Privacy Policy

Last updated: April 11, 2026

multi-ai (“we”, “our”, “us”) builds a multi-AI comparison and synthesis service. This policy explains what data we collect, why, how we keep it safe, and how you can control it.

1. Information we collect

a. Account information

When you sign in via Google, Apple, Kakao, or email magic link, we receive your email address and (if available) display name and profile picture from the provider. We do not receive or store your social account password.

b. Content you create

We store the questions you submit and the AI responses you receive, so that you can revisit conversation history later. You can delete individual chats at any time.

c. Usage data

We log the model identifiers used, approximate token counts, and timestamps for billing-protection and product-improvement purposes. We do not log keystrokes, cursor movements, or any data beyond the chat content itself.

d. Bring Your Own Key (BYOK)

If you register your own API keys for Anthropic / OpenAI / Google / xAI in Settings, those keys are stored in our database under row-level security so that only your authenticated account can read them. We use them only to forward your requests to the corresponding provider. We never share or expose them to other users. Keys are stored as plaintext at this time; encryption at rest is on our roadmap. Only register keys on a device you trust.

e. Device & network

For anonymous demo access, we briefly retain a hashed form of your IP address for 24 hours to enforce a 1-question-per-day demo limit. After that window the hash is deleted.

2. How we use your data

We do not sell your personal data. We do not train any AI model on your data.

3. Third parties

When you ask a question, the relevant model identifier and your prompt are forwarded to the AI provider you selected. Each provider has its own privacy policy:

We also use Supabase for authentication and database storage, and Vercel for application hosting. Both are GDPR-compliant infrastructure providers.

4. Data retention

5. Your rights

You can at any time:

EU residents: you have the right to lodge a complaint with your local data protection authority. California residents: see the CCPA section below.

6. Children

multi-ai is not directed at children under 13 (or 16 in the EU). We do not knowingly collect data from children. If you believe a child has signed up, contact us and we will delete the account.

7. International transfers

Our database resides in Asia (Supabase region: ap-northeast-2 / Seoul). AI providers process your prompts in their global infrastructure (typically US-based). By using the service you consent to these transfers. We rely on standard contractual clauses and provider GDPR commitments where applicable.

8. Security

Authentication is handled by Supabase Auth (industry-standard PKCE/OAuth flows). Database access uses row-level security so that one user cannot read another's rows. All traffic is HTTPS. API keys you provide are protected by the same RLS but are stored in plaintext today — encryption at rest is on our roadmap.

9. Changes

We will update this page when our practices change. Material changes will be announced via email or in-app notice at least 14 days in advance.

10. Contact

Questions or data requests: 106ljune@gmail.com