Privacy Policy

Multifactor, Inc. (the “Company”, “we”, “us”, and “our”) is committed to maintaining robust privacy protections for its users. This Privacy Policy (“Privacy Policy”) explains what personal information we collect, how we use and disclose it, how long we keep it, and the choices and rights you have. It also serves as our notice at collection under California law.

For purposes of this Privacy Policy, “Site” refers to the Company’s website, which can be accessed at multifactor.com, any subdomains thereof (e.g., app.multifactor.com and lite.multifactor.com), other domains we use to provide the Service (such as the domains we use for shared links and for the email addresses we provide to you), as well as our product websites such as mfkdf.com, mfchf.com, and mfdpg.com. “Service” refers to the Company’s services accessed via the Site, or through associated browser extensions, desktop or mobile applications, or APIs, in which users can utilize the Company’s cryptography and cybersecurity solutions. “You” refers to you, as a user of our Site or our Service. Capitalized terms that are not defined here, such as “Third-Party Service”, “Third-Party Account”, and “Account Data”, have the meanings given in our Terms of Use.

This Privacy Policy does not apply to information that a Third-Party Service collects when you or we use your account with it; that is governed by the Third-Party Service’s own privacy policy.

Summary in Plain Language

This summary is here to help you read the policy, not to replace it.

  • The most sensitive data we hold is the data for the accounts you add: usernames, passwords, one-time codes, authenticator secrets, passkeys, recovery codes, signed-in session data (such as cookies), and messages that other services send to email addresses or telephone numbers we give you. Under California law, much of this is “sensitive personal information”. See Section 1.3.
  • This data is encrypted, but some features decrypt it on our systems. Signing in for you when you are not present, keeping shared sessions signed in, and letting software agents use an account all require decrypting it on our servers or in secure computing environments we operate. See Section 7.
  • We use service providers to run the Service, including cloud hosting, remote (cloud-hosted) browsers, AI model providers, and email and text message providers. Page content from the websites we sign in to can be sent to AI model providers. See Sections 3 and 4.
  • We do not sell your personal information, and we do not share it for targeted advertising. We do not use advertising or analytics trackers in our apps. See Sections 3.3 and 5.
  • You can access, export, correct, and delete your information, and depending on where you live you may have additional rights. See Sections 8 through 10.

1. INFORMATION WE COLLECT

We collect the following categories of information. We describe the sources of each category in Section 1.8.

1.1. Account and Contact Information

When you register, we collect your name and email address, the sign-in factors you set up (such as a password or passkey), and information about your profile and settings. We never store your Multifactor password or other sign-in factors in a form that lets us read them; we store only encrypted or derived values that let the Service verify you and protect your data. If you create or join an organization or team, we collect your role and membership. If you contact us, we collect the contents of your message and your contact details. If you join a waitlist or submit a form on the Site, we collect the information you submit.

1.2. Mobile Telephone Numbers and Text Messages (SMS)

Text messaging is optional and is not a condition of using the Site or the Service. If you opt in to receive text messages from us, for example by adding a mobile telephone number in the Solid2FA section of the Service, we collect your mobile telephone number, a record of your opt-in (including the date and time, the disclosure you agreed to, and the account that provided the number), and records of the text messages we send to you, including their delivery status and any STOP or HELP requests you send. We use this information only to verify that you control the number, to deliver the text messages you have requested, to honor your opt-out requests, and to comply with legal and wireless carrier requirements. Your consent to receive text messages, the types of messages we send, and how to opt out are described in our SMS Consent and Text Messaging Terms. See Section 3.2 for how we share text messaging information.

1.3. Account Data for Your Third-Party Accounts

When you add a Third-Party Account to the Service, save a login with our browser extension, or use features that sign in for you, we collect and store Account Data, which may include:

  • Credentials: usernames, email addresses, and phone numbers used to sign in; passwords; authenticator (TOTP) secrets; passkeys and their private keys; and recovery codes.
  • One-time codes and messages: codes and other messages that Third-Party Services send to email addresses or telephone numbers that we provide to you. We keep the codes and a record of each message (such as the sender, its type, and when it was received). Messages that are not sign-in codes may be forwarded to your own email address or telephone number, as you choose.
  • Session data: cookies, browser storage, and similar data that keep you signed in to a Third-Party Account, including for sessions you share with others.
  • Other items you save: such as notes, payment card details, and addresses you choose to store.
  • Metadata: the name and website of each Third-Party Service, which sign-in methods it uses, the type of credentials you saved, and the status of each account. Some metadata (such as account and service names, and the last four digits and brand of a payment card) is stored without end-to-end encryption so that the Service can display and organize it.

