MANTI, INC. PRIVACY POLICY
This Privacy Policy describes how Manti, Inc. ("Manti," "we," "us," or "our"), a Delaware corporation, collects, uses, discloses, and protects your information when you use our robotics engineering design platform, website, and desktop application (collectively, the "Platform").
The Platform consists of (a) Manti Web, a hosted web application; (b) Manti Desktop, a downloadable desktop application that includes both a chat interface and a local project workspace; and (c) cloud-based services that support both. Different features within the Platform process data in different ways, as described in this Privacy Policy.
By using the Platform, you consent to the collection, use, and disclosure of your information as described here. If you do not agree, do not use the Platform.
1. INFORMATION WE COLLECT
1.1 Information You Provide
We collect information you provide directly, including:
Account Information: name, email address, and password.
Payment Information: our payment processor (Stripe) collects your payment card information, billing address, and related financial information. We do not directly store your full payment card number.
Chat Content: when you use Manti Web or the chat tab in Manti Desktop, your messages, prompts, and any content you paste or attach into chat are transmitted to and stored on Manti's servers so we can provide the service, route requests to AI providers, and let you return to your conversations across devices.
Communications: when you contact us for support, the content of your messages and any information you provide.
Feedback: any suggestions, comments, or feedback you provide about the Platform.
1.2 Information from Manti Desktop's Project Workspace
When you use the project tab in Manti Desktop, the bundled local AI agent runs entirely on your device. Under the current default configuration:
Project files, the AI agent's reasoning and transcripts, tool outputs, and the local audit log are stored on your device and are not transmitted to Manti.
From the project workspace, Manti receives only limited project metadata: the project name, a label for your device, and when the project was last opened.
Where the device label you provide includes information that may identify you (for example, a device name like "Jane's MacBook"), we treat that label as personal information subject to this Privacy Policy.
AI model inference calls from the project workspace go from your device directly to the upstream AI model provider that Manti has configured, bypassing Manti's servers in the current default configuration.
When inference calls leave your device, the prompts and content you provide are received by the upstream AI provider and are then governed by that provider's own terms of service and privacy policy, which may differ from this Privacy Policy. Information about current upstream providers is available in our Sub-processor List.
This configuration may change in the future to route inference through Manti's services for quota and routing purposes; if it does, we will update this Privacy Policy and notify you.
1.3 Information We Collect Automatically
Usage Information: information about how you use the Platform, including the features you use, actions you take, time spent on the Platform, and your interactions with the Platform's AI systems on the cloud-served surfaces.
Device Information: device type, operating system, browser type, unique device identifiers, IP address, and (for the desktop application) version information.
Log Information: server logs that record information about your use of the Platform, including access times, pages viewed, and referring URLs.
Note on telemetry: Manti Desktop does not currently transmit third-party usage analytics, crash reports, or other diagnostic information to Manti or external collectors. We may in the future collect anonymous diagnostic information (crash reports, performance metrics, aggregate feature-usage data). If we add such collection, we will update this Privacy Policy and provide an in-app control. We will not transmit the substance of your prompts, designs, files, or project content as part of any diagnostic data.
1.4 Information from Third Parties
We may receive information about you from third parties, such as our payment processor (Stripe), to facilitate billing and prevent fraud.
2. HOW WE USE YOUR INFORMATION
2.1 To Provide and Operate the Platform
To create and manage your account, process transactions, provide customer support, and deliver the services you request.
2.2 To Train and Improve Our AI Models
IMPORTANT:
If you are subscribed to the Basic, Builder, or Pro tier, we may use chat content and prompts you submit through Manti Web or the Manti Desktop chat interface, and any content you explicitly submit to Manti's cloud services (excluding personal information such as your name and email address), to train, fine-tune, test, evaluate, and improve our AI models, and to develop and improve our services.
We do not use project content created or stored locally on your device through Manti Desktop's project workspace for training, because that content does not reach our servers.
Enterprise Tier: if you are subscribed to the Enterprise tier, we will not use Your Content or outputs to train our AI models. Your Content is used solely to provide the Platform services to you.
Charter Program: if you are subscribed under the Charter Program, this Section 2.2 is modified during the Charter Period as described in the Charter Program Addendum. During the Charter Period, your chat content and prompts are not used for AI model training, regardless of tier.
2.3 To Improve and Develop the Platform
We use information to understand how users interact with the Platform, identify areas for improvement, develop new features, and enhance the overall user experience.
2.4 To Communicate With You
We use your contact information to send service-related communications, respond to inquiries, and provide customer support. We may also send promotional communications, from which you can opt out at any time.
