Scope and contact
This policy covers this Synthic website and Workspace. Contact support@usesynthic.com about privacy, access, correction, or deletion. Effective September 30, 2026.
Information we collect
When you sign in using email, Google, or ChatGPT, we receive an account identifier and, when supplied, your name and email. Supabase handles email/password and Google authentication; passwords are submitted to the authentication service and are not stored in the workspace database. We store profile changes, workspace membership, brands, domains, competitors, buyer questions, imported answers, analyses, plans, actions, content, and reports you save. Connection settings may include encrypted API credentials. Billing integrations store customer and subscription identifiers, subscription status, and usage records. Support correspondence includes information you send us. We record the version and server time of Terms acceptance and workspace product events such as audit completion, opening evidence, and saving an evidence-linked action. These records use account and workspace identifiers; they do not include prompt or answer text.
How information is used
We use this information to provide your workspace, authenticate access, organize and analyze research, enforce usage limits, manage billing where enabled, troubleshoot failures, protect the service, and answer support requests. Operational records may include request times, errors, and security events. Hosting providers may process network information such as IP addresses and browser details to deliver and protect the site.
Service providers and sharing
OpenAI / ChatGPT Sites provides hosting and ChatGPT sign-in infrastructure, Cloudflare provides application execution and storage infrastructure, and Supabase provides email and Google authentication. Resend handles transactional messages where configured, including contact-sales submissions, which contain the contact details and message you provide. Stripe processes billing interactions where enabled; payment card entry takes place through Stripe. Workspace members can access information according to their permissions. Information you export or share with others leaves those workspace controls. We may disclose information when legally required or needed to protect rights and security.
AI providers and connected services
Live AI collection depends on enabled provider connections and available workspace allowance. Saving a brand or a question does not itself send it to a model. When execution is enabled and you initiate an eligible task, relevant questions, brand context, and answer text may be sent to the configured collection and analysis providers, including OpenAI, Google, Anthropic, xAI, or Perplexity. Website checks fetch the public pages you select. Optional GitHub and GitLab connections process repository information and proposed changes when you request those actions. Those providers have their own data practices. Do not submit information you lack permission to share.
Cookies and browser storage
The application uses authentication cookies, a sidebar preference cookie, session storage for the selected brand, and local storage for your motion preference. Hosting and sign-in services may also use cookies or similar mechanisms for authentication and security. A session cookie can store a broad, allowlisted campaign source such as google or email; it contains no personal or advertising identifier. Global Privacy Control prevents setting that campaign cookie and makes the recorded source unknown. We use first-party product events to assess activation, excluding known internal and pre-existing workspaces from new-user cohorts. The current application does not install advertising pixels or implement cross-site advertising tracking. It does not change its behavior in response to Do Not Track signals. Clearing browser storage does not delete server-side records.
Retention and security
Workspace information remains stored until removed through available controls or a verified deletion process. Product-event records older than 365 days are removed during subsequent event processing. Authentication throttles store hashed address/email buckets that expire within ten minutes and are removed on subsequent authentication attempts. Terms acceptance is retained as a limited legal record. We retain information needed to operate the service and may retain limited billing, security, or legal records where necessary. Backup copies may remain until the hosting provider’s retention cycle removes them. Authentication, workspace access checks, and encryption of saved credentials help protect information; no service can guarantee absolute security.
Your choices and requests
Review your profile in Account & Team. Export saved evidence and reports using the available workspace controls. To request access, correction, or deletion, email support@usesynthic.com from your account email and identify the relevant workspace and request. We may verify your identity and authority before acting, particularly for shared workspaces. Account & Team offers a JSON export of your profile, memberships, and research in workspaces you own, and self-service deletion for eligible unshared personal workspaces without billing or provider-usage history or active audits. Other accounts require manual review. On self-service deletion, profile fields and personal workspace research are erased from the application database; a minimal sign-in identifier and closure date remain to prevent automatic account recreation. Hosting backups, internal security records, contact-sales records, and third-party records are handled separately. Closing a workspace account does not itself delete your Supabase authentication record, Google account, or ChatGPT account; contact support about authentication-record deletion. Signing out does not delete your account.
California privacy rights
Depending on applicable law, you may have rights to access, correct, or delete personal information, and to opt out of sale or sharing or limit certain uses of sensitive information. Contact support@usesynthic.com to make a request or have an authorized agent contact us. We will handle requests subject to applicable law and verification requirements, without unlawful discrimination. The current application does not sell personal information or share it for cross-context behavioral advertising.
Children and policy changes
Synthic is intended for adult business users, not children under 18. If you believe a child submitted personal information, contact us. We will publish policy changes here with an updated effective date and provide additional notice when required. Third-party websites linked from Synthic follow their own policies.
Or write to support@usesynthic.com using your email service.