Skip to main content

Privacy Policy.

Last updated · 2026-09-03

1. Introduction and scope

This Privacy Policy explains how Mana Agents LLC, doing business as Mana (“Mana,” “we,” “us,” or “our”) collects, uses, and shares personal information in connection with our website at https://withmana.ai and the Mana platform (collectively, the “Services”).
Important: Client data exclusion. This Privacy Policy applies to personal information we process about visitors to our website and individuals who interact with us directly. It does not apply to personal information that we process on behalf of our business clients through their use of the Mana platform (“Client Data”). When Mana deploys AI agents into a client’s workflows, any personal information accessed or processed by those agents is governed by the Master Services Agreement and Data Processing Agreement we have with that client, not by this Privacy Policy. Questions about Client Data should be directed to the relevant client organization. When an authorized user connects a Google account to Mana, the Google Workspace disclosures below also apply to the Google user data handled through that connection.

Mana is a US-based business and our Services are intended for businesses and individuals located in the United States.

2. Information we collect

A. Information you provide to us. We collect personal information when you interact with us directly, including:
  • Contact and inquiry information. Your name, email address, phone number, company name, and job title when you fill out a form, request a demo, or contact us.
  • Account information. If your organization has engaged us under a Master Services Agreement, we collect information necessary to provision and administer authorized user accounts on the Mana platform, including name, business email, and role.
  • Communications. Records of emails, support tickets, demo conversations, and other communications you send us.
  • Payment information. If your organization purchases our Services, we collect billing details. Payment card information is processed directly by Stripe, our payment processor. We do not store full payment card numbers on our systems.
B. Information collected automatically. When you use our Services, we automatically collect:
  • Device and technical data. IP address, browser type, operating system, device identifiers, and referring URLs.
  • Usage data. Pages visited, features used, time spent, and interactions with our Services.
  • Approximate location. General geographic location derived from your IP address (city or region level), used for security and fraud prevention.
  • Cookies and similar technologies. See the Cookies and tracking technologies section below for details.
C. Information from third parties. We may receive information about you from:
  • Business intelligence and prospecting tools (such as sales intelligence platforms) that provide publicly available business contact information.
  • Payment processors. Stripe provides us with transaction status and billing information, but not full payment card details.
  • Referrals. When a current client or partner refers you to us.

3. Google Workspace connections

When you connect a Google account to a Mana agent, Google shows the permissions that the connection requests. Mana requests only the permissions needed for the work your organization has approved.

Data we access. For Gmail workflows, this may include your Google account identity, email address, messages, message metadata, threads, labels, and attachments. If your organization enables other Google Workspace tools, the connection may also access the Calendar, Drive, Docs, or Sheets data covered by the permissions shown on Google’s consent screen.
How we use it. We use Google user data only to provide the features you and your organization request, such as finding relevant email, summarizing a thread, preparing a draft, or completing another approved workflow. We do not sell Google user data, use it for advertising, or use it to train general-purpose AI models.
How it is stored and shared. Composio, our integration service provider, stores and refreshes the OAuth connection and processes Google API requests for Mana. Mana stores limited connection status and audit information. Google user data may also be processed by systems your organization has approved for the requested workflow. We do not share it with data brokers or advertising platforms.
Human access. Mana personnel do not read Google user data unless it is necessary to provide support, investigate a security issue, comply with law, or complete work you have explicitly asked us to perform.
Your control. You can disconnect the account through your Mana agent or revoke Mana’s access in your Google Account security settings. To request deletion of Google user data held by Mana, contact us at privacy@withmana.ai. Disconnecting stops future access. Data already created in an approved business workflow remains subject to your organization’s agreement and retention instructions.
Mana’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

4. How we use information

We use the information we collect to:
  • Operate, maintain, and improve our website and Services.
  • Respond to inquiries, schedule demos, and provide customer support.
  • Provision accounts, deliver our platform, and fulfill our obligations under client agreements.
  • Process payments and manage billing.
  • Send service-related communications (account updates, security alerts, policy changes).
  • Send marketing communications about new features and offerings, with your consent where required.
  • Analyze usage patterns to improve our Services and develop new features.
  • Detect, investigate, and prevent fraud, abuse, and security incidents.
  • Comply with legal obligations, including tax and accounting requirements.
  • Establish, exercise, or defend legal claims.

5. How we share information

We share information with the following categories of recipients:

Service providers. Third-party vendors who help us operate our business, including:
  • Cloud hosting and infrastructure. Providers who host our platform and store data.
  • Payment processing. Stripe processes payments.
  • Customer support and CRM tools used to manage client relationships and communications.

These service providers are contractually limited to using information only to provide services to us.

Analytics service providers. Google Analytics measures website traffic, acquisition, and conversion events. Google Signals and advertising-personalization signals are disabled. PostHog measures roadmap-booking clicks, performance, dead clicks, heatmaps, and privacy-masked session replays. We do not create named PostHog visitor profiles. Google Analytics operates when you visit the site. PostHog starts only after you accept optional session analytics. We do not send names, email addresses, phone numbers, company names, messages, or form contents through our custom analytics events. We do not use cross-site advertising pixels.
Legal and safety disclosures. We may disclose information if required by law, subpoena, court order, or other legal process, or to protect our rights, property, or safety, or that of others.
Business transfers. If Mana is involved in a merger, acquisition, financing, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such transfer.
We do not sell personal information for monetary consideration.

