Privacy Policy

Effective Date: February 26, 2026  |  Last Updated: February 26, 2026

Summary: Multikor.ai, Inc. ("Multikor," "we," "us") is committed to protecting your privacy. This policy explains what data we collect, why we collect it, how we use it, and what rights you have. It applies globally and addresses the requirements of U.S. federal law, CCPA/CPRA, GDPR, the Apple App Store, and the Google Play Store.

1. Services Covered

This policy covers everything we operate.

2. Information We Collect

2.1 Information You Provide Directly

Data CategoryExamplesPurpose
Account Information Name, email, password, company name, job title/role Account creation, authentication, authorization
Waitlist / Form Data Name, email, company, role, company size, primary AI challenge Early access processing, sales qualification
Chat Messages Text messages and queries submitted to the AI Chat Agent Generating AI responses, conversation continuity, service improvement
Voice Input Audio processed via device speech recognition APIs Voice-to-text conversion for the AI Chat Agent
Biometric Data Fingerprint, Face ID, or other biometric identifiers stored on your device Secure authentication for mobile app login
Communications Emails, support requests, feedback Customer support, service improvement

Biometric Authentication Notice: The Multikor mobile apps support biometric login (Face ID, Touch ID, fingerprint) for convenience. Biometric data is processed and stored entirely on your device using your OS's secure enclave (Apple Secure Enclave or Android Keystore). Multikor never receives, transmits, or stores your raw biometric data on our servers. We only receive a confirmation that authentication succeeded or failed. You can enable or disable biometric login at any time in app settings.

2.2 Information Collected Automatically

Data CategoryExamplesPurpose
Device Information Device type, OS, browser type, screen resolution, language preference Service optimization, compatibility, analytics
Usage Data Pages visited, time spent, navigation patterns, features used, login frequency Analytics, service improvement, engagement tracking
Session Data Session identifiers, login timestamps, user agent strings Session management, security, analytics
Network Data IP address, approximate location (derived from IP) Security, fraud prevention, analytics
AI Interaction Metadata Selected AI agent, selected discipline/skill, token usage, response timestamps, conversation session IDs Service delivery, cost management, quality improvement
AI Routing & Confidence Data Confidence scores, routing tier decisions, self-healing events, feedback loop category Platform optimization, decision auditing, model improvement

2.5 Data You Import

When you import data into the platform, here's what we process.

Data CategoryExamplesPurpose
Imported File Data CSV and JSON files you upload, including all field values and content Data ingestion, auto-schema creation, AI-powered analytics and chat
Third-Party System Data Records synced via API from systems like Salesforce, ServiceNow, HubSpot, Jira, Confluence, QuickBooks, SAP, Oracle, and others Data ingestion, auto-schema creation, AI-powered analytics and chat
Schema & Classification Metadata Auto-detected data types, field classifications, relationship mappings, PII flags Enabling AI queries, data navigation, PII protection, compliance
Integration Credentials OAuth tokens, API keys, connection configurations for third-party systems Authenticating and maintaining data source connections

Full content analysis: When you import data, our Auto-Schema system reads the actual values in your data (not just column headers) to classify fields, detect data types, identify relationships, and flag PII or sensitive information. All imported data and resulting schemas remain within your Tenant boundaries.

2.3 Information from Third Parties

We may receive information about you from:

2.4 Information We Do NOT Collect

3. How We Use Your Information

3.1 Service Delivery and Operations

3.2 Model Improvement and Analytics

Here's exactly how we use your data to make the platform better.

3.3 Security and Compliance

3.4 Communications

4. Legal Bases for Processing (GDPR)

If you're in the EEA, UK, or Switzerland, here's our legal basis for each type of processing.

Legal BasisProcessing Activities
Contract Performance Account creation, service delivery, AI Chat Agent responses, conversation storage
Legitimate Interest Analytics, service improvement, security, fraud prevention, AI confidence scoring and routing, self-healing workflow processing, tenant data isolation enforcement, feedback loop refinement using anonymized patterns
Consent Marketing communications, optional voice features, cookies and tracking
Legal Obligation Tax records, regulatory compliance, responding to lawful government requests

5. Organizational Accounts and Administrator Access

If you're part of an Organization, your admin may see some of your activity. Here's what that means.

5.1 Data Provided by Administrators

When an Administrator invites you to an Organization, they provide your personal information (name, email, company, job title, and role) to create your account. The Administrator represents they have the authority and, where required, your consent to share this information.

5.2 Data Visible to Administrators

If you're a Member of an Organization, your Administrator(s) may see:

Heads up: If you're using the Services as part of an Organization, your chatbot conversations and usage may be monitored by your Administrator(s) for quality assurance, compliance, and reporting. Content submitted within an organizational context may not be private from your admin, except as required by law.

5.3 Administrator Obligations

Administrators are required to:

Multikor isn't responsible for how an Organization or its Administrators use the data available through admin features, except as required by law.

