NewThe ManyPI MCP Server is now live

Privacy Policy

How we collect, use, and protect your personal information. Last updated November 15, 2025.

TL;DR

Privacy in a nutshell

We know privacy policies can be long and complex. Here's a quick summary of the most important points before you dive into the full details below.

We protect your data

Your data is encrypted in transit and at rest. We use industry-standard security measures.

We do not sell your data

We never sell your personal information to third parties. Your data is yours.

Minimal data collection

We only collect what's necessary to provide and improve our services.

You can delete anytime

Request deletion of your data at any time. We'll process it within 30 days.

Export your data

Download all your data in a portable format whenever you want.

GDPR & CCPA compliant

We comply with major privacy regulations including GDPR and CCPA.

Table of Contents

Most Searched

Quick answers to the most common privacy questions

Reading progress: 0%

For the purposes of this privacy policy:

Personal Data: Any information relating to an identified or identifiable natural person.

Controller: The entity that determines the purposes and means of processing personal data. ManyPI (Ole Nepomuk Mai) is the controller of your personal data.

Processor: An entity that processes personal data on behalf of the controller.

Services: Our website, API, and related services collectively.

GDPR: General Data Protection Regulation (EU) 2016/679.

User/You: The individual accessing or using our Services.

The data controller responsible for your personal data is:

Company: ManyPI

Owner: Ole Nepomuk Mai

Address: Goethestrasse 70, 10625 Berlin, Federal Republic of Germany

Email: legal@manypi.com

Data Protection Officer: dpo@manypi.com

For any questions regarding data protection, privacy concerns, or to exercise your rights, please contact us using the information above.

We collect and process the following categories of personal data:

Account Information: Name, email address, company name, password (encrypted), and account preferences.

Usage Data: API requests, features used, pages visited, timestamps, and interaction patterns.

Device Information: Hardware model, operating system, browser type, IP address, and unique device identifiers.

Payment Information: Billing address and payment method details (processed by our payment data processors).

Communications: Content of messages, support tickets, and feedback you provide to us.

Technical Data: Log files, error reports, and performance metrics.

We process your personal data for various purposes, each with a specific legal basis under GDPR Article 6. Below is a detailed breakdown of how we use your data and the legal justification for each purpose.

Legal Basis for Processing

Under data protection law, we must have a legal basis for processing your personal data. The table below outlines our purposes and the corresponding legal bases:

PurposeLegal BasisDescription
Provision and operation of the ServiceArt. 6(1)(b) - Contract performanceTo fulfill our contractual obligations to you, enabling access to and functioning of the Service.
Payment and billingArt. 6(1)(b), (f) - Contract performance and legitimate interestTo process subscriptions and payments securely and prevent fraud.
Service notifications and updatesArt. 6(1)(b), (f)To inform you of Service changes, new features, or security alerts.
Usage monitoring and securityArt. 6(1)(f) - Legitimate interestTo monitor service usage patterns, prevent unauthorized access, and enhance security.
Compliance with applicable lawsArt. 6(1)(c) - Legal obligationTo meet statutory requirements, tax obligations, and law enforcement requests.

If you upload images or visual content to our Services:

Processing: Images may be processed using AI and machine learning technologies to extract data, analyze content, or provide requested services.

Storage: Images are stored securely on our servers or with our cloud storage providers for the duration necessary to provide the Services.

Third-Party Processing: Images may be processed by our AI service providers (OpenAI, Google Gemini) as listed in our subprocessors section.

Retention: Images are retained according to our data retention policy unless you request earlier deletion.

Your Control: You can delete uploaded images at any time through your account settings or by contacting us.

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected:

Account Data: Retained for the duration of your account plus 90 days after deletion.

Usage Data: Retained for up to 2 years for analytics and service improvement.

Payment Records: Retained for 7 years to comply with tax and accounting requirements.

Communications: Retained for up to 3 years for customer service purposes.

Images and Uploaded Content: Retained until you delete them or close your account.

You can request deletion of your data at any time by contacting us. We will process your request within 30 days, subject to legal data retention requirements.

We work with trusted third-party service providers (data processors) to help us provide and improve our Services. Below is a comprehensive list of our subprocessors, including their legal information and the purposes for which we use them.

All subprocessors are carefully vetted and required to maintain appropriate security measures and comply with applicable data protection laws, including GDPR where applicable.

