NewThe ManyPI MCP Server is now live

Legal

Privacy Policy

Processing of personal data for which ManyPI acts as controller.

Version 3.0 · Effective 1 October 2026

Overview

We do not sell personal data and do not use advertising or retargeting pixels. Our service providers, their processing locations and transfer safeguards are listed in §10; data locations and international transfers are described in §11.

Cookies, local storage and analytics are covered in §12, and your rights, including your right to object, in §14. The account settings provide data export and account deletion.

The following sections describe specific processing activities: §4 on connected mailbox access, §5 on Google access permissions and the Limited Use requirements, and §8 on the shared operational caches.

This policy covers ManyPI acting as controller. Personal data that you process in the Service as a Customer is covered by the Data Processing Agreement.

1.1

Scope. This Privacy Policy explains how ManyPI ("ManyPI", "we", "us", "our") processes personal data as a controller within the meaning of Article 4(7) GDPR, and gives the information required by Articles 13 and 14 GDPR. It applies to visitors to manypi.com, to users of the application at app.manypi.com and to anyone who contacts us.

1.2

Defined terms. In this policy:

  1. (a)
    "Service" means the ManyPI website, the ManyPI application and the related services we provide;
  2. (b)
    "Customer" means the business that has entered into the Terms of Service with us;
  3. (c)
    "you" means the person whose personal data is concerned or who uses the Service, except that, where this policy describes processing that we carry out as a processor, "you" means the Customer;
  4. (d)
    "Workspace" means a Customer's shared area within the Service (shown in some places as an organisation), whose content is visible to all of its members; and
  5. (e)
    "Contact Data" means personal data about the people a Customer researches, stores or contacts using the Service.
1.3

ManyPI as controller. This policy governs the processing whose purposes and means we determine ourselves, namely the processing of:

  1. (a)
    account, billing, usage and support data;
  2. (b)
    data collected for our own website and product analytics; and
  3. (c)
    data used for our own marketing communications.
1.4

ManyPI as processor. When a Customer uses the Service to import, research, enrich or store Contact Data, to keep CRM records, to synchronise a connected mailbox or to send campaigns, we process the personal data concerned on the Customer's documented instructions and for the Customer's purposes. The Customer is the controller and we are its processor under Article 28 GDPR. That processing is governed by the Data Processing Agreement, not by this policy. §§4 to 7 describe the relevant features for transparency, and §5 contains the disclosures that the Google API Services User Data Policy requires.

1.5

Operational caches. For the two shared operational caches described in §8, we determine the purposes and means of processing independently of our Customers. The caches may contain personal data of individuals who have no ManyPI account.

1.6

People contacted by a Customer. If you received a message that a Customer sent using the Service, that Customer is the controller of your personal data and the first point of contact for your rights. §3 of the Data Rights Notice explains how to exercise them and what we do when you contact us directly.

2.1

Controller. The controller is ManyPI, a sole proprietorship (Einzelunternehmen) under German law owned by Ole Nepomuk Mai:

  1. •
    ManyPI, Ole Nepomuk Mai
  2. •
    Goethestrasse 70, 10625 Berlin, Federal Republic of Germany
  3. •
    VAT ID: DE335582063
  4. •
    Telephone: +49 30 3977 0918
2.2

Contact for data protection matters. Write to privacy@manypi.com with any question about this policy or to exercise your rights under §14. Other legal matters may be sent to legal@manypi.com, and security vulnerabilities to security@manypi.com (clause 13.6).

2.3

Data protection officer. On our assessment, the conditions of Article 37(1) GDPR and § 38 BDSG for the mandatory designation of a data protection officer are not met, and we have not designated one. The owner handles data protection matters personally, at the contact details in clauses 2.1 and 2.2. If the conditions come to be met, we will designate a data protection officer, publish their contact details in this section and communicate them to the supervisory authority.

3.1

Overview. The table at the end of this section lists, for each processing activity for which we act as controller, the categories of personal data, the purposes, the legal basis and the retention period. §§4 to 12 describe particular activities in more detail.

3.2

Sources. We collect most personal data directly from you, when you register, use the Service, buy a plan or contact us. We receive other personal data from the following sources:

  1. (a)
    the payment provider through which you bought your plan (Stripe and Sold through Link, LLC, Polar or Lemon Squeezy), which shares order and billing data with us (§10);
  2. (b)
    Google, where you sign in with Google, which provides your Google account identifier, email address, name and profile picture;
  3. (c)
    the link through which you reached our sign-up page and your browser, which provide the campaign parameters, landing page and referring page recorded as sign-up attribution (clause 12.13); and
  4. (d)
    for the shared operational caches, the websites on which companies publish their contact details and the mail servers queried during email verification (clause 8.3).
3.3

Legitimate interests. Where the table names Article 6(1)(f) GDPR as the legal basis, the legitimate interests we pursue are:

  1. (a)
    operating a secure, available and reliable Service, and diagnosing and correcting faults;
  2. (b)
    keeping a verifiable record of internal access to production systems and investigating security incidents;
  3. (c)
    understanding how the Service is used and operated, through usage metering and server-side operational events (clause 12.7);
  4. (d)
    measuring which of our own marketing channels bring customers, and allocating our marketing expenditure accordingly;
  5. (e)
    responding to correspondence, documenting what was agreed and being able to establish, exercise or defend legal claims;
  6. (f)
    keeping a record of an unsubscribe or an objection, so that we do not contact you again; and
  7. (g)
    avoiding redundant lookups against third-party websites and mail servers, and the load they cause (§8).
3.4

Consent. Where the legal basis is your consent (Article 6(1)(a) GDPR), you may withdraw it at any time with effect for the future. Withdrawal does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal (Article 7(3) GDPR). §14 of this policy and §7 of the Cookie Policy explain how to withdraw.

