Privacy Policy
Version 1.0. Effective [DATE].
This policy explains how [COMPANY NAME] LIMITED ("Manifold", "we", "us" or "our") collects, uses and shares personal data when you use the Manifold website at manifoldmcp.com (the "Site"), the application at app.manifoldmcp.com (the "App"), the MCP server at mcp.manifoldmcp.com and its HTTP API (the "Server"), and when you contact us (together, the "Service"). It also explains your rights.
We are a company registered in England and Wales under company number [COMPANY NUMBER], with our registered office at [REGISTERED OFFICE ADDRESS]. We are the controller of the personal data described in Sections 2 to 4, and we are registered with the Information Commissioner's Office under registration number [ICO REGISTRATION NUMBER]. Section 5 explains the different position for data about other people that the Service returns on your instruction.
Contact us about anything in this policy at [PRIVACY EMAIL].
1. What the Service is
Manifold is one MCP server of read-only marketing data tools. An AI agent or MCP client that you connect can ask it for search rankings and keyword data, backlinks, site health, what AI engines say about a site, data from your own Google Search Console and Bing Webmaster Tools accounts, professional contact data, public ad libraries, and public posts and profiles on Reddit and other social platforms. The Service reads and reports; it never posts, sends or changes anything.
2. The personal data we collect about you
Account data. When you sign in we receive from our identity provider, Clerk, your name, email address, profile picture and a user identifier, and, if you sign in with Google, the identifier Google gives us for you. We do not see your password.
Workspace data. The name of each workspace you belong to, who its members are, their roles, and which workspace you last used.
Billing data. Your plan, your credit balance and its history, your invoices, the amount of any auto top-up you set, and a customer identifier at our billing providers, Autumn and Stripe. Your card details are collected and stored by Stripe; we never see the full card number.
Usage data. For every tool call made through your workspace: the tool called, the data provider used, the credits charged, whether the result came from the cache, the time, whether the call came through OAuth or an API key, which user or key made it, and the target of the call (for example the domain or keyword looked up). For the slower tools, the parameters and results of the task, for 30 days.
API keys. The name you give a key, its first characters, a hash of the key, and when it was created, last used and revoked. We do not store the key itself.
Connected accounts. When you connect a Google Search Console or Bing Webmaster Tools account: the email address and identifier the provider gives us for it, the permissions it granted, and an encrypted refresh token or, for Bing, the API key you pasted. The search data the tools fetch from those accounts is returned to your agent and cached for a short period as described in Section 8; we do not keep it otherwise.
MCP client data. When an agent connects through OAuth, Clerk records which client it is (for example Claude or Cursor), the permissions you granted it, and when. We do not store which client made each call.
Technical data. Our hosting provider, Cloudflare, logs each request to the Site, App and Server: IP address, browser or client identifier, the URL, timing and result, and a request identifier. We keep error and invocation logs and per-call metrics for the operation of the Service.
Communications. Anything you send us by email or through a support channel, and our replies.
We do not collect sensitive (special category) data and ask you not to send us any.
3. Why we use it, and our lawful bases
| Purpose | Data | Lawful basis under the UK GDPR |
|---|---|---|
| Providing the Service: signing you in, running tool calls, charging credits, showing usage, sending receipts and service messages | Account, workspace, billing, usage, API key, connected-account and MCP client data | Performance of our contract with you (Article 6(1)(b)) |
| Reading your Search Console and Bing data on your instruction | Connected-account data and the data fetched | Performance of our contract; your authorisation of the connection |
| Securing the Service: authenticating requests, rate limiting, detecting abuse, investigating incidents | Technical, usage and API key data | Our legitimate interest in the security and integrity of the Service (Article 6(1)(f)) |
| Operating and improving the Service: monitoring reliability and latency, understanding which tools are used and what they cost us | Usage and technical data, in aggregate where possible | Our legitimate interest in running the Service well |
| Answering your questions and support requests | Communications and account data | Our legitimate interest in supporting our customers; our contract with you |
| Telling you about material changes to the Service, the Terms or this policy | Account data | Our contract with you; compliance with legal obligations |
| Keeping accounting and tax records | Billing data | Compliance with legal obligations (Article 6(1)(c)) |
| Establishing, exercising or defending legal claims, and complying with law | Any of the above | Legitimate interests; compliance with legal obligations |
We do not use your personal data for marketing to third parties, for advertising, for profiling, or for automated decisions that have a legal or similarly significant effect on you. If we send you product news, you will be able to opt out in every message, and we will rely on the soft opt-in for existing customers under the Privacy and Electronic Communications Regulations 2003 or on your consent.
