1. Scope and controller
This policy applies to the Multuser website, desktop applications, cloud workspace, Marketplace, managed proxy services, support tools, and mailbox features. “Multuser,” “we,” and “our” refer to the operator of the Multuser service.
Privacy and OAuth questions can be sent to info@tallinio.com.
2. Information we process
Account and company information
Usernames, email addresses, password hashes, company membership, roles, plan limits, preferences, sessions, and security/audit events.
Profile workspace information
Profile names, tags, notes, browser identity settings, proxy configuration, encrypted or protected credentials, activity history, synchronized cookies, and files that you intentionally upload to a profile.
Mailbox information
If you enable mailbox monitoring, we process the mailbox address, provider settings, encrypted OAuth tokens or app credentials, unread/read status, sender, subject, date, and message bodies that you explicitly open. Multuser keeps at most 30 recently opened message bodies in an encrypted per-profile cache so reopened messages load faster.
Payments, Marketplace, and proxies
Plan and order records, Stripe identifiers and payment status, crypto payment references, seller declarations, dispute records, rented proxy usage, health, country, limits, and bandwidth totals. Multuser does not store complete card details.
Diagnostics
Application version, error category, pseudonymous error reference, affected company/profile when available, device-storage health, proxy and fingerprint check results, and security/audit logs. Browsing history and page contents are not included in product error reports.
3. How we use information
- Provide and synchronize the workspace and its access controls.
- Open isolated profiles, apply requested browser settings, and connect configured proxies.
- Show mailbox status and messages and send a reply only when the user requests it.
- Process subscriptions, Marketplace orders, proxy rentals, refunds, and disputes.
- Protect accounts, diagnose failures, prevent abuse, and maintain service availability.
- Meet legal obligations and enforce the Terms of Service.
We do not use connected mailbox content for advertising, profiling, data brokerage, or training general-purpose AI models.
4. Google user data
When you choose “Connect with Google,” Multuser requests your basic account identity and Gmail access needed for IMAP/SMTP mailbox functionality. We use it only to:
- identify the mailbox you selected;
- count and display read or unread messages and their envelope information;
- fetch a message body when you open that message;
- mark a message read or unread at your direction; and
- send a reply when you press the send action.
OAuth access and refresh tokens are encrypted at rest with AES-256-GCM and cryptographically bound to the approving owner, profile, and provider. Cached message bodies are also encrypted at rest, bounded to 30 messages per profile, and removed when mailbox access is disconnected or the profile is deleted.
Google OAuth grants and Gmail-derived message data are never included when a profile is sold or rented through Marketplace. The recipient must connect a mailbox under their own authority.
We do not transfer Google user data to third parties except as necessary to provide or secure the feature, comply with law, or follow an explicit user action. Humans do not read mailbox content except when the user deliberately supplies it in a support request or access is required for security/legal reasons.
6. Retention and deletion
- OAuth grants remain until you disconnect the mailbox, delete the profile/account, revoke access at the provider, or the provider expires the grant.
- Opened message bodies are retained in an encrypted cache of at most 30 messages per profile and are purged on disconnect or profile deletion.
- Mailbox envelope status is refreshed as the feature operates and removed on disconnect or profile deletion.
- Profile files remain until you delete them or the profile.
- Account, billing, fraud-prevention, audit, and transaction records are retained only as reasonably needed for service, security, dispute, and legal requirements.
See Data deletion for self-service instructions and provider revocation links.
7. Security
Multuser uses encrypted transport, access controls, write-only platform secret storage, encrypted OAuth tokens and mailbox caches, scoped authorization, audit records, and bounded data processing. No system is perfectly secure, so users should also protect their devices, provider accounts, recovery methods, and Multuser credentials.
8. Your choices and rights
You can disable mailbox monitoring, disconnect a provider, delete profile files, delete profiles, revoke Google or Microsoft access, and request account deletion. Depending on your location, you may also request access, correction, portability, restriction, objection, or deletion of personal data.
9. International processing and children
Multuser may process information in countries other than your own, subject to appropriate contractual and technical safeguards. The service is not intended for children under 18.
10. Changes
We may update this policy as the product or legal requirements change. Material changes will be dated here and, when appropriate, presented in the application.
11. Contact
Email info@tallinio.com with “Multuser privacy” in the subject, or use the Support area inside Multuser.