Account Data may include personal information about you that is held by the Third-Party Service, and may include personal information about other people (for example, in messages or on pages in a shared account). Section 7 describes how Account Data is protected.

1.4. Activity, Sharing, and Automation Information

We collect information about how the Service is used with your Third-Party Accounts, including: who you share access with, the access level, and any links you create; when accounts are added, changed, shared, or removed; the results of sign-ins and credential checks; and records of activity in shared sessions, including actions that were allowed or blocked by access policies. When the Service signs in or acts on a Third-Party Service for you, it processes the content of the pages it visits, and when we troubleshoot automated sign-ins, we may record screenshots, page content, and network traffic from the remote browser, with known secrets removed. If you use an AI assistant in the Service, we collect your conversations with it and any memories you choose to save.

1.5. Connections, Agents, and Contacts

If you create an identity for a software agent, we collect its name and the accounts you share with it, and we store its keys in hashed or encrypted form. If you connect a partner application to your Multifactor account, we collect the details of the connection. If you add contacts or import them from Google, we collect their names, email addresses, and related details. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

1.6. Device, Usage, and Security Information

When you use the Site or the Service, we automatically collect technical information such as your IP address, browser and device type, operating system, the pages and features you use, the referring URL, the time and date of access, and approximate location derived from your IP address (such as city, region, and country). We record sign-in sessions and security events, and a signed audit log of changes you make, to protect your account and detect suspicious activity (for example, sign-ins from unexpected locations). We collect error reports and diagnostic information to find and fix problems; you can turn off sharing of diagnostics in Settings.

1.7. Cookies and Similar Technologies

We use cookies and similar technologies (such as local storage) that are necessary to run the Site and the Service, for example to keep you signed in, remember your preferences, and protect against abuse and bots. We do not use advertising cookies or third-party analytics trackers in our apps. Some pages of the Site embed content from third parties (such as videos hosted on YouTube), and those third parties may set their own cookies when the content loads, under their own privacy policies. See Section 5 for your choices.

1.8. Sources of Information

We collect information: (a) directly from you; (b) automatically from your browser, devices, and use of the Service; (c) from Third-Party Services, when the Service signs in to or receives messages from them for you; (d) from other users, for example when someone shares an account with you, invites you to an organization, or adds you as a contact; (e) from partner applications you connect; and (f) from service providers, such as providers that help us detect bots and fraud.

1.9. Children’s Privacy

The Site and the Service are not directed to children, and you must be at least 18 years old to use the Service. We do not knowingly collect or solicit personal information from anyone under the age of 18, or allow anyone under the age of 18 to sign up for the Service. In the event that we learn that we have gathered personal information from anyone under the age of 18, we will delete that information as soon as possible. If you believe we have collected such information, please contact us at [email protected].

2. HOW WE USE INFORMATION

We use personal information to:

  1. Provide the Service, including storing and syncing your data, signing in to Third-Party Accounts and acting on them as you direct, receiving and delivering one-time codes, keeping shared sessions signed in, checking that saved credentials still work, running the sharing, access policy, and activity features, and providing the AI assistant.
  2. Secure the Service and your accounts, including authenticating you, detecting and preventing fraud, abuse, bots, and suspicious sign-ins, keeping audit logs, and investigating security incidents.
  3. Communicate with you, including sending service and security notices, one-time codes you request, responses to your questions, and (where permitted, and with the ability to opt out) news about our products.
  4. Maintain and improve the Service, including fixing errors, measuring performance, and improving how the Service works with Third-Party Services. We use information about Third-Party Services’ public sign-in pages, and about how sign-ins succeed or fail, to improve automated sign-in for everyone; we do not use your credentials, one-time codes, or passkeys for this, and we do not use them to train AI models.
  5. Comply with law and enforce our terms, including responding to lawful requests, protecting our rights and the rights and safety of our users and others, and enforcing our Terms of Use.

