Multilo
FeaturesPlatformDocsPricingChangelogContact
Sign inDownload
Privacy policy

How we handle account, billing, and app data.

This policy explains what Multilo collects, why we use it, and how customers can contact us about their information.

Last updated: April 28, 2026

Your papers stay on your device

Multilo runs on your computer. Your documents and project files live on your own disk — we have no copy of them and never upload them to our servers.

We don't sell your data

We do not sell your personal information and do not share it for cross-context behavioural advertising. We don't run ad networks on you.

You're in control

Telemetry is opt-in by tier, product-improvement collection is opt-out, and you can access, export, or delete your data at any time.

On this page

  1. 1Local-first: your work stays with you
  2. 2Who we are
  3. 3Scope of this policy
  4. 4Information we collect
  5. 5How we use information
  6. 6AI processing and your content
  7. 7Legal bases and regional rights
  8. 8Service providers we share data with
  9. 9Payments
  10. 10Cookies, local storage, and device identifiers
  11. 11Anonymous desktop telemetry
  12. 12Product improvement (chat & AI suggestions)
  13. 13International processing
  14. 14How long we keep data
  15. 15Your privacy rights
  16. 16California privacy rights
  17. 17Other U.S. state privacy rights
  18. 18Deleting your account and data
  19. 19Automated decisions
  20. 20Security
  21. 21Children and students
  22. 22Changes to this policy
  23. 23Contact

Local-first: your work stays with you

Multilo is a desktop application, not a website you paste your work into. Your documents, drafts, citations, and project files are saved on your own computer — so your unpublished research and sensitive writing stay private to you.

  • We have no "your documents" database. Your papers are never uploaded to or stored on Multilo's servers — there is simply no copy of them on our side.
  • There is no cloud sync of your document content. Autosave, drafts, and version history live on your device.
  • When you choose to use an AI feature, only the specific text you act on is sent — encrypted, for that single request — to the AI model provider. We never send your whole project, and we do not keep that content afterward.
  • Optional product-improvement collection is off by default and opt-out. Even when on, it stores only a small, time-limited snippet of your chat context — never your documents — and excludes education and enterprise plans.

That's different from web-based writing tools, where you upload your entire document to someone else's cloud just to use it. With Multilo, your secret and unpublished work stays where it belongs — with you.

Who we are

Multilo ("Multilo", "we", "us") provides the Multilo website, desktop application, and related academic-writing services, and is the controller responsible for the personal information described in this policy. For privacy questions or to exercise your rights, contact us at support@multilo.com.

Scope of this policy

This policy covers personal information we process when you visit the website, create an account, download or use the desktop app, subscribe to a paid plan, connect third-party services such as GitHub, or contact support. It does not cover third-party websites or services that have their own privacy policies, or content you choose to share with third parties through integrations you enable.

Information we collect

We collect the information needed to operate the website, desktop app, subscriptions, and support workflows.

Information you provide

  • Account details such as name, email address, profile image, sign in provider, role, and account status.
  • Messages, files, prompts, or other content you choose to submit through the app or connected features.

Information collected automatically

  • Desktop app information such as account connection events, app version, operating system details, project details, agent usage, model selections, timestamps, and diagnostics or crash reports when you choose to enable them.
  • An approximate country (for example “United States”) derived from your IP address when you sign in or your desktop app connects. We store only the resulting country code for product analytics, security, and regional compliance — we do not keep the raw IP address alongside your account.

Information from third parties

When you sign in with Google or connect GitHub, we receive basic profile information (such as your name, email, and avatar) from that provider. When you subscribe, Stripe shares billing status and identifiers with us. We combine this with your account so the service works.

  • Subscription records such as plan, status, Stripe customer ID, Stripe subscription ID, price ID, renewal period, and cancellation status.
  • Optional GitHub connection information when you connect GitHub for project creation.

How we use information

  • Authenticate users and connect the desktop app.
  • Provide AI agent, model access, usage, and project features.
  • Manage free and paid subscription limits.
  • Process billing events, cancellations, and account support.
  • Understand which countries our users are in to prioritise features, languages, and regional compliance.
  • Diagnose errors, prevent abuse, and improve reliability.
  • Comply with legal, tax, security, and payment obligations.

AI processing and your content

Several Multilo features — chat, agents, and inline suggestions — work by sending the content you choose to act on (your prompt, selected text, document context, and any images you attach) to an AI model provider that generates a response. This only happens when you trigger the feature.

  • Content is sent over an encrypted connection to the model provider for that request (currently Anthropic, OpenAI, and/or Google, depending on the model you pick).
  • We send the minimum context the feature needs. We do not send your file names, project paths, or IP address to the model provider.
  • We instruct providers not to retain content for training where that control is available to us (for example, requesting no-storage handling on supported endpoints). Providers may retain limited data briefly for abuse monitoring under their own terms.
  • AI output can be wrong or incomplete. You are responsible for reviewing AI-assisted work before you rely on, submit, or publish it.
  • Sending content to a model provider is required for these features to function. If you do not want your content processed by an AI provider, do not use the AI features; the rest of the app still works.

