MANTI, INC. PRIVACY POLICY
This Privacy Policy describes how Manti, Inc. ("Manti," "we," "us," or "our"), a Delaware corporation, collects, uses, discloses, and protects your information when you use our robotics engineering design platform, website, and desktop application (collectively, the "Platform").
The Platform consists of (a) Manti Web, a hosted web application; (b) Manti Desktop, a downloadable desktop application that includes both a chat interface and a local project workspace; and (c) cloud-based services that support both. Different features within the Platform process data in different ways, as described in this Privacy Policy.
By using the Platform, you consent to the collection, use, and disclosure of your information as described here. If you do not agree, do not use the Platform.
1. INFORMATION WE COLLECT
1.1 Information You Provide
We collect information you provide directly, including:
Account Information: name, email address, and password.
Payment Information: our payment processor (Stripe) collects your payment card information, billing address, and related financial information. We do not directly store your full payment card number.
Chat Content: when you use Manti Web or the chat tab in Manti Desktop, your messages, prompts, and any content you paste or attach into chat are transmitted to and stored on Manti's servers so we can provide the service, route requests to AI providers, and let you return to your conversations across devices.
Communications: when you contact us for support, the content of your messages and any information you provide.
Feedback: any suggestions, comments, or feedback you provide about the Platform.
1.2 Information from Manti Desktop's Project Workspace
When you use the project tab in Manti Desktop, the bundled AI agent runs on your device. Your project files are created and stored on your own disk, where you retain direct access to them.
During a Free trial (as described in our Terms of Service) and on the Plus, Pro, and Max tiers, Manti collects certain project workspace data from your device, including: agent session records (conversations sent to the model, the model's responses, tool calls and their results, terminal commands and output, images shown to the model, and error and crash information); project files and their version history; engineering artifacts such as simulation results, CAD parts, and firmware outputs; and the agent's local memory database. A record of what has been transmitted is available on your device, and credentials and secrets (such as API keys and tokens) are removed before transmission.
On the Enterprise tier and for Charter Program accounts, no project workspace content is collected. Free accounts are collected from only while a Free trial is active. For all accounts, Manti receives limited project metadata: the project name, a label for your device, and when the project was last opened.
Where the device label you provide includes information that may identify you (for example, a device name like "Jane's MacBook"), we treat that label as personal information subject to this Privacy Policy.
AI model calls made by the agent are relayed through Manti's services for routing and billing and then sent to the upstream AI model providers Manti has configured.
When inference calls leave your device, the prompts and content you provide are received by the upstream AI provider and are then governed by that provider's own terms of service and privacy policy, which may differ from this Privacy Policy. Information about current upstream providers is available in our Sub-processor List.
1.3 Information We Collect Automatically
Usage Information: information about how you use the Platform, including the features you use, actions you take, time spent on the Platform, and your interactions with the Platform's AI systems on the cloud-served surfaces.
Device Information: device type, operating system, browser type, unique device identifiers, IP address, and (for the desktop application) version information.
Log Information: server logs that record information about your use of the Platform, including access times, pages viewed, and referring URLs.
Note on Manti Desktop telemetry: in addition to the project workspace collection described in Section 1.2, Manti Desktop sends Manti a limited set of product usage events tied to your account, such as signing in, the local agent becoming ready, and a task starting or finishing, together with the application version and your operating system. These events do not include your prompts, project content, or file names. Crash and error reports are sent only if you turn them on in Manti Desktop's privacy settings. Manti Desktop does not transmit third-party usage analytics or advertising identifiers.
Website analytics: on our public marketing pages we measure traffic ourselves, in aggregate only, without cookies and without third-party analytics services. Each page view records the page visited, the referring site, your operating system family, and an approximate location. Your IP address is read once, in memory, for three purposes and is never stored: to count same-day unique visitors via a one-way hash that changes every day; to look up an approximate location in a geolocation database we host on our own servers; and to recognise visits from our own staff network so we can exclude them from our traffic figures — no third party receives your IP address or any other data from these pages. From that lookup we store your country and city, and a coordinate that the geolocation database gives for the network your connection belongs to, rounded to roughly one kilometre. That coordinate is a property of a network, not of you: it is shared by everyone connecting through the same network, it is not your address, and it is typically accurate only to the neighbourhood or city. We also record how long a page was visible, so we can tell which pages people read. These traffic counts cannot be linked across days or to any person; the separate website usage analytics described in the next paragraph can be.
