- We do not sell your personal information.
- Your email stays in your inbox. Multify reads email in two cases: when you click to send one to a chat from the browser extension, and, if you turn it on, when Pulse checks your connected accounts a few times a day for what needs you. Pulse does not keep copies of your emails on our servers. It keeps short notes instead, like who wrote, the subject, and a one-line summary. An email you send to a chat is saved with that chat. Email is never used for ads, never added to your Stash, and never used to train AI models. You can turn Pulse off at any time, which deletes what it learned. See Sections 2, 6, 8, and 10.
- The free tier is ad-supported. We may use the content of your messages to personalize the first-party ads shown within the Service — but we do not sell that content or use it to build cross-service profiles of you.
- Paid, ad-free subscribers are exempt: no ads, no content sent to advertising providers, and no use of your content for ad targeting or AI training.
- We do not use your prompts, conversations, or files to train AI models unless a specific model or feature is clearly labeled for that use before you use it — see Section 6.
- We share data only with the subprocessors needed to operate the Service — named in Section 7.
- You can request access, correction, or deletion of your data at any time — see Section 13.
This Privacy Policy explains how Multify Inc. ("Multify," "we," "us," or "our") collects, uses, shares, and protects information when you use Multify, our websites, dashboards, agents, bots, and APIs (collectively, the "Service"). It supplements our Terms of Use, which include defined terms used here.
1. Scope and Controller
Multify Inc., a Delaware corporation, is the controller of personal information processed through the Service. You can reach us at hello@multify.co or through our Contact page. If you are in the EU, UK, Switzerland, or another jurisdiction with similar laws, see Sections 12 and 13 for transfer mechanisms and your rights.
2. Information We Collect
We collect the following categories of information:
- Account information: name, email address, phone number (where you sign up or communicate with the Service by text or iMessage, or otherwise provide one), password or authentication credentials, profile preferences, and billing details (collected and stored by Stripe; we do not store full payment-card numbers).
- Invite rewards / fraud checks: if you use our invite-a-friend program, we store the personal share code, who referred whom, reward status, and a coarse phone line type (for example mobile vs. VOIP) from a carrier lookup on a number you just verified. We do not keep the full lookup payload longer than needed to make that decision.
- Telegram identifiers: Telegram user ID, username, chat IDs, and bot tokens you provide or that our managed-bot infrastructure generates on your behalf.
- Agent metadata: agent display names, configuration files (such as SOUL.md and IDENTITY.md), assigned server IPs, SSH keys, and VNC credentials. Sensitive credentials are stored encrypted.
- Conversation and command data: prompts, messages, files, code, and Outputs exchanged between you and your Agent, plus command and audit logs of agent activity.
- Content you choose to send from the browser extension. If you use the Multify browser extension and click a control to attach something to a chat, we receive what that click sends. That can be the address and readable text of a web page, text you selected, a screenshot you asked for, or an email conversation you have open in Gmail (the subject, the participants, the dates, and the message text the page has loaded). We receive it because you clicked. If you ask Multify in the side panel to reply to the Gmail conversation you have open, it reads that conversation the same way so it can write the reply. Multify can also put a draft into your Gmail compose window or reply box for you to review. It never sends email for you; only you can press Send. This control does not read your inbox, your mailbox, or other private pages in the background, and it does not keep a login to your email account. (Pulse, described below, is a separate feature you turn on yourself.) We use the text to answer the chat you start and store it with that conversation, under the retention period in Section 10. We do not add it to your Stash, and we do not make it public. An email conversation you attach this way, and the chat you start from it, are not shared with advertising providers (see Section 7).
