The General Data Protection Regulation gives people in the European Economic Area and the United Kingdom clear rights over their personal data, and puts clear duties on companies that handle it. This page is the plain version of how Synis meets those duties. The Privacy Policy describes what we collect in general; this page is about the law and your rights.
Who is responsible
Synis, based in Tirana, Albania, is the controller of the personal data described here: the data about you as a person who visits the site or holds an account. For the content inside your workspace, such as customer names you type into a post, you are the controller and Synis processes it on your instructions.
Data protection questions and requests go to [email protected]. We answer within one month, as the law requires, and usually much sooner.
What we process and why
We only process personal data when the law gives us a reason to. These are the reasons we rely on:
- To provide the service you signed up for (contract): your name, email address, password hash, workspace membership, the brand details and content you create, and the tokens for the social accounts you connect.
- To make the content you ask for (contract): the brief you type, the brand details you set, and the files you choose, built into a prompt and sent to the AI providers listed under Who helps us, only to produce that result. Examples from a reference library we curate are added as style references; they are not your data.
- To tailor your generations to your brand (legitimate interest): your workspace's recent posts, their performance figures, and what the brand has learned from your edits and feedback, added to each prompt. The interest is results that sound and look like your brand and build on what has worked for it. The data is used only for your own workspace's generations, never for another customer and never to train AI models. It is on by default because it is what the service is for, and you can object at any time, as described under Your rights. For personal data of other people inside your workspace, such as a customer named in a post, you are the controller, and the switch is how you instruct us.
- To keep the service secure and running (legitimate interest): short-lived counters of sign-in and other public requests, keyed by IP address and by a one-way digest of the email address, deleted within minutes; request logs with a request ID, method and route, without IP addresses; and the history of who requested, approved or asked for changes to each post.
- To understand how the service is used and improve it (legitimate interest): product usage events our servers send to PostHog for every account, covering sign-ups, whether a job finished or failed, and what each AI request cost. They are keyed by account or workspace identifier and never include your content. You can object to this, as described under Your rights.
- To bill you (contract and legal obligation): your plan, invoice history, and a customer reference at our payment processor. Card numbers never reach us.
- To write to you about things you asked for (consent): the waitlist and any product news you opt into. You can withdraw consent at any time, from the email itself.
- To measure how the site is used in your browser (consent): the pages you view, only if you turn on analytics at Cookies. Turning it off stops it.
We do not profile you, we do not make automated decisions with legal effect about you, and we do not sell personal data to anyone.
Where your data lives
Our database is self-hosted on our own infrastructure, and uploaded files sit in S3-compatible object storage. Requests reach us through Cloudflare's edge network. Where any of this sits outside the EEA, personal data from the EEA is transferred outside it, and for those providers we rely on the European Commission's Standard Contractual Clauses, or on the provider's certification under the EU-US Data Privacy Framework, so the data keeps the protection it had at home. Our AI provider, Runware, runs generations on servers in the United States, Germany and Romania, so a prompt can also leave the EEA while your content is being made. If you would rather your data stayed in the EU, tell us: an EU region is on our roadmap and your request helps us set its priority.
Who helps us
These companies process personal data on our behalf. Each works under a contract with us to use it only to provide its service to us, except the AI model developers, which work under their own agreements with Runware.
- Cloudflare: fronts every request at the edge, and so processes your IP address before it reaches us.
- Polar: payments, invoices and subscription management.
- Our mail provider: the emails the service sends, such as sign-in and invitations.
- Runware (AI generation): runs the models that write and design your content. It receives each prompt, which can include your brief, brand details, recent posts and their performance figures, and the images the result needs, and returns the result.
- AI model developers, through Runware: Runware passes each prompt to the developer of the model that runs it, currently among OpenAI, Google, Anthropic, Black Forest Labs, ByteDance and Kling AI. They process it to produce the result, under their agreements with Runware.
- Zernio: publishing to Instagram, Facebook and TikTok. It receives the posts you approve for publishing there.
- Our object storage host: the pictures and files you upload or generate.
- PostHog (EU region): product analytics. It receives the usage events our servers send for every account, and browser analytics only if you turn it on at Cookies (off by default).
- The social platforms you connect: they receive the posts you approve for publishing, under their own terms.
We do not use your content to train AI models. Runware's published terms promise not to train on data you upload to customise a model, but do not yet say the same for ordinary generation requests, or for the model developers it works with. Until they do, we do not make that promise on their behalf, and we will update this page if that changes.
We update this list when a provider changes. Business customers can ask for our data processing agreement, which includes it, at [email protected].
How long we keep it
- Account and workspace data: for as long as the account is active. When you delete your account or a workspace it closes at once, can be restored for 30 days from the link we email you, and is then permanently deleted, with personal data deleted or anonymised.
- Content you delete yourself: removed from the live service straight away into Trash, where you can restore it for 30 days. Then it is permanently deleted, and removed from backups within 30 days after that.
- Invoices and billing records: as long as accounting law requires, then deleted.
- Server logs: rotated by size, typically within a few weeks.
- Social account tokens: encrypted while the account is connected, deleted the moment you disconnect it.
Your rights
You can ask us, at any time and for free, to:
- See the personal data we hold about you, and get a copy.
- Correct anything that is wrong or out of date.
- Delete your data, where we have no legal duty to keep it.
- Take it with you, in a machine-readable file you can give to another service.
- Restrict or object to processing that rests on our legitimate interests.
- Withdraw consent for anything that rests on consent, without affecting what came before.
Your right to object to personalisation. You can object at any time to your workspace history being used to personalise generations. An owner or admin does it in the product: under Settings, then Workspace, turn off "Use my workspace history to personalise generations". It applies from the next generation. From then on prompts are built only from your brief and the brand details you set, without your past posts, their performance figures or learned brand history, so results will be less tailored to your brand. Nothing is deleted, and you can turn it back on whenever you like. If you are not an owner or admin, write to us and we will pass your objection to the workspace owner.
Send the request to [email protected] from the email address on the account, so we know it is you. Deleting your account or a workspace is self-serve, from account settings. Export is handled by a person, within a month, until it is self-serve too.
If you believe we have handled your data unlawfully, you also have the right to complain to a data protection authority: the one in the EU or UK country where you live, or Albania's Information and Data Protection Commissioner. We would rather hear from you first, and fix it.
How we protect it
Every connection is encrypted in transit. Passwords are stored only as salted hashes. Social account tokens are encrypted at rest with AES-256-GCM. Each workspace is isolated at the database level, so one customer's data can never be read through another's account. Access by our own team is limited to what support needs.
If something goes wrong
If a breach puts your rights at risk, we will tell the relevant authority within 72 hours and tell you without undue delay, with what happened, what it means for you, and what we are doing about it.
Changes
We update this page when our providers, locations or practices change, and we note the date at the top. Material changes are announced to account holders by email.
Questions? Email [email protected].
Cookies