3.5

Right to object. Where the legal basis is Article 6(1)(f) GDPR, you have the right to object to the processing on grounds relating to your particular situation. Clauses 14.2 and 14.3 set out that right in full.

3.6

Retention periods. Where the table states a period, it runs from the event that ends the need for the data, such as the closure of a support matter. Statutory retention periods under § 257 HGB and § 147 AO begin at the end of the calendar year in which the record was created. "For the life of the account" means until the account is deleted in accordance with §9.

DataProcessing purposeLegal basisRetention period
Account data: name, email address, password hash, profile picture, Workspace name and roleCreating and administering your account, authenticating you, providing supportArt. 6(1)(b) GDPR: performance of the contractFor the life of the account, then deleted (see §9)
Sign-in identifiers from Google, where you sign in with Google: Google account identifier, email address, name, profile pictureAuthenticating you without a separate passwordArt. 6(1)(b) GDPR: performance of the contractFor the life of the account
Billing data: name, email address, billing address, country, VAT ID and status, transaction, subscription and invoice history, as shared with us by our payment provider (see §10)Taking payment, managing subscriptions, issuing invoices, meeting tax and accounting obligationsArt. 6(1)(b) and (c) GDPR: performance of the contract and legal obligationUp to 10 years, as required by § 257 HGB and § 147 AO
Usage telemetry: features used, jobs run, tokens and credits consumed, error eventsMetering your plan and overage, capacity planning, diagnosing faultsArt. 6(1)(b) and (f) GDPR: performance of the contract and our legitimate interest in a working ServiceFor the life of the account; aggregated statistics may be kept longer
Sign-up attribution: campaign (utm) parameters, landing path, referring page, plan selected on the pricing pageMeasuring which of our marketing channels bring customers and allocating marketing expenditureArt. 6(1)(f) GDPR: our legitimate interest in measuring our own marketingFor the life of the account
Support requests and other correspondence you send usResponding to correspondence, documenting agreements, establishing or defending legal claimsArt. 6(1)(b) and (f) GDPR: performance of the contract and our legitimate interests (see clause 3.3)Up to 3 years after the matter is closed
Administrative access logs: actor, path, IP address, user agent, timeAccountability for internal access to production systems, security investigationArt. 6(1)(f) GDPR: our legitimate interest in a verifiable audit trail24 months
Server and request logs held by our hosting providers, including IP addressDelivering the website and app, preventing abuse, diagnosing faultsArt. 6(1)(f) GDPR: our legitimate interest in security and availabilityAs set by the hosting provider's log retention, typically days to weeks
Browser analytics (TWIPLA and PostHog): browser and session identifiers, page views, interactions, referring page, device and browser details, truncated IP address (TWIPLA); browser errors and masked replays where enabled; account ID, name and email when linked in the appUnderstanding website and product usage, diagnosing problems and improving navigationArt. 6(1)(a) GDPR and § 25(1) TDDDG: your consentDevice storage: see the Cookie Policy. Events and recordings: see §9. Browser collection stops when consent is withdrawn
PostHog server telemetry: app user ID, operational and conversion events, counts, plan metadata and error diagnosticsMonitoring the reliability of the Service and understanding how it is operated, separately from browser trackingArt. 6(1)(f) GDPR: our legitimate interest in operating and improving the Service; right to object under clause 14.2Only while needed for the stated operational purposes (see §9)
Marketing preferences and newsletter subscriptionSending the product communications to which you have subscribedArt. 6(1)(a) GDPR: your consent, which you can withdraw at any timeUntil you withdraw consent; a suppression record is then kept so that you are not added again (Art. 6(1)(f) GDPR)
Shared operational caches: published company contact details, email deliverability resultsAvoiding repeated identical lookups against third-party websites and mail serversArt. 6(1)(f) GDPR: our legitimate interest (see §8)Deleted automatically 30 days after the entry was last checked; removed earlier on request
4.1

Allocation of roles. The correspondence in a connected mailbox necessarily contains the personal data of other people. In respect of that data the Customer is the controller and we are its processor (clause 1.4). The Customer's obligations towards those people are set out in §14 of the Data Processing Agreement.

4.2

Access. If you connect a Gmail, Outlook or Microsoft 365 mailbox, or another IMAP mailbox, ManyPI can send messages from it and read messages in it. We access the mailbox over SMTP and IMAP, authenticated by OAuth or by credentials you supply.

4.3

Message headers. For the folders on an allowlist (by default, your inbox and sent items), we read the envelope headers of every message: sender, recipients, copied recipients, subject, date and size. We use the headers to identify the messages that relate to contacts in your Workspace.

4.4

Message bodies. We download and store the body of a message (plain text and HTML) only where at least one of its sender, recipient or copied addresses matches a contact that already exists in your Workspace. Any other message only advances our synchronisation position; it is not stored, and its body is never retrieved. When you add a contact, we may search your mailbox history for earlier correspondence with that address and store the matching messages. Bodies are stored in truncated form. Attachments are never stored.

4.5

Visibility within the Workspace. Stored messages are visible to every member of your Workspace. Anyone you add to the Workspace can read the synchronised correspondence in it. Take this into account before adding members, and before connecting a mailbox that carries confidential or private correspondence.

4.6

Default settings. Where a mailbox is connected with IMAP access, history synchronisation is enabled by default. You can disable synchronisation in the mailbox settings or use a sending-only configuration.

4.7

Disconnection and revocation. You can disconnect a mailbox at any time in the settings. Disconnection deletes the stored credentials and ends our access. You can also revoke our access in the security settings of your Google or Microsoft account. Disconnection stops future synchronisation but does not delete messages already stored; to remove them, delete them in the Service or delete your account (§9).