- An email you are writing, when you use Doubleslash. In Gmail, the browser extension lets you type
\\(two backslashes) in an email you are writing and pick an action. Typing\\on its own sends nothing. While you type what you want, you can type@to add one of your own tasks, pages, files, or stash items, the same as in the side panel chat; that searches your own items as you type. When you pick an action and press Enter, we receive what that action needs:- Write sends what you asked for, the email's subject, its To and Cc recipients, the address you are writing from, the text of your draft around your cursor (not your signature or the quoted earlier messages), on a reply or forward, the conversation Gmail shows, and any of your items you added with
@, which we read from your account. We use it once to write the text you asked for. If you use Pulse and it has learned how you write, we also use that description so the text sounds like you. The text appears in your draft highlighted, and it stays out of your email unless you accept it. We do not store your draft, the conversation, or the text we wrote. We keep only a usage record of the request (such as the model, its size, and its cost) for billing. - Research opens the side panel and starts a chat that looks up what you typed, with your draft, the conversation Gmail shows, and any items you added with
@attached so the answer fits your email. That chat is handled like an email conversation you attach with the Gmail control above: it is stored with that conversation (Section 10), not added to your Stash, not made public, and not shared with advertising providers (Section 7). - Summarize this conversation, offered when you reply, opens the side panel and starts a chat that sums up the conversation you are replying to. It sends that conversation (including earlier messages Gmail had collapsed, which the extension reads from your open Gmail session) and your draft. That chat is handled the same way as Research.
- Create & attach something opens the side panel and starts a chat that makes what you asked for as a file in your Files (for example a PDF, an image, or an export from an app you connected), using your request, your draft, the conversation Gmail shows, and any items you added with
@. The chat is handled the same way as Research. Files made this way stay private: we do not create a public link for them. The extension also remembers which email you started from (an identifier for that compose window and its subject, kept in your browser) so the file can go into that email. A file is added to your email only when you click Attach to email in the side panel; the extension then downloads it from your Files through your signed-in session and adds it to the email in Gmail. Nothing is attached or sent without that click.
- Write sends what you asked for, the email's subject, its To and Cc recipients, the address you are writing from, the text of your draft around your cursor (not your signature or the quoted earlier messages), on a reply or forward, the conversation Gmail shows, and any of your items you added with
- Text you are writing on other websites, when you use Doubleslash there. Where it is available, the browser extension also lets you type
\\in a text box or editor on other websites (not in password or payment forms, code editors, or single-line fields). To notice it, a small script on the pages you visit looks only at the few characters just before your cursor in the box you are typing in; it sends nothing to us. When you pick an action and press Enter, we receive what that action needs:- Write sends what you asked for, the text in that box around your cursor, the website's address (its host name), the page title, the box's label, and any of your items you added with
@. We use it once to write the text you asked for. The text appears in the extension's card first and goes into the box only when you click Insert. We do not store the text you were writing or the text we wrote. We keep only a usage record of the request for billing, as for Write in Gmail. - Research opens the side panel and starts a chat that looks up what you typed, with the text in that box, the website's host name, and the page title attached. That chat is handled the same way as Research in Gmail: stored with that conversation (Section 10), not added to your Stash, not made public, and not shared with advertising providers (Section 7).
- Turn off on this site sends nothing to us. The list of sites where you turned Doubleslash off is kept in your browser, and you can change it in the extension under Settings.
- Write sends what you asked for, the text in that box around your cursor, the website's address (its host name), the page title, the box's label, and any of your items you added with
- Pulse, if you turn it on. Pulse is an optional feature that checks the email, calendar, and Slack accounts you have connected (see Section 8) a few times a day and tells you what needs your attention. To do that, it reads recent messages and events using the access you granted when you connected the account. It also learns what matters to you over time, such as the people you reply to most, who you meet with, and when you usually work. In Slack, it reads the channels you are in and your direct messages, and you can mute any channel. Pulse does not store the emails or messages themselves. It keeps short notes about them: who a message is from, its subject and date, a one-line summary, and whether it still needs you. It also keeps the people and routines it has learned, the instructions you give it, and the feedback you give on what it shows you (for example, marking something "not important"). You choose how often Pulse runs, and you can turn it off at any time. To help draft emails that sound like you, Pulse also reads the emails you sent in the last 60 days and keeps a short description of how you write (for example, how you usually greet people and sign off, and whether you write differently to people inside and outside your organization). It keeps that description, not the emails, and you can have it re-learn your tone from settings. If you have linked a phone number to Multify, Pulse can also send these check-ins to you by text (iMessage or SMS). A text holds the same short notes, such as who wrote and a one-line summary, never the full email. This is on unless you turn it off: switch off "Text me too" in Pulse settings, or reply STOP to stop the texts.
