Privacy Policy

Your privacy is fundamental to everything we do. This policy explains how we protect your data and ensure you maintain complete control.

Last Updated: September 15, 2024

Original Policy Effective: March 1, 2024

Our Core Privacy Commitment

Self Multiplexer (SelfMux) does not directly monetize your data. We do not sell, rent, or trade your personal information. We're flipping the script: companies may pay for access to user data through our platform, but this is monetization of access to data, not direct monetization of the data itself. Your data is shared only with the sites you explicitly authorize, and you maintain complete control over what is shared and when. Businesses pay for the privilege of having you as a customer.

Important: Sites you authorize to access your data have their own business models that may include monetization of the data you share. We cannot control what authorized sites do with the data they receive. We provide tools to help you protect your privacy, including the ability to signal Do Not Track and Do Not Sell preferences with your shared data.

Table of Contents

1 Introduction

Self Multiplexer ("SelfMux," "we," "us," or "our") operates as a distributed identity platform that enables you to control your personal information and share it securely with websites and services you trust. This Privacy Policy describes how we collect, use, protect, and share your personal data when you use our services at selfmux.com, selfmux.xto.email and associated domains (collectively, the "Service").

By using SelfMux, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with this policy, please do not use our Service.

2 Information We Collect

2.1 Information You Provide Directly

2.2 Information Collected Automatically

Important: All automatically-collected information is strictly for your protection. These logs may be purged at any time (automatically or manually) or may not be retained at all beyond what is necessary to protect against abuse.

2.3 Information We Do Not Collect

We do not collect information for advertising purposes, behavioral tracking across websites, or any form of data monetization. We do not participate in ad networks or share your data with data brokers.

3 How We Use Your Information

We use your information solely for the following legitimate purposes:

We do not use your data for marketing, advertising, or any form of monetization beyond providing the Service itself.

4 Data Sharing and Third Parties

4.1 User-Authorized Sharing

Your personal data is shared with third-party websites and services only when you explicitly authorize such sharing. You control:

Critical limitation: Once a site receives your data through an authorized request, we cannot control what that site does with the information, including whether they monetize it, share it with others, or sell it to third parties. While we do not monetize your data, authorized sites may have different business models and privacy practices. We strongly recommend:

4.2 Do Not Track Preferences

SelfMux supports Do Not Track (DNT) preferences to help protect your privacy when sharing data with authorized sites:

Note: DNT is a privacy preference signal, not a legal requirement. Sites may choose to honor it or not. We recommend reviewing each site's DNT policy.

4.3 Service Providers

We may share limited information with service providers who assist in operating our Service:

All service providers are bound by strict contractual obligations to protect your data and use it only for the specific purposes we authorize. We conduct due diligence on all providers to ensure they meet our security and privacy standards.

4.4 Legal Requirements

We may disclose your information if required by law, court order, or legal process, or if we believe in good faith that such disclosure is necessary to:

We will notify you of such disclosures unless prohibited by law or court order, and we will challenge overly broad or inappropriate requests where legally permissible.

4.5 Business Transfers

Binding Protections: In the event of a merger, acquisition, bankruptcy, or sale of assets, your data is protected by legally binding commitments detailed in our Terms of Service that remain in effect for all time. Key protections include:

These protections are absolute, irrevocable, and survive any change of ownership. For complete details, see Section 5 of our Terms of Service.

4.6 What We Never Share

We will never:

5 Your Control Over Your Data

You maintain complete control over your personal information at all times. SelfMux provides the following controls:

5.1 Authorization Management

5.2 Full Audit Trail

5.3 Emergency Kill Switch

In case of emergency (lost device, compromised account, or any security concern), you can activate the kill switch feature that immediately:

5.4 Data Portability

6 Security Measures

We implement industry-leading security practices to protect your data:

6.1 Authentication Security

6.2 Infrastructure Security

6.3 Application Security

7 Data Retention and Deletion

7.1 Active Account Data

We retain your personal data for as long as your account is active and as needed to provide you the Service. You can update or modify your data at any time through your dashboard.

7.2 Audit Logs

Access audit logs are retained for a minimum of 1 year to provide you with complete transparency and to support security investigations. You may retain your audit logs indefinitely by exporting them.

7.3 Deleted Account Data

When you delete your account:

7.4 Authorized Site Data

Important: When you authorize a site to access your data, that site receives a copy of the information. Deleting your SelfMux account does not delete data previously shared with authorized sites. You must contact those sites directly to request deletion of data in their systems.

8 Encryption and Protection

8.1 Data in Transit

8.2 Data at Rest

8.3 End-to-End Protection

When a site requests your data through the API, the data is encrypted end-to-end. Sites receive encrypted payloads that only they can decrypt using their private keys, ensuring SelfMux infrastructure never exposes plaintext sensitive data in transit.

9 Audit Trails and Transparency

9.1 Immutable Audit Logs

Every access to your data is recorded in an immutable audit log that cannot be modified or deleted. Each log entry includes:

9.2 Real-Time Notifications

You can enable notifications to receive alerts when:

9.3 Log Integrity

Audit logs use cryptographic hash chains to ensure integrity. Any tampering with the logs is immediately detectable. If log integrity is compromised, your account is automatically locked and you are notified immediately.

10 Your Privacy Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

10.1 Universal Rights (All Users)

10.2 GDPR Rights (EU/EEA/UK Users)

If you are located in the European Union, European Economic Area, or United Kingdom, you have additional rights under the General Data Protection Regulation (GDPR):

Our legal basis for processing your data is your consent (for data sharing) and contract performance (for providing the Service).

10.3 CCPA Rights (California Users)

If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA):

10.4 Exercising Your Rights

To exercise any of these rights:

11 Children's Privacy

SelfMux is not intended for use by children under the age of 13 (or 16 in the EU). We do not knowingly collect personal information from children. If we learn that we have collected personal data from a child without proper consent, we will delete that information immediately.

Parents or guardians who believe their child has provided us with personal information should contact us at privacy@selfmux.com.

12 International Data Transfers

SelfMux operates globally with distributed infrastructure. Your data may be processed in multiple regions for performance and redundancy. We ensure that all data transfers comply with applicable data protection laws:

Regardless of where your data is processed, it receives the same level of protection described in this Privacy Policy.

Important: We will not provide services to regions that require sacrificing your privacy or security, or our own privacy or security standards.

13 Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes:

We encourage you to review this Privacy Policy periodically. Previous versions are available upon request.

14 Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

For EU users, our representative can be contacted at the same addresses.

We aim to respond to all inquiries within 48 hours and to resolve all requests within 30 days.

Remember: You Are In Control

Your data belongs to you. SelfMux exists to give you the tools to control your personal information, share it securely with sites you trust, and revoke access whenever you choose. We're flipping the script on data monetization: we do not sell, rent, or trade your data. Companies may pay for access to user data through our platform, but you maintain complete control. Businesses pay for the privilege of having you as a customer. We will always be transparent about how your data is used and protected.