Privacy Policy
Last updated: 18 August 2026
Manifest (“we”, “us”, the “App”) is a logbook, gear passport, jump recorder and events platform for skydivers. This policy explains what personal data we collect, why, and your rights over it.
Data controller: André Larsen, Dubai, United Arab Emirates. Contact: andre@manifestjump.com.
1. Data we collect
You provide:
- Account: email address and password (passwords are stored hashed by our auth provider; we never see them in plain text). If you sign in with Apple or Google, we receive your name and email address from them instead. If you use Apple’s “Hide My Email”, we only ever receive Apple’s relay address, never your real one.
- Profile: name, optional avatar photo, license type and licensing body, ratings, bio, home dropzone, coaching details.
- Content you create: jump logs, gear items and service history, event listings and RSVPs, messages to other users, reports you file.
- Credential & verification documents: if you choose to upload them, images of your license, rigger ticket, insurance, medical or other credentials, for your in-app credentials wallet and, if you apply, for blue-check verification. These are stored privately and access-controlled, visible only to you and to authorized Manifest admins reviewing a verification request.
Collected automatically / with permission:
- Location, for finding places. When you tap “Near me” to sort dropzones or events by distance, we read your approximate location once. It is used in memory to compute distance and is not stored on our servers.
- Location, for recording a jump. 3D Jump Track records your precise location continuously while a recording is running, and it keeps recording in the background, with the screen off and the App not on screen. That is deliberate and it is the only way the feature can work: your phone is in a zipped pocket from takeoff to landing. Recording only ever runs when you start it, or when you have switched on automatic start and the load you are on is called. It stops by itself once you are back on the ground, and it stops on its own if it has been running without ever leaving the ground.
- Location, so a recording can start by itself. If you switch on automatic start, your phone also watches for when you arrive at or leave a dropzone, using the operating system’s own boundary monitoring for the dropzones nearest you. This runs even when no recording is running and even when the App has been closed, because it is the only way iOS will wake the App to start recording for you. It reports a crossing and nothing else — there is no continuous tracking, we do not receive a trail of where you have been, and switching automatic start off stops it entirely.
- Motion and barometric pressure, for recording a jump. During a recording we read the barometer (air pressure, which is how altitude is measured) and the device’s motion sensors at up to 100 times per second, which is how exit and canopy deployment are detected.
- The jump track itself: coordinates, altitudes, speeds and timestamps for the recording, together with the dropzone and aircraft it was on.
- Usage data: in-app product-interaction events (screens viewed, features used) and crash reports, collected to keep the App reliable and improve it.
- Notification permission and local reminder scheduling (gear service and currency reminders are scheduled on your device).
- Basic technical data needed to run the service (e.g. session tokens).
Jump tracks stay on your phone
We never upload your jump tracks. A recording, and every position, altitude and sensor sample in it, is written to storage on your own device and stays there. It is not sent to our servers, we cannot see it, and it is not part of your account.
Two consequences worth knowing:
- The App keeps only your most recent tracks (currently the last 25) and older ones are removed automatically to bound the space used on your phone.
- Because a track is on your device rather than in your account, deleting your account does not delete tracks already recorded on that phone, and reinstalling or deleting the App removes them. You can delete any individual track in the App at any time.
A track only ever leaves your device if you choose to send it: exporting it as a CSV or KML file, or sharing the replay image or video. At that point it goes wherever you send it, and that is your choice, not ours.
2. Why we use it (legal bases)
- To provide the service (contract): accounts, logbook, gear, events, messaging.
- Legitimate interests: safety/moderation (reports, suspensions), preventing fraud and abuse, product improvement.
- Consent: device location, background location for jump recording, motion and pressure sensors, and notifications. You can decline any of these, and revoke them at any time in your device settings. Declining location or motion disables jump recording; everything else in the App keeps working.
3. Who we share it with
We do not sell your personal data. We share it only with service providers who process it on our behalf:
- Supabase — database, authentication, and file storage (hosting our backend).
- Expo — app delivery and, where enabled, push notification delivery.
- PostHog (EU region) — product analytics and crash reporting (in-app usage events and crashes, to keep the App reliable; hosted in the EU).
- Mapbox — the maps, satellite imagery and 3D terrain used by the dropzone maps and the jump replay. Rendering a map necessarily tells Mapbox which part of the world you are looking at, and Mapbox collects its own telemetry as described in its privacy policy.
- RevenueCat — manages Manifest Pro subscription status. Payment itself is taken by Apple; we never see your card details.
- Dropzone manifest systems (Burble). Many dropzones publish their live load boards. To show you your own load and to alert you when it is called, the App reads the board for the dropzone you are at and matches the name on your profile against the names the dropzone has published. We store which dropzone you are tracking and the name we matched, and which loads you were manifested on, so your logbook can be pre-filled. We send nothing about you to the dropzone; we only read what it already publishes.
- Apple and Google — only if you choose to sign in with them, to authenticate you and pass us your name and email address.
Other users see the parts of your profile and content you choose to make public (e.g. your name, avatar, public jumps, events you host). Verified-badge status is visible to other users.
4. International transfers
Our providers may process data outside your country (including the EU/EEA and the United States). Where required, transfers rely on appropriate safeguards such as the EU Standard Contractual Clauses.
5. Retention
We keep your data while your account is active. When you delete your account (Profile → Delete account), your profile and associated content are deleted promptly via an automated cascade. Credential and verification documents you upload are kept only while they remain in your wallet or your account is active; removing the credential or deleting your account removes them, and we may keep a minimal record that a verification check took place without retaining the document itself. Some records may be retained where required by law or to resolve disputes.
Jump tracks are the exception, because they are never on our servers in the first place: they live on your device until you delete them, until the App removes an old one to stay inside its limit, or until you delete the App. See “Jump tracks stay on your phone” above.
6. Your rights
Depending on your location (including the EU/EEA under the GDPR), you have the right to access, correct, delete, restrict, or port your data, and to object to certain processing. You can:
- Edit your profile in-app.
- Delete your account in-app (Profile → Delete account), which erases your data.
- Delete a jump track in-app, at any time. Because tracks never reach us, this is entirely in your hands.
- Contact us at andre@manifestjump.com for any other request.
You may also lodge a complaint with your local data protection authority.
7. Children
Manifest is not directed to children under 16. We do not knowingly collect data from children under 16. If you believe a child has provided us data, contact us and we will delete it.
8. Security
We use industry-standard measures (encryption in transit, hashed passwords, row-level access controls). No system is perfectly secure; please use a strong, unique password.
9. Changes
We may update this policy. Material changes will be notified in-app or by email. The “Last updated” date above reflects the current version.
10. Contact
André Larsen — andre@manifestjump.com — Dubai, United Arab Emirates.