Legal

Privacy Policy

How Synthorai handles your data — zero prompt retention by default, GDPR and CCPA alignment, and your privacy rights.

1. Overview

This Privacy Policy explains how Synthorai Technology Inc. ("Synthorai", "we", "us", or "our") handles personal information in connection with the Synthorai platform — our developer API gateway, the associated web console, marketing website, and related services (together, the "Services"). It applies whether you browse our site, create an account, top up a balance, generate API keys, or route requests through the gateway to third-party model providers.

The Services let developers send requests to large language and multimodal model providers through a single, OpenAI-compatible interface. This policy describes the information we handle in that context and the choices you have. It does not cover the practices of the upstream model providers you choose to call, the payment processor that handles your card details, or any third-party website you reach through a link from our Services; those are governed by their own privacy notices.

Where a specific product, region, or interaction is subject to additional terms, a supplemental notice may apply in addition to this policy. In case of conflict, the supplemental notice controls for that context.

2. Who We Are

Synthorai Technology Inc., based in Mountain View, California, provides the Services and is responsible for the personal information handled through them. For privacy questions or requests, you can reach us using the details in the "Contact Us" section below.

3. What Information Do We Collect

The information we collect depends on how you interact with us — whether you use the marketing site, create an account, make payments, or send requests through the gateway. We group it by how it reaches us.

Information You Provide Directly

When you create an account we collect account and identity information such as your name and email address and, where you sign in through a third-party identity provider, the associated identifier. When you add funds we collect billing and transaction information; your card details are collected and processed directly by our payment processor and are not stored on our systems. If you choose to bring your own provider keys, we store those credentials in encrypted form so we can route your requests to your chosen provider on your behalf. When you contact support, respond to a survey, or submit feedback, we collect the information in those communications.

Content You Send Through the Gateway

The core purpose of the Services is to route your requests to the AI model providers you select. To do this we process the content of those requests and the responses returned — this includes the text of your prompts, and, depending on the model, audio you submit for speech-to-text, images you submit or that are generated, and the model's outputs (together, "Content"). We handle Content only to route it to your chosen provider and return the result to you.

On our own systems, Content is processed on a zero-retention basis by default: we do not store the body of your prompts, uploads, or the responses returned once the request has been served. The one exception is our optional, workspace-level debug logging: only if you explicitly enable it do we retain Content for a short, time-limited window (currently up to 30 days) so you can troubleshoot, and you can purge those logs at any time. Separately, and regardless of that setting, we always record non-content operational metadata about each request — such as the model called, token counts, computed cost, timestamps, and the workspace involved — which we use for billing, security, and reliability. We do not use your Content to train or improve any machine-learning models.

Other Information Automatically Collected

When you use the Services, we also automatically collect technical information such as your IP address and browser or device characteristics, and we use cookies and similar technologies as described in the "Cookies and Similar Technologies" section.

Information From Other Sources

We may receive limited information from the providers and partners that help us operate the Services, such as confirmation of a payment from our payment processor, or a referral identifier when you arrive through a referral link. We do not purchase personal information from data brokers.

4. How Do We Use Your Information

We use personal information to provide, secure, and improve the Services, and only as permitted by applicable law. How we use it depends on how you interact with us.

Providing and Operating the Services

We use your account, billing, and usage information to authenticate you, maintain your workspace and balance, route your requests to the model providers you select, meter and bill usage accurately, and provide customer support. Where you bring your own provider keys, we use them solely to fulfil the requests you direct to those providers.

Security, Fraud Prevention, and Reliability

We use technical and usage information — including IP address and request metadata — to keep the Services secure and reliable, enforce rate limits, detect and prevent abuse or fraud, and troubleshoot problems. We also use an approximate, region-level location derived from your IP address to present the correct privacy choices for your jurisdiction.

Analytics and Improvement

Subject to your choices, we use analytics to understand how the Services are used so we can improve them. Our analytics are configured for measurement only, without advertising features. If you opt in to time-limited debug logging, we use the logged content only to diagnose issues.

Communications and Marketing

We use your contact details to send service and account messages, respond to your requests, and — where permitted and subject to your preferences — send product updates. You can opt out of non-essential messages at any time.

Legal and Compliance

We use personal information as needed to comply with legal, tax, and regulatory obligations, to enforce our terms, and to establish, exercise, or defend legal claims.

5. Cookies and Similar Technologies

We and a limited set of service providers use cookies and similar technologies to operate the Services, remember your preferences, keep you signed in, secure your session, and — subject to your consent where required — measure how the Services are used. Some of these technologies are strictly necessary for the Services to function; others are optional.

