LEGAL
Privacy Policy
Last updated: August 2, 2026
Manna Code is local-first by design. Your chats, project files, and model API keys live on your machine — not on our servers. This policy explains what little we do collect through the mannacode.ai website and services, operated by Covenant Labs LLC (Austin, Texas), and what we do with it.
Where the Services are offered
Manna Code and the Services are offered from the United States and are not available to persons in the European Economic Area or the United Kingdom. We do not target those regions, we block them where we detect them, and the Services are not designed to meet the requirements of the GDPR or UK GDPR.
What stays on your device
The Manna Code desktop app stores your conversations, working files, settings, and databases locally. Model API keys you add are stored in your operating system's keychain. When you chat, the app sends your content directly to the AI model providers you configured, under your own accounts and their privacy terms — it does not pass through Covenant Labs servers, and we cannot see it. The desktop app does not send usage analytics to us.
What we collect
Account information. When you create an account: your name, email address, a hash of your password (never the password itself), and — if you sign in with an identity provider — the identifiers that provider shares with us. We use this to operate sign-in, email verification, and download and update entitlements.
Downloads and updates. When you download the installer or the app checks for updates, our servers and infrastructure providers see standard request data — IP address, app version, and timestamps — in ordinary server logs.
Support. If you email us, we keep the correspondence.
Analytics and advertising
We run a self-hosted, cookieless analytics tool (Umami) to count page visits on mannacode.ai. That data stays on our infrastructure and is not shared.
The production website also loads an X (Twitter) advertising pixel, which reports page visits and two conversion events (account signup and download click) to X Corp so we can measure our ads and reach visitors on X. This is the one case where visitor data is shared with an advertising platform. You can limit it with a content blocker, your browser's tracking protection, or X's own ad-preference settings. We do not sell your personal information.
Service providers
We use a small set of providers to run the Services: Railway (application hosting and database), Cloudflare (installer and update file storage and delivery), SendGrid (transactional email such as verification links), and X Corp (advertising measurement, as described above). Each receives only what its role requires.
Retention and deletion
We keep account information while your account is active. To delete your account and its data, email [email protected] from your account address and we will remove it, except where we must retain records to comply with law. Server logs rotate on ordinary operational schedules. Data on your own device is yours to keep or delete — uninstalling does not remove your local data folder, by design.
Security
Passwords are stored only as hashes, account sessions use industry-standard mechanisms, and access to production systems is limited to Covenant Labs. No system is perfectly secure; keep your account password strong and unique.
Children
The Services are not directed to children and may not be used by anyone under 18 or the age of majority where they live.
Your rights
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal information. Requests go to [email protected]; we will verify the request from your account email and respond within the time applicable law requires.
Changes
We will post updates to this policy here with a new date. If a future feature changes what we collect — for example, optional cloud sync or in-app usage reporting — this page will describe it before it applies to you.
Contact
Covenant Labs LLC — covenantlabs.dev · [email protected]. See also our Terms of Service.