Privacy Policy
Last updated July 18, 2026
This Privacy Policy explains how Multra.ai ("Multra.ai," "we," "us," or "our") handles personal information when you visit Multra.ai, create an account, connect services, submit model traffic, use the workbench or repository features, or contact us.
1. Our role
For account, website, billing, security, and support information, Multra.ai generally acts as the business or controller. For prompts, responses, files, tool payloads, and repository content submitted by an organization, Multra.ai generally acts as its service provider or processor and follows that customer’s instructions. Contact your organization first when it controls the data at issue.
2. Information we collect
- Account and organization data: name, work email, organization, role, authentication records, preferences, and plan.
- Customer content: prompts, messages, model responses, tool and MCP payloads, uploaded documents, generated artifacts, and repository content needed for enabled features.
- Provider and integration data: provider type, encrypted credentials, connection status, model and policy settings, GitHub installation and repository metadata, and integration events.
- Usage and receipt data: requested and selected models, task profile, token counts, pricing inputs, savings labels, quality status, latency, workflow lineage, and bounded derived analytics. Claim and verification checks process content transiently; durable receipts retain only their categorical results and counts, not claim text, prompts, source code, compiled context, test output, or model output.
- Billing data: plan, subscription status, transaction identifiers, and billing contact information. Stripe processes payment-card details; Multra.ai does not store complete card numbers.
- Device, log, and security data: IP address, browser and device information, timestamps, request identifiers, audit events, error details, and abuse-prevention signals.
- Communications: support requests, security reports, feedback, and other messages you send us.
3. Sources
We receive information from you, your organization, your use of the service, connected model providers and integrations at your direction, and service providers that support authentication, billing, email, hosting, security, and operations.
4. How we use information
- Provide, secure, troubleshoot, and support Multra.ai.
- Route model requests, compile context, enforce customer policy, validate outputs, and create Optimization Receipts.
- Operate accounts, subscriptions, authentication, support, and customer-requested integrations.
- Monitor reliability, prevent fraud and abuse, investigate incidents, and comply with law.
- Analyze bounded usage and workflow patterns to improve the product. We do not use customer content to train a general-purpose model unless a customer separately gives explicit permission.
- Send service messages and, where permitted, product communications you can opt out of.
5. How we disclose information
We may disclose information to:
- Customer-authorized providers: model providers, cloud services, GitHub, MCP servers, connectors, and other integrations selected by the customer.
- Service providers: infrastructure, storage, database, security, email, support, analytics, and payment vendors under contractual restrictions.
- Your organization: administrators and authorized users who manage the account, policies, traffic, receipts, or billing.
- Legal and safety recipients: when reasonably necessary to comply with law, protect rights and safety, investigate abuse, or respond to valid process.
- Transaction recipients: in a merger, financing, acquisition, reorganization, or sale, subject to appropriate safeguards.
We do not sell personal information or share it for cross-context behavioral advertising. We do not use sensitive personal information to infer characteristics or for purposes unrelated to providing and securing the service.
6. Cookies and similar technologies
We use necessary first-party cookies and local browser storage for sessions, security, CSRF protection, preferences, and core functionality. We do not currently use third-party advertising cookies. If that changes, we will update this notice and provide required choices before activating them.
7. Retention
- Receipt history is normally available for 7 days on Free, 90 days on Pro, and one year on Company, subject to customer settings, legal holds, backups, and contractual requirements.
- Temporary workbench uploads and generated artifacts in production object storage expire after 7 days unless a different customer-approved retention setting applies.
- Request and response content follows the configured processing and retention mode. A zero-retention mode is intended to discard request bodies after processing while retaining permitted content-free receipts, security records, and derived metrics.
- Account, billing, audit, and security records are retained while needed to provide the service, meet legal obligations, resolve disputes, and enforce agreements.
Deletion from active systems may not immediately remove information from encrypted backups. We isolate backup data and remove it through normal rotation unless preservation is legally required.
8. Security
We use tenant-scoped authorization, encryption in transit, encrypted secret and object storage, hashed product API keys, audit logging, restricted service roles, and other administrative, technical, and organizational safeguards. No method of storage or transmission is completely secure. Report a suspected vulnerability to security@blueskyatg.com.
9. Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal information, withdraw consent, or appeal a denied request. You may also opt out of non-essential marketing. Submit a request to privacy@blueskyatg.com. We may verify your identity and authority. Authorized agents may submit requests where permitted. We will not discriminate against you for exercising a privacy right.
If your organization controls the data, we may direct the request to its administrator. Account users can also revoke sessions and request individual account deletion through available product controls. Organization owners must transfer ownership before deleting their individual account. Individual account deletion removes memberships and active authentication credentials and de-identifies the user profile, but does not delete organization-controlled customer data.
10. International transfers
Multra.ai and its providers may process information in the United States and other countries. Where required, we use contractual and organizational safeguards for cross-border transfers. Enterprise customers may request applicable data-processing terms.
11. Children
Multra.ai is a business service and is not directed to children under 13. We do not knowingly collect personal information from children under 13. Customers must not submit children’s data unless legally authorized and covered by an appropriate agreement.
12. Changes
We may update this policy as the service or law changes. We will post the revised date and provide additional notice when a change is material or legally required.
13. Contact
Questions, requests, and complaints: privacy@blueskyatg.com. Support requests: support@blueskyatg.com.
