SyndaiSign inStart free

Privacy Policy

Last updated: October 3, 2026

1. Who We Are and What This Covers

This policy explains what personal information Syndai collects, why, and what your rights are. The short version: we collect what we need to run Syndai for you: building and shipping your product and doing the go-to-market and operations work around it, we process your repository and the content of any accounts you connect to do the work you direct and retain workspace snapshots and encrypted archives while a source stays connected, we do not train models on your content, we do not use cross-site tracking cookies, and we do not sell your data. Syndai is operated by Eternex, Inc., a Delaware corporation doing business as Syndai, 2261 Market Street STE 24499, San Francisco, CA 94114. Eternex is the data controller for the personal information described here, except where we process content on a customer’s behalf, in which case we act as a processor/service provider. This policy covers syndai.ai, the Syndai application and API, the customer portal, and our related communications.

2. Information We Collect

Account data: name, email address, organization, authentication credentials (managed through Supabase), team roles, and settings. Repository content, processed in isolated sandboxes: when you run Syndai against a connected repository, we clone the relevant content into an isolated build sandbox for the duration of the run and send the portions needed to fulfill your prompt to the LLM provider executing the change; live sandboxes are torn down when the run ends, while workspace snapshots and encrypted archives of connected repository content are retained (so runs start fast and can recover) until you disconnect the repository or delete your account, per Section 6; run artifacts you’d expect to keep (prompts, diffs, evidence, run logs) are retained with your account. Connected-account content and outreach data: when you connect accounts beyond a repository (for example, social, email, or analytics accounts) and direct work through them, we process the content of those accounts and the contact information you provide or ask us to use (for example, the people you ask us to draft or send outreach to), only to perform the work you direct, and we send each result to you to approve before anything is published or sent; where that content includes personal data of people you choose to contact, you act as the controller of that data and we process it on your behalf, and we retain it while the account stays connected and delete it on disconnection or account deletion. Usage and telemetry data: product analytics events (PostHog, EU-hosted), error reports (Sentry), API request logs, run metadata, device and browser information, and IP addresses for security and rate-limiting. To keep the free starting credits to one per person, we keep a keyed one-way hash of your email address's mailbox (ignoring +tags and, for Gmail, dots). We keep it after you delete your account, because its only purpose is to stop the same mailbox getting the free starting credits twice. Without our key, nobody can recover your email from it. Billing data: subscription tier, credit purchases and consumption, invoices, and tax location. Payment card details go directly to Polar, our merchant of record, and we never see or store full card numbers. We also keep the messages you send us. We do not buy data about you from data brokers.

3. How We Use Information

We use personal information to provide the Service (run your prompts, operate sandboxes, open pull requests, operate the API and portal), personalize your later runs using persistent run-derived memory scoped to you and your connected repositories (on by default, disableable per run, never pooled across customers or used to train models, and erasable on request), administer and authenticate your account, meter usage and bill you, secure the Service and prevent abuse, understand product usage through first-party analytics, communicate with you about the Service (transactional email via Resend, support, security notices, and material changes), and comply with law. We do not use your repository content or generated output to train machine-learning models, and we require the LLM providers that execute your requests not to train on it either. We do not sell personal information.

4. Legal Bases (GDPR)

Where the EU or UK GDPR applies, we process personal information on these bases: contract, for account data, repository content and connected-account content processed to fulfill the work you direct, persistent memory used to personalize your runs, billing, and support; a processor role for the outreach you direct, where you act as the controller of the personal data of the people you choose to contact and we process it on your behalf on the basis you rely on as the sender (for example, your legitimate interest or the recipient’s consent), and you are responsible for having that basis, as covered in the Acceptable Use Policy; legitimate interests, for securing the Service, preventing abuse, first-party analytics, measuring the performance of our own ads, and product improvement, balanced against your rights; consent, where we ask for it (for example, optional marketing email), which you can withdraw at any time; and legal obligation, for tax, accounting, and lawful requests.

5. Subprocessors and Third Parties

We use these providers to run the Service, each processing data on our behalf under a data-processing agreement and barred from using it for their own purposes: Cloudflare (hosting and content delivery), Fly.io (application hosting), Supabase (database and authentication, including the persistent coding-run memory store), E2B and Modal (isolated build sandboxes), the LLM model providers that execute the work you request in code, documentation, posts, media, and outreach, and that review screenshots and page-derived text of the web app being built (which can show its signed-in pages) for visual design (e.g., Anthropic, OpenAI, Google, reached directly or through the OpenRouter routing service, and contractually barred from training on your content), media generation providers (Replicate, fal) engaged only when media generation is enabled for your account, Resend (transactional email), PostHog (product analytics, EU-hosted), and Sentry (error monitoring). We keep this list current as it changes. Polar sells your purchases as our merchant of record and collects applicable taxes; it processes your payment and tax details as an independent controller under its own privacy policy, not on our behalf. We may also disclose information if required by law or valid legal process, to protect the rights, safety, or security of Syndai, our customers, or others, or as part of a merger or sale of assets, in which case this policy continues to apply until you are told otherwise.

