Your data is yours.
Full stop.

MultipleChat connects you to the world’s best AI models without compromising your data. We do not train on your content, we encrypt everything, and we are transparent about exactly how your data flows through the system.

No training on user data
Encrypted in transit and at rest
GDPR compliant

Security by design, not by afterthought.

Your data is never used for model training

Your conversations, documents, presentations, and uploaded files are never used to train or fine-tune any AI model. Not by us. Not by our AI providers. This is contractual, not just policy. We use API agreements with Anthropic, OpenAI, Google, and xAI that explicitly exclude customer data from training.

Encryption everywhere

All data is encrypted in transit using TLS 1.2+ and at rest using AES-256. This applies to conversations, uploaded files, generated documents, and all metadata. No exceptions.

Transparent data flow

When you send a message, you see which AI model processes it and the exact cost before generation. No hidden routing, no undisclosed model switching, no background data collection. You know exactly where your data goes at every step.

GDPR and privacy compliance

MultipleChat complies with GDPR and applicable data protection regulations. You can export your data, request deletion, and exercise all rights under applicable privacy law. Our privacy policy details exactly what we collect, why, and for how long.

From your message to your answer. Nothing else.

Here is exactly what happens when you use MultipleChat.

1

You send a message

Your message is encrypted and sent to MultipleChat servers over TLS. We store the conversation so you can access your history.

2

We route to your chosen AI model

Your message is sent via encrypted API to the AI provider you selected — Anthropic (Claude), OpenAI (ChatGPT), Google (Gemini), or xAI (Grok). We use API agreements that prohibit the provider from using your data for training.

3

The AI generates a response

The AI provider processes your message and returns a response. In multi-model modes, this happens with two models — the second model receives the first model’s output for review.

4

You see the result

The response is returned to you over TLS. For document and presentation generation, the file is built on our servers and delivered to your browser for download. Files are stored in your account until you delete them.

What does NOT happen

Your data is not sold. It is not shared with third parties for advertising. It is not used for model training or fine-tuning. It is not retained by AI providers beyond the time needed to generate a response. It is not analysed for profiling or targeting.

What each provider does with your data.

MultipleChat accesses all AI models via their official APIs with enterprise-grade data handling agreements. Here is what each provider commits to.

ProviderModelTraining on API dataData retentionEncryption
Anthropic Claude No — API data excluded from training Not retained beyond processing TLS in transit, AES at rest
OpenAI ChatGPT No — API data excluded from training 30 days for abuse monitoring, then deleted TLS in transit, AES at rest
Google Gemini No — API data excluded from training Not retained beyond processing TLS in transit, AES at rest
xAI Grok No — API data excluded from training 30 days for abuse monitoring, then deleted TLS in transit, encrypted at rest

All provider data handling is governed by their respective API terms of service. MultipleChat uses enterprise API tiers where available.

Built on secure infrastructure.

Cloud hosting

MultipleChat runs on enterprise-grade cloud infrastructure with automatic scaling, redundancy, and 99.9% uptime SLA.

Authentication

Secure authentication with password hashing, rate limiting on login attempts, and session management. SSO support available for enterprise plans.

Payment security

All payment processing is handled by Stripe, a PCI DSS Level 1 certified processor. MultipleChat never stores credit card numbers or sensitive payment data.

Access controls

Internal access to production systems is restricted by role, requires multi-factor authentication, and is logged for audit purposes.

Vulnerability management

Regular dependency updates, automated security scanning, and responsible disclosure practices. If you find a security issue, contact us at [email protected].

Data deletion

You can delete conversations, documents, and your entire account at any time. Deletion is permanent — once removed, your data cannot be recovered by us or anyone else.

You control your data. Always.

Right to access

Request a copy of all data we hold about you at any time.

Right to deletion

Delete individual conversations, documents, or your entire account permanently.

Right to export

Export your data in standard formats. Your content belongs to you.

Right to object

Object to specific data processing activities under GDPR and applicable law.

Security questions

Does MultipleChat train AI models on my data?

No. Your conversations and documents are never used for training. We use API agreements that explicitly prohibit providers from using your data for model training or improvement.

Is my data shared with third parties?

Only with the AI model providers you select, solely to generate your response. We do not sell data, share it for advertising, or provide it to any other third party.

Where is my data stored?

MultipleChat uses enterprise-grade cloud infrastructure. All data is encrypted at rest and in transit. Specific data residency options may be available for enterprise customers.

Can I delete my data?

Yes. You can delete individual conversations, specific documents, or your entire account. Deletion is permanent and irreversible.

Is MultipleChat SOC 2 certified?

We are building toward SOC 2 Type II certification. Our infrastructure and practices are designed to meet SOC 2 requirements. Contact us for our current security posture documentation.

How do I report a security vulnerability?

Email [email protected] with details. We take all reports seriously and will respond within 48 hours. We practise responsible disclosure and appreciate the security community’s help.

Questions about security?

We are happy to discuss our security practices in detail. For enterprise security reviews, compliance documentation, or specific questions about data handling, reach out directly.

[email protected] · Response within 4