The specific providers we use can change as we add or remove models. The active list of model providers is reflected in the app's model picker and in our list of service providers below.

Legal bases and regional rights

Depending on where you live, you may have rights to access, know, correct, delete, export, restrict, or object to certain processing of personal information. You may also have rights to withdraw consent where processing is based on consent.

For EEA, UK, and similar privacy-law users, our legal bases may include performance of the service contract, consent, legitimate interests in security and product operation, and compliance with legal obligations. For California and similar state-law users, we do not sell personal information or share it for cross-context behavioural advertising.

Service providers we share data with

We share limited personal information with vendors that process it on our behalf to run the service. Each is bound by contract to use the data only to provide their service to us. We do not sell personal information to any of them.

ProviderWhat they doData they receive
StripePayments and subscription billingName, email, billing/card details (entered directly with Stripe), customer and subscription identifiers
AnthropicAI model responses (Claude)The prompt and context you submit when you use an AI feature with a Claude model
OpenAIAI model responses (GPT)The prompt and context you submit when you use an AI feature with an OpenAI model
GoogleSign-in and AI model responses (Gemini)Basic profile for sign-in; prompt and context when you use a Gemini model
GitHubOptional GitHub project workflowsGitHub login, access token, and repository actions you initiate
ResendTransactional and account email deliveryEmail address and message content (verification, billing, support, notifications)
ConvexApplication database and backend hostingAccount, subscription, usage, support, and related records
VercelWebsite hosting and edge deliveryRequest metadata; approximate country derived at the edge

We may add or change providers as the product evolves. We update this list when our core processors change.

Payments

Payments are processed by Stripe. We do not store full credit card numbers or bank account details on our servers. Stripe provides us with billing status, subscription identifiers, customer identifiers, and related payment details so we can provision and support paid plans.

Cookies, local storage, and device identifiers

We keep our use of browser storage minimal and do not use third-party advertising cookies.

  • Essential cookies — used to keep you signed in and secure your session on the website. The service does not work without these.
  • Local storage on your device — remembers your theme, interface language, and which legal and AI-processing notices you have accepted. This stays on your device.
  • Device identifier — when you opt in to desktop telemetry, the app generates a random identifier stored locally. It is never linked to your email, account, or hardware, and you can delete it any time in Settings → Privacy.

Because we do not use advertising trackers, we treat a Global Privacy Control or "Do Not Track" signal as an opt-out of any non-essential analytics where applicable.

Anonymous desktop telemetry

The Multilo desktop app can send anonymous usage data so we can fix what breaks and ship features that get used. We ask you to choose on first launch between three options: Standard only (recommended), Standard + crash diagnostics, or No telemetry. Whichever you choose can be changed any time in Settings → Privacy.

  • Standard tier sends: app version, operating-system label (e.g. “Windows 11”), CPU architecture, locale, primary screen size, daily counts of named events from a closed allow-list (e.g. doc.opened, citation.inserted), tagged events for the update funnel and AI completions with small allow-listed property bags (e.g. modelId, latencyMs), and session start/end markers.
  • Crash diagnostics tier adds short error messages and reason strings to crash events. These sometimes include file paths from your machine, which is why this tier is a separate opt-in and OFF by default.
  • Every payload is tied to a random per-device identifier that we generate locally on first opt-in. It is never linked to your email, account, or hardware. We never receive document content, AI prompts, file names, project paths, or your IP address (the server sees IP via TCP but does not log it).

Raw events and counts are retained for 90 days, then automatically deleted by a daily cron. Per-device fingerprints (without raw event history) are retained for the life of the device. Aggregated daily snapshots (DAU/MAU, version distribution) are retained indefinitely for trend analysis — these never contain per-device data.

You can delete every row tied to your device id with one click in Settings → Privacy. The full catalogue of event names and property keys is at /privacy/telemetry.

Product improvement (chat & AI suggestions)

To improve Multilo and the AI features in it, we may collect the content of your chat messages and the text context sent for inline AI suggestions, tied to your account. This is separate from the anonymous telemetry described above, and you control it:

  • It is opt-out. You can turn it off at any time in the desktop app under Settings → Data Controls. When off, no chat or suggestion content is collected for improvement.
  • Education and enterprise plans are excluded by default — content from those accounts is not collected for improvement unless separately agreed.
  • Collected content is retained for a limited period (about 30 days by default) and then automatically deleted, and it is removed entirely if you delete your account.
  • We use it to understand what users ask for, fix failures, and improve our models and features. We do not sell it or use it for advertising.