4. Who we share it with
We share personal data only with the providers below, who process it on our behalf under contracts that require them to protect it, and otherwise only as stated after the table.
| Provider | What it does for us | Data it processes |
|---|---|---|
| Cloudflare | Hosts the Site, the App and the Server; stores our database, cache, task results and logs; runs our request and security layer | All categories in Section 2 |
| Clerk | Sign-in, accounts, workspaces and the OAuth authorisation server that MCP clients sign in through | Account, workspace and MCP client data |
| Autumn | Credit ledger, plans and top-ups | Billing data and per-call charges |
| Stripe | Payment processing, invoices and sales tax | Billing data and card details |
| Google (Google Search Console API) | Provides the data for the console tools when you connect a Google account |
The connected-account credential and the queries the tools make |
| Microsoft (Bing Webmaster Tools API) | Provides the data for the console tools when you connect a Bing account |
The connected-account credential and the queries the tools make |
| DataForSEO | Search, keyword, backlink, site audit and AI answer data (the seo_* and aeo_* tools) |
The parameters of each call (domains, keywords, prompts, URLs) |
| ScrapeCreators | Public Reddit, social platform and ad library data (the reddit_*, ads_* and platform tools) |
The parameters of each call |
| Apollo, Hunter, Findymail and Icypeas | Company and professional contact data and email verification (the leads_* tools) |
The parameters of each call (names, domains, email addresses, search filters) |
The data providers in the last four rows receive only what a tool call needs. They do not receive your name, email address or account identifier.
We may also share personal data with our professional advisers (lawyers, accountants, insurers) where they need it to advise us; with a buyer or successor if we sell or transfer our business, in which case this policy will continue to apply; and with courts, regulators and law enforcement where we are required to, or where we believe in good faith that it is necessary to protect the rights, property or safety of Manifold, our users or others.
We do not sell personal data, and we do not share it with advertisers.
5. Data about other people that the Service returns
Several tools return information about identifiable people: the leads_* tools return names, job titles, employers, work email addresses and similar professional data from Apollo, Hunter, Findymail and Icypeas; the social and Reddit tools return public profiles, posts and comments; and the AI answer tools may quote content that names people.
For that data, the customer whose agent made the call is the controller. They decide what to look for and what to do with the result, and they are responsible for having a lawful basis for it. We act as their processor: we pass the request to the data provider, return the result to their agent, and hold a copy in our cache and, for the slower tools, in our task store, for the periods in Section 8. We do not build or keep a database of people from these results, we do not combine results across customers, and we do not use them for any purpose of our own beyond operating the cache.
Our data providers are independent controllers of the data they hold and supply. Their policies explain where it comes from and how to exercise your rights with them: Apollo, Hunter, Findymail, Icypeas, DataForSEO and ScrapeCreators.
If you are one of the people this data is about, you can ask us at [PRIVACY EMAIL] to remove any copy of your data from our cache and task store, and we will do so within 30 days and tell you which providers the data came from so that you can contact them. We cannot remove you from our providers' databases or from the public platforms the data describes.
6. Google API Services User Data Policy
The App connects to Google Search Console through Google APIs, with the read-only Search Console scope. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular, we use that data only to provide the console tools to the workspace that connected the account; we do not transfer it to anyone except as necessary to provide those tools, to comply with law, or as part of a merger or acquisition with notice to you; we do not use it for advertising; and no human at Manifold reads it except with your permission, for security purposes, to comply with law, or in aggregated and anonymised form for internal operations.