5.1

Purpose of this section. This section is our disclosure under the Google API Services User Data Policy. It applies if you sign in with Google or connect a Gmail or Google Workspace mailbox.

5.2

Scopes we request. We request the following scopes:

  1. (a)
    for sign-in, `openid`, `email` and `profile`, which give us your Google account identifier, email address, name and profile picture, so that we can create your account and authenticate you; and
  2. (b)
    for mailbox access, `https://mail.google.com/`, a restricted scope that grants full access to your Gmail mailbox, including the ability to read, compose, send and permanently delete messages. We request it because ManyPI connects to Gmail over standard SMTP and IMAP using OAuth, and Google grants that form of access only through this scope.
5.3

How we use Google user data. The access that the mailbox scope grants is broader than our use of it. We use Google user data only to:

  1. (a)
    create your account and authenticate you;
  2. (b)
    send the messages you instruct us to send from your mailbox;
  3. (c)
    read message headers in the folders on your allowlist, to identify replies, bounces and correspondence with your contacts;
  4. (d)
    download and store message bodies only under the conditions in clause 4.4;
  5. (e)
    classify the replies you receive, by sending an excerpt to our AI provider as described in clause 6.3(c); and
  6. (f)
    record which folder a message was in and how far synchronisation has progressed.
5.4

Operations we do not perform. We do not delete or modify messages, mark them as read, move them or empty folders.

5.5

Storage, sharing and deletion. We store Google user data in the European Union (§11). Credentials and OAuth tokens are additionally encrypted at the application layer (clause 13.2). We share Google user data only with the service providers needed to provide the features in clause 5.3, namely our hosting providers and, for reply classification, OpenAI, and only within the limits of clause 5.6. Stored messages are deleted when you delete them, your Workspace or your account (clause 4.7 and §9).

5.6

Limited Use. ManyPI's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements. In particular:

  1. (a)
    we use Google user data only to provide or improve user-facing features that are prominent in the user interface of the Service, as described in clause 5.3;
  2. (b)
    we transfer Google user data to others only where necessary to provide or improve those features and only with your consent, for security purposes (for example, investigating abuse), to comply with applicable law, or as part of a merger, acquisition or sale of assets of ManyPI after obtaining your explicit prior consent;
  3. (c)
    we do not allow humans to read Google user data unless we have first obtained your affirmative agreement to view specific messages, files or other data, it is necessary for security purposes (for example, investigating a bug or abuse), it is necessary to comply with applicable law, or the data (including derivations) is aggregated and used for internal operations in accordance with applicable privacy and other legal requirements;
  4. (d)
    we do not transfer, sell or use Google user data for serving advertisements, including retargeting, personalised or interest-based advertising;
  5. (e)
    we do not transfer or sell Google user data to third parties such as advertising platforms, data brokers or information resellers;
  6. (f)
    we do not transfer, sell or use Google user data to determine creditworthiness or for lending purposes; and
  7. (g)
    we do not transfer, sell or use Google user data to create, train or improve any machine-learning or artificial-intelligence model, whether generalised or personalised. Reply excerpts are sent to our AI provider only for the classification described in clause 6.3(c), under contractual terms that exclude their use for training.
5.7

Revoking access. You can disconnect the mailbox in the settings of the Service (clause 4.7), or remove ManyPI under third-party access on the security page of your Google Account. Revocation in your Google Account prevents us from obtaining further access to your mailbox.

5.8

Microsoft. The same commitments apply to data obtained from Microsoft where you connect an Outlook or Microsoft 365 mailbox.

6.1

AI features. The assistant, the research agent and the drafting features of the Service use artificial intelligence. We identify them as such at the point of use.

6.2

AI provider. OpenAI is our only provider of AI models. It processes the data described in clause 6.3 on our behalf. Transfers to it are covered by §11.

6.3

Data transmitted. We transmit to OpenAI only the data that a feature needs:

  1. (a)
    your instructions and questions to the assistant;
  2. (b)
    contact records supplied as context when you ask for a draft;
  3. (c)
    excerpts of the text of replies you receive, of up to about 1,200 characters, to classify their sentiment and intent;
  4. (d)
    the contents of files you upload for analysis; and
  5. (e)
    excerpts of web pages retrieved during research. Full pages are processed on our own infrastructure, and only the relevant excerpts are sent onward.
6.4

No training. We do not use your data, or the personal data of your contacts, to train, fine-tune or otherwise improve any AI model, whether our own or a third party's. Our contract with OpenAI prohibits it from using data submitted through its API to train its models.

6.5

Accuracy and human review. AI output is generated on a probabilistic basis. It can be inaccurate, outdated or fabricated, including about named individuals. It supports human judgement and does not replace it. Users must review it before relying on it, and in particular before sending it to anyone (§8 of the Terms of Service).

6.6

Scoring of contacts. The Service scores and ranks contacts to help users decide whom to approach first. The decision remains with the user. The scoring produces no legal effects concerning the person scored and does not similarly significantly affect them, and is therefore not a decision within the meaning of Article 22 GDPR. §8 of the Terms of Service prohibits using the Service to make, or materially to inform, decisions of that kind.

6.7

No automated decisions about you. We do not take decisions about you that are based solely on automated processing and produce legal effects concerning you or similarly significantly affect you (Article 22 GDPR).

7.1

Allocation of roles. Outreach, open tracking and email verification process Contact Data. The Customer is the controller and we are its processor, and the Data Processing Agreement governs the processing. This section describes the functions for transparency.