Website usage analytics and session recordings: to find errors, improve signup and onboarding, and understand demand, we also measure how people use our public website, the signup journey, and selected signed-in pages (such as the account, billing, download, and onboarding pages). We record page and section views, clicks and taps, scroll depth, video progress, errors, and signup and free trial steps and their outcomes, together with your approximate country, device type, the site version, and the site that referred you. We measure how long a page was open and visible and estimate active time from recent interaction; these measurements do not show what anyone read, understood, or intended. We set a first-party cookie containing a random identifier so that we can connect visits from the same browser; it lasts up to 395 days. When you sign in, we link that browser's activity, including activity from before you signed in, to your account. We may also record a masked reconstruction of your visit to these pages, including sampled pointer movement: page text and everything you type are masked in your browser before anything is sent, payment forms are not recorded, and a recording can have gaps and is not a video of your screen. We keep structured analytics for up to 395 days and delete recordings and pointer data after 90 days. Recordings are stored in a private Google Cloud Storage bucket and the analytics in our database, both controlled by Manti; access is limited to authorized Manti staff and is logged. We do not share this information with third-party analytics or advertising services. For Enterprise tier and Charter Program accounts, we do not link this analytics or these recordings to the account, and collection stops once the account signs in. Deleting your account deletes the analytics and recordings linked to it. If your browser sends a Global Privacy Control signal, we do not collect this website usage analytics or these recordings from that browser.
Approximate location when Manti Desktop talks to our servers: when Manti Desktop relays an AI model call through Manti's services (from the chat interface or from the project workspace, as described in Section 1.2), we see the network address the call connects from. We read that address once, in memory, to look up an approximate location in the same geolocation database we host on our own servers, and we do not store the address itself; no third party receives it. From that lookup we keep your country, your approximate city, and a coordinate that the geolocation database gives for the network your connection belongs to, rounded to roughly one kilometre, together with a one-way hash of the address that changes every day and from which the address cannot be recovered. We keep this information tied to your account for up to thirteen (13) months and then delete it. We use it to understand how the Platform is used and to detect account sharing, which our Terms of Service prohibit. That coordinate is a property of a network, not of you: it is shared by everyone connecting through the same network, it is not your address, and it is typically accurate only to the neighbourhood or city. The country and city we infer can be wrong, and if you connect through a VPN or a corporate network the location will be that network's, not yours.
1.4 Information from Third Parties
We may receive information about you from third parties, such as our payment processor (Stripe), to facilitate billing and prevent fraud.
2. HOW WE USE YOUR INFORMATION
2.1 To Provide and Operate the Platform
To create and manage your account, process transactions, provide customer support, and deliver the services you request.
2.2 To Train and Improve Our AI Models
IMPORTANT:
If you are using a Free trial or are subscribed to the Plus, Pro, or Max tier, we may use chat content and prompts you submit through Manti Web or the Manti Desktop chat interface, and any content you explicitly submit to Manti's cloud services (excluding personal information such as your name and email address), to train, fine-tune, test, evaluate, and improve our AI models, and to develop and improve our services.
During a Free trial and on the Plus, Pro, and Max tiers, we may also use project workspace data collected as described in Section 1.2, including project files, agent session records, and related artifacts, to diagnose and fix defects, improve the Platform, and train our AI models. Project workspace content is not collected from Enterprise tier or Charter Program accounts.
Enterprise Tier: if you are subscribed to the Enterprise tier, we will not use Your Content or outputs to train our AI models. Your Content is used solely to provide the Platform services to you.
Charter Program: if you are subscribed under the Charter Program, this Section 2.2 is modified during the Charter Period as described in the Charter Program Addendum. During the Charter Period, your chat content and prompts are not used for AI model training, regardless of tier.
2.3 To Improve and Develop the Platform
We use information to understand how users interact with the Platform, identify areas for improvement, develop new features, and enhance the overall user experience.
2.4 To Communicate With You
We use your contact information to send service-related communications, respond to inquiries, and provide customer support. We may also send promotional communications, from which you can opt out at any time.
2.5 To Protect and Secure
To protect the security and integrity of the Platform, detect and prevent fraud, enforce our Terms of Service, and comply with legal obligations.
3. HOW WE SHARE YOUR INFORMATION
3.1 Service Providers (Sub-processors)
We engage third-party service providers ("sub-processors") to support the Platform. Different sub-processors are engaged for different surfaces of the Platform:
Common to all features: Google (Firebase Authentication for sign-in, and Google Workspace for the email we send you), Stripe (payment processing), Resend (transactional email).
Manti Web and Manti Desktop chat tab: Google Cloud Platform (infrastructure hosting and database services); upstream AI model providers reached via Manti's infrastructure, currently including Anthropic, Google (Gemini), and xAI (Grok); and OpenRouter (model routing).
Manti Desktop project workspace: AI model calls are relayed through Manti's infrastructure and routed to upstream AI model providers including Anthropic, Google (Gemini), and xAI (Grok) via OpenRouter. Google Cloud Platform hosts project workspace data collected from Free trial, Plus, Pro, and Max accounts.