7. International transfers
We are based in the United Kingdom, and our providers store and process data in the United Kingdom, the European Economic Area and the United States. Cloudflare processes requests at the data centre nearest the caller and stores our data in [DATA STORAGE REGION]. Where personal data leaves the United Kingdom for a country the UK Government has not found to give adequate protection, we transfer it under the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, or, for providers certified under the UK Extension to the EU-US Data Privacy Framework, under that framework. You can ask us at [PRIVACY EMAIL] for details of the mechanism used for a particular provider.
8. How long we keep it
| Data | Kept for |
|---|---|
| Account and workspace data | While you have an account, then deleted within 30 days of you deleting your workspace or asking us to close your account |
| Billing records and the credit ledger | Six years after the end of the tax year they relate to, as UK accounting and tax law requires |
| Usage records (which tool, when, how many credits, the target) | While the workspace exists, for your usage history, then deleted with the workspace |
| API keys | Until revoked or the workspace is deleted; a revoked key's record is kept for 30 days for audit |
| Connected-account credentials | Until you disconnect the account or delete the workspace; deleted immediately then |
Task results for the slower tools (run_*) |
30 days |
| Cached tool results | From one hour to 90 days depending on the data, as described in the documentation; most are kept 24 hours to 7 days |
| Request and error logs, per-call metrics | No more than 90 days |
| Support correspondence | Two years after the last message |
When we no longer need personal data we delete it or anonymise it. Where deletion from a backup is not immediately possible, the backup is overwritten on its normal cycle and the data is not restored from it.
9. Cookies and similar technologies
The Site sets no cookies. The App uses only cookies that are strictly necessary to run it: Clerk's session cookies, which keep you signed in and protect against cross-site request forgery, and which last until you sign out or the session expires. The App stores your theme preference in your browser's local storage. Neither is used for analytics or advertising, so no consent banner is shown. You can clear these through your browser, though the App will then sign you out. The Server sets no cookies; it authenticates each request by its bearer token.
10. Security
Everything in transit is encrypted with TLS. API keys are stored as SHA-256 hashes. Connected-account refresh tokens are encrypted at rest with AES-256-GCM under a key held in our hosting provider's secret store, separate from the database. Access to production systems is restricted to the people who operate the Service and protected by multi-factor authentication. Payment card details never touch our systems. No system is perfectly secure; if we learn of a breach that is likely to affect your rights, we will tell you and the ICO without undue delay, as the law requires.
11. Your rights
Under the UK GDPR you have the right to: access the personal data we hold about you; have it corrected if it is inaccurate; have it erased where we no longer need it or you object and we have no overriding reason to keep it; restrict how we use it while a question about it is resolved; receive a copy of the data you gave us in a portable format; object to processing we base on our legitimate interests, and to any direct marketing; and withdraw consent where we rely on it, without affecting what was done before.
You can see and change your account details, workspace, keys, connected accounts and billing in the App, and delete a workspace from its settings. For anything else, email [PRIVACY EMAIL]. We will reply within one month, and we may ask you to confirm your identity first. There is no fee unless a request is manifestly unfounded or excessive.
If you are unhappy with how we handle your data or your request, you can complain to the Information Commissioner's Office at ico.org.uk, by phone on 0303 123 1113, or by post to Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. We would appreciate the chance to resolve it first. If you are in the European Economic Area you may also complain to your local supervisory authority.
12. Children
The Service is not for anyone under 18, and we do not knowingly collect data from children. If you believe a child has given us personal data, contact us and we will delete it.
13. Changes to this policy
We will post any new version here with a new date and version number. If a change materially affects how we use your personal data, we will tell you by email or in the App at least 30 days before it takes effect.
14. Contact
[COMPANY NAME] LIMITED, [REGISTERED OFFICE ADDRESS]. Email: [PRIVACY EMAIL].
Adapted from the General Legal Privacy Policy (GDPR Enhanced) template, released under CC0 1.0, for a controller in the United Kingdom.