Whether optional technologies are used, and whether your consent is required first, depends on your region. In the European Economic Area, the United Kingdom, Switzerland, and California, optional cookies are off until you opt in; elsewhere they are on by default and you may opt out. You can review and change your choices at any time through the "Your Privacy Choices" control available on our pages, and you can also control cookies through your browser settings. We honor Global Privacy Control (GPC) and similar opt-out preference signals for visitors in the United States. For the specific technologies we use and their purposes, see our Cookie Policy.

6. Who Do We Share Your Information With

We share personal information only as described here. We do not sell your personal information.

We share information with service providers that process it on our behalf and under contract — including our payment processor, cloud hosting provider, authentication provider, email and notification provider, and analytics provider — so they can perform services for us.

Model providers. To fulfil your request, the Content you send (your prompt text, and any audio or images) is transmitted to the AI model provider you select — for example OpenAI, Anthropic, or Google — which processes it to generate a response. You direct this transfer when you choose a provider and send a request; it is inherent to using the gateway. Each provider handles that Content, including how long it retains it and whether it uses it to improve its models, under its own terms and privacy policy, which we do not control; we encourage you to review the policies of the providers you use. Where a provider offers zero-retention or limited-retention processing, we use those terms where available, but the provider's handling ultimately governs. If you use "bring your own key" (BYOK), your Content is sent to that provider under your own account and agreement with them. Our own zero-retention posture described above applies to Synthorai's systems and does not extend to the independent providers you choose to call.

We may also disclose information to comply with law or valid legal process, to protect the rights, safety, and security of Synthorai, our users, or the public, and in connection with a merger, acquisition, financing, or similar corporate transaction, subject to appropriate confidentiality protections.

7. International Transfers

Synthorai operates from the United States, and we and our service providers may store, access, or process personal information in countries other than the one in which you are located. Those countries may have data-protection rules that differ from those in your home country.

Where we transfer personal information from the European Economic Area, the United Kingdom, or Switzerland to a country that has not been recognized as providing an adequate level of protection, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable), together with contractual and organizational measures. When you route a request to a model provider located outside your region, that transfer is made at your direction and as necessary to perform the service you requested. You can contact us using the details below for more information about these safeguards.

8. How Long Do We Keep Your Information

We keep personal information only for as long as necessary to fulfil the purposes described in this policy, and for as long as permitted or required by applicable law. Different types of information are kept for different periods depending on the context.

In deciding how long to keep information, we consider factors such as whether we still need it to provide the Services or perform our contract with you, your most recent activity, and our legal, tax, accounting, audit, or regulatory obligations, as well as the need to resolve disputes or enforce our agreements. As a general matter, account information is retained for the life of your account and for a limited period afterward, billing and transaction records are retained for the period required by tax and accounting rules, and operational and technical logs are retained for shorter periods. Request and response content is not retained unless you opt in to time-limited debug logging, in which case it is kept only for the short window of that logging. When information is no longer needed, we delete, anonymize, or de-identify it where permitted by law. You can contact us for more detail about retention.

9. How Do We Keep Your Information Secure

We maintain administrative, technical, and physical safeguards designed to protect the confidentiality, integrity, and availability of personal information, taking into account the nature of the information and the risks involved. These include measures such as encryption, access controls, and authentication, together with monitoring and vendor-management practices.

No method of transmission over the Internet or method of storage is completely secure, so while we work to protect your information we cannot guarantee its absolute security.

10. Your Privacy Rights and Choices

Depending on your location and subject to applicable law, you may have rights over your personal information, such as the right to access it, to correct or update it, to delete it, to withdraw consent where our processing is based on consent, and to object to or restrict certain processing. You can also manage your marketing and cookie choices at any time.

To exercise a right, contact us using the details in the "Contact Us" section; we may need to verify your identity before acting on a request. You can manage cookie and tracking choices through the "Your Privacy Choices" control on our pages or your browser settings, and you can opt out of non-essential emails using the link in those messages. We will not treat you unfairly for exercising your privacy rights. Depending on where you live, you may also have the right to lodge a complaint with your local data-protection authority.

11. Children's Privacy

The Services are intended for developers and businesses and are not directed to individuals under 18, and our Terms of Use require account holders to be at least 18. We do not knowingly collect personal information from children under the age of 16, or under the age otherwise defined by applicable law. If we become aware that we have collected personal information from a child without appropriate consent, we will take reasonable steps to delete it. A parent or guardian who believes a child has provided us with personal information may contact us using the details below.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in technology, our practices, or legal and regulatory requirements. The latest version will always be published on our website with an updated "Last Updated" date. Where a change is material, we will provide additional notice as appropriate — for example through a notice on our website, an in-product message, or email — and, where required by law, obtain your consent.

