01 Who we are
Manifiesto is a mobile application for managing personal and family finances operated by Manifiesto ("Manifiesto", "we", "us", "our"), an independent project based in the Republic of Argentina. This policy applies to the use of the Manifiesto mobile application on iOS and, soon, Android, as well as to this website (manifiestoapp.com).
For the purposes of Argentine legislation (Law No. 25.326, Personal Data Protection, Argentina) and the European General Data Protection Regulation (GDPR), Manifiesto acts as data controller of your personal data.
02 What data we collect
Manifiesto collects only the data it needs for the app to work. We group it by category:
Account data
- Email — to create your account, recover your password and communicate important changes to you.
- Username that you choose to display within your household.
- Avatar — a visual identifier chosen from a predefined list (you do not upload photos).
- Password — stored in encrypted form (hash) by our authentication provider. No one at Manifiesto sees it in plain text.
- Social provider identifier — if you sign in with Apple or Google, we store the unique identifier that those providers return to us in order to recognize you. We do not access your contacts, photos, or any other data from your Apple or Google account.
Financial data that you enter
- Monthly income declared (numeric figures, with no employer information).
- Payday and the configuration of your monthly cycle.
- Expenses — amount, category, date and, optionally, a short note.
- Fixed expenses / subscriptions — name, amount and frequency and, if you enter them, the name of the creditor, the outstanding balance and the installments of a loan. If you include another person's name, you are responsible for doing so in accordance with the law.
- Savings goals and contributions to those goals.
- Composition of your household — the other Manifiesto users with whom you decided to share your finances and, where applicable, each one's monthly contribution. If you send a notice or reminder to another member, that message is stored and shown to that person.
- Import from a screenshot (optional) — if you choose to enter a transaction from a photo in your gallery, we read the amounts with text recognition that runs on your own device. The image is not uploaded to our servers nor stored: only the data you confirm remains.
Technical data
- Push notification token — a device identifier, associated with your account, that Apple or Google gives us to send you notices. If you disable notifications or sign out, we delete it.
- Platform and version — the operating system and the version of the app you use (we receive it when registering your device for notifications), to provide support and prioritize improvements.
- Device time zone — to schedule your notices and cycle closings in your local time.
- Usage events — which assistant suggestions we show you and how you interact with them (you view them, apply them or dismiss them). They are associated with your account —they are not anonymous— and may include the amount or the name of the item the suggestion acted on. They live in our own database and are not exported to third parties.
We do not access your camera, contacts, location or calendar. Manifiesto does not connect to your bank accounts, cards or wallets, nor does it read your financial information from banks or other institutions. All financial information is entered by you, manually.
Nor do we scan your gallery: the only access to your photos occurs when you choose to import a screenshot (as we explain above), and that image is processed on your device.
Today Manifiesto does not use language models (LLMs) nor generative AI to process your data. The assistant builds its suggestions with deterministic rules and calculations on your own numbers, within our infrastructure, and the text recognition when importing a screenshot runs on your device.
If in the future we were to incorporate AI that processes your data, we would update this policy and inform you before doing so.
03 What we use your data for
- Operate the app: show you your expenses, calculate your daily allowance, sync with your partner or housemate.
- Functional notifications: notify you when a fixed expense is approaching, when you are about to exceed your allowance or when your partner recorded an expense.
- Financial assistant: generate suggestions based on your own spending pattern. The calculation is deterministic (rules and math on your numbers) and runs within our infrastructure; your data is not sent to language models (LLMs) nor to third-party generative AI.
- Support: respond when you write to us at [email protected].
- Improve the product: understand what works and what doesn't, in aggregate (without identifying you individually).
- Comply with the law: respond to valid judicial requests and tax obligations (where applicable).
We never use your data to sell it, rent it, show you third-party advertising, nor to "profile" your financial behavior for commercial purposes.
04 Legal bases for processing
We process your data on the basis of the following justifications, under Law No. 25.326 (Argentina), the GDPR (European Union) and the CCPA (California, USA):
- Performance of a contract: the data we need for the app to work when you accept the Terms.
- Consent: push notifications, syncing with other household members, and any other optional use.
- Legitimate interest: protecting the app against abuse, improving the product in aggregate.
- Legal obligation: retention of tax information or response to requirements from authorities.
05 Third-party services that touch your data
To operate the app we rely on infrastructure providers. Each one processes only the portion of data it needs and under contracts that require them to maintain the same standard of protection that we apply.
