Privacy Policy

MultiHat AI Privacy Policy

Last updated: June 14, 2026

Overview

MultiHat AI helps users create concise inbox briefs from their connected email accounts. We design the product to minimize stored data, keep sensitive processing server-side, and protect stored tokens, summaries, action items, and provider identifiers.

Information We Collect

We may collect the following information:

  • Account information used to sign in, such as your email.
  • Waitlist information you submit, such as your email.
  • OAuth connection data needed to connect Gmail, including an encrypted refresh token and granted scopes.
  • Gmail message metadata and snippets needed transiently to generate an inbox brief.
  • Encrypted inbox summaries and encrypted action items generated for your account.
  • Operational metadata such as counts, timestamps, and safe error codes.

Google User Data

If you connect Gmail, MultiHat AI requests read-only Gmail access to retrieve recent message metadata and snippets for the purpose of generating your inbox brief. We do not send emails, modify emails, delete emails, or access attachments for the MVP.

We do not store raw email bodies or full raw message payloads. Provider account email addresses and Gmail message/thread identifiers are hashed before persistence. OAuth refresh tokens, summaries, and action items are encrypted before persistence.

To generate an inbox brief, selected Gmail metadata and snippets may be sent to our AI provider, OpenAI, for processing. MultiHat AI does not use Google user data to train its own generalized AI models.

How We Use Information

We use information to:

  • Authenticate you and provide your dashboard.
  • Connect email accounts you choose to authorize.
  • Generate and display inbox briefs and action items.
  • Operate, secure, debug, and improve the service.
  • Send waitlist or product updates if you requested them.

How We Share Information

We do not sell user data. We may share information with service providers that help operate MultiHat AI, such as authentication, database hosting, application hosting, and AI processing providers. We may also disclose information if required by law or to protect the security and integrity of the service.

Data Security

We use encryption, hashing, row level security, and server-side handling for sensitive workflows. No method of transmission or storage is perfectly secure, but we work to limit stored data and protect the data required to provide the service.

Data Retention and Deletion

We keep information only as long as needed to provide the service, comply with legal obligations, resolve disputes, and enforce our agreements. Disconnecting Gmail removes the stored Gmail connection record for that account. You may contact us to request deletion of account-related data.

Contact

For privacy questions or requests, contact us at admin@multihatai.com.