6. California privacy disclosures

This section provides additional disclosures for California residents under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, “CCPA”). Similar rights may apply to residents of Virginia, Colorado, Connecticut, Utah, and other states with comprehensive privacy laws.

A. Categories of personal information collected, sold, or shared. In the past 12 months, we have collected the following categories of personal information:
  • Identifiers (such as name, email address, and IP address).
  • Commercial information (such as transaction and purchase history).
  • Internet or other electronic network activity (such as browsing and usage data).
  • Geolocation data (approximate location derived from IP address).
  • Professional or employment-related information (such as job title and company name).
  • Inferences drawn from the above information.

Under CCPA, “selling” and “sharing” include disclosing personal information for cross-context behavioral advertising, even without monetary exchange. We do not sell personal information, and we do not share personal information for cross-context behavioral advertising. Our website does not use cross-site advertising pixels. Google Analytics is used for measurement, and PostHog product analytics and replay remain optional.

B. We do not knowingly sell or share sensitive personal information or minor data. We do not knowingly sell or share sensitive personal information as defined under CCPA, and we do not knowingly sell or share personal information of individuals under 16 years of age.
C. Your CCPA rights. California residents have the right to:
  • Know what personal information we collect, use, and disclose about you.
  • Access a copy of your personal information.
  • Delete your personal information, subject to certain exceptions.
  • Correct inaccurate personal information.
  • Opt out of the sale or sharing of your personal information.
  • Limit our use of sensitive personal information (we do not currently use sensitive personal information beyond permitted purposes).
  • Non-discrimination for exercising your rights.
D. How to exercise your rights. You may exercise your privacy rights by:
  • Opt-out of sale/sharing and targeted advertising. Not applicable. We do not sell personal information or share it for cross-context behavioral advertising, so there is nothing to opt out of.
  • All rights requests. Email us at privacy@withmana.ai.
  • Authorized agents. You may designate an authorized agent to submit requests on your behalf. We may require verification of the agent’s authority.

We will respond to verifiable requests within the timeframes required by applicable law (typically 45 days, with possible extension).

7. Your choices

  • Marketing emails. You can unsubscribe from marketing emails using the link at the bottom of any marketing message. You will continue to receive transactional and service-related communications.
  • Optional session analytics. Use the “Privacy choices” control in the website footer to accept or decline PostHog product analytics and privacy-masked session replay, or to withdraw consent later. Google Analytics remains active. You can also manage or block cookies through your browser settings.
  • Account information. Authorized users can update account information through the platform or by contacting us.

8. Cookies and tracking technologies

We do not use advertising cookies or cross-site advertising pixels. We use cookies and similar technologies for the following purposes:
  • Strictly necessary. Required for the website and platform to function (login, security, load balancing).
  • Functional. Remember your preferences and settings.
  • Analytics. Google Analytics measures traffic, acquisition, and conversion events. PostHog measures roadmap-booking clicks, performance, dead clicks, scrolling, and navigation through privacy-masked heatmaps and session replays. Google Analytics operates when you visit the site. PostHog starts only after you accept optional session analytics.

You can change your optional session-analytics choice at any time through the “Privacy choices” control in the footer. Withdrawing consent stops PostHog capture and replay, removes PostHog browser storage, and reloads the page without PostHog. Google Analytics remains active.

When optional session analytics are enabled, our PostHog configuration honors Do Not Track (DNT) browser signals.

9. Data security

We take security seriously. Because our platform involves deploying AI agents into client workflows, we maintain security practices appropriate to that data risk profile:
  • Encryption. We use SSL/TLS encryption for data in transit and encryption for data at rest.
  • Access controls. Internal access to data is limited to personnel who require it to perform their roles.
  • Authentication. We support and encourage Multi-Factor Authentication (MFA) for platform accounts.
  • Vendor management. We evaluate the security practices of our service providers.
An honest note. No system connected to the internet is 100% secure. While we implement strong security measures, we cannot guarantee absolute security. You play an important role too: use strong, unique passwords, enable MFA, and keep your credentials confidential.
Breach notification. If we experience a data breach affecting your personal information, we will notify you and the appropriate regulatory authorities as required by law, without undue delay.

10. Data retention

We retain personal information for as long as necessary to fulfill the purposes described in this Privacy Policy, including:
  • Account data. Retained while you have an active account and for a reasonable period after account termination to fulfill ongoing obligations.
  • Financial and transaction records. Retained for up to seven years to comply with tax and accounting requirements.
  • Marketing contact information. Retained until you unsubscribe or request deletion.
  • Technical logs. Routinely purged on a rolling basis.
  • Communications. Retained as needed to resolve disputes and improve our Services.

Specific retention periods depend on the nature of the information and applicable legal requirements.

11. Children's privacy

Our Services are designed for businesses and professionals and are not directed to children. We do not knowingly collect personal information from children under 13 in compliance with the Children’s Online Privacy Protection Act (COPPA). If we learn that we have collected personal information from a child under 13, we will delete it promptly. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at privacy@withmana.ai.

12. Third-party links

Our Services may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies before providing any personal information.

13. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you via email (to the address associated with your account) or by posting a prominent notice on our website before the changes take effect. The “Last updated” date at the top of this policy indicates when it was most recently revised. We encourage you to review this policy periodically.

14. Contact us

If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:

Mana Agents LLC (dba Mana)

We aim to respond to all privacy-related inquiries promptly.