13. Contact Us

If you have any questions about this Privacy Policy or how we handle your personal information, you can contact us at dpo@synthorai.ai.

Supplemental Information for Residents of Certain U.S. States (including California)

This section provides additional disclosures for residents of California and other U.S. states with comprehensive privacy laws. It supplements, and does not replace, the rest of this policy. Terms such as "personal information", "sale", and "share" have the meanings given in the applicable state law.

In the preceding twelve months, we collected the categories of personal information described in the table below, from the sources and for the business or commercial purposes indicated. We do not sell personal information, and we do not "share" personal information for cross-context behavioral advertising: our analytics are configured for measurement only, with Google signals disabled and Restricted Data Processing enabled, so that our analytics provider does not use the data for its own advertising purposes. When you route a request, the Content you send is transmitted to the model provider you select at your direction to fulfil that request; a disclosure made at your direction is not a sale or share.

Category of Personal InformationSourcesBusiness or Commercial PurposesCategories of Recipients (Business Purpose)Sold / Shared
Identifiers (e.g., name, email, account and referral identifiers, IP address)You; your device; identity provider; referral linksProvide and secure the Services; account management; communications; fraud preventionAuthentication, hosting, email, and analytics providersNo
Commercial information (top-ups, balances, transaction and usage records)You; payment processor; your use of the gatewayBilling and metering; support; compliancePayment processor; hosting providerNo
Internet or network activity (usage metadata, log and diagnostic data)Automatically from your use of the ServicesSecurity, reliability, analytics, and improvementHosting and analytics providersNo
Geolocation (approximate, region-level, derived from IP)Automatically from your IP addressPresent the correct privacy choices; securityHandled internallyNo
Account access credentials (sensitive personal information)YouAuthenticate you and secure your account onlyAuthentication providerNo
Content sent through the gateway and other content you submit (prompts, audio, images, support, feedback)YouRoute requests to your selected model provider and return the result; respond to you; diagnose issues you reportThe AI model provider you select; hosting providerNo

Account access credentials are the only category we treat as sensitive personal information, and we use them solely to authenticate you and secure your account — a purpose for which the law does not require a separate "right to limit" option, so we do not offer one.

Subject to applicable law, you may have the right to know and access the personal information we have collected, to request its deletion or correction, and to opt out of any sale or sharing of personal information. To exercise these rights, contact us at dpo@synthorai.ai; you do not need to create an account to submit an opt-out request. We may ask for information needed to verify your request, and you may use an authorized agent where the law permits. We honor Global Privacy Control (GPC) and similar opt-out preference signals as a valid request to opt out of sale and sharing for U.S. visitors, and we provide a "Your Privacy Choices" control on our pages. Where your state provides a right to appeal a decision on your request, you may do so by contacting us at the same address. We will not discriminate against you for exercising your rights.

Supplemental Information for Residents of the EEA and UK

This section provides additional information for individuals in the European Economic Area, the United Kingdom, and Switzerland, and supplements the rest of this policy. For the processing described here, the data controller is Synthorai Technology Inc., contactable at dpo@synthorai.ai. Where you use the Services to process personal data for which you are the controller — for example, personal data contained in the requests you submit — we act as your processor for that data, and a data processing addendum (DPA) is available on request at dpo@synthorai.ai.

We process personal information on the legal bases appropriate to each activity: to perform our contract with you (for example, to operate your account, route your requests, and bill usage); for our legitimate interests (for example, to secure the Services, prevent fraud, and improve our products), balanced against your rights; to comply with legal obligations (for example, tax and accounting record-keeping); and on the basis of your consent where we ask for it (for example, for optional analytics cookies and opt-in debug logging), which you may withdraw at any time without affecting processing carried out before withdrawal.

Subject to the conditions in the GDPR and UK GDPR, you have the right to access your personal data and to rectification, erasure, restriction, portability, and objection, as well as the right to withdraw consent and to lodge a complaint with your supervisory authority. Where we transfer personal data outside the EEA, the UK, or Switzerland, we rely on appropriate safeguards such as the Standard Contractual Clauses, as described in the International Transfers section. We use automated processes to detect fraud and abuse and to keep the Services secure; we do not make decisions producing legal or similarly significant effects concerning you based solely on automated processing without a means to request human review.