ServiceLegal NameAddressPurposeLegal BasisPrivacy Policy
PolarPolar Software Inc.3500 South DuPont Highway, Dover, DE 19901, USAPayment processing, subscription management, and merchant of record servicesContractual necessity (Art. 6(1)(b) GDPR)View Policy
LemonSqueezyLemon Squeezy LLC228 Park Ave S, PMB 22435, New York, NY 10003, USAPayment processing and subscription managementContractual necessityView Policy
NetlifyNetlify, Inc.44 Montgomery Street, Suite 300, San Francisco, CA 94104, USAWebsite hosting and content deliveryLegitimate interestView Policy
SupabaseSupabase, Inc.970 Toa Payoh North, #07-04, Singapore 318992Database hosting and authentication servicesContractual necessityView Policy
OpenAIOpenAI, L.L.C.3180 18th Street, San Francisco, CA 94110, USAAI-powered data processing and analysisLegitimate interestView Policy
Google GeminiGoogle LLC1600 Amphitheatre Parkway, Mountain View, CA 94043, USAAI model services and data processingLegitimate interestView Policy
Bright DataBright Data Ltd.Habarzel 40, Tel Aviv, 6971054, IsraelWeb data collection and proxy servicesContractual necessityView Policy
CrawlbaseCrawlbase LLC651 N Broad St, Suite 201, Middletown, DE 19709, USAWeb scraping and data extraction servicesContractual necessityView Policy
DecodoUAB "Data troops"Švitrigailos str. 34, Vilnius, LithuaniaData transformation and processing services (Legal entity code: 305893779)Contractual necessityView Policy
ResendPlus Five Five, Inc.2261 Market Street Suite 5039, San Francisco, CA 94114, United StatesEmail delivery and transactional email servicesContractual necessityView Policy
MailgunMailgun Technologies, Inc.535 Mission St, San Francisco, CA 94105, United StatesEmail delivery and transactional email servicesContractual necessityView Policy

Under GDPR, CCPA, and other data protection laws, you have the following rights regarding your personal data:

Right of Access (Art. 15 GDPR): You can request a copy of the personal data we hold about you.

Right to Rectification (Art. 16 GDPR): You can request that we correct inaccurate or incomplete personal data.

Right to Erasure (Art. 17 GDPR): You can request that we delete your personal data, subject to certain exceptions.

Right to Data Portability (Art. 20 GDPR): You can request a copy of your data in a structured, machine-readable format.

Right to Object (Art. 21 GDPR): You can object to our processing of your personal data in certain circumstances.

Right to Restriction (Art. 18 GDPR): You can request that we restrict the processing of your personal data.

Right to Withdraw Consent: Where we rely on consent, you can withdraw it at any time.

To exercise these rights, please contact us at legal@manypi.com. We will respond to your request within 30 days (1 month under GDPR).

We use cookies and similar tracking technologies to collect and track information about your use of our Services.

Essential Cookies: Required for the Services to function properly, such as authentication and security.

Analytics Cookies: Help us understand how visitors interact with our Services by collecting and reporting information anonymously.

Preference Cookies: Remember your settings and preferences to provide a personalized experience.

Marketing Cookies: Used to track visitors across websites to display relevant advertisements.

You can control cookies through your browser settings. However, disabling essential cookies may affect the functionality of our Services. For more information, see our Cookie Policy.

If you subscribe to our newsletter:

Subscription: You can subscribe by providing your email address through our website or during account creation.

Content: We send product updates, feature announcements, tips, and promotional content.

Legal Basis: Your consent (Art. 6(1)(a) GDPR) or legitimate interest for existing customers.

Frequency: We send newsletters periodically, typically weekly or monthly.

Unsubscribe: You can unsubscribe at any time by clicking the unsubscribe link in any newsletter or by contacting us.

Data Processing: Your email address and interaction data (opens, clicks) are processed by our email service provider.

In accordance with our obligations under Art. 32 GDPR, we implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk and to protect your personal data against unauthorized or unlawful processing, accidental loss, destruction, or damage. These measures are reviewed and updated regularly to account for the state of the art, the costs of implementation, and the nature, scope, context, and purposes of our processing.

Technical Measures

We encrypt your personal data in transit using industry-standard TLS/SSL protocols and encrypt data at rest using AES-256 encryption. We conduct regular security assessments and penetration testing to identify and remediate vulnerabilities, and we operate intrusion detection and prevention systems to monitor for and respond to unauthorized access. Access to your account is protected by secure authentication mechanisms, including the option to enable two-factor authentication (2FA).

