Legal
Privacy Policy
§1Introduction
Multinex AI, Inc. (“Multinex,” “we,” “our,” or “us”) is committed to protecting the privacy, security, and sovereignty of data entrusted to us by our customers, users, and website visitors.
This Privacy Policy describes how we collect, use, store, share, and protect personal information when you visit our website (multinex.ai), use our products — including AIEGES Shield, MemQ, Multinex Legion, Airlock-VISA, and the munx-cli — or interact with our services in any capacity.
By accessing our website or using our services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree, please discontinue use of our services.
§2Zero-Trust Data Sovereignty
Our infrastructure is architected around the principle of absolute data sovereignty. In sovereign and self-hosted deployment modes, your data — including vector memory, graph relationships, conversational prompts, policy decisions, and telemetry — is stored and processed entirely within environments you control.
Multinex does not collect, index, transmit, or train on your proprietary data unless explicitly authorized by your organizational administrators. Where AIEGES Shield operates as a reverse proxy, traffic flows through Zero-Trust perimeters with real-time redaction — unredacted payloads are never persisted by Multinex cloud services.
Deployment Tiers
- 01Sovereign Stack: Fully on-premise. No data leaves your network. All memory, telemetry, and policy enforcement runs on your infrastructure.
- 02Hybrid (VPC Proxy): Control-plane metadata may traverse Multinex edge, but all sensitive payloads remain in your VPC. Redaction occurs before any data exits the boundary.
- 03Cloud API: Managed service with encryption at rest (AES-256) and in transit (TLS 1.3). Data processing governed by your Data Processing Agreement (DPA).
§3Information We Collect
Information You Provide
- Account Data: Name, email address, company name, job title, phone number when you create an account or request a demo.
- Billing Data: Payment method details, billing address, and tax identifiers processed by our PCI DSS-compliant payment processor (Stripe).
- Support Data: Communications, attachments, and diagnostic information you provide when contacting support.
- Feedback: Survey responses, product feedback, or feature requests.
Information Collected Automatically
- Usage Telemetry: Anonymized API request volumes, latency metrics, error rates, and feature adoption for system performance monitoring.
- Device & Browser: IP address, browser type and version, operating system, device type, screen resolution, and referring URL.
- Cookies & Pixels: Session identifiers, preference cookies, and analytics tracking (see Section 10).
Information We Do Not Collect
In self-hosted and sovereign deployments, Multinex does not collect, access, or process: prompt content, model responses, memory writes, graph entities, policy evaluation logs, or any data flowing through AIEGES Shield that is redacted by the Airlock boundary. This data remains entirely within your controlled environment.
§4Use of Information
We use collected information to:
- Provision, maintain, and improve our services
- Process payments and manage your subscription or enterprise agreement
- Provide customer support and respond to your requests or inquiries
- Send transactional communications (account confirmations, billing notices, security alerts)
- Enforce our Terms of Service, detect fraud, and maintain platform security
- Conduct anonymized and aggregated analysis to improve product performance, reliability, and security posture
- Comply with legal obligations, regulatory requirements, and lawful requests from authorities
We do not sell, rent, or lease your personal information to third-party data brokers, advertisers, or marketing partners under any circumstances.
§5Data Sharing & Disclosure
We share personal information only in the following limited circumstances:
- Service Providers: Infrastructure hosting (Google Cloud, Cloudflare), payment processing (Stripe), customer support tooling, and analytics services — each bound by data processing agreements.
- Legal Compliance: When required by applicable law, subpoena, court order, or governmental regulation.
- Business Transfers: In connection with a merger, acquisition, reorganization, or sale of assets, subject to the acquiring entity honoring this policy.
- With Your Consent: When you explicitly authorize sharing with a specific third party.
§6Data Security
We implement industry-standard technical and organizational measures to protect your data, including:
- Encryption at rest (AES-256) and in transit (TLS 1.3)
- Network isolation, role-based access control (RBAC), and least-privilege principles across all internal systems
- Real-time PII/PHI redaction through AIEGES Shield's zero-copy Aho-Corasick classification engine
- Cryptographic identity verification and organization-scoped boundaries via Airlock-VISA
- Regular security assessments, penetration testing, and vulnerability management
- Employee background checks, security training, and strict access-control policies
No system is 100% secure. While we take commercially reasonable precautions, we cannot guarantee absolute security of transmitted or stored data.
§7Data Retention
We retain personal information only for as long as necessary to fulfill the purposes for which it was collected, provide our services, comply with legal obligations, resolve disputes, and enforce our agreements.
- Account Data: Retained for the duration of your account plus 30 days after deletion request.
- Billing Records: Retained for 7 years to comply with financial reporting and tax obligations.
- Usage Telemetry: Anonymized and aggregated telemetry is retained for up to 24 months. Raw telemetry is purged within 90 days.
