
Identity & AI
Your face stays your face
Manifest Engine changes the wardrobe, the setting and the light. It does not change the person. Identity lock is the first instruction in the prompt stack and the last condition checked before a frame reaches the mirror.
The rule
A transformation only works if the guest recognises herself
A guest steps in front of the mirror and sees a queen of Egypt, a fencing champion, a noir detective. The costume is new. The room is new. The face is not. The moment a face drifts — a different nose, a smoothed jaw, ten years removed — the effect collapses into a picture of a stranger, and the guest stops believing it.
Face and features
Bone structure, skin tone, hair, age and the small asymmetries that make a face readable are carried through every frame. Nothing is beautified, slimmed or corrected.
Body and proportions
Height, build and posture stay the guest's own. The garment is fitted to the body in front of the camera rather than the body being fitted to a garment.
Expression and motion
A smile arrives as a smile. A turn of the head turns the head. Expression and movement are preserved live, which is what makes guests test the mirror by pulling faces at it.
Brand world → moment → look → identity lock
Prompt architecture
Identity first, identity last
Every frame is generated from a layered instruction set assembled by Manifest Engine. Identity preservation opens the stack and closes it, so no creative layer can quietly outrank it.
- Layer one: identity. The guest in front of the camera is defined as fixed before any creative instruction is read.
- Layer two: brand world. The world sets the register — museum, cinema, summit, travel, sport, celebration.
- Layer three: moment. One of ten moments per world supplies wardrobe, setting and light.
- Layer four: look. The venue's chosen UI look frames the session on screen, from Gold to Noir to Concierge.
- Layer five: identity, again. The lock is restated last so that costume detail never negotiates with the face.
Cinema world — the setting moves with the guest
Continuous video
A video engine, not a photo filter
The mirror shows a live stream, not a still. The guest moves, the costume moves with them, the light in the scene answers the movement. Latency is sub-second, which is the difference between a mirror and a screen.
- Frame-to-frame coherence. The same person persists across the session rather than being re-invented every second.
- Movement is the test. Guests turn, step back and raise an arm within the first seconds; the image has to hold.
- Switching mid-session. A guest can change moment or outfit during the 90 seconds without losing the identity lock.
- Built for the room. The same stream drives all five mirror formats, from 9:16 window units to 16:9 wall units.
Outfit only — the store stays in the frame
Two modes
Outfit only, when the room should stay real
The venue chooses how far the transformation goes. In Outfit only the real background is kept and the garment changes — virtual try-on in the actual store. In Full world the setting, light and horizon change with it.
- Outfit only. Retail floors, fan shops and boutiques, where the product and the place are the point.
- Full world. Museums, lobbies, premieres and booths, where the destination is the point.
- Set centrally. Mode, session length and look are configured for the fleet, not fiddled with on the unit.
The contract
What the model may change, what it must keep
Identity lock is easier to trust when it is written down. This is the line the engine holds in every world, every moment and every look.
May change
- Wardrobe. Garments, armour, kit, gowns, uniforms and their fit on the guest's own body.
- Setting. Backgrounds, architecture, weather and horizon in Full world mode.
- Light. Colour temperature, direction and atmosphere to match the moment.
- Props and styling. Period detail, accessories and surfaces that belong to the world.
- Framing. The composition adapts to the mirror format in use.
Must keep
- The face. Features, skin tone, apparent age and distinguishing marks.
- The body. Height, build and proportions as the camera sees them.
- The expression. What the guest is doing with their face, in the moment they do it.
- Identity signals the guest chose. Glasses, head coverings, beards, hairstyles and mobility aids.
- The truth of the mirror. No slimming, no smoothing, no silent retouching.
Brand worlds are demonstration concepts built for the Manifest Mirror platform; they do not imply a commercial relationship with the brands shown.
Same person, different world
Ten settings, one face
Across seven brand worlds and more than sixty moments, only the layer around the guest moves. Each frame below is a different moment from the library.