- Connected Account credentials: OAuth tokens and API keys for third-party integrations you authorize (typically through Composio); we receive only the scopes you grant.
- Usage and telemetry: feature usage, credit consumption, session frequency, error reports, and audit events.
- Device and technical data: IP address, browser type and version, device identifiers, language, time zone, and access logs.
- Communications: support tickets, survey responses, and other correspondence with us.
3. Sources of Data
We collect information directly from you when you sign up, configure agents, or contact us; automatically when you use the Service (such as logs and telemetry); from Connected Accounts and Third-Party Services you authorize; and from our payment, infrastructure, and communication providers (such as Stripe webhooks and Telegram).
4. Legal Bases for Processing (EU/UK Users)
Where the GDPR or UK GDPR applies, we process personal information on the following bases:
- Performance of a contract: to provide the Service you request, including provisioning agents, processing payments, and responding to support requests;
- Legitimate interests: to secure the Service, prevent fraud and abuse, debug and improve the Service, and communicate with users about their accounts;
- Consent: for optional features and marketing communications, where required by law;
- Legal obligation: to comply with tax, accounting, anti-money-laundering, and other legal requirements.
5. How We Use Your Information
We use the information we collect to:
- Provide, operate, secure, and improve the Service;
- Provision, manage, and (when needed) repair agent infrastructure;
- Authenticate users and protect accounts;
- Process payments and manage subscriptions;
- Respond to support requests and communicate about your account;
- Detect, investigate, and prevent fraud, abuse, and security incidents;
- Enforce our Terms of Use;
- Comply with legal obligations and respond to lawful requests;
- Send transactional messages (such as receipts, security notices, trial reminders) and, with your consent where required, marketing messages;
- Display, personalize the relevance of, and measure the performance of advertising shown within the free, ad-supported tier of the Service, including through the use of identifiers and the content of your recent messages as described in Section 7. We do not use your messages to target advertising based on sensitive characteristics, and we do not use separately uploaded files or connected-repository or Connected Account contents for advertising. Paid, ad-free subscribers are not shown advertising and have no content used for this purpose. An email conversation you attach from the browser extension, and the chat started from it, are not used for advertising (see Section 7);
- Generate aggregated, de-identified analytics about Service usage;
- Answer chats you start from the browser extension, including chats about content you chose to attach, such as an email conversation.
- If you turn on Pulse, show you a short summary of what needs your attention in your connected accounts, and use your feedback and instructions to make later summaries more useful to you. Pulse content is not used for advertising.
6. AI Model Processing and Training
To generate Agent responses, your prompts, conversation context, and Outputs are sent to one or more LLM providers, primarily through OpenRouter. Depending on routing, the upstream model providers may include Anthropic, OpenAI, xAI, Google, Mistral, Moonshot AI, and others. Moonshot AI is also used to generate initial agent persona files.
If you attach an email conversation or other private page content through the browser extension, that text is sent to the model provider as part of the prompt, so the model can answer. The training rule in this section applies to it.
When Pulse checks your connected accounts, the text of recent messages is sent to a model provider so it can be sorted and summarized for you. We use that text for the check and do not keep it afterward; only the short notes described in Section 2 are saved. We do not use your email, calendar, or Slack content to train AI models.
We use customer Content to generate the response or Output you requested and to operate the Service. We do not use your prompts, conversations, files, or Outputs to train or fine-tune AI models unless, before you use a specific model or feature, we clearly state that data submitted through that model or feature may be used for AI training. A general notice that data is collected, stored, or processed does not by itself permit training. Where you use a model or feature that is not labeled for training, and where supported by an LLM or infrastructure provider, we contract for zero-data-retention and no-training treatment of customer Content.
If you are a paid, ad-free subscriber, we do not use your Content for AI training. Each provider's own privacy policy applies to the data we send them; please review their policies for details.
7. How We Share Your Information
We share information only as needed to operate the Service, comply with law, or with your consent. Categories of recipients include:
- LLM and AI infrastructure providers: OpenRouter and the upstream model providers it routes to (including Anthropic, OpenAI, xAI, Google, Mistral, Moonshot AI, and others, depending on configuration); Moonshot AI directly for persona generation.