2.5 To Protect and Secure
To protect the security and integrity of the Platform, detect and prevent fraud, enforce our Terms of Service, and comply with legal obligations.
3. HOW WE SHARE YOUR INFORMATION
3.1 Service Providers (Sub-processors)
We engage third-party service providers ("sub-processors") to support the Platform. Different sub-processors are engaged for different surfaces of the Platform:
Common to all features: Google (Firebase Authentication for sign-in), Stripe (payment processing), Resend (transactional email).
Manti Web and Manti Desktop chat tab: Google Cloud Platform (infrastructure hosting and database services); upstream AI model providers reached via Manti's infrastructure, currently including Anthropic and Google (Gemini), and OpenRouter (model routing).
Manti Desktop project workspace: OpenRouter (called directly from your device), routing to upstream AI model providers including Anthropic and Google (Gemini). Google Cloud Platform is not a sub-processor for content processed through the project workspace under the current configuration.
Manti is solely responsible for selecting and routing among upstream model providers. Users do not select specific upstream providers. The list of upstream providers may change from time to time without notice; the current list is available in our Sub-processor List at [URL].
A current list of sub-processors is available at [URL]. We will update this list as sub-processors change.
3.2 Legal Requirements
We may disclose information if required by law, regulation, legal process, or governmental request, or when we believe disclosure is necessary to protect our rights, your safety or the safety of others, investigate fraud, or respond to a government request.
3.3 Business Transfers
If Manti is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, your information may be transferred as part of that transaction.
3.4 With Your Consent
We may share your information with third parties when you have given us consent to do so.
3.5 We Do Not Sell Your Personal Information
We do not sell your personal information to third parties as defined under the California Consumer Privacy Act (CCPA) or other applicable privacy laws.
4. DATA RETENTION
4.1 Chat Content (Manti Web and Manti Desktop Chat Tab)
Chat content stored on Manti's servers is retained per tier-specific rules:
Basic, Builder, and Pro tiers: chat content may be retained for as long as necessary to fulfill the purposes described in this Privacy Policy, including AI model training and improvement, even after you delete the conversation or close your account. Personal information (such as name and email) is not retained for training purposes.
Enterprise tier: chat content is retained while your subscription is active. On termination, we will delete chat content from our active systems within ninety (90) days, subject to standard backup retention with deletion in the ordinary course.
Charter Program: chat content retention during the Charter Period is governed by the Charter Program Addendum, including the four-option transition mechanism that controls what happens to Charter Period content when the Charter Period ends.
4.2 Project Content (Manti Desktop Project Workspace)
Project files, agent transcripts, local audit logs, and other content created within Manti Desktop's project workspace remain on your device and under your control. Manti retains only the project metadata described in Section 1.2. To delete project content, delete the project folder or uninstall the desktop application.
4.3 Local Audit Log
The desktop application maintains a tamper-evident audit log of agent actions on your device. The audit log is retained until you delete the project. Manti does not have a remote copy.
4.4 Account Information
We retain your account information for as long as your account is active and for a reasonable period thereafter to comply with legal obligations, resolve disputes, and enforce our agreements.
5. DATA SECURITY
5.1 Cloud Services
We implement encryption in transit (TLS 1.2 or higher), encryption at rest (AES-256), tenant isolation, audit logging, vulnerability scanning, and incident response procedures. SOC 2 Type 2 audit is in progress. Additional detail is available in our Security Overview.
5.2 Desktop Application
Manti Desktop installers and updates are cryptographically signed and verified before installation. Authentication tokens are stored in your operating system's secure credential store (macOS Keychain, Windows Credential Manager, or Linux Secret Service), not in plain files. Manti Desktop maintains a tamper-evident local audit log using a SHA-256 hash chain that you can verify. Local project files and databases are stored using standard operating-system file storage. We rely on your operating system's disk encryption (FileVault, BitLocker, LUKS) to protect local data at rest. Because content created in the project workspace is stored only on your device, the security of that content also depends on measures within your control, including your device passcode, enabling full-disk encryption, and your operating system account protections.
5.3 Limitations
No method of transmission over the Internet or electronic storage is completely secure. We do not currently hold SOC 2 Type 2 certification (in progress) or ISO 27001 certification. While we strive to protect your information, we cannot guarantee absolute security.
5.4 Breach Notification
In the event of a confirmed data breach affecting your personal information, we will notify you in accordance with applicable law and within 72 hours of confirmation where reasonably practicable.