International processing

We may process and store information in countries other than where you live. When legally required, we use appropriate safeguards for cross-border transfers, such as contracts, vendor terms, or other recognised transfer mechanisms.

How long we keep data

We keep account, billing, usage, telemetry, and support records for as long as needed to provide the service, comply with obligations, resolve disputes, and maintain security. You can ask us to access, correct, export, or delete personal information, subject to legal and operational retention requirements.

DataRetention
Account and profileWhile your account is active; deleted on account closure (minus legal holds)
Billing and invoicesAs required by tax and accounting law (typically several years)
Anonymous telemetry events90 days, then auto-deleted
Product-improvement contentAbout 30 days by default; removed on account deletion
Support ticketsKept while needed for support history, then periodically purged
Verification / reset tokensDeleted within ~30 days of expiry

The desktop app asks for required legal and AI-processing consent before completing account connection. Diagnostic telemetry and crash reporting are optional and can be changed from desktop settings. Extension installs require a separate permission review.

Your privacy rights

Subject to your location and applicable law, you have the following rights over your personal information. We will not discriminate against you for exercising them.

  • Access — request a copy of the personal information we hold about you.
  • Correction — ask us to fix inaccurate or incomplete information.
  • Deletion — ask us to delete your personal information, subject to legal retention limits.
  • Portability — receive certain information in a portable, machine-readable format.
  • Restriction and objection — ask us to limit or stop certain processing, including processing based on legitimate interests.
  • Withdraw consent — where processing is based on consent (such as product-improvement collection or optional telemetry), withdraw it at any time without affecting prior processing.
  • Complain — lodge a complaint with your local data protection authority.

How to exercise your rights

Email support@multilo.com or use the controls in your account and the desktop app. We may need to verify your identity before acting on a request. We respond within the timeframe required by applicable law. You can authorise an agent to make a request on your behalf where the law allows.

California privacy rights

If you are a California resident, the CCPA/CPRA gives you the rights to know, access, correct, and delete your personal information, and to limit the use of sensitive personal information. We do not sell your personal information and do not share it for cross-context behavioural advertising, so there is no "sale" or "share" to opt out of. We do not use or disclose sensitive personal information for purposes that require an opt-out. You may exercise these rights using the contact details below, and we will not discriminate against you for doing so.

Other U.S. state privacy rights

Residents of states with comprehensive privacy laws (such as Colorado, Connecticut, Virginia, Utah, Texas, Oregon, and others) have rights to access, correct, delete, and obtain a portable copy of their personal data, and to opt out of targeted advertising, sale, or certain profiling. We do not sell personal data or use it for targeted advertising. Contact us to exercise these rights; where required, you may appeal a decision by replying to our response.

Deleting your account and data

You can delete your account from your account settings or by emailing support@multilo.com. When you delete your account we cancel any active subscription, send you a confirmation, and remove your personal records from our systems in bounded batches. Some data may be retained only as long as required for legal, tax, security, or dispute-resolution purposes, after which it is deleted. Anonymous telemetry tied to a device identifier can be deleted separately from Settings → Privacy.

Deleting your account and data

Automated decisions

We use automated checks for usage limits, fraud and abuse prevention, and rate limiting. These do not produce legal or similarly significant effects about you without human involvement. AI features generate suggestions, not decisions about you — you remain in control of whether to use their output.

Security

We use reasonable administrative, technical, and organisational safeguards for customer information. No online service can guarantee absolute security, so customers should use strong account credentials and protect desktop connection credentials.

Children and students

Multilo is intended for students, researchers, and adult academic users. It is not directed to children under 13. Do not submit personal information from children under 13 unless you have the authority and verified consent required by applicable law. Minors should use the service only with appropriate parent, guardian, school, or institutional permission.

Changes to this policy

We may update this policy as the product and the law change. We will post the updated version here with a new "last updated" date, and for material changes we will provide additional notice where appropriate. Your continued use of the service after an update means you accept the revised policy.

Contact

For privacy requests, email support@multilo.com. You can also review our Terms, Refund Policy, and Contact page.

Privacy contact

Email privacy or account questions to support@multilo.com.

Privacy contactsupport@multilo.comYour privacy rightsHow to exercise your rightsTermsRefunds · Fulfilment
Account and usage data powers subscriptions, quotas, support, and product security.
Multilo

AI document IWE downloads, desktop account connection, agents, and GitHub project workflows in one product hub.

DocsPricingChangelogSupportDownloadAccountPrivacyTermsRefund policyFulfilmentContact
Interface Language
Theme

Multilo uses AI to support your academic writing. Generated content may contain inaccuracies, and is not always identifiable as AI-written by detection tools. See our Terms & Policies for the full details.