We use sensitive personal information (such as credentials, the contents of messages we receive for you, and payment card details you store) only to provide the Service you request, to secure the Service, and for the other purposes permitted by applicable law. We do not use it to infer characteristics about you.

We may create de-identified or aggregated information from personal information. When we do, we will maintain it in de-identified form and will not attempt to re-identify it, except as permitted by law.

3. HOW WE DISCLOSE INFORMATION

3.1. Who We Disclose Information To

We disclose personal information only as described below.

  • Service providers. We use vendors that process information on our behalf and under our instructions, including: cloud hosting, networking, storage, and database providers (such as Cloudflare and Amazon Web Services); providers of secure computing environments; remote browser and proxy providers that run the browsers we use to sign in for you (such as Browserbase); AI model providers (such as Anthropic, OpenAI, and Google); email delivery providers (such as Resend and Amazon Web Services); telephone number and text message providers (such as Telnyx) and the wireless carriers they work with; push notification providers (such as Google Firebase); error monitoring providers (such as Sentry); bot and abuse prevention providers (such as Cloudflare); address autocomplete (Google Maps, which receives the addresses you type into address fields); form providers on the Site (such as Formspree); and software update distribution for our desktop apps. We may add or replace providers that perform similar functions. Our providers may use personal information only to provide services to us, except as required by law.
  • People and agents you share with, and your organization. When you share access to an account, create a link, or add a software agent, the recipients can see the information and use the access you choose. If you belong to an organization, its administrators may see your membership and related activity.
  • Third-Party Services and partner applications, at your direction. When the Service signs in to a Third-Party Service for you, it submits your credentials and codes to that service, and that service receives information such as the IP address of the remote browser and your activity. If you connect a partner application, we disclose to it the information and access you authorize.
  • Legal and safety. We may disclose personal information if we have a good-faith belief that access, use, preservation or disclosure of the information is reasonably necessary to meet any applicable legal process or enforceable governmental request; to enforce applicable Terms of Use, including investigation of potential violations; address fraud, security or technical concerns; or to protect against harm to the rights, property, or safety of our users or the public as required or permitted by law. Some data, such as data that is end-to-end encrypted, we may be unable to decrypt or disclose.
  • Business transfers. In the event we undergo a business transaction such as a merger, acquisition by another company, or sale of all or a portion of our assets, your personal information may be among the assets transferred. We will require any acquirer to honor this Privacy Policy with respect to the information it receives, or will notify you before your information becomes subject to a different privacy policy.
  • With your consent or at your direction in other cases.

3.2. Text Messaging (SMS) Information

We do not share, sell, rent, or provide your mobile telephone number, your SMS opt-in, or your consent status to third parties or affiliates for marketing or promotional purposes. All of the categories of use and sharing described in this Privacy Policy exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties, except for the wireless carriers and text messaging service providers that help us deliver text messages to you, which may use it only to deliver those messages on our behalf. We do not use your mobile telephone number to send you marketing or promotional text messages unless you separately give us your express written consent to receive them. Message frequency for our text messaging program varies, and message and data rates may apply; see our SMS Consent and Text Messaging Terms.

3.3. No Sale or Sharing for Targeted Advertising

We do not sell personal information, and we do not share personal information for cross-context behavioral advertising (targeted advertising), as those terms are defined under U.S. state privacy laws. We have not done so in the preceding 12 months, and we do not knowingly sell or share the personal information of consumers under 16 years of age.

4. AI PROCESSING

Some features use AI models. When the Service signs in or takes an action on a Third-Party Service for you, it sends the content of the page (such as its text and structure) to an AI model provider so the model can find the right steps; we remove known secrets, such as your password, before sending, but other information on the page, which may include personal information, can be sent. When you use the AI assistant, your messages and the information it needs to answer them (such as your name, the names of your accounts, and relevant activity) are sent to an AI model provider. We use AI model providers under terms that do not allow them to use this data to train their models, and they may keep it for a limited time for purposes such as abuse monitoring. AI outputs can be inaccurate; see our Terms of Use. The Service does not use AI to make decisions about you that produce legal or similarly significant effects.

