things do leave your device, each for a specific reason, and each is listed below. If you go a step further and choose a public handle, that handle and the quotes you share under it are world-visible — anyone can see them, while your email and account stay private. That is described under "Your handle, your profile, and following" below.
What stays on your device
- Your playlists, saved clips and quotes, play history and likes: a local database inside the app's own storage.
- Your preferences and last session.
- Your voice recordings. If you record yourself reading a quote, the audio file is stored on your device. There is no code path in the app that sends a recording off the device, and we never receive one.
Deleting the app deletes all of this from your device.
Your phone's own backup is the one thing that can copy this list off the device. Manifest takes part in it deliberately, so that your library comes back when you set up a new phone or reinstall the app. From version 1.0.1, on Android, your voice recordings are left out of that backup, so they come to a new phone only if you copy the app straight from your old one on Android 12 or later. That backup goes to your own account with Apple or Google, not to us: we never receive it and cannot read it, and you turn it on or off in your phone's settings. Your Manifest sign-in is left out of it, so a restored app starts signed out.
What leaves your device, and why
Spoken audio (text-to-speech)
When you ask the app to create spoken audio for a quote, the app sends the quote's text, the speaker's name, the source link (for video clips) and a voice choice to our server. Our server uses ElevenLabs, a third-party text-to-speech provider, to synthesize the audio on our behalf. The resulting audio file is AI-synthesized speech, not a human recording, and it is stored on our server so it does not have to be synthesized again.
Each synthesis request is also recorded in a server-side ledger. That ledger row includes the request's IP address, which we use to rate-limit requests and cap spending, along with technical details of the rendering (character count, engine version, the audio file's address). Ledger rows are kept because they prevent removed audio from being silently re-created. We commit to deleting the IP address from a ledger row no later than 24 months after it is recorded.
Crash reports and diagnostics
The app uses Sentry, a crash-reporting service, as a service provider. If the app crashes or hits an internal fault, a report is sent that includes technical device context (device model, OS version, app version) and recent technical events. Sentry also receives a session signal when the app starts and performance timing for a sample of app operations. Our own diagnostic events are deliberately content-free: they carry no quote text, no titles and no identifiers of what you saved or played, and the app strips query parameters from any web addresses recorded in diagnostic data before it is buffered.
YouTube
Manifest uses YouTube API Services. When you save a YouTube clip, and periodically afterwards, the app asks YouTube's data service for that video's public details (title, channel, duration, embeddability) so your saved clip stays accurate and compliant. When you play a YouTube clip, the video plays inside YouTube's embedded player, which loads content directly from YouTube: Google receives your IP address, cookies and playback telemetry directly, under Google's own terms, exactly as it would if you watched an embedded video in a browser. By using the YouTube features you are also subject to the YouTube Terms of Service (https://www.youtube.com/t/terms). You can read the Google Privacy Policy at https://policies.google.com/privacy.
Downloading audio for playback
The first time you play a piece of hosted audio, your device downloads it from our storage server, which transiently sees your device's IP address as part of serving the file. The app then keeps a local copy, so later plays happen from your device without any network request.
Your account
If you choose to share a quote to the community or vote, you create an account with your email address. We send a one-time code to that address to sign you in; we store your email address and an account identifier so you can sign in again and so your shared quotes and votes stay attached to you. Our authentication provider, Supabase, handles sign-in on our behalf. You do not need an account to browse the app, listen to anything, or use your own playlists — an account exists only to publish or vote.
Making a quote public in the community
When you make one of your quotes public, its text, the speaker name and source link you gave it, and the synthesized audio for it are stored on our server and shown to other people in the app's Community section. For a quote made from a video clip, a reference to that clip (the video and the time range) is stored too. Other people can browse and listen to a public quote; that is the point of making it public. How your public quote is labelled depends on whether you have a handle. If you do not, it is shown as "Shared by a listener" — nothing on it points to you. If you have chosen a handle, quotes you make public from then on show your handle and link to your profile; your email and account are still never shown. On our servers the quote is connected to your account so we can manage and remove it, but that connection is not something other people can see. A public quote is removed from the community when we act on a report or takedown, or when you delete your account (see "Retention and deletion").
Voting on a community quote
When you vote on a community quote, we store your vote — up or down — attached to your account. Your vote is private to you and to us: we never show other people how you voted, or that you voted, only a combined count. Votes help order the review queue; they do not decide what is marked verified.
Reporting a community quote or a handle
When you report a community quote — or report a handle (for example, one that impersonates a real person) — the report is anonymous. You do not need an account to report a handle. We store the reason for the report and a one-way fingerprint derived from your IP address, which we use only to stop one person flooding us with reports. We do not store your identity, and a report is never linked to your account.
