Privacy Policy
Last updated: 17 August 2026 · v2026.08
This Privacy Policy explains how AiCoaches dot com LLC ("we", "us", "our"), operating NurtureCRM.ai under the brand Multiplai.tech, handles personal data in connection with the NurtureCRM platform (the "Service").
It covers both the data we hold about our own customers, and the data our customers process using the Service — including email from connected Microsoft 365 and Google Gmail mailboxes.
Google API Services Limited Use disclosure
NurtureCRM's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Concretely, and as a statement about how the system behaves rather than an aspiration:
- Google user data is used only to provide or improve the user-facing features that are prominent in the NurtureCRM interface — the unified inbox, thread history, reply detection, contact activity, and the AI drafting and summarization features a user explicitly invokes on a message.
- Google user data is not transferred to third parties except to provide or improve those features, for security purposes, to comply with applicable law, or as part of a merger or acquisition with prior notice.
- Google user data is never used for advertising.
- No human reads Google user data, except where the user explicitly consents for a specific message (for example, when they ask support to investigate one), where it is necessary for security purposes or to comply with applicable law, or where the data has been aggregated and anonymised for internal operations.
Google user data is not used to develop, improve or train generalized artificial intelligence or machine learning models. The AI features described in the AI Policy process message content only to produce a result for the user who requested it, using providers contractually bound not to train on that content.
A short standalone version of this disclosure is published at Google Limited Use.
Who is responsible for what
NurtureCRM is used by organizations ("Customers"). Those organizations load contact data and connect mailboxes.
- For CRM records, mail content, and any other personal data a Customer brings to the Service, the Customer is the data controller and NurtureCRM is the data processor, acting on the Customer's instructions.
- For our own account, billing and support data about our Customers and their administrators, NurtureCRM is the controller.
If you are an End Contact whose data is held in a Customer's CRM, that Customer decides why your data is there and for how long. Direct requests to that organization in the first instance; we will assist them in responding.
Data we collect
Account and billing data
Company name, chosen subdomain, industry and company size; administrator name, email address, phone number and job title; subscription tier; payment status. Card details are collected and stored by Stripe, not by us.
Service and diagnostic data
Authentication events, provisioning and deployment events, module install and audit records, error logs, and request metadata such as timestamps and IP addresses. These are used to operate, secure and support the Service.
CRM data loaded by the Customer
Contacts, companies, deals, activities, notes, tasks, bookings, and form submissions. The categories are determined by the Customer.
Photographs and facial-recognition data (Marketing Events only)
Where a Customer uses the Marketing Events feature and uploads event photographs, we use Amazon Rekognition to detect faces in those photographs and match them against contact profile photos, so attendance can be recorded. This produces facial-geometry templates, which may be biometric data under some privacy laws. Templates are held in a collection scoped to that Customer and are never compared across Customers.
This processing happens only if the Customer uses Marketing Events and uploads photographs. The Customer is the controller for it and is responsible for having a lawful basis — which in several jurisdictions means explicit consent from the people photographed. Matches are reviewed and approved by a person at the Customer before attendance is recorded.
Meeting audio (Meeting Copilot only)
Where a Customer uses meeting transcription, audio from the recorded session is sent to a speech-to-text provider and returned as a transcript stored in the Customer's own database. Recording is initiated by a user, not by us. The provider is OpenAI, or AssemblyAI where that provider is configured for the deployment — see the AI Policy for what each may do with what it receives.
Google user data from connected Gmail mailboxes
Where a mailbox owner connects a Gmail mailbox, we access:
| Data | Feature it serves |
|---|---|
| Message headers — sender, recipients, subject, date, thread and message identifiers | Building the unified inbox, threading conversations, matching messages to CRM contacts, and reply detection |
| Message bodies and snippets | Displaying the conversation, and providing AI summaries and reply drafts when a user invokes them |
| Attachment metadata — filename, type, size | Showing users what a message contains. Attachment contents are fetched only when a user opens them |
Labels — for example INBOX, SENT |
Determining which messages belong in the unified inbox and whether a message was sent or received |
| The mailbox owner's email address and basic profile | Identifying whose mailbox is connected and binding it to a user account |
We request the gmail.readonly and gmail.send scopes, plus openid,
userinfo.email and userinfo.profile. We do not request permission to modify or
delete messages in a Gmail mailbox.
Microsoft 365 mailbox data
Where a mailbox owner connects a Microsoft 365 mailbox, we access the equivalent data
using the Mail.Read, Mail.Send, offline_access and User.Read delegated
permissions, for the same features.
How we use data
- To provide the Service and the features a Customer has enabled.
- To provision, operate, monitor, back up and secure each Customer's isolated runtime.
- To process payments and manage subscriptions.
