Trust & privacy

Privacy, explained
without hidden language.

This policy describes the information Multuser processes, why it is needed, how connected Google and Microsoft mailbox data is handled, and how you can remove it.

Effective and last updated: 5 August 2026

1. Scope and controller

This policy applies to the Multuser website, desktop applications, cloud workspace, Marketplace, managed proxy services, support tools, and mailbox features. “Multuser,” “we,” and “our” refer to the operator of the Multuser service.

Privacy and OAuth questions can be sent to info@tallinio.com.

2. Information we process

Account and company information

Usernames, email addresses, password hashes, company membership, roles, plan limits, preferences, sessions, and security/audit events.

Profile workspace information

Profile names, tags, notes, browser identity settings, proxy configuration, encrypted or protected credentials, activity history, synchronized cookies, and files that you intentionally upload to a profile.

Mailbox information

If you enable mailbox monitoring, we process the mailbox address, provider settings, encrypted OAuth tokens or app credentials, unread/read status, sender, subject, date, and message bodies that you explicitly open. Multuser keeps at most 30 recently opened message bodies in an encrypted per-profile cache so reopened messages load faster.

Payments, Marketplace, and proxies

Plan and order records, Stripe identifiers and payment status, crypto payment references, seller declarations, dispute records, rented proxy usage, health, country, limits, and bandwidth totals. Multuser does not store complete card details.

Diagnostics

Application version, error category, pseudonymous error reference, affected company/profile when available, device-storage health, proxy and fingerprint check results, and security/audit logs. Browsing history and page contents are not included in product error reports.

3. How we use information

  • Provide and synchronize the workspace and its access controls.
  • Open isolated profiles, apply requested browser settings, and connect configured proxies.
  • Show mailbox status and messages and send a reply only when the user requests it.
  • Process subscriptions, Marketplace orders, proxy rentals, refunds, and disputes.
  • Protect accounts, diagnose failures, prevent abuse, and maintain service availability.
  • Meet legal obligations and enforce the Terms of Service.

We do not use connected mailbox content for advertising, profiling, data brokerage, or training general-purpose AI models.

4. Google user data

Limited Use commitment. Multuser handles information received from Google APIs only as permitted by the Google API Services User Data Policy, including its Limited Use requirements.

When you choose “Connect with Google,” Multuser requests your basic account identity and Gmail access needed for IMAP/SMTP mailbox functionality. We use it only to:

  • identify the mailbox you selected;
  • count and display read or unread messages and their envelope information;
  • fetch a message body when you open that message;
  • mark a message read or unread at your direction; and
  • send a reply when you press the send action.

OAuth access and refresh tokens are encrypted at rest with AES-256-GCM and cryptographically bound to the approving owner, profile, and provider. Cached message bodies are also encrypted at rest, bounded to 30 messages per profile, and removed when mailbox access is disconnected or the profile is deleted.

Google OAuth grants and Gmail-derived message data are never included when a profile is sold or rented through Marketplace. The recipient must connect a mailbox under their own authority.

We do not transfer Google user data to third parties except as necessary to provide or secure the feature, comply with law, or follow an explicit user action. Humans do not read mailbox content except when the user deliberately supplies it in a support request or access is required for security/legal reasons.

5. Service providers and disclosures

We use limited service providers for hosting, email delivery, payments, security, and infrastructure. They receive only the information needed for their function and are required to protect it. Payment processing is provided by Stripe; card information is handled by Stripe rather than Multuser.

We may disclose information when required by law, to protect users or the service, or as part of a legitimate business reorganization with appropriate safeguards. We do not sell personal information or connected mailbox data.

6. Retention and deletion

  • OAuth grants remain until you disconnect the mailbox, delete the profile/account, revoke access at the provider, or the provider expires the grant.
  • Opened message bodies are retained in an encrypted cache of at most 30 messages per profile and are purged on disconnect or profile deletion.
  • Mailbox envelope status is refreshed as the feature operates and removed on disconnect or profile deletion.
  • Profile files remain until you delete them or the profile.
  • Account, billing, fraud-prevention, audit, and transaction records are retained only as reasonably needed for service, security, dispute, and legal requirements.

See Data deletion for self-service instructions and provider revocation links.

7. Security

Multuser uses encrypted transport, access controls, write-only platform secret storage, encrypted OAuth tokens and mailbox caches, scoped authorization, audit records, and bounded data processing. No system is perfectly secure, so users should also protect their devices, provider accounts, recovery methods, and Multuser credentials.

8. Your choices and rights

You can disable mailbox monitoring, disconnect a provider, delete profile files, delete profiles, revoke Google or Microsoft access, and request account deletion. Depending on your location, you may also request access, correction, portability, restriction, objection, or deletion of personal data.

9. International processing and children

Multuser may process information in countries other than your own, subject to appropriate contractual and technical safeguards. The service is not intended for children under 18.

10. Changes

We may update this policy as the product or legal requirements change. Material changes will be dated here and, when appropriate, presented in the application.

11. Contact

Email info@tallinio.com with “Multuser privacy” in the subject, or use the Support area inside Multuser.