// Legal
Privacy Policy
This policy explains what Synthic collects when you use Synthic, why we collect it, who we share it with, and the choices you have. We've written it to be read, not skimmed past.
Last updated: August 30, 2026
01Who we are
Synthic is an AI search visibility platform operated by Synthic (“Synthic,” “we,” “us”). We are the data controller for personal data processed through the Service, except where we act as a processor on your behalf (see section 4).
Contact us about privacy at support@usesynthic.com.
02What we collect
Information you give us
- Account data: email address, password hash (we never see your password in plain text), and, if you sign in with Google, your Google account email, name, and profile image.
- Workspace and brand data: workspace names, brand names, domains, keywords, and competitor names you enter.
- Billing data: handled by Stripe. We store your Stripe customer ID, plan, subscription status, and renewal date. We never receive or store your full card number.
- Support communications: anything you send us by email.
Information we generate for you
- Audit results: the prompts we send to AI engines, the verbatim responses those engines return, and the scores, citations, competitor mentions, and confidence readings we compute from them.
- Crawl data: publicly available content retrieved from the websites you ask us to analyze.
- Usage and audit-trail records: which features were used, by which workspace member, and when — used for billing limits, security, and support.
Information collected automatically
- Technical data: IP address, browser type, device type, pages viewed, and timestamps, collected by our hosting provider for security, abuse prevention, and performance.
- Essential cookies: a session cookie that keeps you signed in. It is required for the Service to function and is not used for advertising.
We do not knowingly collect special-category personal data (health, biometrics, political opinions, and similar). Please do not enter such data into brand names, keywords, or prompts.
03How we use it, and our legal bases
- To provide the Service — running audits, storing results, enforcing plan limits. Legal basis: performance of a contract.
- To take payment — processing subscriptions through Stripe. Legal basis: performance of a contract.
- To secure the Service — detecting abuse, debugging, maintaining audit trails. Legal basis: legitimate interests.
- To communicate with you — service notices, security alerts, and billing messages. Legal basis: performance of a contract or legitimate interests.
- To improve the Service — aggregate, de-identified analysis of feature usage. Legal basis: legitimate interests.
- To meet legal obligations — tax, accounting, and lawful requests. Legal basis: legal obligation.
We do not sell your personal data, and we do not share it with advertisers or data brokers. We do not use your content to train our own machine-learning models.
04Your content and the AI engines
This is the part most specific to Synthic, so we want to be plain about it. To measure how AI engines describe your brand, the Service sends prompts containing your brand name, domain, and keywords to third-party AI providers over their APIs, and stores the responses those providers return.
Those prompts are generally not personal data — they are brand and product terms. But if you enter personal data into a brand name, keyword, prompt, or competitor field, that data will be transmitted to the AI providers listed in section 5 and handled under their terms. Please do not enter personal data into those fields.
We send this data through each provider’s business or developer API. At the time of writing, the providers we use state that data submitted through these APIs is not used to train their models by default, but their terms are theirs to change and we cannot warrant them. If that matters to your organization, review each provider’s terms directly, or use the bring-your-own-key feature so requests run under your own account and your own agreement with that provider.
Where you use Synthic to process data about your own customers or employees, you are the controller and we act as your processor, handling that data only to provide the Service and on your instructions.
05Who we share data with
We share data only with service providers who help us run Synthic. Each is bound by contract to protect it and to use it only for the services they provide to us.
- Supabase — database, authentication, and storage.
- Vercel — application hosting and edge delivery.
- Stripe — payment processing, subscription billing, and, where enabled, tax handling as merchant of record.
- AI answer engines — OpenAI, Google, Anthropic, Perplexity, and xAI, which receive audit prompts and return the responses we measure. Which of these are used depends on your plan and configuration.
- Google — if you sign in with Google, or connect Google Search Console or Google Analytics.
- Optional providers you enable — such as web-search, crawling, email-delivery, and SEO-data providers used to power specific features.
We may also disclose data if required by law, to enforce our terms, to protect the rights and safety of any person, or in connection with a merger, acquisition, or sale of assets — in which case we will give you notice before your data becomes subject to a different policy.
06International transfers
Synthic is operated from the State of California, United States, and our providers operate globally, so your data may be processed in countries other than your own, including the United States. Where we transfer personal data out of the UK, EEA, or Switzerland, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses, or the provider’s certification under an approved framework.
07How long we keep it
- Account and workspace data — for as long as your account is open.
- Audit results and stored engine responses — until you delete the brand or workspace, or close your account.
- Billing records — up to seven years, as tax and accounting law requires.
- Security and audit-trail logs — typically up to twelve months.
When you close your account we delete or de-identify your personal data within 90 days, except where we must keep it to meet a legal obligation, resolve a dispute, or enforce our agreements. Backups are purged on their normal rotation.
08Your rights
Depending on where you live, you may have the right to access, correct, delete, port, or restrict processing of your personal data, to object to processing based on legitimate interests, and to withdraw consent.
If you are in the EEA, UK, or Switzerland (GDPR): you may exercise these rights at any time and may lodge a complaint with your local supervisory authority.
If you are a California resident (CCPA/CPRA): you have the right to know what we collect, to delete it, to correct it, and to opt out of sale or sharing. We do not sell or share personal data as those terms are defined, and we will not discriminate against you for exercising any right.
To exercise any right, email support@usesynthic.com. We will respond within the period the applicable law requires — generally 30 days — and may need to verify your identity first. You can also delete most data yourself from the dashboard at any time.
09Security
We protect data in transit with TLS and at rest with our providers’ encryption. Access is restricted by row-level security so workspace members see only their own workspace’s data. Any API keys you store are encrypted before they reach our database, and are never shown again after saving. Administrative access is limited to personnel who need it.
No system is perfectly secure, and we cannot guarantee absolute security. If a breach affects your personal data, we will notify you and the relevant regulators as the law requires.
10Children
Synthic is a business tool and is not directed to anyone under 16. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.
11Changes to this policy
We may update this policy as the Service evolves. We will change the “last updated” date above, and for material changes we will give notice by email or in the app before they take effect. Continuing to use Synthic after a change means you accept the updated policy.
12Contact
Questions, requests, or complaints: support@usesynthic.com. We answer privacy enquiries from the same address.
See also our Terms of Service.