Privacy Policy

Last updated: March 16, 2026

Overview

Multipl.tools (“we,” “us,” or “our”) builds software that helps organizations understand and reduce waste. This privacy policy explains how we collect, use, and protect your information across our products, including the Burn Counter Chrome extension and the Multipl.tools website.

Our core principle: your sensitive data stays on your device. We are privacy-first by design, not by afterthought.

Burn Counter Chrome Extension

Data stored locally on your device

The Burn Counter extension operates with a local-only architecture. The following data is stored exclusively on your device using Chrome's built-in storage APIs:

  • Compensation data (salary/hourly rates) — Encrypted using AES-256-GCM with a unique encryption key generated on your device. This data never leaves your browser.
  • Participant profiles — Names and roles of meeting participants, stored locally.
  • Meeting history — Records of past meetings including duration and calculated costs, stored locally.
  • Active meeting state — Current meeting timer data, stored in Chrome's extension storage (managed by the service worker). Cleared when the meeting ends or the extension is uninstalled.
  • Extension settings — Your display preferences and theme selection.

Encryption

All compensation data is encrypted using AES-256-GCM before storage. A unique encryption key is generated on first install using the Web Crypto API and stored locally. Each encryption operation uses a unique initialization vector (IV). We never have access to your encryption key or unencrypted compensation data.

No data collection (free tier)

The free version of Burn Counter makes zero network requests. No analytics, no telemetry, no usage tracking. Your data stays entirely on your device.

Premium Features (Optional)

If you choose to create an account and subscribe to Premium, the following additional data is processed:

  • Account information — Email address and authentication data, managed by Clerk (our authentication provider).
  • Payment information — Processed by Stripe. We never store your credit card details.
  • Theme preferences — Your selected visual theme, synced across devices.

Important: Even with Premium, your compensation data (salary/hourly rates) remains encrypted on your local device and is only transmitted to our servers temporarily to perform aggregation for remote meetings.

Multipl.tools Website

When you visit multipl.tools, we collect minimal data necessary to operate the website:

  • Authentication data — If you sign in, Clerk manages your session. See Clerk's Privacy Policy.
  • Hosting logs — Standard server logs (IP address, browser type, pages visited) as maintained by Vercel. See Vercel's Privacy Policy.

We do not use cookies for advertising or tracking. The multipl.tools website uses Vercel Analytics for aggregate, anonymous page view data — no individual users are identified or tracked. We do not sell, share, or transfer your data to third parties for advertising or marketing purposes.

Third-Party Services

We use the following third-party services:

  • Clerk — Authentication and user management (Premium accounts only).
  • Stripe — Payment processing (Premium subscriptions only).
  • Vercel — Website hosting, deployment, and anonymous page view analytics.
  • Supabase — Database hosting for Premium account data.

Each service processes only the minimum data required for its function. We do not share user data between services beyond what is necessary for product functionality.

Data Retention & Deletion

  • Local extension data — Deleted when you uninstall the extension or clear browser data. You control this entirely.
  • Premium account data — Retained while your account is active. Contact us through our contact page to request account deletion. We will delete your data within 30 days.
  • Payment records — Retained by Stripe per their data retention policies and applicable financial regulations.

Your Rights Under GDPR (European Users)

If you are located in the European Economic Area (EEA) or the United Kingdom, you have the following rights regarding your personal data:

  • Right to access — You may request a copy of the personal data we hold about you.
  • Right to rectification — You may request correction of inaccurate personal data.
  • Right to erasure — You may request deletion of your personal data. For local extension data, you control this directly by uninstalling the extension or clearing browser data. For Premium account data, we will delete your data within 30 days of your request.
  • Right to data portability — You may request an export of your personal data in a structured, machine-readable format. Local extension data is already stored on your device. For Premium account data, contact us through our contact page to request an export.
  • Right to restrict processing — You may request that we limit processing of your personal data in certain circumstances.
  • Right to object — You may object to the processing of your personal data where we rely on legitimate interests as the legal basis.

Legal basis: We process personal data based on (a) your consent when you create an account, (b) contractual necessity to provide the Services, and (c) our legitimate interest in operating and improving the Services.

Sub-processors: We use Clerk (authentication), Stripe (payments), Supabase (database), and Vercel (hosting). Each processes only the minimum data required for its function. Their respective privacy policies and data processing terms govern their handling of your data.

To exercise any of these rights, contact us through our contact page. We will respond within 30 days.

Your Rights Under CCPA (California Users)

If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with the following rights:

  • Right to know — You have the right to know what personal information we collect, how it is used, and with whom it is shared. The sections above describe this in detail.
  • Right to delete — You may request deletion of your personal information. For local extension data, you control this directly. For Premium account data, we will delete your data within 30 days of your request.
  • Right to opt-out of sale — We do not sell, share, or trade your personal information to third parties for monetary or other valuable consideration. We have never sold personal information and have no plans to do so.
  • Right to non-discrimination — We will not discriminate against you for exercising any of your CCPA rights. You will not receive different pricing, quality, or service levels for making a privacy request.

To exercise any of these rights, contact us through our contact page.

Children's Privacy

Our services are not directed at children under the age of 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.

Changes to This Policy

We may update this privacy policy from time to time. If we make material changes, we will notify users through the extension or website before the changes take effect. Your continued use of our services after changes are posted constitutes acceptance of the updated policy.

Contact Us

If you have questions about this privacy policy or our data practices, contact us at:

Visit our contact page