Legal
Privacy Policy
Last updated: July 2026
MultiProfile is local-first, so this policy is shorter than most: the data that would be sensitive never leaves your machine. This explains the little we do hold, why we are allowed to hold it, how long we keep it, and what you can make us do about it.
1. Controller
The data controller is the sole trader identified on our Legal Notice page. For anything in this policy, including to exercise your rights, write to hello@multiprofile.app. We have not appointed a data protection officer, which our size does not require.
2. What stays on your machine
Your browser profiles, cookies, fingerprints, proxy credentials, extensions and app settings are stored locally on your Windows machine. They are never uploaded to us. We do not know how many profiles you run, what sites you visit, which proxies you use or what is in your cookie jars — not because we promise not to look, but because the data is not sent to us and we have no way to reach it.
Two consequences follow. We cannot restore this data if you lose it. And we cannot hand it over — to anyone, including a court — because we do not have it.
3. What we actually process
Running the business requires a small amount of data. This is all of it.
- Your account: email address, optionally a name, and your password. The password is never stored: we keep only a scrypt-derived hash and its salt, from which the password cannot be recovered.
- Your subscription: plan, status, seats, renewal date, cancellation status, and the customer and subscription identifiers issued by Stripe. We do not receive or store your card number.
- Your licence: licence key, status and expiry.
- Your activated devices: a machine identifier, an optional device name, the platform, and a last-seen timestamp. This is how a plan’s device limit is enforced.
- Technical logs: IP address and timestamps, used to rate-limit login and registration so accounts cannot be brute-forced.
- Support: whatever you send us, and the context around it.
4. Why, and on what legal basis
Under article 6 of the GDPR:
- Performance of our contract — creating and authenticating your account, activating your licence on your devices, running your subscription and supporting you. Without this data there is no service to provide.
- Our legitimate interests — rate-limiting credential endpoints, detecting fraud and abuse, enforcing device limits and our Acceptable Use Policy, and keeping the service secure. We use the minimum that achieves this.
- Legal obligation — keeping invoices and accounting records, and answering lawful requests from authorities.
- Your consent — only ever for optional diagnostics, and only if you turn them on. You can withdraw it at any time, with no effect on your service.
We do not sell personal data, we do not share it for advertising, and we do not profile you.
5. Website
This site sets no advertising or analytics cookies, and runs no tracking scripts. There is no cookie banner because there is nothing to consent to. Your theme preference is stored in your browser’s local storage and never reaches us.
To show prices in the right currency, our host passes us the country your IP resolves to for the duration of the request (falling back to your browser’s language setting). It is used to pick euros or dollars and is not stored or logged.
6. Who else sees this data
We use a small number of processors, each bound by a contract under article 28 of the GDPR:
- Stripe — payment processing and fraud prevention. Stripe is an independent controller for its own fraud and compliance duties and applies its own checks to your payment.
- Vercel Inc. — hosting of this website.
- Our infrastructure and email providers — hosting the account database and sending transactional email (confirmations, renewal reminders, password resets).
Some of these are established in, or transfer data to, the United States. Those transfers rely on the European Commission’s adequacy decision for the EU–US Data Privacy Framework where the provider is certified, and otherwise on Standard Contractual Clauses. Copies are available on request.
7. How long we keep it
- Account, subscription, licence and device records: for as long as your account exists, then deleted or anonymised within 3 months of closure.
- Invoices and accounting records: 10 years, because French commercial law requires it (article L.123-22 of the Commercial Code). This retention survives account deletion — we are not permitted to erase it on request.
- Rate-limiting logs: a few days at most.
- Support correspondence: up to 3 years after our last exchange.
8. Your rights
Under the GDPR you may ask us to give you access to your data, correct it, erase it, restrict or object to how we use it, or export it in a portable format. You can withdraw consent to diagnostics whenever you like, and you may set directives on what happens to your data after your death.
Write to hello@multiprofile.app. We reply within one month. We may need to confirm who you are first — for an account, that means writing from the address on it.
If our answer does not satisfy you, you can complain to the CNIL (3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, www.cnil.fr), or to the supervisory authority where you live.
9. Security
Passwords are scrypt-derived and salted. Traffic is encrypted in transit. Credential endpoints are rate-limited per IP. Locally, the app’s store is encrypted with the operating system’s own facility. No system is perfect; if a breach affects your rights, we notify the CNIL within 72 hours and tell you directly where the law requires it.
10. Children
MultiProfile is not for under-18s, and we do not knowingly process their data. If you believe we hold data about a minor, tell us and we will delete it.
11. Changes
We may update this policy. Material changes are announced in the app or by email before they take effect, and the date at the top always reflects the current version.