GDPR / RODO
Effective Date: 27 July 2026 · Last Updated: 27 July 2026
App-owner note: This page is maintained by MultiMind to provide GDPR/RODO transparency for users of the MultiMind Service. It describes our current practices and enabled controls. It is not a legal certification, DPA, or guarantee of compliance.
1. Data controller
For the purposes of GDPR, the data controller for MultiMind is:
Email: contact@multimind.com
2. Personal data we process
- Identity and contact data: email address, authentication provider identifier, profile settings.
- Content data: questions, prompts, debate responses, follow-up chat messages, and any outputs you generate.
- Transactional data: subscription tier, quota usage, payment status, and related records processed by Stripe.
- Technical data: IP address, browser type, device type, and timestamps collected for security and service operation.
3. Legal basis for processing
- Performance of a contract: to provide debates, chat, and account access.
- Legitimate interests: to maintain security, prevent abuse, and improve the Service.
- Legal obligation: to comply with tax, accounting, and regulatory requirements.
- Consent: where required for optional analytics or marketing communications. You can withdraw consent at any time.
4. Your rights under GDPR / RODO
If you are in the European Economic Area or otherwise covered by GDPR, you have the following rights:
- Right of access — request a copy of the personal data we hold about you.
- Right to rectification — ask us to correct inaccurate or incomplete data.
- Right to erasure (“right to be forgotten”) — ask us to delete your data in certain circumstances.
- Right to restrict processing — ask us to limit how we use your data.
- Right to data portability — receive your data in a structured, commonly used format.
- Right to object — object to processing based on legitimate interests or direct marketing.
To exercise any of these rights, contact us at contact@multimind.com. We will respond within one month, or longer if permitted by law.
5. Data transfers and subprocessors
Your data may be transferred to and processed in countries outside the European Economic Area, including the United States, by our subprocessors. We rely on appropriate safeguards, such as the EU Standard Contractual Clauses and providers’ certifications, where applicable. Current subprocessors include:
- Supabase — database and authentication hosting.
- Stripe — payment processing.
- OpenRouter — AI model request routing.
- Cloudflare — security and Turnstile verification.
- Lovable — application hosting platform.
6. Retention
We retain personal data only for as long as necessary for the purposes described in this notice, including legal, accounting, and fraud-prevention needs. When you delete your account, we delete or anonymize your data unless a longer retention period is required by law.
7. Complaints
If you believe your data protection rights have been violated, you have the right to lodge a complaint with your local data protection authority. We encourage you to contact us first so we can try to resolve the issue.
8. Changes to this notice
We may update this GDPR notice from time to time. We will post the revised version on this page with a new effective date. Continued use of the Service after changes means you accept the revised notice.
9. Contact
For privacy requests, data subject rights, or GDPR questions, contact:
contact@multimind.com