7.2

Sending. Outreach is sent from the Customer's own mailbox. ManyPI does not relay these messages through mail servers of its own. The Customer is the sender identified to recipients and their mail providers.

7.3

Open tracking. Where open tracking is enabled, we add a one-pixel image to outgoing messages. When the image is loaded, we record that the message was opened by incrementing a counter. We do not record the recipient's IP address or user agent for this purpose. Open tracking can be disabled for each campaign. Where the law that applies to a recipient requires notice or consent for open tracking (in Germany, for example, under § 25(1) TDDDG), providing it is the responsibility of the Customer as sender.

7.4

Unsubscribe and suppression. Messages carry an unsubscribe link and standard one-click unsubscribe headers. An unsubscribe, a hard bounce or a complaint adds the address to the suppression list of the Workspace concerned, which blocks further messages to it from every campaign in that Workspace. Suppression lists are kept per Workspace; there is no suppression list that applies across the Workspaces of different Customers.

7.5

Requests made directly to ManyPI. If you received a message sent through the Service and ask us directly to stop further contact, we add your address to the suppression list of the Workspace from which the message was sent and inform the Customer, under the standing instruction in §7 of the Data Processing Agreement. This does not prevent other Customers from contacting you. §3 of the Data Rights Notice explains the procedure and its limits.

7.6

Email verification. To check whether an address is likely to be deliverable, our infrastructure opens a connection to the mail server responsible for it and begins the delivery handshake far enough to learn whether the mailbox exists, then stops before any message is sent. No message reaches the recipient. We record only the outcome and the server's response code. Verification runs from dedicated infrastructure and is rate-limited per domain, so as not to burden the servers we query. The results are also kept in the deliverability cache described in §8.

8.1

The caches. To avoid repeated requests to public websites and mail servers, and to maintain the performance of the Service, we keep two caches that are shared across all Customers:

  1. (a)
    published company contact details, keyed by website domain: email addresses, telephone numbers, named roles and links to social media profiles, as published by a company on its own website; and
  2. (b)
    email deliverability results, keyed by email address: whether the mailbox was found to exist, the reason for that result and the response code of the responding mail server.
8.2

ManyPI as controller. We are the controller for both caches, independently of our Customers (§13 of the Data Processing Agreement). The caches may contain personal data of individuals who do not use ManyPI, for example an employee whose business email address a company publishes on its website.

8.3

Sources. The data in the company contact cache is taken from companies' own websites, which are publicly accessible. The data in the deliverability cache comes from the responses of the mail servers queried during email verification (clause 7.6).

8.4

Legal basis. We rely on Article 6(1)(f) GDPR. Our legitimate interest, which the operators of the systems queried share, is to avoid redundant lookups and to reduce the load on their infrastructure and ours. We have carried out and documented a balancing of that interest against the interests of the people concerned.

8.5

Safeguards. The following safeguards apply:

  1. (a)
    entries are not used, and are deleted automatically, thirty (30) days after they were last checked; some kinds of result are used for a shorter period;
  2. (b)
    no Customer account can browse or search the deliverability cache; only internal service processes can reach it, and a Customer receives only the result for an address it has itself submitted for verification, so that the cache cannot be used to test whether arbitrary email addresses exist;
  3. (c)
    an entry in the company contact cache is returned to a Customer whose research concerns that domain, in place of retrieving the company's website again;
  4. (d)
    neither cache records which Customer or user performed a lookup; and
  5. (e)
    neither cache is used to build profiles of individuals, and neither is otherwise disclosed, sold or licensed.
8.6

Information to the people concerned. We do not inform each person whose data is in the caches individually. Doing so would require us to contact people with whom we have no relationship, using data held only for the purposes in clause 8.1, and would involve disproportionate effort within the meaning of Article 14(5)(b) GDPR. We make the information in this section publicly available instead.

8.7

Your rights. You can request access to, rectification or erasure of, or restriction of the processing of, data about you in either cache, or object to its processing (clause 14.2), by writing to privacy@manypi.com. We handle these requests ourselves, without involving any Customer and without requiring a Customer's authorisation. §4 of the Data Rights Notice gives further information.

9.1

Principle. We keep personal data only for as long as one of the following grounds applies, and delete it when none does:

  1. (a)
    contractual necessity: the data is needed to provide the Service to you, which lasts for the life of your account;
  2. (b)
    legal obligation: the law requires us to keep the data, principally invoices and accounting records, which German commercial and tax law (§ 257 HGB, § 147 AO) requires us to retain for up to ten years;
  3. (c)
    legitimate interest: for example, keeping an access log long enough to investigate an incident, or keeping a suppression record so that someone who has unsubscribed is not added back; or
  4. (d)
    consent: until you withdraw it.
9.2

Specific periods. The table in §3 states the retention period for each category of data.

9.3

Statutory retention. Data that we keep only to meet a statutory retention obligation is restricted to that purpose and deleted when the period expires.

9.4

PostHog analytics and diagnostics. The storage periods in the Cookie Policy apply to your device; they are not the retention period for data already sent to PostHog. Events, person profiles and session recordings are subject to the retention settings of our PostHog project. We keep them only while they are needed to analyse usage or investigate faults, taking into account the age and relevance of the information, unresolved incidents and any request for erasure. You can ask for the current retention settings, or request erasure, at privacy@manypi.com. Withdrawing consent in the browser stops new browser collection and clears analytics storage on the current site; it does not erase data already collected and does not affect the server-side events described in clause 12.7. We handle requests for erasure and objections under §14.

