Manifest

Privacy policy

Effective 24 July 2026 · Last updated 26 July 2026

Manifest is practice software that holds clinical records, so this policy is written to be specific rather than reassuring. It names every category of information the application handles, every outside company that information reaches, and what you can ask us to do about it.

Who we are

Manifest is operated by KVEC Systems ("we", "us"). You can reach us at ekim@kvec.ai.

Manifest is licensed to healthcare practices, which use it to run their own clinical operations. Throughout this policy, "the practice" means the practice that provides your care and whose records are held in Manifest — your own practice if you are a practitioner, or the one treating you if you are a client. You may see that practice's name rather than ours inside the application and on email we send on its behalf.

Each practice is set up on its own installation of Manifest, holding only that practice's records.

Who is responsible for what. The practice decides what information goes into Manifest, who may see it, and how long it is kept. It is the controller of the clinical record. We host and operate the software on the practice's instructions, and we process that information only to provide and support the service — never for our own purposes.

If you are a client of the practice and you want your record corrected, exported, or deleted, the fastest route is to ask the practice directly. You can also write to us and we will pass the request on.

Information the practice records about clients

Clinicians and administrators at the practice enter and generate the following about the people they care for. Much of it is health information.

  • Identity and contact details — name, email address, phone number, and date of birth.
  • Clinical context — the client's primary goal, reported pain points, current plan of care, and ICD-10 diagnosis codes.
  • Session notes — the clinical narrative for each session, along with its author, type (initial evaluation or follow-up), status, date of service, and, once signed, who signed it and when.
  • Plan history — a snapshot of the plan of care each time it is edited, kept so the practice can see how care changed over time.
  • Appointments and attendance — scheduled sessions, including session type, time, duration, instructor, and location.
  • Intake forms and consent — answers to intake questionnaires and the signed liability waiver, release, and informed consent.
  • Documents — files the practice requests and the client uploads, such as referrals, imaging reports, or lab results, together with the file's name, type, size, and who uploaded it.
  • Billing records — superbill receipts containing CPT procedure codes, ICD-10 diagnosis codes, charges, dates of service, and the provider the services are attributed to.

Information we hold about staff accounts

For administrators and clinicians, Manifest stores the account holder's name, email address, and assigned role, plus the professional and practice details needed to produce a valid superbill: specialty, credentials, NPI, licence number, practice name, practice address, practice phone number, and tax identification number.

Signing in with Google

Manifest offers Google as one way to sign in. When you choose it, we receive from Google only the basic profile information covered by the openid, email, and profile scopes:

  • your Google account identifier;
  • your email address and whether Google has verified it;
  • your name and profile picture, if your Google account has them.

We use that information for one purpose: to create your Manifest account and to recognise you when you sign in again. We do not request access to your Gmail, Google Drive, Contacts, Calendar, or any other Google service, and we could not read them if we tried — the application never asks for those permissions.

Information received from Google is not sold, not shared with third parties for their own purposes, not used for advertising, and not used to train AI models. It is retained for as long as your account exists and is deleted when the account is deleted. You can withdraw Manifest's access at any time from your Google account's third-party access settings; doing so prevents future Google sign-ins but does not by itself delete your Manifest account or the practice's clinical record.

The other way to sign in is a single-use link emailed to your address. There is no password in Manifest, so there is no password for us to store or lose.

Information collected automatically

  • Product analytics. A closed, fixed list of product events — signing in, completing a note, signing a note, starting or issuing a superbill, resending a receipt, correcting a receipt's dates — with non-identifying properties such as role and note type.
  • Error reports. Diagnostic details when something breaks: the error, the operation attempted, and the database path involved, which contains opaque record identifiers rather than health data.
  • Server and security logs. Standard request logs kept by our hosting provider, including IP address, timestamp, and user agent.

What analytics deliberately cannot see. Because Manifest handles health information, its analytics is configured to close the paths that would otherwise leak it. Session and screen recording is disabled. All on-screen text and element attributes are masked before any event is sent, so a click is recorded but the words on the button are not. Residual text properties are stripped in the browser as a second line of defence. Clients are never identified to our analytics provider at all — only staff accounts are, and only by an opaque account identifier together with their role and specialty. Never a name, never an email address, never note content, never a diagnosis.

Where information reaches us from

  • From you, when you fill in a form or upload a document.
  • From the practice, when a clinician or administrator records something about your care.
  • From Arketa, the practice's booking system. Manifest regularly imports the practice's class and appointment schedule, including the reservation, session name, time, instructor, location, and the name and email address of the client who booked. This is what lets a clinical note be anchored to a session that genuinely took place.

How the information is used

  • To operate the practice's clinical record and make it available to the right people.
  • To authenticate you and apply the correct level of access to your account.
  • To draft, edit, sign, and retain clinical documentation.
  • To produce superbill receipts a client can submit for reimbursement.
  • To send transactional email: invitations, sign-in links, issued receipts, document requests, and reminders about outstanding intake forms.
  • To keep the service secure, diagnose faults, and prevent abuse.
  • To meet legal, professional, and record-keeping obligations.

We do not use personal or health information for advertising, we do not sell or share it for cross-context behavioural advertising, and we do not use it to train general-purpose AI models.

AI-assisted drafting

Clinicians can ask Manifest to draft a session note or a specialty summary. When they do, the request is composed on our servers and processed by Google's Gemini models running on Vertex AI. It contains the client's name and, depending on what the clinician asks for, their primary goal, reported pain points, current plan of care, and recent session notes — together with the clinician's own instruction.

Vertex AI runs inside the same Google Cloud project that holds the rest of the record, authenticated by the application's own service account, and is covered by the same agreement with Google as the database and file storage. Health information is not sent to a separate AI vendor, is not sent outside that project, and is not used to train Google's models.

