This policy explains what information Synis ("we", "us") collects when you use the Synis website, apps and services (the "Service"), what we do with it, and the choices you have. It is written to be read, not skimmed. If anything is unclear, ask us.
Information we collect
- Account data: your name, email address and password, stored only as a salted hash, plus the workspaces you belong to and your role in each.
- Content you provide: your brand details, writing samples, briefs, uploaded photos and logos, and the posts, pictures, emails and campaigns you make with the Service.
- Website imports before sign-up: if you give us your website address before creating an account, we fetch that site's publicly available pages, logo and colours to show you a brand preview, and we keep the address and what we found for 24 hours, deleting them then unless you create an account, when they become part of your brand details.
- Connected accounts: when you link a social platform, the access token and basic profile details needed to publish on your behalf. Tokens are encrypted at rest.
- Your posts and how they performed: the posts published through the accounts you connect, and their performance figures such as impressions, reach, clicks, likes, comments, shares and saves. These figures are counts, not the people behind them.
- Comments and messages: the comments on your posts and the messages sent to the accounts you connect, with the sender's name and handle, so you can read and answer them in your inbox.
- Billing data: handled by Polar. We keep your plan, your subscription status and a customer reference. Your card number never reaches our servers.
- Usage and device data: request logs with a request ID, method and route (no IP address), and short-lived counters of sign-in and other public requests keyed by IP address, used to run and secure the Service. We run no advertising trackers.
- Product usage events: that you signed up, that a job such as a generation finished or failed, and what each AI request cost. Each event is keyed by your account or workspace identifier and carries only details like the sign-up method, the job type and outcome, and the AI provider, model and cost, never your content. Our servers send these events to PostHog whether or not you turn on browser analytics, so we can see how the Service is used and improve it.
- Browser analytics: the pages you view, recorded in your browser by PostHog only if you turn it on at Cookies. It is off by default.
- Messages: what you send to support or leave on the waitlist.
How we use it
- to provide, maintain and improve the Service;
- to make the content you ask for: we build a prompt from your brief and brand details and send it, with any images it needs, to the AI providers listed below;
- to tailor that content to your brand, unless you turn personalisation off: we add your recent posts, how they performed, and what the brand has learned from your edits and feedback;
- to publish to the accounts you connect, when you tell us to;
- to take payment and manage your subscription;
- to keep the Service secure, prevent abuse and meet legal duties;
- to write to you about your account and important changes.
The legal reasons behind each of these, for people in the EEA and the UK, are set out on the GDPR page.
Who we share it with
We share the minimum needed with companies that help us run the Service. Each works under a contract with us, except the AI model developers, which work under their own agreements with Runware:
- Runware: AI text, image and video generation. It receives each prompt we build and the images it needs, and runs it on servers in the United States, Germany and Romania.
- AI model developers, through Runware: the company whose model runs a prompt, currently among OpenAI, Google, Anthropic, Black Forest Labs, ByteDance and Kling AI. They receive the prompt from Runware only to produce the result.
- Cloudflare: fronts every request at the edge, and so processes your IP address before it reaches us.
- Polar: payments and subscription management.
- Our mail provider: the emails the Service sends you, such as security alerts, verification links, invitations and activity notifications.
- Our object storage host: the files and pictures you upload or generate.
- PostHog (EU region): product analytics. It receives the product usage events described above and, only if you turn it on, browser analytics.
- Zernio and the social platforms you connect: publishing the posts you approve, and fetching how they performed.
We never sell personal information. We disclose it only if the law requires it, or to protect the rights and safety of Synis, our users or the public.
Your content and AI
Each time you generate something, we build a prompt for an AI model and send it through Runware. What goes into the prompt:
- Always: the brief you type, the brand details you set (such as name, industry, tone, colours, rules, goals and logo), and the files you choose for that result.
- Unless personalisation is off: your workspace's recent posts, their performance figures, and what the brand has learned from the edits and feedback in your workspace. This is what makes results sound and look like your brand.
- Reference designs: examples from a library we curate, used as style and structure references. They are not your data and never include another customer's content.
All of this is used only for your own workspace's generations. It is never used for another customer, and the edits you make stay inside your workspace.
We do not use your content to train AI models. Runware's published terms promise not to train on data uploaded to customise a model, but they do not yet make that promise for ordinary generation requests, or for the model developers Runware works with, so we cannot make it on their behalf. We will update this page if that changes. Runware keeps generated files for a limited time, seven days by default.
Turning personalisation off. A workspace owner or admin can turn off "Use my workspace history to personalise generations" under Settings, then Workspace. From the next generation, prompts use only your brief, the brand details you set and the reference designs; your past posts, their performance figures and learned brand history are left out. Results will be less tailored to your brand, and every signed-in page shows a reminder until you dismiss it. Nothing is deleted, and you can turn it back on at any time.
Cookies
The site sets up to three cookies: one that keeps you signed in, one that holds a website import you start before signing up, and one that remembers your cookie choice. If you turn on browser analytics, PostHog sets one more, to recognise you between page views. There are no advertising cookies. The full list, and the switches, are on the Cookies page.
Where your data is stored
Our database and file storage are hosted in the United States. If you are in the EEA or the UK, that is a transfer outside your region. We rely on Standard Contractual Clauses, or the provider's Data Privacy Framework certification, to keep the same protection in place. Runware, our AI provider, runs generations in the United States, Germany and Romania. Details are on the GDPR page.
How long we keep it
For as long as your account is active, and then long enough to close it properly. When you delete content, a workspace or your account, it leaves the live Service at once and stays recoverable for 30 days, from Trash or from the link we email you. For a deleted account, workspace or brand we send a reminder with that link each week, which you can stop from the reminder, and every day in the last week. After those 30 days it is permanently deleted, and it leaves our backups within 30 days after that. When you delete your account we delete or anonymise your personal data once its 30-day recovery window ends, except records the law makes us keep, such as invoices. Server logs are rotated by size, typically within a few weeks.
Your rights and choices
You can ask to see, correct, export or delete your personal data, and to object to or restrict certain uses of it. Write to [email protected] from the address on your account and we will answer within a month. You can disconnect any social account and cancel your subscription at any time from your settings. Marketing emails have an unsubscribe link in every message.
Emails about your account. We email you security alerts when your account is signed in to or its sign-in methods change, showing the time, IP address and browser involved, along with billing and account notices and activity emails about publishing, approvals, your team and autoposting. Security, billing and account emails are always sent. Activity emails can be turned off, and autoposting emails received as a daily summary, under Settings, then Account, then Email, and every activity email has a one-click unsubscribe link. A queued email, with the IP address and browser shown in it, is kept for up to 7 days after it is sent.
Your right to object to personalisation. You can object at any time to your workspace history being used to personalise generations. A workspace owner or admin does it by turning off "Use my workspace history to personalise generations" under Settings, then Workspace, and it takes effect from the next generation. Anyone else can write to [email protected] and we will pass it to the workspace owner. What turning it off changes is set out under Your content and AI.
Security
Every connection is encrypted in transit. Passwords are hashed, social account tokens are encrypted at rest, and every workspace is isolated at the database level so no customer can reach another's data. No system is perfectly secure, and if a breach ever affects you we will tell you promptly and plainly.
Children
The Service is for people running a business and is not directed at anyone under 18. We do not knowingly collect their data, and we delete it if we learn we have.
Changes
We update this policy when our practices change and note the date at the top. If a change matters to you, we will say so by email before it takes effect.
Contact
For any privacy question or request, email [email protected]. We are based in Tirana, Albania.
Questions? Email [email protected].
Data protection (GDPR)