- Messaging transport: Telegram, which carries your messages to and from your Agent, and the iMessage and SMS providers that carry texts between you and Multify, including Pulse check-ins if you get them by text.
- Payment processing: Stripe.
- Transactional email: Postmark.
- Cloud and agent infrastructure: Hetzner Cloud (agent servers; EU data center option) and our database and hosting providers.
- Connected Account integration broker: Composio, which mediates third-party API integrations you authorize.
- Analytics, error monitoring, and security tooling: service providers that help us operate and secure the Service.
- Advertising and measurement providers: third-party advertising partners (such as Gravity) that help us serve and measure the advertising displayed within the free, ad-supported tier of the Service. To select, deliver, cap the frequency of, personalize the relevance of, and measure the performance of these ads, we may share with these providers a hashed, pseudonymized (SHA-256) version of your email address (the raw email address never leaves our servers), your IP address, your device and browser information, a session or conversation identifier, and the content of your recent messages and Agent responses in the current conversation for contextual matching. We do not share separately uploaded files or the contents of connected repositories or Connected Accounts with these providers. We share this information solely to display and attribute advertising within the Multify experience, and not to enable these providers to build cross-service profiles of you. Paid, ad-free subscribers have no information sent to advertising providers. An email conversation attached from the browser extension, and the chat started from it, are also withheld from these providers, as described below.
- Professional advisors: auditors, lawyers, and accountants.
- Legal and safety: when required by law, court order, or to protect the rights, property, or safety of Multify, our users, or the public.
- Business transfers: in connection with a merger, acquisition, financing, or sale of assets, in which case we will notify you and ensure continuity of this Privacy Policy or provide a comparable replacement.
- With your consent: any other recipient you direct.
All service providers are contractually bound to protect your information and to use it only for the purposes we specify. The advertising we display is first-party and contextual — it is shown within the Multify experience and is informed by your current conversation rather than by tracking you across other companies' websites or apps. We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
Content the browser extension attaches from a private mailbox, including an email conversation you open in Gmail, an email you are writing (Doubleslash), or text you are writing on another website (Doubleslash), is not shared with advertising providers. Neither is the chat you start from that attachment, including later messages in the same conversation. We treat that material like separately uploaded files and Connected Account contents for this purpose. Doubleslash Write requests, in Gmail or on other websites, are not shown ads and are not shared with advertising providers either. Your other chats on the free tier are unchanged.
8. Connected Accounts
When you authorize a Connected Account (such as a Gmail or other third-party app via Composio), we receive only the scopes you grant. Tokens and credentials are stored encrypted and used only to do what you ask, including features you turn on yourself, such as Pulse. You can revoke a Connected Account at any time, which terminates our access except as needed for legal-retention or security purposes. Disconnecting an account also stops Pulse from checking it and deletes the Pulse notes for that account.
Multify's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
The Gmail control in the browser extension is separate from a Connected Account. It does not ask you for an OAuth grant and it does not keep a token. It sends the conversation you chose, once, into the chat you start. Doubleslash works the same way: it sends the email, or the text on another website, you are writing only when you pick an action. See Section 2.
9. Cookies and Similar Technologies
We use a small number of cookies and similar technologies, limited to what is necessary to operate the Service:
- Strictly necessary: session authentication, CSRF protection, and load balancing.
- Functional: remembering preferences such as theme.
- Service-provider cookies: Stripe sets cookies during checkout for fraud prevention.
We do not use third-party advertising cookies or cross-site tracking. You can control cookies through your browser settings; disabling strictly necessary cookies may break Service functionality.
10. Data Retention
We retain personal information for as long as needed to provide the Service and for the periods described below, after which we delete or de-identify it, except where longer retention is required by law:
- Account data: while your account is active; up to 30 days after account closure (longer if needed for fraud or legal-hold purposes).
- Conversation and Agent content: up to 90 days, then purged unless you have opted to extend retention for context continuity or you are subject to an active legal hold. Content you attach from the browser extension, including an email conversation, is part of that conversation and follows this period. It is not kept as a separate stash item.