It is still processing of health information, so we describe it plainly rather than calling it "AI features". Two things follow from it:

  • The output is a draft. A clinician reviews, edits, and signs it. Manifest does not diagnose, does not treat, and does not make clinical decisions.
  • Drafting is available only to clinicians and administrators, is subject to a per-account usage limit, and generated drafts may be cached so that repeating the same request does not send the information again.

Service providers

Manifest is not self-contained. These companies process information on our behalf, each limited to what its function requires.

Provider What it does What it can reach
Google Cloud / Firebase Hosting, authentication, database, file storage, server functions Everything in the application
Google Vertex AI (Gemini models) Drafting session notes and specialty summaries on request Only what is sent in a drafting request: client name, goals, pain points, plan, recent notes. Runs inside the same Google Cloud project as the rest of the record
Google Workspace (Gmail) Sending superbill receipts — the only email that carries health information The recipient's name and email address, the receipt total, and the attached superbill PDF with its billing and diagnosis codes
Resend Sending every other email: invitations, sign-in links, document requests, and reminders about outstanding intake forms The recipient's name and email address, and the contents of those messages. Deliberately never a superbill — see below
Arketa The practice's booking system, and the source of the schedule Booking and attendance data held in the practice's own account
PostHog Product analytics and error reporting Product events and masked interactions only, as described above. No client identities and no clinical content
Vercel Hosting this public website Only requests to manifest.solar. No access to the application or its records

Why two email providers. A superbill is the only thing we email that contains health information — the attached PDF carries billing and diagnosis codes. Those receipts are sent through Gmail, which is covered by a business associate agreement with Google that permits handling health information.

Everything else we send — an invitation, a sign-in link, a request for a document, a reminder about an unsigned form — contains no health information, and goes through Resend. Resend offers no business associate agreement, so it never carries a superbill. The split is deliberate, and it is enforced in the code rather than by convention.

We may also disclose information when the law requires it, to protect someone's safety or our rights, or as part of a merger or acquisition — in which case this policy travels with the information.

How long information is kept

We keep information only as long as it is needed for the purpose it was collected for, or as long as the law and the professions of the practice's clinicians require — whichever is longer.

  • Clinical records — session notes, plan history, intake forms, and documents: ten years from the client's last session with the practice. Where the client was a minor, until their twenty-eighth birthday if that is later.
  • Billing records — issued superbills and receipts: seven years from the date of issue, which covers the periods during which a tax authority or an insurer may reasonably query them.
  • Account records — staff and client accounts: for as long as the account is active, then ninety days after it is closed, after which the account is deleted. Anything that forms part of the clinical record is kept under the clinical retention period above instead.
  • Product analytics and error reportstwelve months.
  • Server and security logsthirty days, unless a longer period is needed to investigate a specific security incident.

Some records are deliberately append-only, because a clinical record that can be rewritten is not a reliable one. Signed notes, plan history snapshots, and issued receipts are preserved as written; corrections are recorded as corrections rather than by overwriting what was there before.

Your choices and your rights

Depending on where you live, you may have the right to:

  • see the information held about you, and get a copy of it;
  • have inaccurate information corrected;
  • have information deleted, where no legal or professional retention obligation requires it to be kept;
  • object to or restrict certain processing;
  • withdraw consent you have given, without affecting what was done before.

For clinical records, ask the practice — it holds the record and decides these requests. For anything else, write to ekim@kvec.ai and we will respond within the period the applicable law allows. We will ask you to verify your identity first, because handing a clinical record to the wrong person is the failure this policy exists to prevent.

We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is nothing to opt out of on that front. Manifest is a tool used by staff and clients of the practice, not an advertising product.

Security

Access to every record is enforced by rules on the database itself, not merely hidden in the interface: a clinician reaches the clients assigned to them, a client reaches their own record, and an account with no role assigned reaches nothing. Certain fields — the author of a note, the session it is anchored to, when a record was created — are rejected by the database if anything later tries to change them.

Information is encrypted in transit and at rest by our hosting provider. There are no passwords to steal, because sign-in is by single-use email link or Google account. Sign-in link requests are rate-limited.

No system is perfectly secure. If we discover a breach affecting your information, we will notify the practice and, where the law requires it, you and the relevant regulator.

Health information and HIPAA

The practice is a healthcare provider, and the records it keeps in Manifest are protected health information. We are its service provider: we handle that information only on the practice's instructions, and only to provide and support Manifest. Never for our own purposes.

Where HIPAA requires a business associate agreement between the practice and us, we enter into one. An agreement of that kind limits what we may do with protected health information, obliges us to safeguard it, requires us to report a breach, and requires us to hold our own service providers to equivalent terms. That last obligation is why the providers listed above are chosen for whether they will accept it — and why a superbill is sent through Gmail rather than through a provider that will not.

This policy describes our own practices. Your rights in the health record itself come from the practice's notice of privacy practices, which prevails over this policy wherever the two differ.

Children

Manifest is not offered directly to children. Where the practice treats a minor, the record is created and accessed by the practice and the minor's parent or guardian under the practice's own policies. We do not knowingly collect information from a child through this website.

Where information is processed

Manifest is hosted in the United States, and our service providers process information there. If you use Manifest from outside the United States, you are sending information to be processed in the United States, where privacy law differs from your own.

Changes to this policy

When this policy changes we update the date at the top. If a change materially affects how we handle personal or health information, we will tell the practice and, where appropriate, notify you in the application or by email before it takes effect.

Contact

Questions, requests, or complaints about this policy: ekim@kvec.ai.

About the contents of a clinical record specifically, contact the practice directly — it holds the record and decides those requests.