This is a draft policy and hasn’t been reviewed by a lawyer — do not rely on it for a live product handling real user data.
Company
Privacy Policy
Last updated: draft — no fixed date until this is finalized.
What Manila is
Manila is a tool that lets a freelancer or small business (the “account holder”) build a request for files, documents, or short answers, and send it to a client as a single link. The client fills it in without creating an account of their own. This policy covers both account holders and the clients who use a request link.
What we collect
- Account data: the email and password used to sign up (handled by Supabase Auth), plus a display name, brand color, and optional logo you add to your profile.
- Request data: the titles, field labels, and settings you create when building a request, and any client label or client email you attach to it.
- Client submissions: whatever a client uploads or answers through a request link — files, short or long text answers, yes/no responses, or a submitted link.
How it’s used
Collected data is used only to run the product: authenticating you, storing and displaying your requests, delivering uploaded files back to you, and showing status as a client completes a request. We do not use request or submission content for advertising, and we do not sell any of this data to third parties.
Where it’s stored
Account records, request data, and uploaded files are stored with Supabase (database, authentication, and file storage). Notification emails are sent through Resend. When paid plans are available, payment processing will be handled by a third-party processor such as Stripe — Manila itself never stores full card details.
Client request links
A request link works like a password: anyone who has it can open and submit the request it belongs to, without a separate login. Account holders are responsible for sharing request links only with their intended client. If a link is shared more widely than intended, treat it as compromised and contact us to have it reset.
Cookies
Manila uses a session cookie, set by Supabase Auth, to keep you signed in between visits. There is no third-party advertising or analytics tracking on the site at this time.
Data retention and deletion
We don’t yet have a formal, automated retention schedule. If you want your account, your requests, or a client’s submitted data deleted, email us and we’ll handle it manually.
Who’s responsible for what
Manila is infrastructure for the account holder’s own client relationships — we are not a party to those relationships. Account holders are responsible for having a lawful basis to request the information and files they ask their clients for, and for how they use whatever is submitted back to them.
Changes to this policy
This policy will change as the product does. Material changes will be reflected on this page; there is no separate notification mechanism yet.
Contact
Questions about this policy can go to medhansh.builds@gmail.com.