Privacy Policy
Last updated: August 22, 2026
0. Who is responsible for your data
The data controller for everything described below:
Company registration details are being finalised and will be published here. Until then, reach us at support@syntfluence.com — we answer every message.
1. What we collect
- Account data — email, optional name, hashed password (bcrypt; we never see or store the plain password).
- Usage records — your generations (prompts, settings, resulting files), token ledger and payment records. These exist so your balance is correct and your history is yours to see.
- Session cookie — a single cookie that keeps you signed in. No advertising trackers, no analytics cookies.
- Interaction statistics — where clicks land on a page, how far it was scrolled and how long it stayed open, so we can tell which parts of the product confuse people. We record positions only — never the text on your screen, never what you type, never your files. Nothing is stored on your device for this, and visitors are counted with an anonymous code that is regenerated every day, so it cannot follow anyone from one day to the next.
2. What we do with it
We run the service. That is the whole list: authentication, generating what you asked for, accounting for tokens, sending transactional email (password reset, receipts). We do not sell data, we do not run ads, and we do not use your content or prompts to train models.
2b. Our legal basis (GDPR Art. 6)
- Performance of a contract — your account, your generations, your token balance and your subscription. Without this data there is no service to give you.
- Legal obligation — invoices and payment records, kept because tax law says so.
- Legitimate interest — keeping the service secure and fixing what confuses people (the anonymous interaction statistics above). You can object to this at any time and we will stop.
- Consent — marketing email only. One click in any such message unsubscribes you, and it never affects your account.
3. Third parties that process data
- AI providers — your prompts and reference files are sent to the generation provider strictly to produce what you requested.
- Email — transactional messages go through Resend.
- Payments — handled by our payment processor as merchant of record; we never see your card number.
3b. Where your data goes (transfers outside the EU)
Some of the companies above are based in the United States, so your data reaches them there. Those transfers rely on the EU–US Data Privacy Framework where the provider is certified under it, and otherwise on the European Commission’s Standard Contractual Clauses (Decision 2021/914), which we have in place with each of them.
We send AI providers only what is needed to produce what you asked for, and we do not licence your prompts or files to anyone for training.
4. Retention and deletion
- Account and generated files — for as long as your account exists. Write to us to have the account and its files deleted, and we do it within 30 days.
- Invoices and payment records — 10 years, because accounting law requires it. These survive account deletion; that is a legal obligation, not a choice.
- Interaction statistics — 14 months, then deleted automatically. They are anonymous, so they cannot be traced back to you anyway.
- Sessions and security logs — 90 days.
5. Your rights (GDPR Art. 15–22)
You have the right to get a copy of your data, correct it, have it deleted, receive it in a portable format, restrict how we use it, and object to processing based on legitimate interest. Where processing rests on consent, you can withdraw it at any time without affecting what happened before.
One email is enough: support@syntfluence.com. We answer within one month, free of charge. We will never make you justify a deletion request.
If you think we have handled your data badly, you can complain to your national data protection authority. In Romania that is the ANSPDCP; elsewhere in the EU, the authority where you live.
5b. No automated decisions about you
The service generates content with AI, but nothing here makes automated decisions that affect you legally or similarly significantly, and we do not profile you.
6. Security
Passwords are hashed, sessions are server-side, traffic is encrypted in transit, and provider API keys never leave the server. No system is perfect; if a breach affects your data we notify you without undue delay.