9.5

Account deletion. Deleting your account in the account settings ends the agreement and constitutes an instruction to delete Customer Data without an export window (§12 of the Terms of Service). Deletion takes effect immediately and removes from our production database:

  1. (a)
    your profile and your sign-in;
  2. (b)
    every Workspace you own, together with the lead, CRM, outreach and mailbox data, stored credentials and files in it; and
  3. (c)
    your memberships of Workspaces owned by other users.
9.6

Workspaces of other users. Workspaces owned by other users, and the data in them, are not deleted with your account and remain under their owners' control.

9.7

Conditions for account deletion. Account deletion is not available while you own a Workspace that other people use, or while a paid subscription is active. Transfer the Workspace or remove its other members, or cancel the subscription, first. These conditions prevent other members' work from being deleted with your account and prevent charges after deletion.

9.8

Data not removed by account deletion. The following data is not removed by account deletion:

  1. (a)
    data we are legally required to keep, principally billing records, which we retain only for that purpose and delete when the period expires (clause 9.3);
  2. (b)
    entries in the shared operational caches (§8), which are not linked to your account and which you can have removed on request (clause 8.7); and
  3. (c)
    data that our service providers hold in their own systems on our behalf, in particular analytics data at PostHog (clause 9.4) and your entry in the contact list of our email delivery provider, which you can have erased by writing to privacy@manypi.com.
9.9

Termination without account deletion. Where the agreement ends without the account being deleted, §13 of the Terms of Service applies: Customer Data remains available for export for thirty (30) days and is then deleted from our production systems, or earlier on your instruction.

9.10

Backups. We keep encrypted backups on a rolling cycle for disaster recovery. Data deleted from production systems remains in backups until they are overwritten, and in any event for no longer than 90 days. During that time it is not accessible in ordinary operation and is used only to restore the Service.

9.11

Export before deletion. Deletion cannot be undone. Export your data before you delete your account, using the export function in the settings and the separate export for your contact records.

10.1

No sale and no advertising. We do not sell personal data and do not disclose it for advertising purposes. We do not use advertising or retargeting pixels.

10.2

Service providers. Service providers process personal data on our behalf under written agreements that meet the requirements of Article 28 GDPR. The table at the end of this section lists each provider with its purpose, location and transfer safeguard. The current list is maintained in §1 of the Sub-processor List, which also forms Annex III of the Data Processing Agreement. Where a provider also acts as an independent controller, this section says so.

10.3

Payments. New purchases are processed through Stripe Managed Payments, a service of Stripe, Inc. Stripe's affiliate Sold through Link, LLC is the merchant of record. You enter your payment details directly with Stripe; ManyPI never receives your card details. Stripe and Sold through Link, LLC process checkout, payment, fraud-prevention, tax and transaction-support data as independent controllers under the Stripe Privacy Policy (stripe.com/privacy) and the Link Privacy Policy (link.com/privacy). Stripe also holds our customer and subscription records as our processor.

10.4

Data we receive from the payment provider. Stripe and Sold through Link, LLC share the order data with us: your name, email address, billing address, country, tax ID and the details of the transaction. We process it as described in §3.

10.5

Deletion of a Link account. If you ask Link to delete your Link account, Link cancels any subscription it bills and deletes the order data it holds. Records that we keep under our own statutory retention obligations are not affected.

10.6

Earlier subscriptions. Subscriptions bought earlier through Polar, and legacy subscriptions on Lemon Squeezy, continue to be billed by those providers.

10.7

Other members of your Workspace. Members of a Workspace can see the names, email addresses, profile pictures and roles of the other members, and the content shared in the Workspace, including synchronised mail (clause 4.5).

10.8

Customer-configured integrations. Integrations that a Customer connects, such as a CRM, a project tracker or a custom MCP server, are not our sub-processors. The Customer chooses them and directs the data flow, and is the controller of it (§3 of the Sub-processor List).

10.9

Public authorities. We disclose personal data to a public authority only where we are legally obliged to do so. Where we may lawfully do so, we notify you before the disclosure, and we challenge requests that appear unlawful or excessive.

10.10

Business transfer. If the business is sold or reorganised, personal data may be transferred to the acquirer on the basis of our legitimate interest in the transfer of the business (Article 6(1)(f) GDPR). We will notify you before the transfer and before any change of purpose, and your rights under this policy remain unaffected. Google user data is transferred only as clause 5.6 permits.