Your handle, your profile, and following
Choosing a handle is optional. A handle is a public name you pick — not your real name; we never ask for or store your real name. If you choose one, it is stored on our server and is world-visible: anyone can see it, whether or not they use Manifest and whether or not they are signed in. Your handle appears on the quotes you make public after you claim it, and on your public profile, which gathers those quotes together. Your email address and your account identifier are never shown on your profile or anywhere else public — we hold the link between your handle and your account on our servers only, and we do not surface it. Only content you make public after you have a handle is attributed to it; quotes you shared before, votes, reports, and everything on your device are not.
You can follow other people, and they can follow you. We store each follow as a connection between two accounts. Two numbers from this are public on a profile: how many followers a person has, and how many people they follow. The connections themselves are not public: no one can see your list of followers, or the list of people you follow. The one exception is your own followers — you can always see who follows you, so you can block any of them. We do not notify anyone when you follow them, and these follow connections are used for nothing except the counts and your own-followers list.
Usage analytics
Usage analytics. Manifest records anonymous usage counts, for example that a category rail was opened, or that the daily passage was played. Each count is tagged with a random identifier created when you install the app; it is not derived from you or your device, it is not linked to your identity, and reinstalling the app resets it. These counts never include the text of your quotes, the titles of your clips, or anything you type, play, or save. They are sent to and stored only in our own database (hosted by Supabase) and are not shared with, or processed by, any third-party analytics service. Raw usage counts are deleted after 24 months.
Accounts, and what they mean
Most of Manifest needs no account. Browsing, listening, saving your own quotes and building playlists all work without one, and that personal activity stays on your device, not linked to any identity on our servers. An account exists for the community — sharing a quote, voting, and (if you choose) holding a handle and following people. Those actions are connected to your email address and account identifier on our servers; your private, on-device activity is not. Your email and account identifier are private and are never shown to other people. When you choose a handle, you are choosing a separate, public name that other people see instead — the handle is public, the account behind it is not. The honest limits, unchanged from before: a synthesis ledger row contains the IP address the render request came from (described above), and our storage server transiently sees IP addresses when serving files, as every web server does — neither of those is tied to an account.
Retention and deletion
- Everything on your device: deleted when you delete it in the app, or when you delete the app. Setting the app up again from your phone's own backup can bring it back (from version 1.0.1, on Android, everything except your voice recordings).
- Voice recordings: on your device; delete them in the app, or delete the app to remove all of them. On iPhone, if your phone backs itself up, a copy can also sit in that backup, which is yours to manage in your phone's settings. From version 1.0.1, on Android they are left out of the backup.
- Rendered audio files on our server: kept so playback keeps working; removed through the process described in our Terms of Service when a valid request is made.
- Render-ledger rows: kept, because a kept row is what prevents removed audio from being re-created. We commit to deleting the IP address within a row no later than 24 months after it is recorded.
- Your account, your public quotes and your votes: kept while your account exists. To delete your account, email us at novee.manifestapp@proton.me; we delete the account, the votes attached to it, and take your public quotes out of the community. A single public quote can also be removed on request or when we act on a report or takedown.
- Your handle and your follows: kept while your account exists. Deleting your account also deletes your handle and every follow connection involving you — both the people you followed and the people who followed you — so those follower and following counts stay correct. Any public quotes that showed your handle go back to being shown as "Shared by a listener," with nothing left that links them to you. A freed handle is not immediately available for someone else to take: it rests for a cooldown period first, and a handle we reclaimed for impersonation is retired for good.
- Giving up a handle without deleting your account: you can drop your handle at any time. When you do, your quotes that showed it go back to "Shared by a listener" with nothing linking them to you, exactly as on account deletion, and the freed handle rests for the same cooldown before anyone else can claim it.
- Community reports: the reason and the anonymous IP fingerprint are kept while we work the report queue and for a period afterwards to detect repeat abuse; they are never linked to an account.
- Raw usage counts: deleted after 24 months.
- Crash and diagnostic data: retained by Sentry under its own product retention schedule.
Children
Manifest is not directed at children under 13, and we do not knowingly collect personal data from children.
Changes to this policy
When the app's behavior changes in a way that affects this policy, we update this page and the effective date above. The current version at this address is the one that applies.
Contact
Novee Consultants (SSM business registration no. CA0324687-D) B-52, Tingkat 1, Lorong IM 5/2, Persiaran Sultan Abu Bakar, Bandar Indera Mahkota, 25200 Kuantan, Pahang, Malaysia
Email: novee.manifestapp@proton.me