5. COOKIES, GLOBAL PRIVACY CONTROL, AND DO NOT TRACK

You can control cookies through your browser settings. Blocking cookies that are necessary for the Service may stop it from working, for example by signing you out. We honor Global Privacy Control (GPC) signals as a valid request to opt out of the sale or sharing of personal information for the browser that sends them (and, if you are signed in, for your Account). Because we do not sell or share personal information for targeted advertising, a GPC signal does not change how the Service works. Our Site and Service do not respond to other “Do Not Track” signals.

6. HOW LONG WE KEEP INFORMATION

We keep personal information for as long as we need it for the purposes described in this Privacy Policy, which generally means for as long as you have an Account, and then for a limited additional period as described below. The criteria we use include how long we need the information to provide the Service, whether you have asked us to delete it, and our legal, security, and dispute resolution needs. For example:

  • Account Data and account information are kept while your Account is active. When you delete a Third-Party Account from the Service or delete your Account, we mark the data as deleted, stop using it to provide the Service, and end any shared sessions and access that depend on it. We keep deleted records only as long as reasonably necessary for security, fraud prevention, backup, legal compliance, and dispute resolution, and then delete or de-identify them.
  • One-time codes are shown in the Service for a short period (currently about 15 minutes). The original contents of email messages we receive for you are kept, in encrypted form, only for a short period (currently about 15 minutes) so that they can be forwarded to you. Encrypted records of the codes and messages you received are kept with your Account.
  • Shared session data (such as cookies for a shared account) is kept until you delete the account in the Service or delete your Account. Revoking a link ends access through that link, and archiving an account pauses its session but keeps its data so that you can restore it.
  • Data exports you request are available to download for 7 days and then deleted.
  • Notifications are deleted 90 days after they are resolved.
  • Security, audit, and sign-in records are kept while your Account is active and afterward as long as reasonably necessary to protect the Service, investigate incidents, and meet legal obligations.
  • Text messaging opt-in records are kept as long as needed to demonstrate your consent and honor your opt-out, as required by law and wireless carrier rules.

7. HOW WE PROTECT INFORMATION

We implement security measures designed to protect your information from unauthorized access, including encryption in transit and at rest, access controls, and audit logging. Much of your Account Data is encrypted on your device with keys derived from your sign-in factors, so that we cannot read it. However, some features require your Account Data to be decrypted outside your device: for example, signing in to a Third-Party Account when you are not present, keeping a shared session signed in, letting a software agent or another person use an account without seeing its password, and checking that saved credentials still work. For these features, the data is decrypted within our systems or within secure computing environments that we operate, and it may be visible to the systems that perform the sign-in while they work. Shared session data (such as cookies) is stored on our servers so that the session can be shared. You can choose not to use these features for an account.

You also play a role in protecting your information: keep your sign-in factors and devices secure, do not disclose your recovery information, and revoke access and links you no longer need.

No method of transmission or storage is completely secure. These measures do not guarantee that your information will not be accessed, disclosed, altered or destroyed, and features that limit or monitor what others can do in a shared account may not prevent or record every action. By using our Service, you acknowledge that you understand and agree to assume these risks. If we learn of a security breach that affects your personal information, we will notify you as required by law.

8. YOUR CHOICES AND RIGHTS

These choices are available to all users, wherever you live:

  • Access and export. You can view your information in the Service and request an export of your data in Settings.
  • Correction. You can update your profile and Account Data in the Service.
  • Deletion. You can delete individual Third-Party Accounts, or your entire Account, in the Service. Before deleting, make sure you can still sign in to your Third-Party Accounts without the Service, as described in Section 2.5 of our Terms of Use; deletion can cause you to lose access to them.
  • Marketing emails. You have the right at any time to prevent us from contacting you for marketing purposes. When we send a promotional communication to a user, the user can opt out of further promotional communications by following the unsubscribe instructions provided in each promotional e-mail. You can also indicate which communications you wish to receive from us in the “Settings” section of the Site. Please note that notwithstanding the promotional preferences you indicate by either unsubscribing or opting out in the “Settings” section of the Site, we may continue to send you critical administrative emails including, for example, periodic updates to our Privacy Policy or Terms of Use.
  • Text messages. You can opt out of text messages at any time by replying STOP to any text message from us, by removing your mobile telephone number (or turning off text delivery) in the Solid2FA section of the Site, or by emailing [email protected]. After you opt out, we will send one final message confirming your opt-out and will not send further text messages to that number unless you opt in again. See our SMS Consent and Text Messaging Terms for details.
  • Diagnostics. You can turn off sharing of diagnostics (error reports) in Settings.
  • Sharing and connections. You can revoke shares, links, software agents, and partner application connections at any time.