ProviderLegal entityPurposeLocationSafeguard
SupabaseSupabase, Inc.Primary database, authentication, file storage and serverless functions. The ManyPI project is provisioned in an EU region.Singapore (company seat); data stored in the European UnionEEA, no transfer
HetznerHetzner Online GmbHVirtual servers running the background job worker, the email verification engine and the web data collection gateway.Germany and FinlandEEA, no transfer
NetlifyNetlify, Inc.Application and website hosting, content delivery, TLS termination.United StatesEU-US Data Privacy Framework and EU Standard Contractual Clauses
OpenAIOpenAI, L.L.C.All AI model inference: research agent reasoning, drafting assistance, structured extraction, and classification of inbound replies. OpenAI is contractually prohibited from training on data submitted through the API.United StatesEU-US Data Privacy Framework and EU Standard Contractual Clauses
Bright DataBright Data Ltd.Web search, page retrieval and proxy infrastructure used to collect publicly accessible business information.IsraelAdequacy decision
Stripe Managed PaymentsStripe, Inc., with its affiliate Sold through Link, LLC as merchant of recordMerchant of record for new purchases: checkout, payment processing, subscription and seat billing, metered overage billing, invoices and receipts, indirect tax, fraud prevention, refunds, disputes and transaction support through Link. Stripe and Sold through Link, LLC act as independent controllers for the sale, fraud prevention and tax, and Stripe as our processor for the customer and subscription records it holds for us.United States; Stripe's European entities in IrelandEU-US Data Privacy Framework and EU Standard Contractual Clauses
PolarSubscriptions purchased through PolarPolar Software Inc.Merchant of record for subscriptions purchased through Polar, which continue to be billed by Polar: subscription management, customer billing portal and metered overage billing.United StatesEU-US Data Privacy Framework and EU Standard Contractual Clauses
Lemon SqueezyLegacy subscribers onlySold through Link, LLC (formerly Lemon Squeezy LLC)Legacy merchant of record through the Lemon Squeezy platform. Engaged only for subscribers who purchased before our migration to Polar and have not since re-subscribed. The company is now a Stripe affiliate.United StatesEU-US Data Privacy Framework and EU Standard Contractual Clauses
ResendPlus Five Five, Inc.Delivery of the transactional, service and lifecycle email that ManyPI sends to you, and maintenance of the corresponding contact list. Also delivers workflow emails you configure without connecting your own SMTP server, and notifications about finished agent runs. Outreach campaigns are not sent through Resend: they leave your own mailbox.United StatesEU-US Data Privacy Framework and EU Standard Contractual Clauses
GoogleSign-in with Google, or a connected Gmail mailboxGoogle Ireland Limited / Google LLCSign-in with Google. Separately, where you choose to connect a Gmail or Google Workspace mailbox, access to that mailbox over SMTP and IMAP using OAuth.Ireland / United StatesEU-US Data Privacy Framework and EU Standard Contractual Clauses
MicrosoftOnly if you connect a Microsoft mailboxMicrosoft Ireland Operations Limited / Microsoft CorporationWhere you choose to connect an Outlook or Microsoft 365 mailbox, access to that mailbox over SMTP and IMAP using OAuth.Ireland / United StatesEU-US Data Privacy Framework and EU Standard Contractual Clauses
TWIPLAOnly with your analytics consentTWIPLA GmbHWebsite and in-app analytics. Loaded only after you accept the analytics category in our cookie banner, and never before.GermanyEEA, no transfer
PostHogBrowser tracking only with analytics consent; app server telemetry operates separatelyPostHog, Inc.Website and app product analytics, browser error tracking and masked session replay where enabled, only after analytics consent. Separately, server-side operational events and error diagnostics from the app.United States (company); EU project hosted in Frankfurt, Germany; international access may occurEU-US Data Privacy Framework and EU Standard Contractual Clauses
Simple AnalyticsSimple Analytics B.V.Aggregate, cookieless traffic measurement for the marketing website. Sets no cookies and stores nothing on your device.NetherlandsEEA, no transfer
ContentfulContentful GmbHContent management for the marketing website and blog. Holds no customer data.GermanyEEA, no transfer
11.1

Primary locations. Your account data, CRM records, lead records and synchronised mail are stored on servers located in the European Union. In particular:

  1. •
    Primary database, authentication and file storage: European Union (Supabase, EU region)
  2. •
    Background processing, email verification and the research gateway: Germany and Finland (Hetzner Online GmbH)
11.2

Providers outside the EEA. These are the locations of our primary storage and background infrastructure. They do not mean that every service provider processes data only within the European Economic Area. Personal data is transferred to a third country where a function requires a provider established there: in particular for website hosting and content delivery, AI inference, payment processing, the delivery of our own service email and, where you use them, sign-in with Google and mailbox connectivity (United States), and for web data collection (Israel). The table in §10 states the safeguard relied on for each provider.

11.3

United States. For recipients in the United States, we rely on the adequacy decision for the EU-US Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795) where the recipient is certified under the Framework. In addition, the recipient's data processing terms contain the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914).

11.4

Reason for retaining the Standard Contractual Clauses. We retain the Standard Contractual Clauses alongside the Data Privacy Framework so that a recognised transfer mechanism remains in place for a recipient that is not, or ceases to be, certified, and in case the Framework is invalidated or suspended, as the Court of Justice of the European Union invalidated its predecessors, Safe Harbor (2015) and the Privacy Shield (2020). Where a transfer relies on the Standard Contractual Clauses, we have assessed, as Clause 14 of those clauses requires, whether the law and practice of the country of destination could prevent the recipient from complying with them.

11.5

Israel. For transfers to Bright Data in Israel, we rely on the adequacy decision of the European Commission for Israel (Commission Decision 2011/61/EU).

11.6

PostHog. Our PostHog project is hosted in Germany (PostHog Cloud EU, Frankfurt). PostHog, Inc. is a US company, and EU hosting does not exclude support or administrative access from outside the EEA. PostHog's data processing terms cover such transfers through the Data Privacy Framework, where applicable, and the Standard Contractual Clauses.

11.7

Copies of the safeguards. You can obtain a copy of the safeguards in place for a specific transfer by writing to privacy@manypi.com. The Commission decisions referred to in this section, including the Standard Contractual Clauses, are published in the Official Journal of the European Union.

12.1

Consent before use. We use technologies that require consent under § 25(1) TDDDG only after you have given that consent. The Cookie Policy lists every cookie and storage item, with its purpose and storage period.

12.2

Storage without consent. Without your consent, only the following are stored on your device, as described in §2 of the Cookie Policy:

  1. (a)
    in the app, your authentication session;
  2. (b)
    your cookie consent record and your PostHog opt-in or opt-out choice; and
  3. (c)
    in the app, local storage entries that remember interface settings, such as your preferred view mode.
12.3

Consent-based analytics. With your analytics consent we load TWIPLA and initialise PostHog on the website and in the app. PostHog records page views, interactions, browser and session identifiers, device and browser information and browser errors. TWIPLA records the pages viewed, the referring page, device and browser characteristics and a truncated IP address.