Manti is solely responsible for selecting and routing among upstream model providers. Users do not select specific upstream providers. The list of upstream providers may change from time to time without notice; the current list is available in our Sub-processor List at mantiai.com/subprocessors.
A current list of sub-processors is available at mantiai.com/subprocessors. We will update this list as sub-processors change.
3.2 Legal Requirements
We may disclose information if required by law, regulation, legal process, or governmental request, or when we believe disclosure is necessary to protect our rights, your safety or the safety of others, investigate fraud, or respond to a government request.
3.3 Business Transfers
If Manti is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, your information may be transferred as part of that transaction.
3.4 With Your Consent
We may share your information with third parties when you have given us consent to do so.
3.5 We Do Not Sell Your Personal Information
We do not sell your personal information to third parties as defined under the California Consumer Privacy Act (CCPA) or other applicable privacy laws.
4. DATA RETENTION
4.1 Chat Content (Manti Web and Manti Desktop Chat Tab)
Chat content stored on Manti's servers is retained per tier-specific rules:
Free trial and Plus, Pro, and Max tiers: chat content may be retained for as long as necessary to fulfill the purposes described in this Privacy Policy, including AI model training and improvement, even after you delete the conversation or close your account. Personal information (such as name and email) is not retained for training purposes.
Enterprise tier: chat content is retained while your subscription is active. On termination, we will delete chat content from our active systems within ninety (90) days, subject to standard backup retention with deletion in the ordinary course.
Charter Program: chat content retention during the Charter Period is governed by the Charter Program Addendum, including the four-option transition mechanism that controls what happens to Charter Period content when the Charter Period ends.
4.2 Project Content (Manti Desktop Project Workspace)
Project files, agent transcripts, local audit logs, and other content created within Manti Desktop's project workspace are stored on your device and remain under your control there. During a Free trial and on the Plus, Pro, and Max tiers, copies of project workspace data collected as described in Section 1.2 are retained on Manti's systems for as long as necessary for the purposes described in this Privacy Policy. If you delete your account, we will delete collected project workspace data from our active systems, subject to standard backup retention with deletion in the ordinary course; content already incorporated into a trained model cannot be removed from that model. To delete the local copies on your device, delete the project folder or uninstall the desktop application. On the Enterprise tier and for Charter Program accounts, Manti retains only the project metadata described in Section 1.2.
4.3 Local Audit Log
The desktop application maintains a tamper-evident audit log of agent actions on your device. The audit log is retained until you delete the project. Manti does not have a remote copy.
4.4 Account Information
We retain your account information for as long as your account is active and for a reasonable period thereafter to comply with legal obligations, resolve disputes, and enforce our agreements.
4.5 Free Trial Eligibility Records
To limit Free trials to one per person and prevent abuse, when you create an account we compute a one-way keyed hash of your email address, from which the address cannot be read back. With that hash we keep whether and when the address claimed a Free trial (and the internal account identifier that claimed it) or had paid access, and the trial's usage records. We keep this record after you delete your account, for as long as needed to enforce the one-trial-per-person rule.
5. DATA SECURITY
5.1 Cloud Services
We implement encryption in transit (TLS 1.2 or higher), encryption at rest (AES-256), tenant isolation, audit logging, vulnerability scanning, and incident response procedures. SOC 2 Type 2 audit is in progress. Additional detail is available in our Security Overview.
5.2 Desktop Application
Manti Desktop installers and updates are cryptographically signed and verified before installation. Authentication tokens are stored in your operating system's secure credential store (macOS Keychain, Windows Credential Manager, or Linux Secret Service), not in plain files. Manti Desktop maintains a tamper-evident local audit log using a SHA-256 hash chain that you can verify. Local project files and databases are stored using standard operating-system file storage. We rely on your operating system's disk encryption (FileVault, BitLocker, LUKS) to protect local data at rest. Because content created in the project workspace is stored only on your device, the security of that content also depends on measures within your control, including your device passcode, enabling full-disk encryption, and your operating system account protections.
5.3 Limitations
No method of transmission over the Internet or electronic storage is completely secure. We do not currently hold SOC 2 Type 2 certification (in progress) or ISO 27001 certification. While we strive to protect your information, we cannot guarantee absolute security.
5.4 Breach Notification
In the event of a confirmed data breach affecting your personal information, we will notify you in accordance with applicable law and within 72 hours of confirmation where reasonably practicable.
6. YOUR RIGHTS AND CHOICES
6.1 Access and Export
You can access and export chat history from Manti Web and Manti Desktop chat tab using the export features in the Platform. Project content created within Manti Desktop's project workspace is already stored as files on your device and can be accessed and copied directly through your operating system.