5.4 Member Rights Within Organizations

As a Member, you keep all privacy rights in Section 10. Account deactivation is managed by your Organization's Administrator(s)—you cannot deactivate your own account. Data retention for deactivated accounts is governed by your Organization's retention policies in addition to ours. Questions? Contact your Administrator or privacy@multikor.ai.

6. AI Chat Agent — Specific Disclosures

The AI Chat Agent is central to our Services. Here's exactly what happens with your data.

6.1 What We Store

6.2 How Long We Store It

6.3 Third-Party AI Providers

Your messages are sent to third-party AI providers to generate responses. Current providers include:

These providers process your messages solely to generate AI responses. We contractually require them to handle your data per applicable privacy laws. We do not authorize third-party AI providers to use your data to train their models. See each provider's privacy policy for their retention and processing practices.

6.4 How We Learn from Your Data

Important: Multikor refines its classification and routing models using interaction patterns. This is different from many AI providers, and it's a core part of how our platform gets better over time. Here's exactly how it works.

What our SLMs actually do: Our small language models (DistilBERT/TinyBERT) handle classification and routing. They decide where your request goes—they don't generate the content you see. The "learning" comes from feedback loops, not from training on your raw messages.

How the feedback loops work:

Your data ownership is preserved:

6.5 Voice Data

When using voice input:

6.6 AI Decision Routing and Confidence Scoring

We store metadata about how the AI routes and scores your requests.

For every AI interaction, we store routing metadata including:

Retention: Routing metadata is retained for the duration of your account plus applicable audit periods. Feedback loop data is retained indefinitely in aggregated, anonymized form for continuous platform improvement.

6.7 Data Ingestion and Integration

When you import data from files or connect third-party systems, here's how we handle that data.

What we process:

How we protect it:

Third-party data source connections:

Retention: Imported data is retained for the duration of your account. When your account is deactivated, imported data is retained per your Organization's retention policies and purged per our data retention schedule (Section 9).

7. How We Share Your Information

We don't sell your data. Here's who we do share it with and why.

RecipientPurposeData Shared
AI Model Providers (Anthropic, OpenAI, Google, and others) Generating AI responses Chat messages, conversation context
Cloud Infrastructure (AWS, Google Cloud/Firebase, Vercel) Hosting, data storage, serverless computing All data necessary to operate the Services
Analytics Providers (Google Analytics) Usage analytics Anonymized/pseudonymized usage data
Form Processors (Formspree) Processing waitlist submissions Name, email, company, role
Multikor Internal Administrators Platform management, support Account info, usage data, conversation logs
Organization Administrators Member management, monitoring, reporting, compliance Member account info, usage activity, chatbot conversations, analytics (see Section 5)
Third-Party Data Sources (Salesforce, ServiceNow, HubSpot, etc.) Bidirectional data sync (import only unless you enable write-back) Data you authorize per integration scope; OAuth tokens for authentication
Cross-Client Learning (Aggregated) Platform-wide model improvement via feedback loops Anonymized interaction patterns only. Raw data never crosses Tenant boundaries.
Legal / Regulatory Compliance with laws, legal proceedings, government requests As required by law
Business Transfers Merger, acquisition, or asset sale All user data (with prior notice)

8. Data Storage and Security

8.1 Where We Store Data

Your data is stored on servers in the United States, operated by our infrastructure providers (AWS, Google Cloud/Firebase, Vercel). If you access the Services from outside the US, your data will be transferred to the US for processing and storage.

8.2 International Data Transfers (GDPR)

For users in the EEA, UK, or Switzerland, we protect international data transfers with:

8.3 Security Measures

We take security seriously. Here's a detailed look at how we protect your data.

8.3.1 Encryption

8.3.2 Multi-Tenant Data Isolation

Your data is isolated from every other customer's data through five layers:

  1. Data tagging: Every record is tagged with your Tenant ID at write time
  2. Query filtering: All database queries are scoped to your Tenant—cross-tenant queries are architecturally impossible
  3. Index partitioning: Search indexes are partitioned per Tenant
  4. Compute isolation: Processing workloads are separated per Tenant
  5. Audit logging: All access is logged and traceable to specific users and tenants

8.3.3 Authentication and Access Control

8.3.4 PII Detection and Protection

8.3.5 Network Security

8.3.6 Content Safety

8.3.7 Data Ingestion Pipeline Security

Data ingestion operates through a dedicated security pipeline separate from the AI chat pipeline:

No security system is perfect. While we work hard to protect your data, we can't guarantee absolute security.

8.4 Disaster Recovery

We plan for the worst so you don't have to.

8.5 Incident Response

8.6 Compliance Frameworks

The Multikor platform is designed to support compliance with:

FrameworkScope
HIPAAProtected health information handling for healthcare customers
SOC 2 Type IISecurity, availability, and confidentiality controls
GDPREU/EEA data protection and privacy rights
PCI-DSSPayment card data protection (where applicable)
SOXFinancial reporting and audit controls
CCPA/CPRACalifornia consumer privacy rights
FERPAEducation records protection (where applicable)

Industry-specific compliance documentation and certifications are available to enterprise customers under NDA. Contact security@multikor.ai for details.