12.4

Session replay. Where Session Replay is enabled, PostHog records how a page changes and how it is used. Page text, input values and element attributes are masked; images, video and canvas elements are blocked; and console logs, request headers and request bodies are not recorded. These measures reduce the exposure of content, but diagnostic details may still contain personal data.

12.5

Linking of activity. The same PostHog project covers manypi.com and app.manypi.com, so consented activity on both can be joined. In the app we associate consented activity with your account ID and, where available, your name and email address. These analytics are therefore not anonymous. We do not deliberately attach lead records, mailbox content, research output or uploaded documents to analytics events.

12.6

Withdrawal of analytics consent. Withdrawing consent stops browser tracking, opts you out of PostHog, removes analytics cookies and PostHog storage on the current site, and reloads the page. A page cannot erase browser storage that belongs to another site; your decision is applied there when that site next loads, and analytics does not start. PostHog's opt-out record may remain so that your choice is respected. Clause 9.4 explains what happens to data already collected.

12.7

Server-side operational events. Independently of the browser, the app's servers send PostHog operational events for actions such as creating workflows, starting agent runs, checkout and subscription changes, together with error diagnostics. These events use your account ID and limited event metadata, do not use cookies or other storage on your device and do not depend on your consent decision. We rely on our legitimate interest in monitoring the reliability of the Service and understanding how it is operated (Article 6(1)(f) GDPR). You can object under clause 14.2; the "Reject all" option in the cookie banner does not control this processing.

12.8

Cookieless measurement. On the marketing website we use Simple Analytics for aggregate traffic counts. It sets no cookies and stores nothing on your device. We rely on our legitimate interest in knowing how much traffic the website receives (Article 6(1)(f) GDPR). §4 of the Cookie Policy gives details.

12.9

Sign-in with Google. On the marketing website we offer Google's One Tap sign-in prompt, as a separate consent category in the cookie banner. Only if you accept that category does the website load Google's sign-in client, which connects your browser to Google's servers, and check with app.manypi.com whether you are already signed in (§ 25(1) TDDDG and Article 6(1)(a) GDPR). If you sign in through the prompt, Google provides us with your Google account identifier, email address, name and profile picture, which we use to create or authenticate your account (Article 6(1)(b) GDPR). §5 of the Cookie Policy describes the prompt and the storage it uses.

12.10

Technologies not used. We do not use Google Analytics, or advertising or retargeting pixels.

12.11

Legal bases. Storage of information on your device, and access to it, that is strictly necessary to provide a service you have expressly requested is based on § 25(2) no. 2 TDDDG; all other storage and access requires your consent under § 25(1) TDDDG. The subsequent processing of personal data is based on Article 6(1)(a) GDPR for consent-based analytics and for Google's sign-in prompt, and otherwise on the legal bases stated in the table in §3.

12.12

Your choices. You can change your choices at any time through "Cookie settings" in the footer of the website or in the account menu of the app, as described in §7 of the Cookie Policy.

12.13

Sign-up attribution. If the link that brought you to our sign-up page carried campaign (utm) parameters, we record them, together with the page on which you landed, the referring page reported by your browser and the plan you selected, with your account. For a sign-up with Google, this information travels in the address of the sign-in redirect; for a sign-up by email, it is stored with your pending account. Nothing is stored on your device for this purpose. We use it to measure our own marketing channels (Article 6(1)(f) GDPR; see the table in §3).

13.1

Encryption in transit. Data is encrypted in transit using TLS.

13.2

Encryption at rest. Data is encrypted at rest at the storage layer by our hosting providers. Credentials for third-party systems (mailbox passwords, OAuth access and refresh tokens and integration tokens) are additionally encrypted at the application layer with AES-256-GCM, using a key held only in the runtime environment. In production the application does not start without that key and does not fall back to a default. Passwords for database connections that you configure are held in a dedicated secrets vault.

13.3

Tenant isolation. Tenant isolation is enforced in the database engine through row-level security, so that a query made with one Customer's credentials cannot return another Customer's records, even if the application layer were bypassed. The most sensitive tables are additionally closed at the level of database grants, so that two independent controls would have to fail before they were exposed.

13.4

Internal access. Access to production systems is limited to the owner and individually authorised personnel (employees or contractors) bound by written confidentiality obligations. It is controlled by a credential held outside the database, so that no write to the database can grant it and a change of email address cannot escalate privileges. Every access is logged with the actor, path, IP address, user agent and time, and every administrative write additionally requires a one-time code delivered through a separate channel.

13.5

Personal data breaches. If a personal data breach occurs, we notify the competent supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons (Article 33 GDPR). Where the breach is likely to result in a high risk to your rights and freedoms, we also inform you without undue delay, unless one of the conditions in Article 34(3) GDPR applies (Article 34 GDPR). Where a breach affects personal data that we process as a processor, we notify the Customer in accordance with §8 of the Data Processing Agreement.

13.6

Reporting vulnerabilities. Please report security vulnerabilities to security@manypi.com. We will not take legal action against a researcher who reports a vulnerability to us in good faith.

14.1

Your rights. Under the GDPR, and subject to the conditions of each provision, you have the right:

  1. (a)
    of access to your personal data (Article 15);
  2. (b)
    to rectification of inaccurate personal data (Article 16);
  3. (c)
    to erasure (Article 17);
  4. (d)
    to restriction of processing (Article 18);
  5. (e)
    to data portability, for personal data you have provided to us and that we process by automated means on the basis of consent or contract (Article 20);
  6. (f)
    to object to processing (Article 21), as set out in clauses 14.2 and 14.3;
  7. (g)
    to withdraw consent at any time, with effect for the future (Article 7(3)); and
  8. (h)
    not to be subject to a decision based solely on automated processing that produces legal effects concerning you or similarly significantly affects you (Article 22).