How to make a request. For any request you cannot complete in the Service, email [email protected] from the email address associated with your Account and tell us what you are asking for. We will verify your request by confirming that you control your Account or its email address, and we may ask for more information if needed. You may use an authorized agent to make a request on your behalf; we may ask the agent for proof of your written permission and ask you to verify your identity with us directly. We will respond within the time required by applicable law. We will not discriminate against you for exercising your privacy rights. Because much of your Account Data is end-to-end encrypted, we may be unable to read it or provide it in readable form in response to a request; you can export it yourself from the Service.

9. U.S. STATE PRIVACY RIGHTS

9.1. Your Rights

Depending on the state where you live, including California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia, and other states with similar laws, and subject to exceptions in those laws, you may have the right to:

  • Know and access the personal information we have collected about you, including the categories of information, its sources, the purposes for which we use it, and the categories of third parties to whom we disclose it, and to obtain a copy of it in a portable format;
  • Correct inaccurate personal information;
  • Delete personal information;
  • Opt out of the sale of personal information, of sharing for cross-context behavioral advertising or targeted advertising, and of profiling in furtherance of decisions that produce legal or similarly significant effects (we do not do any of these);
  • Limit the use and disclosure of sensitive personal information, or, in some states, have it processed only with your consent (we process sensitive personal information only as described in Section 9.3);
  • Obtain a list of the specific third parties to which we have disclosed personal information, where your state provides this right; and
  • Not be discriminated against for exercising these rights.

To exercise these rights, follow the instructions in Section 8. If we deny your request, you may appeal by replying to our decision or emailing [email protected] with the subject “Privacy Appeal”. We will respond to your appeal within the time required by law, and if we deny it, you may contact your state attorney general.

9.2. California Notice at Collection and Disclosures

The table below describes the categories of personal information we collect (and have collected in the preceding 12 months), as defined by the California Consumer Privacy Act, the purposes for which we use each category (see Section 2), and the categories of recipients to whom we disclose it for a business purpose (see Section 3). We collect personal information from the sources described in Section 1.8. We keep each category for the periods described in Section 6. We do not sell or share any category of personal information.

CategoryExamplesPurposesDisclosed to
IdentifiersName, email address, IP address, account and device identifiers, mobile telephone numberProvide, secure, communicate, improve, complyService providers; people you share with and your organization; Third-Party Services and partner applications at your direction; legal and safety recipients
Customer recordsName, contact details, payment card details and addresses you choose to storeProvide, secure, complyService providers; people you share with
Internet or other electronic network activityUse of the Site and Service, audit logs, activity in shared sessions, content of pages visited when signing in for youProvide, secure, improve, complyService providers; people you share with and your organization
Geolocation dataApproximate location derived from your IP addressSecureService providers
Audio, electronic, visual, or similar informationScreenshots of pages recorded while troubleshooting automated sign-insProvide, secure, improveService providers
Professional informationOrganization and team membership and roleProvideYour organization; service providers
InferencesWhether a sign-in looks suspiciousSecureService providers
Sensitive personal informationAccount log-in credentials for your Multifactor Account and your Third-Party Accounts; contents of email and text messages we receive for you; payment card numbers with security codes, if you store themProvide, secure, complyService providers; Third-Party Services at your direction; people you share with, within the access you choose

9.3. Sensitive Personal Information

We use and disclose sensitive personal information only for the purposes that California law permits without offering a right to limit, such as performing the services you request, ensuring security and integrity, and complying with law. We do not use it to infer characteristics about you. Because of this, we do not offer a separate “Limit the Use of My Sensitive Personal Information” link. If you live in a state that requires consent to process sensitive data, you give that consent by choosing to store the data in the Service, and you can withdraw it at any time by deleting the data.