9. Data Retention

Here's how long we keep different types of data.

Data TypeRetention Period
Account informationDuration of account + Organization retention policy; purged per retention schedule after deactivation
Chat conversation dataDuration of account + Organization retention policy; purged per retention schedule after deactivation
AI routing and confidence dataDuration of account + 36 months for audit; feedback loop data retained indefinitely in aggregated form
Imported data (files, API syncs)Duration of account + Organization retention policy; integration credentials deleted immediately on disconnect
Auto-Schema metadataDuration of account + Organization retention policy; purged per retention schedule after deactivation
Waitlist / form submissionsUntil processed or 24 months, whichever is shorter
Usage analytics (identifiable)24 months from collection
Aggregated / anonymized analyticsIndefinitely (can't be linked to individuals)
Security and audit logsUp to 7 years (CloudTrail); up to 36 months (operational)
Records required by lawAs required by applicable law

10. Your Privacy Rights

10.1 Rights for All Users

Regardless of where you are, you have the right to:

10.2 GDPR Rights (EEA, UK, Switzerland)

If you're in the EEA, UK, or Switzerland, you also have these rights under the GDPR:

To exercise these rights, contact privacy@multikor.ai. We'll respond within 30 days (extendable by 60 days for complex requests).

10.3 CCPA/CPRA Rights (California Residents)

California residents have these additional rights:

To exercise these rights, contact privacy@multikor.ai or use the account settings in the app. We'll verify your identity and respond within 45 days.

10.4 Account Deactivation

Account management is centralized through your Organization's Administrator(s). Accounts are provisioned via administrator invitation and deactivated through administrator controls.

You cannot deactivate your own account. To request deactivation:

When an account is deactivated:

  1. Your access to the Services is immediately revoked
  2. Your data is retained per your Organization's retention policies and our data retention schedule (Section 9)
  3. Data that is no longer needed is purged according to the applicable retention period
  4. Data we're legally required to keep (e.g., billing records, audit logs) is retained as required

Your Organization's Administrator may reactivate your account at their discretion. Anonymized, aggregated data that can no longer be linked to you may be retained indefinitely for analytics.

10.5 Data Erasure Requests

If you want your personal data erased (under GDPR, CCPA, or other applicable law), contact your Organization's Administrator or email privacy@multikor.ai. We'll work with your Organization to process the request. Erasure may be subject to your Organization's retention policies and applicable legal requirements.

11. Cookies and Tracking Technologies

11.1 What We Use

11.2 AI Bot Detection

We detect and log visits from AI crawlers and bots (including ChatGPT, Claude, Perplexity, Google, Bing, and others) for analytics. This tracking applies only to automated bot traffic, not individual users.

11.3 Online Data Partners and Advertising

When you visit or log in to our website, cookies and similar technologies may be used by our online data partners or vendors to associate these activities with other personal information they or others have about you, including by association with your email. We (or service providers on our behalf) may then send communications and marketing to these email addresses. You may opt out of receiving this advertising by visiting https://app.retention.com/optout.

11.4 Managing Cookies

You can control cookies through your browser settings. Disabling essential cookies may limit certain features. For analytics opt-out, visit Google Analytics Opt-Out.

12. Mobile Application Privacy

Privacy details specific to the Multikor iOS and Android apps.

12.1 Device Permissions

PermissionPurposeRequired?
Internet AccessAll functionality requires network connectivityYes
Biometric (Face ID / Fingerprint)Secure authentication; processed on-device onlyNo (optional)
MicrophoneVoice input for the AI Chat AgentNo (optional)
Push NotificationsService updates, events, account alerts, security notificationsNo (optional)
Storage / CacheCaching for performance and offline accessYes

You can manage all optional permissions through your device settings at any time.

12.2 Apple App Privacy (iOS)

Per Apple's App Privacy requirements:

12.3 Google Play Data Safety (Android)

Per Google Play's Data Safety requirements:

12.4 No Sale of Data

We don't sell personal information collected through the mobile apps. Ever.

13. Children's Privacy

The Services aren't directed to anyone under 18. We don't knowingly collect personal information from children. If we learn we have, we'll delete it promptly. If you believe a child under 18 has provided us with personal data, contact privacy@multikor.ai.

14. Third-Party Links and Services

The Services may contain links to third-party websites or services (e.g., Google Calendar for scheduling demos). We're not responsible for their privacy practices. Review their policies before sharing personal information.

15. Do Not Track Signals

Some browsers offer a "Do Not Track" (DNT) setting. There's currently no industry standard for responding to DNT signals. We don't currently respond to them. We'll update this policy if a standard is established.

16. Changes to This Privacy Policy

We may update this policy to reflect changes in our practices, technology, legal requirements, or business. When we make material changes:

Continued use after changes take effect means you accept the updated policy.

17. Contact Us

Questions about this policy or your data? We're here to help.

For GDPR-related inquiries, you may also contact your local data protection authority. A list of EEA DPAs is available at edpb.europa.eu.