MultiFW Copilot AI — Chrome Extension Privacy Policy

This policy applies exclusively to the MultiFW Copilot AI browser extension.

Last Updated: March 22, 2026

1. Extension Purpose

MultiFW Copilot AI is a Chrome extension that helps users fill out compliance questionnaires on third-party websites. When a user manually activates the extension on a web page containing a form, the extension analyzes the form fields and suggests answers based on the user's previously uploaded knowledge base stored in their MultiFW account.

The extension does NOT passively monitor browsing activity. It only activates when the user explicitly clicks the extension icon and initiates a scan.

2. Data Collected

The following table describes all data the extension collects:

Data Type When Collected Purpose
Form field content (labels, input types, current values) Only when user clicks "Scan Page" Identify questionnaire fields to suggest answers
Page URL and title Only when user clicks "Scan Page" Provide context for form identification
Page screenshot (optional) Only when user clicks "Visual Scan" Visual analysis of form layout when DOM scan is insufficient
Email and password At login Authenticate user with existing MultiFW account
Authentication token After login Maintain session (stored locally in chrome.storage)

Data NOT Collected

  • Browsing history
  • Data from pages the user does not explicitly scan
  • Cookies from other websites
  • Personal files or downloads
  • Keystrokes or clipboard content
  • Data from other browser tabs

3. How Data Is Used

  • Form content is sent to MultiFW backend servers to identify questionnaire fields and generate AI-powered answer suggestions based on the user's knowledge base.
  • Screenshots (when taken) are sent to MultiFW backend for visual form analysis and are not stored permanently.
  • Authentication credentials are used solely to verify the user's identity and retrieve their company's knowledge base.
  • Session tokens are stored locally in chrome.storage.local and automatically expire after the configured timeout (default: 4 hours).

No data is used for advertising, analytics, or any purpose other than providing the core form-filling functionality.

4. Data Sharing

Data collected by the extension is shared exclusively with the following services, solely for providing core functionality:

Service Location Data Received Purpose
Supabase United States Form content, authentication tokens Backend API, database, authentication
OpenAI United States Form field text (no personal identifiers) AI-powered answer suggestion generation
Google Gemini United States Form field text (no personal identifiers) Alternative AI processing
Anthropic Claude United States Form field text (no personal identifiers) Alternative AI processing

No data is sold to third parties. Data sent to AI providers via API is not used for model training, per their respective API terms of service.

5. Permissions Justification

The extension requests the following Chrome permissions:

Permission Why It Is Needed
activeTab Access the current tab's content when user clicks "Scan Page" to extract form fields
scripting Inject content script into the active page to read form HTML and apply suggested answers
storage Store authentication token locally so the user stays logged in between browser sessions
tabs Capture visible tab screenshot when user opts for "Visual Scan" mode
sidePanel Display the Copilot AI interface as a Chrome side panel for easier interaction

The extension only communicates with https://*.supabase.co/* (host permission). No other external domains are contacted.

6. Data Security

  • All data transmitted between the extension and backend uses HTTPS/TLS 1.2+ encryption.
  • Data at rest is encrypted with AES-256.
  • Authentication uses JWT tokens with configurable expiration (default: 4 hours).
  • Multi-tenant isolation via Row Level Security (RLS) ensures each organization's data is separated.
  • Form content scans are processed in real-time and not permanently stored after answer generation is complete.

7. Data Retention and Deletion

  • Scan data (form content, screenshots): Processed in real-time and discarded after answer suggestions are generated. Not permanently stored.
  • Session tokens: Stored locally in chrome.storage.local and automatically expire after the configured timeout.
  • Account data: Retained while the user's MultiFW account is active. Users can request complete data deletion by contacting [email protected].

Uninstalling the extension removes all locally stored data (chrome.storage.local).

8. User Rights

Users have the right to:

  • Access their data by logging into their MultiFW account
  • Delete their account and all associated data
  • Export their data in standard formats (PDF, XLSX, JSON)
  • Revoke consent by uninstalling the extension

For data requests, contact: [email protected]

9. Changes to This Policy

We may update this policy from time to time. Significant changes will be communicated through the extension's update notes on the Chrome Web Store. Continued use of the extension after changes constitutes acceptance of the updated policy.

10. Contact

Data Controller: Rupengk Empreendimentos e Participações Ltda. (CNPJ/MF 19.921.573/0001-86), Rua Martinho Gonçalves, 2214, São José do Rio Preto/SP, Brazil, operating as MultiFW.

Data Protection Officer (DPO): [email protected]

Website: www.multifw.com