Right to object under Article 21 GDPR

14.2

Objection on grounds relating to your particular situation. Where we process your personal data on the basis of Article 6(1)(f) GDPR (legitimate interests), you have the right to object to that processing at any time, on grounds relating to your particular situation, including to profiling based on that provision. This applies in particular to the activities that the table in §3 bases on legitimate interests, to the server-side operational events in clause 12.7, to cookieless measurement under clause 12.8 and to the shared operational caches in §8. If you object, we will no longer process the personal data concerned unless we demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.

14.3

Objection to direct marketing. Where we process your personal data for direct marketing, you have the right to object at any time to that processing, including to profiling to the extent that it is related to such direct marketing. If you object, we will no longer process your personal data for that purpose. You do not need to give reasons.

14.4

How to object. You can object informally, for example by email to privacy@manypi.com. For marketing emails you can also use the unsubscribe link in each email or the notification settings in your account.

Exercising your rights

14.5

How to make a request. You can export your data and delete your account in the account settings, manage your marketing preferences in the notification settings and change your cookie choices through "Cookie settings". For any other request, write to privacy@manypi.com.

14.6

Time limits and charges. We respond within one month of receiving your request. We may extend that period by up to two further months where necessary, taking into account the complexity and number of requests; if we do, we will tell you within the first month and give our reasons. Requests are free of charge unless they are manifestly unfounded or excessive (Article 12(3) and (5) GDPR).

14.7

Verification of identity. Where we have reasonable doubts about the identity of the person making a request, we may ask for the additional information necessary to confirm it, and no more (Article 12(6) GDPR).

14.8

Further information. The Data Rights Notice explains the procedures for exercising your rights in more detail. §3 of the Data Rights Notice explains the procedure for people contacted by a Customer.

14.9

Right to lodge a complaint. You can raise any complaint with us at privacy@manypi.com. This does not affect your right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, your place of work or the place of the alleged infringement (Article 77 GDPR). The supervisory authority competent for ManyPI is:

  1. •
    Berliner Beauftragte für Datenschutz und Informationsfreiheit
  2. •
    Alt-Moabit 59-61, 10555 Berlin, Germany
  3. •
    Telephone: +49 30 13889-0
  4. •
    https://www.datenschutz-berlin.de
15.1

Data required to conclude the contract. To create an account, you must provide an email address and either a password or a Google account for sign-in. This data is necessary to conclude and perform the contract; without it we cannot create an account or provide the Service.

15.2

Data required for a purchase. To buy a paid plan, you must provide payment details and billing information, such as your billing address and, where applicable, your tax ID, to the merchant of record (clause 10.3), which needs part of this information to meet its tax obligations. Without it the purchase cannot be completed. The Free Plan remains available without payment details.

15.3

No statutory obligation. Apart from clause 15.2, you are under no statutory obligation to provide personal data to us.

15.4

Optional data. All other data is optional. Declining analytics consent or marketing communications, or leaving an onboarding question unanswered, does not affect your access to the Service or the price you pay. Connecting a mailbox is also optional; without a connected mailbox, the features that send from or read a mailbox are not available.

16.1

Business users only. The Service is a business tool offered only to businesses. It is not directed at children, and we do not knowingly process the personal data of anyone under 18.

16.2

Deletion. If you believe that a child has provided us with personal data, write to privacy@manypi.com and we will delete it.

16.3

Customer obligation. §6 of the Terms of Service prohibits Customers from processing the personal data of children through the Service.

17.1

Reasons for changes. We update this policy to reflect changes in applicable law, in the Service or in our processing activities, and to correct or clarify its provisions.

17.2

Material changes. For a material change that affects your rights or how we use your personal data, we give at least thirty (30) days' notice by email to the address of your account and by updating the version and effective date at the top of this page. Corrections and clarifications that do not change how we process personal data take effect on publication.

17.3

Consent. Where a change requires your consent, we obtain it before the processing concerned begins. Silence does not constitute consent.

17.4

Version history.

  1. •
    Version 3.0 (1 October 2026): divides the policy into numbered clauses; names Stripe Managed Payments, with Sold through Link, LLC as merchant of record, as the payment provider for new purchases and describes the payment data shared with us; aligns the transfer safeguards with the provider table (Data Privacy Framework and Standard Contractual Clauses for the United States, adequacy decision for Israel); sets out the right to object separately; aligns the breach notification wording with Articles 33 and 34 GDPR; adds the legitimate interests pursued, the sources of data and the information on the shared caches required by Article 14 GDPR; describes account deletion, its conditions and the data it does not remove; states that suppression applies per Workspace; completes the Google Limited Use disclosures; places Google's sign-in prompt behind a separate consent category; records sign-up attribution without storing anything on your device; deletes entries in the shared caches automatically after thirty days; and corrects the statement of required data for the Free Plan.
  2. •
    Version 2.1.1 (14 September 2026): revised the wording without changing the processing activities described.
  3. •
    Version 2.1 (14 September 2026): added PostHog and disclosures concerning browser consent, server telemetry, storage and replay.
  4. •
    Version 2.0 (5 September 2026): revised the processing, provider and retention disclosures and added information on mailbox synchronisation, Google access permissions, AI processing, email verification and shared caches.
17.5

Previous versions. Previous versions of this policy are available on request at privacy@manypi.com.

Contact

Privacy: privacy@manypi.com
Legal: legal@manypi.com
Security: security@manypi.com

ManyPI, Ole Nepomuk Mai, Goethestrasse 70, 10625 Berlin, Federal Republic of Germany

We already know your next customer

Describe your ideal customer. ManyPI finds validated leads, reaches out, and turns emails into sales.