Supabase (database hosting and authentication)
Stores all the information of your account and your household. Servers located in the United States (region us-east-1). Supabase privacy policy.
Apple and Google (social authentication, optional)
If you choose to sign in with Apple or Google, they return to us a unique identifier for your account. We do not access any more information than that.
Expo (push notifications)
Processes the delivery of notifications from our servers to your device, via Apple Push Notification service (APNs) and Firebase Cloud Messaging (FCM) according to your platform. Expo privacy policy.
App Store and Google Play
Manifiesto is distributed through Apple's App Store and, soon, Google Play. Those services collect download and installation metrics under their own policies.
Exchange rate providers (optional)
If you enable conversion to dollars, we query the exchange rate from public exchange rate sources (for example, dolarapi.com and open.er-api.com). We only ask them for the value of the exchange rate: we do not send them any personal or financial data of yours.
We do not use Google Analytics, Facebook Pixel, nor any advertising or tracking SDK. We do not sell your data to brokers. We do not load social media pixels in the app nor on this site.
06 How long we keep your data
- Active account: as long as you have an open account, your data lives in the app and in your database.
- Notifications: kept for up to 14 days (those you have already read, less), after which they are automatically purged.
- Archived expenses: the expenses of a closed cycle remain available in your history for about 14 days after the closing; afterwards they are automatically deleted (we keep some recent fixed-expense payments for tracking your installments).
- Telemetry events: 30 days, after which they are purged.
- Operational backups: we retain backup copies of the database for up to 30 days in order to be able to recover the service in the event of failures.
- Deletion request: when you request to delete your account from Settings → Account → Delete account, we schedule the deletion for 30 days later. During that window you can cancel the deletion by signing in again. After the 30 days, your personal data is deleted irreversibly. The records you have entered in a shared household (for example, expenses of a joint household economy) may remain visible to the other members, dissociated from your identity. We may also keep information that the law requires us to keep (for example, payment receipts during the tax period).
07 How we protect your data
- Encryption in transit: all communication between the app and our servers uses TLS 1.2 or higher.
- Encryption at rest: the database is encrypted at the disk level by our provider.
- Row-Level Security: our tables have rules that prevent a user from reading or modifying data of another household. Any access validates your identity before returning results.
- Authentication with PKCE: the login flow uses Proof Key for Code Exchange to prevent session fixation attacks.
- Local biometrics: the app can request Face ID or Touch ID before opening your data if you enable it. Biometric credentials never leave your device.
- Encrypted local storage: on your device we store your session tokens and a copy of your data in the system's secure store (Keychain on iOS, Keystore on Android) so that the app can work offline.
- Internal audits: periodic security reviews of our own codebase and our access policies.
Despite all of the above, no system is 100% impenetrable. If we detect a breach that affects your personal data, we will notify you by email within the timeframes required by applicable legislation.
08 Your rights over your data
As the holder of your personal data, you have the right to:
- Access a copy of the data we hold about you.
- Rectify incorrect or outdated data (most of it you can edit directly in the app, in Settings).
- Delete your account and the associated data (Settings → Account → Delete account within the app, or by writing to us).
- Port your data in a structured, machine-readable format.
- Object to certain processing (for example, withdraw consent for push notifications).
- Restrict processing while a dispute is being reviewed.
To exercise any of these rights, write to us at [email protected]. We respond within a maximum of 30 calendar days.
If you consider that we are not complying, you can file a complaint with the Agency for Access to Public Information (Argentina) or with the data protection authority of your country of residence.
09 Minors
Manifiesto is intended for people over 18 years of age. We do not knowingly collect data from minors under 13 years of age. If we identify that a minor under 13 created an account without parental authorization, we delete it along with all their data associated.
10 International transfers
Our main infrastructure (Supabase) operates in the United States. When you use Manifiesto from Argentina or from the European Union, your data travels to those servers. These transfers are carried out under:
- The standard contractual clauses (SCC) approved by the European Commission for transfers to the USA.
- The contractual security and confidentiality commitments assumed by the provider.
11 Changes to this policy
If we update this policy, we show the date of the new version above and, if the changes are substantial, we notify you within the app before they take effect. Previous versions remain available upon request to support.
12 Contact
For any inquiry, complaint or exercise of rights:
- Email: [email protected]
We respond in the shortest possible time — we commit to a maximum of 5 business days for acknowledgments of receipt and 30 days for final resolutions.