- Support Records: Retained for 3 years from resolution, unless longer retention is required for legal purposes.
For sovereign and self-hosted deployments, data retention is entirely governed by your organization's policies and infrastructure.
§8International Data Transfers
Multinex processes data primarily in the United States. If you access our services from the European Economic Area (EEA), United Kingdom, Switzerland, or other jurisdictions with data transfer restrictions, your data may be transferred to, stored, and processed in the United States or other countries.
We rely on the following transfer mechanisms to ensure adequate protections:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Data Processing Agreements with all sub-processors
- Sovereign deployment options that keep all data within your jurisdiction
Enterprise customers requiring data residency guarantees should contact us about sovereign or regional deployment options.
§9Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
Under GDPR (EEA/UK)
- Access: Request a copy of personal data we hold about you.
- Rectification: Request correction of inaccurate or incomplete data.
- Erasure: Request deletion of your personal data (“right to be forgotten”).
- Portability: Receive your data in a structured, machine-readable format.
- Restriction: Request restriction of processing under certain conditions.
- Objection: Object to processing based on legitimate interests or direct marketing.
- Automated Decision-Making: Right not to be subject to decisions based solely on automated processing.
Under CCPA/CPRA (California)
- Right to know what personal information is collected and how it is used.
- Right to delete personal information.
- Right to opt-out of the sale or sharing of personal information. Multinex does not sell personal information.
- Right to non-discrimination for exercising your rights.
- Right to correct inaccurate personal information.
- Right to limit the use of sensitive personal information.
To exercise any of these rights, contact privacy@multinex.ai. We will respond within the timeframes required by applicable law (30 days for GDPR, 45 days for CCPA).
§11AI-Specific Privacy Provisions
Given the nature of our products, we maintain specific commitments regarding AI data handling:
- No Training on Customer Data: Multinex does not use customer prompts, responses, memory content, or any data flowing through our products to train, fine-tune, or improve AI models.
- Redaction Before Transit: AIEGES Shield classifies and redacts PII, PHI, and sensitive business data before it reaches any external model provider. Unredacted content is never stored by Multinex cloud services.
- Memory Sovereignty: MemQ memory (hot, warm, and cold tiers) belongs to the organization that created it. In sovereign deployments, all memory resides in your infrastructure.
- Audit Trail Integrity: Policy decisions, agent execution records, and compliance events logged by Legion are append-only and cryptographically verifiable.
- Model Agnosticism: Your choice of model provider is independent of Multinex. We do not route data to undisclosed third-party models.
Chrome Extension — AIEGES Shield
The AIEGES Shield Chrome extension operates with a minimal permission footprint. The following details apply specifically to the browser extension:
- Data Stored Locally: The extension uses
chrome.storage.localto persist configuration preferences, scan statistics, license key, a randomly-generated device ID, vault secret entries, and SoulJournal audit logs. All data remains on your device and is never synced to any cloud service by default. - Data Transmitted: The extension transmits data only in two scenarios: (1) license activation and validation requests to
billing.multinex.ai, and (2) cloud policy fetch when explicitly configured by your enterprise administrator. No browsing history, page content, prompt text, or personally-identifiable information is transmitted to Multinex or any third party. - Scanning & Processing: All text scanning is performed client-side within your browser using a WebAssembly (WASM) Aho-Corasick classifier. Scanned text is never transmitted off-device. Scan results (alert counts, categories, matched patterns) are stored in-memory only and are discarded when the browser session ends.
- Data Sharing: The extension does not share any user data with third parties, advertising networks, or analytics providers. No telemetry is collected from the browser extension.
- Host Permissions: The extension requests host permissions for specific AI platform domains (e.g., ChatGPT, Claude, Gemini) to inject content scripts that perform real-time prompt scanning. These permissions are limited to the supported platforms listed in the extension manifest and are not used on any other websites.
- Permissions: The extension requests only the
storagepermission to persist configuration and scan data locally. No other browser permissions are requested.
§12Children's Privacy
Our services are designed for enterprise and professional use and are not directed at individuals under the age of 16 (or the applicable age of consent in your jurisdiction). We do not knowingly collect personal information from children.
If we become aware that we have collected personal information from a child without parental or guardian consent, we will take immediate steps to delete that information. Please contact privacy@multinex.ai if you believe a child has provided us with personal information.
§13Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, products, legal requirements, or industry standards. When we make material changes, we will:
- Update the “Last Updated” date at the top of this page
- Notify enterprise customers via email
- Provide at least 30 days' notice before material changes take effect for existing customers
Continued use of our services after the effective date of changes constitutes acceptance of the updated policy.
§14Contact
For privacy inquiries, data subject requests, Data Processing Agreements (DPAs), or questions about our Zero-Trust architecture and data handling practices:
© 2026 Multinex AI, Inc. All rights reserved.