This policy applies exclusively to the MultiFW Copilot AI browser extension.
Last Updated: March 22, 2026
MultiFW Copilot AI is a Chrome extension that helps users fill out compliance questionnaires on third-party websites. When a user manually activates the extension on a web page containing a form, the extension analyzes the form fields and suggests answers based on the user's previously uploaded knowledge base stored in their MultiFW account.
The extension does NOT passively monitor browsing activity. It only activates when the user explicitly clicks the extension icon and initiates a scan.
The following table describes all data the extension collects:
| Data Type | When Collected | Purpose |
|---|---|---|
| Form field content (labels, input types, current values) | Only when user clicks "Scan Page" | Identify questionnaire fields to suggest answers |
| Page URL and title | Only when user clicks "Scan Page" | Provide context for form identification |
| Page screenshot (optional) | Only when user clicks "Visual Scan" | Visual analysis of form layout when DOM scan is insufficient |
| Email and password | At login | Authenticate user with existing MultiFW account |
| Authentication token | After login | Maintain session (stored locally in chrome.storage) |
No data is used for advertising, analytics, or any purpose other than providing the core form-filling functionality.
Data collected by the extension is shared exclusively with the following services, solely for providing core functionality:
| Service | Location | Data Received | Purpose |
|---|---|---|---|
| Supabase | United States | Form content, authentication tokens | Backend API, database, authentication |
| OpenAI | United States | Form field text (no personal identifiers) | AI-powered answer suggestion generation |
| Google Gemini | United States | Form field text (no personal identifiers) | Alternative AI processing |
| Anthropic Claude | United States | Form field text (no personal identifiers) | Alternative AI processing |
No data is sold to third parties. Data sent to AI providers via API is not used for model training, per their respective API terms of service.
The extension requests the following Chrome permissions:
| Permission | Why It Is Needed |
|---|---|
| activeTab | Access the current tab's content when user clicks "Scan Page" to extract form fields |
| scripting | Inject content script into the active page to read form HTML and apply suggested answers |
| storage | Store authentication token locally so the user stays logged in between browser sessions |
| tabs | Capture visible tab screenshot when user opts for "Visual Scan" mode |
| sidePanel | Display the Copilot AI interface as a Chrome side panel for easier interaction |
The extension only communicates with https://*.supabase.co/* (host permission). No other external domains are contacted.
Uninstalling the extension removes all locally stored data (chrome.storage.local).
Users have the right to:
For data requests, contact: [email protected]
We may update this policy from time to time. Significant changes will be communicated through the extension's update notes on the Chrome Web Store. Continued use of the extension after changes constitutes acceptance of the updated policy.
Data Controller: Rupengk Empreendimentos e Participações Ltda. (CNPJ/MF 19.921.573/0001-86), Rua Martinho Gonçalves, 2214, São José do Rio Preto/SP, Brazil, operating as MultiFW.
Data Protection Officer (DPO): [email protected]
Website: www.multifw.com