Privacy policy
Last updated 10 September 2026
multiai.online lets you put several AI models in one room and talk to them together. To do that it stores your account, your conversations and the files you share, and it sends what you write to the AI vendors you have chosen. This page says exactly what that means.
Who runs this service
multiai.online is operated by the site owner, who is also the data controller. Questions or requests about your data go to privacy@multiai.online.
What is stored
Your account
An email address, a display name, and — if you sign in with Google — the account identifier Google gives us and the URL of your profile picture. If you register with a password instead, we store a hash of it, never the password itself. Accounts created through Google have no password stored at all.
Your conversations
Everything written in a chat is kept: your messages, every reply from every agent, timestamps, and technical details such as how long a model took and how much text it was sent. This is what makes a conversation still be there when you come back to it.
Files you upload
Files shared into a chat are stored on the server, along with the text extracted from them. That text is sent to the agents in the room. Uploaded images used as agent avatars are stored too.
Provider API keys
Keys you add for Anthropic, OpenAI, Google or your own endpoint are encrypted before they are written to the database, using a key held separately from it. Only the first and last few characters are ever shown back to you. A copy of the database on its own does not reveal them.
Logs
The server writes ordinary operational logs: requests, errors, and a record of each turn in a conversation — which agent spoke, how long it took, whether it failed. Logs rotate and are overwritten in the normal course of running the service.
Who your messages are sent to
This is the part worth reading carefully. When an agent takes a turn, the contents of that conversation — your messages, the other agents' replies, and any files you have shared — are sent to that agent's vendor over the internet, so the model can produce a reply. There is no way to run this service without that happening.
Which vendor receives it depends on which agents you seat in a chat. That may be Anthropic, OpenAI, Google, or any provider whose endpoint you have configured yourself. Each of them handles your data under their own terms and privacy policy, not this one:
If an agent has web search switched on, its vendor also performs searches on its behalf, which means the search terms the model chooses leave that vendor's systems.
Nothing is sent anywhere else. There is no analytics, no advertising, no tracking, and your conversations are not sold, shared or used to train anything by this service.
Cookies
One cookie, which keeps you signed in. It is not used for tracking and there are no third-party cookies. Fonts are loaded from Google Fonts, which means your browser contacts Google's servers to fetch them.
Google sign-in
If you sign in with Google, we ask for three things and nothing more: that
you are signed in (openid), your email address, and your basic
profile — name and picture. We do not request access to Gmail, Drive,
Calendar, contacts, or anything else in your Google account, and could not
reach them if we wanted to. You can revoke this at any time from your
Google account permissions.
How long things are kept
Your chats, files and keys stay until you delete them or delete your account. Deleting a chat removes its messages and its files. Deleting your account removes everything belonging to it. Deletion here is permanent; there is no recycle bin, and once your provider keys are gone they cannot be recovered.
Your rights
You can see, correct, export or delete your data. Export is built in — every chat downloads as Markdown or JSON from inside the app. For anything else, or to have your whole account removed, write to privacy@multiai.online and it will be dealt with within 30 days. If you are in the EU or UK you also have the right to complain to your national data protection authority.
Security, honestly stated
Traffic is encrypted in transit, provider keys are encrypted at rest, passwords are hashed, and each account can only reach its own data. That is a reasonable standard of care, not a guarantee: no service can promise it will never be breached. Treat this the way you would any small self-hosted tool — useful for work you would be comfortable having on a server you do not personally administer.
Children
This service is not intended for anyone under 16.
Changes
If this policy changes in a way that affects what happens to your data, the date at the top changes and the change is described here. Continuing to use the service after that means you accept the updated policy.
Contact: privacy@multiai.online · Terms of service