Organizational Measures

We restrict access to personal data through access controls and role-based permissions, ensuring that only authorized personnel can access data strictly necessary for their duties. Our staff receive regular training on data protection and information security, and we maintain documented incident response procedures to address any security breaches promptly. We carry out regular security audits and enter into data processing agreements with all of our processors in accordance with Art. 28 GDPR.

Despite these measures, please be aware that no method of transmission over the Internet or method of electronic storage is completely secure. While we strive to protect your personal data using commercially acceptable means, we cannot guarantee its absolute security. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority and, where required, affected individuals in accordance with Art. 33 and Art. 34 GDPR.

Our Services are not directed to children under the age of 16, and we do not knowingly collect personal data from children under 16.

If we learn that we have collected personal data from a child under 16 without parental consent, we will take steps to delete such information as soon as possible.

If you believe that we might have information from or about a child under 16, please contact us immediately at legal@manypi.com.

Parents and guardians have the right to request access to and deletion of their child's personal data.

We may update this privacy policy from time to time to reflect changes in our data processing practices, applicable legal or regulatory requirements, or for other operational reasons.

Notification of Changes

Whenever we revise this policy, we will post the updated version on this page and update the "Last Updated" date shown at the top of the document. Where the changes are material, we will provide you with additional notice, typically by sending an email notification to the address associated with your account. Where a change materially affects processing that relies on your consent as the legal basis (Art. 6(1)(a) GDPR), we will, where legally required, seek your renewed consent before the change takes effect.

Your Responsibility

We encourage you to review this privacy policy periodically so that you remain informed about how we collect, use, and protect your personal data.

Continued Use

Except where your consent is required, your continued use of the Services after the revised policy becomes effective constitutes your acknowledgement of, and agreement to, the updated policy.

Because several of our subprocessors are established outside the European Economic Area (EEA), your personal data may be transferred to, stored in, and processed in countries other than your country of residence. These countries may have data protection laws that differ from, and in some cases offer a lower standard of protection than, the laws of your country.

Data Transfer Locations

We may transfer your data to the United States and to other countries in which our service providers operate, as identified in the subprocessors section of this policy.

Safeguards for EEA Transfers

Where we transfer personal data outside the EEA, we ensure that the transfer is subject to appropriate safeguards in accordance with Chapter V of the GDPR (Art. 44 to 49). In particular, we rely on the Standard Contractual Clauses (SCCs) adopted by the European Commission pursuant to Art. 46(2)(c) GDPR where no adequacy decision applies. Where the European Commission has determined under Art. 45 GDPR that a country ensures an adequate level of protection, we rely on that adequacy decision. For transfers within a corporate group, we may rely on Binding Corporate Rules approved under Art. 47 GDPR where applicable. In all cases, we supplement these legal mechanisms with additional technical and organizational safeguards, such as encryption, access controls, and regular audits, to protect the transferred data.

Your Rights

You have the right to obtain information about the safeguards we apply to international transfers of your personal data and to request a copy of the relevant documentation. To do so, please contact us at legal@manypi.com.

We take reasonable steps to ensure that your data continues to receive an adequate level of protection in all jurisdictions in which we process it.

If you are located in the European Economic Area (EEA), you have the right under Art. 77 GDPR to lodge a complaint with a data protection supervisory authority — in particular in the Member State of your habitual residence, place of work, or the place of the alleged infringement — if you believe that our processing of your personal data infringes applicable data protection laws. This right is without prejudice to any other administrative or judicial remedy available to you.

Finding Your Supervisory Authority

You can find a list of the EEA supervisory authorities and their contact details on the website of the European Data Protection Board at https://edpb.europa.eu/about-edpb/board/members_en.

Lead Supervisory Authority

As we are established in Germany, our competent supervisory authority is the data protection authority of the Federal State of Berlin, the Berliner Beauftragte für Datenschutz und Informationsfreiheit (Alt-Moabit 59-61, 10555 Berlin, Germany). For reference, other commonly contacted authorities include the Commission Nationale de l'Informatique et des Libertés (CNIL) in France, the Information Commissioner's Office (ICO) in the United Kingdom, and the Data Protection Commission (DPC) in Ireland.

Before Filing a Complaint

We would appreciate the opportunity to address your concerns directly, so we encourage you to contact us first at legal@manypi.com before lodging a formal complaint.