Privacy Policy
Last updated: June 26, 2026
This Privacy Policy explains how Kiwana AI, Inc.(“Multipliers,” “we,” “us”) collects, uses, discloses, and safeguards information when you use the Multipliers AI platform, websites, APIs, and MCP servers (the “Service”).
Information we collect
- Account & identity: name, email, organization, and authentication identifiers (via Firebase Authentication).
- Billing: subscription and payment metadata processed by Stripe. We do not store full card numbers — Stripe handles payment data as an independent processor.
- Business & process data: the processes, agents, connectors, and context you configure, plus content you submit to agents (e.g., URLs for Site Auditor).
- Usage & telemetry: API calls, agent runs, audit events, IP address, and device/browser information for security, billing, and reliability.
- Connected systems: when you connect a platform (e.g., Salesforce, Shopify, NetSuite, Slack), we access only the scopes you authorize, via credentials you control.
How we use information
- To provide, operate, secure, and improve the Service.
- To authenticate users and enforce tenant isolation and access controls.
- To process subscriptions, billing, and usage metering.
- To run the AI agents and integrations you configure, and to surface their outputs to you.
- To detect, prevent, and respond to fraud, abuse, and security incidents.
- To comply with legal obligations.
We do not sell personal information, and we do not use your business data or connected-system content to train foundation models.
Sub-processors
We rely on the following processors, each bound by their own data-protection terms:
- Google Cloud / Firebase — hosting, authentication, infrastructure.
- Neon — managed Postgres database.
- Stripe — payments and subscription billing.
- Anthropic and other model providers you select — LLM inference for agent reasoning. Prompts/outputs are processed to deliver the Service and are not used to train their models under our agreements.
Data sharing
We share information only with the sub-processors above, with parties you direct us to (the systems you connect), and where required by law or to protect rights and safety. We may share aggregated, de-identified data that cannot reasonably identify you.
Data retention
We retain account and business data for as long as your account is active and as needed to provide the Service, then delete or de-identify it within a commercially reasonable period, subject to legal and audit requirements.
Security
We apply tenant isolation, encryption in transit, least-privilege access, audit logging, and secret management. See our Vulnerability Disclosure Policy for how to report issues.
Your rights
Depending on your jurisdiction (including the GDPR and CCPA/CPRA), you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing. To exercise these rights, contact us at the address below.
International transfers
We may process data in the United States and other countries where our sub-processors operate, with appropriate safeguards for cross-border transfers.
Changes
We may update this policy; material changes will be reflected by the “Last updated” date above and, where appropriate, additional notice.
Contact
Questions or requests: contact@kiwana.ai.