- To provide support, when a Customer asks for it.
- To detect, investigate and prevent abuse, fraud and security incidents.
- To comply with legal obligations.
We do not sell personal data. We do not use Customer data or mailbox data for advertising or for cross-customer analytics.
AI processing
AI features send a scoped extract of Customer data to third-party model providers — currently OpenAI and Anthropic for text, and OpenAI or AssemblyAI for speech transcription depending on how the deployment is configured — to produce a result for the user who invoked the feature.
- Only the context needed for that request is sent, not a Customer's whole database.
- Only OpenAI and Anthropic are on the path that can receive mail content. No speech provider ever receives email.
- Output is written back into the Customer's own database and is subject to the same access controls as any other record.
- Customer data, including mail content, is not used to train or improve any model. The contractual basis for each provider is stated in the AI Policy.
- Provider retention terms and the controls available to Customers — including turning AI features off entirely — are described in the AI Policy.
Sub-processors
We use a small set of sub-processors to run the Service — hosting, DNS and edge, payments, email providers, and the AI providers above. Each is named, with its purpose, data categories and processing region, at Sub-processors. We give advance notice of additions as described on that page.
Retention
| Data | Retention |
|---|---|
| CRM records | For as long as the Customer keeps them, then per the Customer's instruction |
| Mail content ingested from a connected mailbox | Held in the Customer's own database until the Customer deletes it or the account is terminated |
| OAuth tokens for connected mailboxes | Until revoked. On revocation the token is marked revoked and can no longer be used; the record is retained in that revoked state for audit rather than deleted |
| Account, billing and audit records | For the life of the account and thereafter as required for tax, accounting and legal purposes |
| Backups | On the cadence described in the Data Policy, with restores verified |
| Terminated accounts | Suspended, archived, and permanently deleted after the 90-day export window described in the Terms |
Disconnecting a mailbox stops further ingestion. It does not by itself delete mail already ingested into the Customer's database — that is the Customer's data, and the Customer decides whether to delete it.
Sharing and disclosure
We disclose personal data only:
- to the sub-processors listed at Sub-processors, under contract;
- to a Customer's own administrators, in respect of their own tenant;
- where required by law, or to protect rights, safety or the security of the Service; and
- in connection with a merger, acquisition or sale of assets, with prior notice.
We do not transfer Google user data outside these categories, consistent with the Limited Use requirements above.
International transfers
The Service is hosted on Amazon Web Services infrastructure in the United States. DNS and edge services are provided by Cloudflare, which operates globally. Where personal data originating in the European Economic Area or the United Kingdom is transferred to the United States, the transfer is made under Standard Contractual Clauses or another lawful transfer mechanism agreed with the Customer.
Your rights
Depending on where you are, you may have rights to access, correct, delete, port, restrict or object to the processing of your personal data, and to withdraw consent.
- If you are an End Contact in a Customer's CRM, contact that Customer — they are the controller. We act on their instruction and will support them in responding.
- If you are a Customer or an administrator, contact support@aicoaches.com.
- If you connected a mailbox, you can disconnect it at any time from within the Service or from your Google or Microsoft account settings. Revoking access at the provider also ends our access.
We do not charge for responding to a rights request unless it is manifestly unfounded or excessive, and we respond within the period applicable law requires.
Security
- Encryption in transit. All external traffic is served over TLS. Certificates are issued and renewed automatically.
- Encryption at rest. Mailbox OAuth tokens are encrypted at rest with envelope encryption. Provider client secrets are held by the platform and are never written into a Customer's runtime container.
- Tenant isolation. Each Customer has its own container, its own database, its own object storage and its own network. There is no shared application database holding multiple Customers' CRM records.
- Access control. Role-based access control governs what each Authorized User can see and do. Internal administrative endpoints are separately authenticated, and the control plane authenticates to each tenant runtime with per-instance keyed credentials rather than a shared secret.
- Audit logging. Authentication, provisioning, module and administrative actions are logged.
- Backups and recovery. Backups run automatically and restores are verified rather than assumed. See the Data Policy.
- Staff access. Support and engineering access to a Customer's tenant is limited to what is needed to resolve a specific request or security incident, consistent with Limited Use commitment 4 above.
No system is perfectly secure. We will notify affected Customers of a personal data breach without undue delay and, where applicable law requires it, within the required period.
Children
The Service is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child's data has been provided to us, contact support@aicoaches.com and we will delete it.
Changes to this policy
We may update this policy. The version and effective date at the top of this page change with it, and material changes are notified as described in the Terms.
Contact
AiCoaches dot com LLC 111 NE 1ST ST, 8TH FLOOR 89145, Miami, Florida, USA 33132 Privacy enquiries: support@aicoaches.com