Security
MultiScreenAI is designed so that we never hold your API keys or your conversations.
Your API keys
- Keys are saved only in your browser's local storage, scoped to your Google account on that device.
- When you send a message, the key for that panel travels over HTTPS with that single request to our server, which forwards it to the provider and discards it. Keys are never written to a database or a log.
- Our server only ever calls the official API addresses of the supported providers. It never fetches an address supplied by the browser.
Your chats and files
- Prompts, answers, images and attachments pass through our server on the way to and from the provider and are not stored.
- Chat history is kept in your browser. Clear it any time from Settings, Delete local data.
- Files created by Claude are downloaded directly from Anthropic with your key when you click them.
Accounts
- Sign in uses Google OAuth. We receive your name, email address and profile picture only.
- We keep a small account record (Google account id, name, email, join date and last activity) in an encrypted Postgres database. It never contains API keys or chats.
- Sessions use a signed, HTTP-only cookie. The workspace and every API route require a valid session.
Infrastructure
- Hosted on Vercel with HTTPS enforced on every page.
- No advertising or third-party tracking scripts.
Report a vulnerability
Please email support@multiscreenai.com with the details and steps to reproduce. Do not include real API keys. See also our Privacy Policy.