6.2 Account Deletion
You may request deletion of your account by contacting us at privacy@mantiai.com. Account deletion will remove data that Manti holds on its servers, including collected project workspace data, subject to the retention rules in Section 4 and tier-specific terms. Local copies of project content on your device remain under your control and must be deleted by you (by deleting the project folder or uninstalling the application). For Free trial, Plus, Pro, and Max tier users, content used for AI training may persist as described in Sections 4.1 and 4.2. The Free trial eligibility record described in Section 4.5 is kept after deletion.
6.3 Communication Preferences
You can opt out of receiving promotional communications, including Free trial invitations and opening notices, by following the unsubscribe link in those messages; we keep a record of your choice so that we can honor it. We may still send you non-promotional communications about your account.
6.4 Choosing a Tier Where Your Content Is Not Used for Training
If you do not want Your Content to be used to train our AI models, you may upgrade to the Enterprise tier, which does not use Your Content for training and is excluded from project workspace collection. Charter Program participants receive enhanced training treatment during the Charter Period as described in the Charter Program Addendum.
7. CALIFORNIA PRIVACY RIGHTS (CCPA)
7.1 Right to Know
California residents have the right to request that we disclose the categories and specific pieces of personal information we have collected, the categories of sources, our business or commercial purpose for collecting it, and the categories of third parties with whom we share it.
7.2 Right to Delete
On a valid request, Manti will delete the personal information it holds about you from its active databases and will direct its service providers to do the same, subject to standard backup retention with deletion in the ordinary course. Manti excludes personal information (such as your name and email address) from AI training inputs. Local copies of project content stored on your device are under your control and are deleted by you (by deleting the project folder or uninstalling the application); copies collected by Manti are deleted as described in Section 4.2. As a technical clarification, where personal information has already been incorporated into a trained model, the model itself may not be able to be "un-trained," but Manti will delete the underlying source data as described above.
7.3 Right to Correct
You have the right to request that we correct inaccurate personal information we maintain about you.
7.4 Right to Non-Discrimination
We will not discriminate against you for exercising any of your CCPA rights.
7.5 Exercising Your Rights
To exercise your CCPA rights, please contact us at privacy@mantiai.com. We will verify your identity before responding to your request.
7.6 Categories of Information Collected
In the past 12 months, we have collected the following categories of personal information: identifiers (name, email address, IP address, and a first-party cookie identifier); commercial information (subscription tier, payment history); internet or other electronic network activity information (usage data, device information); geolocation data (the approximate location, at country and city level, that we infer from your network address as described in Section 1.3); and professional or employment-related information (if you provide it in the context of using the Platform).
8. OPT-OUT PREFERENCE SIGNALS (DNT AND GPC)
Some browsers and browser extensions enable users to send opt-out preference signals, including "Do Not Track" (DNT) signals and "Global Privacy Control" (GPC) signals.
Global Privacy Control: For California residents, when we receive a Global Privacy Control signal from your browser, we treat it as a valid request to opt out of the sale or sharing of your personal information as defined by the CCPA. Manti does not sell or share personal information as defined by the CCPA, so the practical effect of the GPC signal on our processing is limited, but we honor it as a valid opt-out request. Global Privacy Control also turns off, for that browser, the website usage analytics and session recordings described in Section 1.3.
Do Not Track: Manti does not currently respond to Do Not Track browser signals because no industry standard has been adopted for interpreting them. We continue to monitor developments in this area.
9. CHILDREN'S PRIVACY
The Platform is available to users who are 18 years of age or older. We do not knowingly collect personal information from children under 18.
Consistent with the Children's Online Privacy Protection Act (COPPA), we do not knowingly collect personal information from children under 13. Consistent with the California Consumer Privacy Act (CCPA), we do not knowingly collect, sell, or share the personal information of consumers under 16 without affirmative consent.
If you are a parent or legal guardian and believe that a child under 13 has provided personal information to the Platform, please contact us at privacy@mantiai.com and we will take steps to delete the information and terminate the child's account.
10. INTERNATIONAL USERS
The Platform is currently available only to users in the United States. The desktop application may be technically downloadable outside the United States, but it is licensed only for use by users in the United States. If you access the Platform from outside the United States, your information may be transferred to, stored, and processed in the United States. We do not currently offer GDPR-specific protections; we will update this Privacy Policy if and when we expand internationally.
11. THIRD-PARTY LINKS
The Platform may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties.
12. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by posting the updated Privacy Policy on the Platform and sending notice to your account email at least sixty (60) days before the changes take effect.
13. CONTACT US
Manti, Inc.
Email: privacy@mantiai.com
Support: support@mantiai.com
* * *
By using the Platform, you acknowledge that you have read and understood this Privacy Policy.