The short version. You'll have a Maneku account, and we don't sell your data or run ads. How AI processing happens depends on your plan. On Bring-Your-Own-Key (BYOK), you add your own provider keys and they stay on your device — the app talks to the AI providers directly. On a credit plan, you don't handle keys; your summons run through Maneku's servers, which call the AI providers for you and meter your usage. Either way, the app sends conversation audio and text to AI providers (Anthropic for responses, Groq for transcription, and — if enabled — ElevenLabs for voice) so the co-host can listen and reply. Syncing your transcripts to the cloud is a separate opt-in.
1. Who we are
Maneku ("we," "us") is operated by [LEGAL ENTITY]. This policy explains what data the Maneku desktop application and website handle, where it's stored, and who it's shared with. It should be read alongside our Terms of Service.
2. Two ways to use Maneku
Maneku is a desktop application, and using it requires a Maneku account. How AI processing is handled — and what data passes through our servers — depends on your plan:
- Bring-Your-Own-Key (BYOK). You provide your own API keys for the AI providers. Your keys are stored on your device, encrypted using your operating system's secure storage (for example, the macOS Keychain or the Windows Credential Locker), and are never transmitted to Maneku's servers. On this plan, the app calls the AI providers directly from your device.
- Credit plan. You don't handle any provider keys. When you summon the co-host, the request runs through Maneku's summon service, which calls the AI providers on your behalf using our keys, returns the result, and records how many credits you used. On this plan, the conversation audio and text needed for a summon pass through our servers.
On both plans, your settings, presets, and account data are stored in your Maneku account so they're available across your devices, and your session transcripts stay on your device unless you opt in to syncing them (see Your account & cloud sync).
3. Data we handle
| Category | Examples | Where it lives |
|---|---|---|
| Account data | Email, display name | Our cloud (Supabase) — required to use Maneku |
| Provider API keys (BYOK plan only) | Your Anthropic / Groq / ElevenLabs keys | Local only, encrypted in OS secure storage; never sent to us |
| Settings & presets | Voice/TTS choice, cost budgets, hotkeys, personas, show presets | Local and synced to your account |
| Session content | Transcript text, episode notes, reference materials you add | Local; transcripts sync only if you opt in |
| Usage & billing | Per-summon tokens/latency/model, estimated cost; on credit plans, credits consumed and payment records | Local logs; session summaries and (credit plan) billing data in our cloud / payment processor |
4. What is sent to AI providers, and how
To deliver core features, the conversation data needed for a summon is sent to the AI providers. On the BYOK plan this happens directly from your device using your own keys; on the credit plan it passes through Maneku's summon service, which relays it to the same providers using our keys. In both cases, only what each provider needs to perform the operation is sent:
| Provider | What is sent | When | Required? |
|---|---|---|---|
| Anthropic (Claude) | Your message/prompt, recent conversation transcript, the persona's system prompt, and any web-search queries the model makes | Each time you summon the co-host | Yes — core feature |
| Groq (Whisper) | Short audio segments from the room, to transcribe into text | Continuously, so the co-host has a live transcript to respond to | Yes — the co-host can't respond without a transcript |
| ElevenLabs | The co-host's response text, to synthesize into speech | When ElevenLabs is selected for voice | No — system voice is the on-device default |
| Maneku summon service (credit plan) | The summon request and the conversation data above, relayed to the AI providers on your behalf; plus the credit count for the summon | Each summon, on the credit plan only | Yes on the credit plan; not used on BYOK |
| Content sources | A URL you paste, fetched to extract article text or a video transcript you add as reference material | Only when you add a source | No |
Each provider processes this data under its own privacy policy and terms. We encourage you to review them.
5. Audio & transcripts
For the co-host to respond, it needs a live transcript of the conversation, so the app continuously captures short audio segments from the room and sends them to be transcribed into text. The audio itself is not stored by Maneku — neither on your device nor in our cloud. Only the resulting transcript text is kept, and that text stays on your device unless you opt in to syncing transcripts.
The underlying recording of your session is produced and owned by the recording platform you use (for example, Descript or Riverside), not by Maneku.
6. Your account & cloud sync
Using Maneku requires an account, which you create via email magic-link or Google sign-in. We use a hosted backend (Supabase) to authenticate you, to store your profile (such as your email and display name), and to back up and sync data across your devices. On credit plans, your account also holds your credit balance and links to your payment records held by our payment processor.
By default, account sync covers your settings, personas, and show presets, plus session summaries (such as duration and cost totals). Syncing full transcripts is a separate setting that is off by default — transcripts only leave your device if you turn it on. Room links, where stored in our cloud, are saved as a one-way hash rather than the raw URL. On the BYOK plan, we never store or sync your provider API keys.
7. Third-party sub-processors
We rely on the following providers to operate the Service. They process data only as described in this policy.
- Anthropic — AI language responses (always used for summons).
- Groq — speech-to-text transcription (always used so the co-host has a transcript).
- ElevenLabs — voice synthesis (only when you choose it).
- Supabase — authentication, database, and sync (always — accounts are required).
- Stripe — payment processing for paid/credit plans (handles card data; we don't store full card numbers). [CONFIRM Stripe before paid launch]
- Vercel — website hosting for maneku.ai.
- Cloudflare — DNS and content delivery for maneku.ai.
- Porkbun — domain registrar for maneku.ai.
- [CREDIT-PLAN SUMMON-PROXY HOST — add the service you run the proxy on, e.g. Fly.io / Railway / Cloudflare]
- [ERROR/ANALYTICS PROVIDER, e.g. Sentry — add if/when enabled, or delete this line]
8. Retention & deletion
We keep your account data for as long as your account is active. Data stored only on your device (such as local transcripts, session logs, and — on BYOK — your provider keys) is under your direct control: deleting those files or uninstalling the app removes it.
You can delete your account and associated cloud data at any time by contacting us at support@maneku.ai. When you do, we delete your personal data within 30 days and purge it from our backups within 90 days. We may retain limited billing and transaction records longer where required by law (for example, tax and accounting obligations, typically up to 7 years); payment-card data is held by our payment processor, not by us. [CONFIRM these retention periods with counsel]
9. Your rights
Depending on where you live (for example, under the GDPR or CCPA/CPRA), you may have rights to access, correct, delete, or port your personal data, and to object to or restrict certain processing. To exercise these rights for data held in your account, contact us at support@maneku.ai. For data stored only on your device, you can exercise these rights directly through the app and your file system. [CONFIRM legal basis & any region-specific disclosures with counsel]
10. Security
We take reasonable measures to protect your data, including encrypting BYOK provider keys in your operating system's secure storage, using encrypted connections to providers and to our services, and protecting credit-plan keys on the server side. No method of storage or transmission is perfectly secure, and you are responsible for securing your own device and your account credentials.
11. Children
The Service is not directed to children and is intended for users 18 and older. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.
12. Changes to this policy
We may update this policy from time to time. If we make material changes, we will update the date above and take reasonable steps to notify you.
13. Contact
Questions or requests about your privacy? Contact us at support@maneku.ai.[ Optional: add a postal address — a virtual mailbox / PO box or business address, not your home.]
Not legal advice. This policy is a starting template generated from how the product actually works. It has not been reviewed by a lawyer. Replace every [PLACEHOLDER] and have qualified counsel review it before publishing.