Identity & AI

Your face stays your face

Manifest Engine changes the wardrobe, the setting and the light. It does not change the person. Identity lock is the first instruction in the prompt stack and the last condition checked before a frame reaches the mirror.

Real timeContinuous video
90 sDefault session
2Transformation modes
NoneBiometric templates stored

The rule

A transformation only works if the guest recognises herself

A guest steps in front of the mirror and sees a queen of Egypt, a fencing champion, a noir detective. The costume is new. The room is new. The face is not. The moment a face drifts — a different nose, a smoothed jaw, ten years removed — the effect collapses into a picture of a stranger, and the guest stops believing it.

FA

Face and features

Bone structure, skin tone, hair, age and the small asymmetries that make a face readable are carried through every frame. Nothing is beautified, slimmed or corrected.

PR

Body and proportions

Height, build and posture stay the guest's own. The garment is fitted to the body in front of the camera rather than the body being fitted to a garment.

EX

Expression and motion

A smile arrives as a smile. A turn of the head turns the head. Expression and movement are preserved live, which is what makes guests test the mirror by pulling faces at it.

Abstract swirl of golden light Brand world → moment → look → identity lock

Prompt architecture

Identity first, identity last

Every frame is generated from a layered instruction set assembled by Manifest Engine. Identity preservation opens the stack and closes it, so no creative layer can quietly outrank it.

  • Layer one: identity. The guest in front of the camera is defined as fixed before any creative instruction is read.
  • Layer two: brand world. The world sets the register — museum, cinema, summit, travel, sport, celebration.
  • Layer three: moment. One of ten moments per world supplies wardrobe, setting and light.
  • Layer four: look. The venue's chosen UI look frames the session on screen, from Gold to Noir to Concierge.
  • Layer five: identity, again. The lock is restated last so that costume detail never negotiates with the face.
Cinema brand world scene Cinema world — the setting moves with the guest

Continuous video

A video engine, not a photo filter

The mirror shows a live stream, not a still. The guest moves, the costume moves with them, the light in the scene answers the movement. Latency is sub-second, which is the difference between a mirror and a screen.

  • Frame-to-frame coherence. The same person persists across the session rather than being re-invented every second.
  • Movement is the test. Guests turn, step back and raise an arm within the first seconds; the image has to hold.
  • Switching mid-session. A guest can change moment or outfit during the 90 seconds without losing the identity lock.
  • Built for the room. The same stream drives all five mirror formats, from 9:16 window units to 16:9 wall units.
Guest in a sports store seeing herself as a fencing champion Outfit only — the store stays in the frame

Two modes

Outfit only, when the room should stay real

The venue chooses how far the transformation goes. In Outfit only the real background is kept and the garment changes — virtual try-on in the actual store. In Full world the setting, light and horizon change with it.

  • Outfit only. Retail floors, fan shops and boutiques, where the product and the place are the point.
  • Full world. Museums, lobbies, premieres and booths, where the destination is the point.
  • Set centrally. Mode, session length and look are configured for the fleet, not fiddled with on the unit.

The contract

What the model may change, what it must keep

Identity lock is easier to trust when it is written down. This is the line the engine holds in every world, every moment and every look.

May change

  • Wardrobe. Garments, armour, kit, gowns, uniforms and their fit on the guest's own body.
  • Setting. Backgrounds, architecture, weather and horizon in Full world mode.
  • Light. Colour temperature, direction and atmosphere to match the moment.
  • Props and styling. Period detail, accessories and surfaces that belong to the world.
  • Framing. The composition adapts to the mirror format in use.

Must keep

  • The face. Features, skin tone, apparent age and distinguishing marks.
  • The body. Height, build and proportions as the camera sees them.
  • The expression. What the guest is doing with their face, in the moment they do it.
  • Identity signals the guest chose. Glasses, head coverings, beards, hairstyles and mobility aids.
  • The truth of the mirror. No slimming, no smoothing, no silent retouching.

Brand worlds are demonstration concepts built for the Manifest Mirror platform; they do not imply a commercial relationship with the brands shown.

