Back to home

Privacy Policy

Last updated: 26 July 2026

1. About this policy

This policy explains what data the MultiAiPlatform service — the multiaiplatform.ai website and the app.multiaiplatform.ai application — processes, why, on what legal basis and for how long.

The data controller is the owner of the MultiAiPlatform service; you can reach us at [email protected]. By using the website or the application you agree to the processing described here.

2. What data we process

Account data — email address, name, password hash, role within a project, two-factor authentication settings.

Working data — text, images and video you create or upload, your knowledge base, product and service catalog, publication plans, and the tasks and results of your AI agents.

Connection data — access tokens for external services, identifiers of connected accounts and publishing destinations (boards, communities, channels, mailboxes), identifiers of the items we published and their public statistics.

Your customers' data — conversations in connected channels, CRM contacts, call recordings and transcripts. You enter this data yourself and we process it on your instructions.

Technical data — request logs, IP address, request time and identifier, metrics and traces of model calls; personal data is masked in traces.

Waitlist data — if you left your email on the website before signing up, that address is all we store.

3. Why we process data

To provide the service — to run the tasks you assign to AI agents, store the results and show them to you. To handle billing — to meter credit usage and issue invoices. To keep the service secure — to detect abuse, investigate incidents and maintain an audit log of administrative actions. To answer support requests and notify you about important service changes.

Legal bases: performance of our contract with you, your consent, our legitimate interest in the security of the service, and legal obligations.

4. Connecting external services and publishing on your behalf

The platform can act in external services on your behalf — publish content, send email, read replies. You always initiate the connection yourself: you authorise it on the service's own side via OAuth, or enter credentials in the Connections section. Only then does the platform receive a limited set of permissions.

What we store per connection: the access token in encrypted form, the account identifier, the list of publishing destinations, and the identifiers of the items we published together with their public statistics.

What we do not do: we never publish anything without your explicit approval — every item goes through a review queue where you approve that specific publication; we do not download or retain content from the external platform beyond what is required to operate the connection and show the status of your publications; we never move data from one connection into another project — projects are isolated at the database level.

Disconnecting: you can disconnect a service in the Connections section at any time — we delete the stored token and stop calling the platform. You can also revoke access on the service's own side.

5. Supported platforms

The platform supports connections to Pinterest, VK, Telegram, Slack, WhatsApp, Google Calendar and Bitrix24, as well as to mailboxes over IMAP and SMTP and to external databases you specify yourself.

For Pinterest we request permission to read and create pins and boards (pins:read, pins:write, boards:read, boards:write) and to read account information (user_accounts:read). We store the account identifier, the list of your boards, the identifiers of the pins we created and their impression, save and outbound-click statistics.

Information obtained from Pinterest is used solely to show you the status and performance of your own publications; it is not shared with third parties and is deleted when you disconnect the account. A pin is published only after you have approved that specific pin.

6. Who else receives data

Hosting and backups — Timeweb Cloud, data centre in Moscow.

Language and generative model providers — Anthropic, OpenAI, Google, DeepSeek, Together AI, fal.ai. They receive the content of a specific request — text or an image — needed to produce the response. These companies are located outside the Russian Federation, so a cross-border transfer takes place; what is transferred is the content of an individual request, not your database as a whole.

Payments — the YooKassa payment provider: we pass the amount and the order identifier; card details never reach us and are not stored by us.

External services you connected yourself — to the extent described in sections 4 and 5.

The Langfuse observability system, the MinIO file storage and the SearXNG search service run on our own server — data in them never leaves our infrastructure.

Otherwise we neither share nor sell your data. Disclosure is possible only upon a lawful, substantiated request from authorised bodies.

7. Models and training

We do not train models on your data and do not pass it to providers for training: request content is used only to produce the response to that specific call.

Call traces are stored in our own observability system with personal data masked — they are used to diagnose errors and account for costs. The material the platform creates on your instructions belongs to you.

8. How long we keep data

Project data is kept while the project is active. When a project is deleted it enters a 30-day pending state — it can be restored during that period — after which it is archived and queued for physical deletion.

Backups are kept for 30 days and then overwritten. Billing and administrative audit logs are kept longer: they substantiate charges and cannot be altered retroactively. A waitlist address is kept until you withdraw consent.

9. How we protect data

Projects are isolated from one another at the database level by enforced row-level security policies, not only by application code.

Tokens and credentials for external services are stored encrypted with AES-256-GCM using a separate key per secret. Administrative actions require two-factor authentication and are recorded in a tamper-evident hash-chained log. Backups run regularly and the restore procedure is periodically exercised in drills.

10. Your rights

You may request information about the processing of your data, obtain an export of it, ask for correction or deletion, withdraw consent and object to processing.

Write to [email protected] from the address registered in your account. We respond within 10 business days; deletion is carried out within 30 days of the request, except for records we are legally required to retain, such as billing documents.

11. Your customers' data

For the information you enter into the platform about your own customers — contacts, conversations, call recordings — you are the controller and we act on your instructions as a processor.

You are responsible for the lawfulness of collecting that data and for obtaining any required consents; we are responsible for the security of processing, for following your instructions, and for deleting the data at your request or when the project is deleted.

12. Cookies and analytics

We use strictly necessary cookies for the website — language preference and consent settings. If you choose «Accept all», we additionally store the referral source and campaign parameters to understand which channels work.

The application uses technical session cookies — sign-in is impossible without them. We do not deploy third-party tracking systems such as Google Analytics or Facebook Pixel.

13. Minors

The service is intended for businesses and is not designed for anyone under 18. We do not knowingly collect children's data; if such data has reached us by mistake, let us know and we will delete it.

14. Changes to this policy

We may update this policy. The current version is always published on this page and the date of the latest change is shown at the top. We will notify you by email at the address registered in your account about material changes before they take effect.

15. Contact

Questions about data processing, export and deletion requests: [email protected]. We respond within 10 business days.