Manualify logo Manualify Nederlands Open the app

Manualify Privacy Policy

Effective date: [DATE — set when published]
Last updated: 2026-10-01

Who we are

Manualify is operated by:

[FULL NAME or BUSINESS NAME]
[STREET ADDRESS, POSTAL CODE, CITY]
The Netherlands
[KVK NUMBER, if registered as a business]
Contact: [SUPPORT EMAIL]

We are the "controller" for the personal data described below, within the meaning of the EU General Data Protection Regulation (GDPR).

The short version

Manualify is local-first: your device library — appliances, manuals, photos, receipts, notes — lives on your own device, in your browser's storage. We do not see it unless you sign in and enable sync. We use no advertising, no third-party trackers and no profiles, and the app sends us no usage data. The only data that leaves your device is what a feature you actively use needs, plus the technical data every website receives — all described precisely below.

Data we process, and why

1. Without an account (local use)

Your library: nothing. Your library is stored in your browser's local storage (IndexedDB and its file storage) on your device. We cannot access it. Backups you download are files on your device. If you clear your browser data or lose the device without a backup, the data is gone — we hold no copy.

A few things do reach us without an account: what a feature you use needs (for example a catalogue search, whose text we use to answer it and do not store), and the technical data every website receives with a request (see "Server logs" in section 6a).

2. If you create an account

Our backend is hosted on Supabase infrastructure provisioned through Lovable ("Lovable Cloud"). [CONFIRM HOSTING REGION — if the project region is in the EU, state: "Data is hosted in the European Union." Otherwise name the region and rely on the transfer mechanisms below.]

3. If you use AI features (photo recognition)

When you photograph a rating plate, product, box or manual cover and AI reading is enabled, that photo is sent to our server and forwarded to an AI model provider (via OpenRouter, Inc., USA) to read the brand, model and specifications. The photo is processed to answer that one request; we do not use your photos to train models. You can disable AI reading in Settings at any time; the app then uses on-device text recognition only, which never leaves your device. Legal basis: consent (Art. 6(1)(a) GDPR), given in the app before the first AI read and withdrawable in Settings.

4. If you use manual search

When the app searches the web for your device's manual, the brand, model and product-line text (never photos, never your name or email) is sent to search providers (Serper.dev; and as fallbacks SerpApi, Brave Search, or OpenRouter, all USA) to find candidate documents. Legal basis: performance of a contract.

5. Shared community catalog

When a manual is verified and attached, the app may contribute the link (URL, brand, model, document type — never the file, never anything about you beyond an internal account identifier used for abuse prevention) to a shared catalog so the next user finds it instantly. Reports and contributions are rate-limited and moderated.

6. If you back up to your own cloud storage (optional)

Manualify can upload the backup file it already makes to a cloud account you own — today, Google Drive. This is off until you connect it, and the app tells you what is being sent, and to whom, before the connection is made.

Because the file never reaches us, your cloud provider is not our processor for it. That is your own storage relationship, under your agreement with them.

6a. Server logs and totals

Server logs. Like every website, our server receives your IP address and browser type with each request. Our web proxy and our sign-in and file services log each request: IP address, browser type, time, the address requested (in the proxy's access log, without anything after the "?") and the result; for the file service also the file's path, which contains its file name. When a request fails on our side, the proxy's error log keeps the full address, including what comes after the "?". We keep these logs for at most 14 days, for security and fault-finding, and never use them for statistics or to follow anyone. To stop abuse of the public catalogue, we count requests per IP address per minute and delete those counts after 10 minutes. Legal basis: legitimate interest (security and keeping the service running).

Totals from data we already hold. To see whether Manualify works, we look at totals from data we already hold to run your account and sync — for example how many accounts confirmed their email, at which introduction step people stop, which kind of platform is used, or how many synced appliances have a manual. Only as totals, and never to decide anything about you. We also count, per day and without any link to a user, how often each catalogue product is added to a library; this feeds the "popular" list. Legal basis: legitimate interest.

Your right to object. You can object to the processing in this section at any time by emailing [SUPPORT EMAIL].

7. What we deliberately do not do

Cookies and local storage

We use no cookies at all. The app stores on your device: your library (that is the product), your preferences, local diagnostics and usage numbers that you can view, share and delete in Settings, an authentication token if you sign in, and — if you connect a cloud backup destination — the short-lived sign-in token for that destination. All of this is strictly necessary for the app to work and is never sent to us.

Processors and international transfers

We use these processors under data-processing agreements:

ProcessorPurposeLocation
Lovable / SupabaseHosting, database, authentication, file storage[CONFIRM REGION]
OpenRouter, Inc.AI photo reading (only when enabled)USA
Serper.dev (and fallback search providers)Manual search queries (brand/model text only)USA

Where a processor is outside the EEA, transfers rely on the EU Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework. Only the minimal data described above is transferred.

Retention

Your rights

Under the GDPR you can ask us for access, correction, deletion, restriction, portability, and to withdraw consent at any time (withdrawing consent does not affect processing that happened before). Because Manualify is local-first, most of your data is already fully in your hands — you can export a complete backup from Settings at any moment.

To delete your account and all synced data, [use Settings → Delete account, or] email [SUPPORT EMAIL] from your account address; we will complete the deletion within 30 days and confirm it. You also have the right to complain to the supervisory authority where you live (in the Netherlands: the Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl).

Children

Manualify is a household tool intended for adults. We do not knowingly process children's data; accounts are for users 16 and over.

Changes

If we change this policy, we will update the date above and, for meaningful changes, tell you in the app before they take effect.