Privacy notice · 27 July 2026
Private by design, inspectable by choice.
This notice describes the data Multibrain needs to operate and the choices available to account holders. A deliberation is private unless its owner deliberately creates a share snapshot.
Data we process
- Account identity, verification state, profile settings, and database-backed sessions.
- Questions, panel configuration, model responses, reviews, verdicts, citations, feedback, usage, and cost records needed to deliver and explain a run.
- Documents you upload, extracted text and provenance, until they are deleted under the applicable retention or account-deletion process.
- Billing, subscriptions, managed provider funding, and Stripe payment processing are unavailable in the initial closed beta.
- Bounded security and operational records such as job state, provider request IDs, audit actions, and normalized errors. Credentials and raw secret-bearing headers are excluded.
Provider credentials
User-supplied provider credentials are validated, encrypted with authenticated encryption, and stored separately from their nonce, authentication tag, and key version. The plaintext is decrypted only for the selected provider operation. Interfaces, logs, events, exports, and share snapshots receive masked metadata rather than the credential value.
Where data goes
The question, necessary evidence, and stage prompt are sent to the BYOK model providers selected for a run. Those providers process the material under the terms of the account that supplied the credential. The configured email service processes verification and password-reset messages. Private uploads are kept in non-public application storage and are not served directly by NGINX.
Sharing and exports
Creating a share makes an immutable, allowlisted snapshot available to anyone holding its random link until expiry or revocation. Shares exclude account identity, credentials, private document bodies, hidden prompts, and raw provider payloads. Exports are delivered only to the authenticated owner; what you do with a downloaded export is your responsibility.
Security, retention, and deletion
Multibrain uses owner-scoped authorization, encrypted transport, private storage, durable audit records, bounded request handling, and secret-redacted logging. Retention differs by record type: private content can be removed through document and account controls, while narrowly required fraud-prevention, security, and audit facts may be retained in anonymized form. An account-deletion request immediately disables access and starts durable cleanup rather than claiming that every external processor erases data synchronously.
Your choices
- Use only your own supported provider credentials during the closed beta.
- Delete reusable documents and revoke provider credentials or public shares.
- Billing, subscriptions, and managed provider access are unavailable in this release.
- Export your run data and request account deletion from profile settings.