Transparency
Generated images, declared as such
A guest should never have to work out whether what they are looking at is real. The mirror says so, the recording says so, and the data behind it is deliberately thin.
An AI notice on the glass
Before the camera starts and during the session, the mirror states that the image is generated by AI. The notice travels with the recording delivered by email.
Read the AI statementNo biometric templates
Identity lock works on the live stream. No face template is computed, stored or matched, and there is no gallery of guests to search against.
Privacy by designGuest footage does not train
Sessions are ephemeral. Recordings are auto-deleted after seven days and email deliveries after thirty. Nothing a guest does in front of the mirror is used to improve the model.
Privacy noticeGuardrails
Nothing reaches a mirror unreviewed
Generative systems fail in public. The defence is not a single filter but a chain: constrained worlds, human review, a test on real hardware, and a session that can be stopped centrally.
- Constrained by design
Moments are built in Manifest Studio from a scene image, a garment reference, a written prompt and an ambient video. The model composes inside those bounds instead of inventing freely.
- Human review
Every moment is reviewed before a world is published: costume plausibility, cultural and historical care, age-appropriateness, and whether the identity lock holds across body types.
- Test on the mirror
Worlds are run on a real unit in the target format and look before they go to venues. What passes on a laptop does not always pass at full height in a lobby.
- Operate and revoke
Manifest OS distributes worlds and can withdraw a moment across the fleet centrally. Session length, mode and look stay under venue policy, not local improvisation.
At a glance
Identity lock, in specification
| Output | Continuous real-time video, not a still image |
|---|---|
| Latency | Sub-second, streamed to the mirror |
| Identity | Locked: face, skin tone, apparent age, expression, proportions |
| Transformable | Wardrobe, setting, light, props, framing |
| Modes | Outfit only (real background) / Full world |
| Library | 7 brand worlds, 10 moments each, 60+ moments |
| Session | 90 seconds by default, configured centrally |
| Biometrics | No templates computed or stored |
| Training | Guest footage is never used to train models |
| Transparency | AI notice shown on the mirror and with the recording |
A mirror that flatters you is a screen. A mirror that keeps you honest and still makes you extraordinary is a medium.
Manifest Media manifesto
Read the essay
Why the face must never change — the failure mode of generative video, and what it costs a brand when trust breaks in front of an audience.
Identity lock, in long formQuestions
What venues and DPOs ask first
Yes. Glasses are treated as part of the guest's identity, not as an obstacle to be removed. They are preserved through the transformation unless the moment itself supplies eyewear the guest chooses, such as a diving mask or goggles.
Head coverings are kept. The engine is instructed to treat religious and cultural dress as fixed identity, so a guest wearing a hijab sees herself in the world of the moment, still wearing it. Where a historical moment implies specific headwear, the guest keeps their own covering and the rest of the costume adapts around it.
Yes. Mobility aids are part of the guest and stay in frame. Mirror units can be installed with the camera at seated eye height, and moments are reviewed to make sure the composition works for guests who are seated as well as standing.
Only with the consent of a parent or guardian, given at the mirror before the session starts. Apparent age is preserved: a child sees a child in armour, not an adult. Recordings follow the same retention rules as every other session and are deleted after seven days.
No. Skin tone is an identity attribute and is held constant. Scene lighting can change how a face is lit — a candlelit hall is warmer than an alpine slope — but the person is not re-coloured, lightened or darkened to fit a world.
Moments that drift are not published. Review happens in Manifest Studio before a world reaches venues, and Manifest OS can withdraw a moment across the fleet if an issue appears in operation. A guest can also end a session at any point from the phone remote or the mirror itself.
Manifest Engine orchestrates leading real-time video foundation models rather than betting the platform on one. The prompt stack, identity lock, session policy and delivery pipeline are ours, which is what keeps behaviour consistent as the underlying models improve.