9.4. Other California Disclosures

We do not disclose personal information to third parties for their own direct marketing purposes (California Civil Code § 1798.83). We do not offer financial incentives in exchange for personal information.

10. USERS IN THE EUROPEAN ECONOMIC AREA, UNITED KINGDOM, AND SWITZERLAND

10.1. Controller

Multifactor, Inc., 131 Continental Dr, Suite 305, Newark, Delaware 19713, USA, is the controller of the personal information described in this Privacy Policy. Where we provide the Service to an organization that decides how the Service is used for its members, that organization may also be a controller of its members’ information. If we are required to appoint a representative in the European Union or the United Kingdom, we will list its contact details here; until then, you can contact us directly at [email protected].

We rely on the following legal bases under the General Data Protection Regulation (GDPR) and the UK GDPR:

Purpose (Section 2)Legal basis
Provide the Service, including storing Account Data and acting on Third-Party Accounts as you directPerformance of our contract with you
Secure the Service and your accountsOur legitimate interests in protecting you, our users, and the Service; compliance with legal obligations
Communicate with you about the ServicePerformance of our contract; our legitimate interests
Marketing emails and optional text messagesYour consent, where required by law, which you can withdraw at any time; otherwise our legitimate interests
Maintain and improve the ServiceOur legitimate interests in providing a reliable and useful Service
Comply with law and enforce our termsCompliance with legal obligations; our legitimate interests in protecting our rights

Where we rely on legitimate interests, we have balanced those interests against your rights, and you can object as described below. Providing your name, email address, and sign-in factors is necessary to create an Account; other information is optional, but some features will not work without it.

10.3. International Transfers

We are based in the United States, and we and our service providers process personal information in the United States and other countries whose laws may not provide the same level of protection as your own. When we transfer personal information from the EEA, the UK, or Switzerland, we rely on appropriate safeguards, such as the European Commission’s Standard Contractual Clauses (with the UK Addendum where applicable) or a recipient’s certification under the EU-U.S. Data Privacy Framework and its UK and Swiss extensions. You can request more information about these safeguards by contacting us.

10.4. Your Rights

You have the right to access, correct, delete, and receive a portable copy of your personal information; to restrict or object to our processing of it (including processing based on legitimate interests and direct marketing); and to withdraw consent at any time, without affecting processing that took place before. To exercise these rights, follow Section 8. You also have the right to lodge a complaint with your local data protection authority, although we would appreciate the chance to address your concern first.

As part of the Service, we may provide links to or compatibility with other websites or applications. However, we are not responsible for the privacy practices employed by those websites or the information or content they contain. This Privacy Policy applies solely to information collected by us through the Site and the Service. Therefore, this Privacy Policy does not apply to your use of a third party website accessed by selecting a link on our Site or via our Service, or to information a Third-Party Service collects when the Service signs in to it for you. To the extent that you access or use the Service through or on another website or application, then the privacy policy of that other website or application will apply to your access or use of that site or application. We encourage our users to read the privacy statements of other websites before proceeding to use them.

12. CHANGES TO OUR PRIVACY POLICY

The Company reserves the right to change this policy and our Terms of Use at any time. We will notify you of significant changes to our Privacy Policy by sending a notice to the primary email address specified in your account, by placing a prominent notice on our site, and/or by asking you to review the updated policy in the Service. Significant changes will go into effect 30 days following such notification. Non-material changes or clarifications will take effect immediately. We will not use personal information we collected under a previous version of this policy in a materially different way without your consent where the law requires it. You should periodically check the Site and this privacy page for updates.

13. CONTACT US

If you have any questions regarding this Privacy Policy or the practices of this Site, or want to exercise your rights, please contact us by sending an email to [email protected], or by mail to Multifactor, Inc., 131 Continental Dr, Suite 305, Newark, Delaware 19713, USA.

Last Updated: This Privacy Policy was last updated on September 28, 2026.