6. YOUR RIGHTS AND CHOICES
6.1 Access and Export
You can access and export chat history from Manti Web and Manti Desktop chat tab using the export features in the Platform. Project content created within Manti Desktop's project workspace is already stored as files on your device and can be accessed and copied directly through your operating system.
6.2 Account Deletion
You may request deletion of your account by contacting us at privacy@mantiai.com. Account deletion will remove data that Manti holds on its servers (subject to the retention rules in Section 4 and tier-specific terms). Project content stored locally on your device through Manti Desktop is not held by Manti and must be deleted by you (by deleting the project folder or uninstalling the application). For Basic, Builder, and Pro tier users, content used for AI training may persist as described in Section 4.1.
6.3 Communication Preferences
You can opt out of receiving promotional communications by following the unsubscribe instructions in those messages. We may still send you non-promotional communications about your account.
6.4 Opting Out of AI Training
If you do not want Your Content to be used to train our AI models, you may (a) upgrade to the Enterprise tier, which does not use Your Content for training, or (b) use Manti Desktop's project workspace, where project content stays on your device and never reaches our servers. Charter Program participants receive enhanced training treatment during the Charter Period as described in the Charter Program Addendum.
7. CALIFORNIA PRIVACY RIGHTS (CCPA)
7.1 Right to Know
California residents have the right to request that we disclose the categories and specific pieces of personal information we have collected, the categories of sources, our business or commercial purpose for collecting it, and the categories of third parties with whom we share it.
7.2 Right to Delete
On a valid request, Manti will delete the personal information it holds about you from its active databases and will direct its service providers to do the same, subject to standard backup retention with deletion in the ordinary course. Manti excludes personal information (such as your name and email address) from AI training inputs. Project content stored locally on your device is not held by Manti and is deleted by you (by deleting the project folder or uninstalling the application). As a technical clarification, where personal information has already been incorporated into a trained model, the model itself may not be able to be "un-trained," but Manti will delete the underlying source data as described above.
7.3 Right to Correct
You have the right to request that we correct inaccurate personal information we maintain about you.
7.4 Right to Non-Discrimination
We will not discriminate against you for exercising any of your CCPA rights.
7.5 Exercising Your Rights
To exercise your CCPA rights, please contact us at privacy@mantiai.com. We will verify your identity before responding to your request.
7.6 Categories of Information Collected
In the past 12 months, we have collected the following categories of personal information: identifiers (name, email address, IP address); commercial information (subscription tier, payment history); internet or other electronic network activity information (usage data, device information); and professional or employment-related information (if you provide it in the context of using the Platform).
8. OPT-OUT PREFERENCE SIGNALS (DNT AND GPC)
Some browsers and browser extensions enable users to send opt-out preference signals, including "Do Not Track" (DNT) signals and "Global Privacy Control" (GPC) signals.
Global Privacy Control: For California residents, when we receive a Global Privacy Control signal from your browser, we treat it as a valid request to opt out of the sale or sharing of your personal information as defined by the CCPA. Manti does not sell or share personal information as defined by the CCPA, so the practical effect of the GPC signal on our processing is limited, but we honor it as a valid opt-out request.
Do Not Track: Manti does not currently respond to Do Not Track browser signals because no industry standard has been adopted for interpreting them. We continue to monitor developments in this area.
9. CHILDREN'S PRIVACY
The Platform is available to users who are 18 years of age or older. We do not knowingly collect personal information from children under 18.
Consistent with the Children's Online Privacy Protection Act (COPPA), we do not knowingly collect personal information from children under 13. Consistent with the California Consumer Privacy Act (CCPA), we do not knowingly collect, sell, or share the personal information of consumers under 16 without affirmative consent.
If you are a parent or legal guardian and believe that a child under 13 has provided personal information to the Platform, please contact us at privacy@mantiai.com and we will take steps to delete the information and terminate the child's account.
10. INTERNATIONAL USERS
The Platform is currently available only to users in the United States. The desktop application may be technically downloadable outside the United States, but it is licensed only for use by users in the United States. If you access the Platform from outside the United States, your information may be transferred to, stored, and processed in the United States. We do not currently offer GDPR-specific protections; we will update this Privacy Policy if and when we expand internationally.
11. THIRD-PARTY LINKS
The Platform may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties.
12. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by posting the updated Privacy Policy on the Platform and sending notice to your account email at least sixty (60) days before the changes take effect.
13. CONTACT US
Manti, Inc.
Email: privacy@mantiai.com
Support: support@mantiai.com
* * *
By using the Platform, you acknowledge that you have read and understood this Privacy Policy.