← Back to ManifoldGen
Privacy Policy
Effective August 24, 2026 · manifoldgen.com
Data we collect
- Account identifier. You sign in with a crypto wallet address. We store the address as your account ID.
- Optional credentials. If you add an email and password we store the email and a salted hash of the password — never the password itself.
- API key. Each account gets an API key for programmatic access. Treat it as a secret; anyone holding it can spend your credits.
- Billing records. Credit deposits and usage are stored as billing events (amounts, timestamps, descriptions). Card payments go through Stripe; we never receive your card number. Crypto deposits are recorded on-chain and indexed by deposit address.
- Generated content. Prompts, generation settings (model, seed, size), and output files for images, video, audio, and voice are stored so your library persists across sessions.
- Local browser storage. Your session token and API key live in localStorage on your device. Crash reports are buffered in sessionStorage and sent only when a failure occurs.
What is public
- Generated images may be included in the public gallery and search results unless they are flagged as adult content. Adult-flagged results stay in your account and never appear in public search.
- Prompts attached to publicly visible gallery images are visible with them. If you do not want a prompt associated with you publicly, keep the result out of the gallery or use an account without identifying details.
- We publish aggregate leaderboards of model benchmark results, not personal data.
What we do not do
- No third-party analytics or advertising trackers. No Google Analytics, no ad pixels, no fingerprinting scripts.
- No selling of personal data. There is no data broker arrangement of any kind.
- No email marketing. Email is used only for account recovery and essential account notices if you provided one.
Retention and deletion
- Your library is kept while your account exists so generations remain downloadable.
- You can delete individual generations from your account at any time; deleted files are removed from storage.
- To delete your entire account and associated data, contact us from the email on the account or from the linked community channel and we will process the deletion.
Third parties
- Stripe processes card payments. Stripe receives payment details directly under its own privacy policy; we receive only the payment status and identifiers.
- Cloudflare serves and caches this site and our static assets.
- Upstream AI model providers process prompts to generate outputs; they are not given your wallet address or email.
Security
- Passwords are stored only as hashes. API keys are unique per account and can be regenerated. Traffic is served over HTTPS.
- No system is perfectly secure. Keep your API key private and report anything suspicious.