Same person, different world

Ten settings, one face

Across seven brand worlds and more than sixty moments, only the layer around the guest moves. Each frame below is a different moment from the library.

Transparency

Generated images, declared as such

A guest should never have to work out whether what they are looking at is real. The mirror says so, the recording says so, and the data behind it is deliberately thin.

01

An AI notice on the glass

Before the camera starts and during the session, the mirror states that the image is generated by AI. The notice travels with the recording delivered by email.

Read the AI statement
02

No biometric templates

Identity lock works on the live stream. No face template is computed, stored or matched, and there is no gallery of guests to search against.

Privacy by design
03

Guest footage does not train

Sessions are ephemeral. Recordings are auto-deleted after seven days and email deliveries after thirty. Nothing a guest does in front of the mirror is used to improve the model.

Privacy notice

Guardrails

Nothing reaches a mirror unreviewed

Generative systems fail in public. The defence is not a single filter but a chain: constrained worlds, human review, a test on real hardware, and a session that can be stopped centrally.

  1. Constrained by design

    Moments are built in Manifest Studio from a scene image, a garment reference, a written prompt and an ambient video. The model composes inside those bounds instead of inventing freely.

  2. Human review

    Every moment is reviewed before a world is published: costume plausibility, cultural and historical care, age-appropriateness, and whether the identity lock holds across body types.

  3. Test on the mirror

    Worlds are run on a real unit in the target format and look before they go to venues. What passes on a laptop does not always pass at full height in a lobby.

  4. Operate and revoke

    Manifest OS distributes worlds and can withdraw a moment across the fleet centrally. Session length, mode and look stay under venue policy, not local improvisation.

At a glance

Identity lock, in specification

OutputContinuous real-time video, not a still image
LatencySub-second, streamed to the mirror
IdentityLocked: face, skin tone, apparent age, expression, proportions
TransformableWardrobe, setting, light, props, framing
ModesOutfit only (real background) / Full world
Library7 brand worlds, 10 moments each, 60+ moments
Session90 seconds by default, configured centrally
BiometricsNo templates computed or stored
TrainingGuest footage is never used to train models
TransparencyAI notice shown on the mirror and with the recording

A mirror that flatters you is a screen. A mirror that keeps you honest and still makes you extraordinary is a medium.

Manifest Media manifesto

Read the essay

Why the face must never change — the failure mode of generative video, and what it costs a brand when trust breaks in front of an audience.

Identity lock, in long form
Identity lock Real-time video Outfit only Full world AI notice

Questions

What venues and DPOs ask first

Yes. Glasses are treated as part of the guest's identity, not as an obstacle to be removed. They are preserved through the transformation unless the moment itself supplies eyewear the guest chooses, such as a diving mask or goggles.

Head coverings are kept. The engine is instructed to treat religious and cultural dress as fixed identity, so a guest wearing a hijab sees herself in the world of the moment, still wearing it. Where a historical moment implies specific headwear, the guest keeps their own covering and the rest of the costume adapts around it.

Yes. Mobility aids are part of the guest and stay in frame. Mirror units can be installed with the camera at seated eye height, and moments are reviewed to make sure the composition works for guests who are seated as well as standing.

Only with the consent of a parent or guardian, given at the mirror before the session starts. Apparent age is preserved: a child sees a child in armour, not an adult. Recordings follow the same retention rules as every other session and are deleted after seven days.

No. Skin tone is an identity attribute and is held constant. Scene lighting can change how a face is lit — a candlelit hall is warmer than an alpine slope — but the person is not re-coloured, lightened or darkened to fit a world.

Moments that drift are not published. Review happens in Manifest Studio before a world reaches venues, and Manifest OS can withdraw a moment across the fleet if an issue appears in operation. A guest can also end a session at any point from the phone remote or the mirror itself.

Manifest Engine orchestrates leading real-time video foundation models rather than betting the platform on one. The prompt stack, identity lock, session policy and delivery pipeline are ours, which is what keeps behaviour consistent as the underlying models improve.

Next step

See yourself in it. Then decide.

Ninety seconds in front of the mirror explains more than any deck. Book a live session in Cologne or run the browser demo now.