6. Data Retention

Live sandboxes are torn down when the run ends. Workspace snapshots and encrypted archives of connected repository content, kept so runs start fast and can recover, are retained while the repository stays connected and deleted on a rolling schedule and on repository disconnection or account deletion. Connected-account content and outreach data are retained while the account stays connected and while needed to perform the work you direct, and deleted on disconnection or account deletion. Run artifacts (prompts, diffs, evidence, logs) are retained while your account is active and deleted on account deletion, subject to the backup window. Website drafts from the instant builder: a draft made without an account is deleted 72 hours after it was made unless you keep it by confirming your email; a kept draft, or one made while signed in, is retained while your account is active. A share link you create stays public for 90 days, or for as long as its draft is kept. Account and billing records are retained while your account is active and afterward as needed for tax, accounting, and legal obligations (typically up to 7 years for financial records). Telemetry and error data are retained on rolling windows (typically 90 days to 12 months). Persistent coding-run memory scoped to you is retained while your account is active to personalize your runs, is never pooled across customers, and is erasable on request and hard-deleted when you delete your account. Deleted data ages out of encrypted backups within a bounded window (target: 30 days). When you delete your account, we delete or irreversibly anonymize your personal information on this schedule unless the law requires longer retention.

7. International Transfers

We are a US company, and our providers process data in the United States and the European Union (PostHog analytics is EU-hosted). Where we transfer personal information from the EEA, the UK, or Switzerland to countries without an adequacy decision, we rely on the European Commission’s Standard Contractual Clauses (and the UK Addendum where applicable), together with supplementary technical measures such as encryption in transit and at rest.

8. Your Rights

You can access and update most account data in the portal, and you can contact privacy@syndai.ai to exercise any right below; we will verify your request, respond within the time the law requires, and never discriminate against you for exercising your rights. Under the GDPR (EEA/UK/Switzerland) you have the rights of access, rectification, erasure, restriction, portability, and objection, the right to withdraw consent, and the right to complain to your supervisory authority. Under the CCPA/CPRA (California) you have the right to know, access, correct, and delete your personal information and to opt out of “sale” or “sharing”: we do not sell personal information. If you live in another US state with a comprehensive privacy law, you have similar rights to access, correct, delete, and receive a copy of your information and to opt out of targeted advertising and any sale or sharing, exercisable at privacy@syndai.ai or through Global Privacy Control; we honor these regardless of your state, and if we deny a request you may appeal by replying to our decision. We do not use or disclose sensitive personal information for purposes requiring a right to limit. Where we process content on behalf of a customer (for example, personal data inside a repository or connected account, or your data because a Syndai customer added you to outreach), direct your request to that customer and we will assist them in fulfilling it.

9. Cookies

We use only essential cookies (session and authentication cookies the Service cannot function without) and first-party analytics cookies (PostHog) that help us understand how the site and product are used. We do not use advertising cookies or cross-site tracking cookies. You can block or clear cookies in your browser; blocking essential cookies will break sign-in. We recognize the Global Privacy Control signal: when your browser sends it, we treat it as a request to opt out of any “sharing” of your personal information.

10. Security and Breach Notification

We use security measures appropriate to what we hold: encryption in transit and at rest, isolated per-run build sandboxes, scoped API keys, least-privilege internal access with audit logging, vulnerability monitoring, and separation between customers’ data and environments. No system is perfectly secure and we cannot guarantee absolute security. If a breach of security affects your personal information, we will notify you and the relevant regulators without undue delay and in accordance with applicable law (including within 72 hours to supervisory authorities where the GDPR requires it), and tell you what happened, what data was involved, and what we are doing about it. Report suspected vulnerabilities to privacy@syndai.ai.

11. Children

The Service is not directed to anyone under 16, and we do not knowingly collect personal information from children under 16. If you believe a child has provided us personal information, contact privacy@syndai.ai and we will delete it.

12. Changes and Contact

We may update this policy from time to time. We will post the updated policy on this page and refresh the effective date, and for material changes we will also notify you by email or in the portal before they take effect. Privacy questions, requests, or complaints: privacy@syndai.ai, or write to Eternex, Inc., 2261 Market Street STE 24499, San Francisco, CA 94114. If you are in the EEA or UK and we cannot resolve your concern, you may contact your local data-protection authority.