- Pulse notes: notes about individual messages and calendar changes are cleared after about 30 days. The people, routines, writing-style description, instructions, and feedback Pulse has learned are kept while Pulse is on, and you can reset them from settings. Turning Pulse off or closing your account deletes all of it.
- System and security logs: up to 12 months.
- Billing and tax records: as long as required by tax and accounting law (typically up to 7 years).
- Backups: rolled off within 35 days.
11. Data Security
We implement reasonable technical and organizational measures designed to protect personal information, including encryption in transit (TLS) and at rest, role-based access controls, audit logging, SSH key management, and least-privilege access for personnel. We will notify affected users of confirmed breaches of personal information without undue delay, consistent with applicable law. No security control is perfect; we cannot guarantee absolute security.
12. International Data Transfers
We are based in the United States and operate globally. Your information may be processed in the United States, the European Union (including Hetzner data centers in Germany or Finland), and other countries where our service providers operate. For transfers from the EEA, UK, or Switzerland to other jurisdictions, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum, where applicable.
13. Your Rights and Choices
13.1 EU/UK/Swiss Residents. Subject to applicable law, you have the right to:
- Access the personal information we hold about you;
- Request correction of inaccurate or incomplete information;
- Request erasure ("right to be forgotten");
- Request restriction of processing;
- Receive a portable copy of your data in a machine-readable format;
- Object to processing based on legitimate interests;
- Withdraw consent (where processing is based on consent), without affecting prior lawful processing;
- Lodge a complaint with your supervisory authority.
13.2 California Residents (CCPA/CPRA). You have the right to know what personal information we collect, use, and disclose; to request deletion; to request correction; and to limit use of "sensitive personal information." We do not sell personal information and do not share personal information for cross-context behavioral advertising; the first-party contextual advertising we display within the free tier of the Service, and the identifiers and message content we share with our advertising partner to serve and measure it (see Section 7), are used only for advertising within the Multify experience and do not constitute a "sale" or "sharing" under the CCPA/CPRA. Paid, ad-free subscribers are not shown advertising and have no information shared for this purpose. We will not discriminate against you for exercising these rights. You may designate an authorized agent to make a request on your behalf.
13.3 Other U.S. State Laws. We honor equivalent rights provided to residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws. Mention of a state does not imply that we are subject to its specific law; rights are extended where required.
13.4 How to Exercise Rights. To exercise any of these rights, contact us at hello@multify.co. We will verify your identity, generally by confirming control of the account email, and respond within the timeframe required by applicable law (typically 30 days, with one extension of up to 60 days where permitted). Some rights are not absolute and may be subject to legal exceptions.
14. Automated Decision-Making
The Service uses automated systems (large language models) to generate Agent responses. These responses are advisory; you and your Agent operators retain control over what actions are taken. Pulse uses the same kind of automated systems to decide which messages to show you; it only suggests, and you can tell it when it got something wrong. The Service does not use solely automated decision-making to produce legal or similarly significant effects on you within the meaning of GDPR Article 22.
15. Children's Privacy
The Service is not directed to individuals under 18, and we do not knowingly collect personal information from minors. If you believe a minor has provided us with personal data, please contact us and we will take steps to remove that information.
16. Marketing Communications
We may send you transactional communications (such as receipts, trial reminders, and security notices) regardless of marketing preferences. With your consent where required, we may also send marketing communications; you can unsubscribe at any time using the link in any marketing email or by contacting us.
17. Telegram and Bot Operation
Multify Agents are accessed through Telegram. Messages sent through Telegram are routed through Telegram's infrastructure and are subject to Telegram's privacy policy in addition to ours. Please review Telegram's Privacy Policy.
18. Changes to This Policy
We may update this Privacy Policy from time to time. For material changes, we will provide at least 14 days' notice by email or by prominent notice within the Service before the changes take effect. Continued use of the Service after the effective date constitutes acceptance of the updated policy.
19. Contact Us
For questions, requests, or concerns about this Privacy Policy or our data practices, contact us at hello@multify.co or through our Contact page. If we are required to designate an EU/UK representative, we will identify them in this Policy.
Multify is a product of Multify Inc, a Delaware corporation.