Legal

Privacy Policy

Effective date: 12 July 2026

Synaptor processes account information, API usage, creative briefs, reference assets, and generated media to provide its creative-media generation platform.

This policy distinguishes data Synaptor controls for its own business from data it processes on behalf of platform customers.

1. Scope and our role

This Privacy Policy explains how Synaptor collects, uses, shares, retains, and protects personal data when you visit the website, use the portal or APIs, submit generation jobs, receive support, or otherwise interact with the Services.

Synaptor acts as a Data Fiduciary for account, website, billing, security, and direct relationship data for which it determines the purpose and means of processing. When a business customer submits personal data about its own users or subjects in Customer Content, Synaptor generally processes that data on the customer's documented instructions as a processor. The customer remains responsible for its own notices, permissions, and lawful basis.

2. Personal data we collect

  • Account data: name, business email, organisation, role, account identifiers, and password hashes.
  • Customer Content: prompts, briefs, uploaded images or audio, reference assets, likenesses, character descriptors, metadata, and generated outputs.
  • API and usage data: tenant and key identifiers, job IDs, request parameters, model and quality choices, timestamps, usage, errors, rate-limit events, and webhook URLs.
  • Technical data: IP address, browser and device information, session data, authentication events, security logs, and diagnostic records.
  • Billing data: credit balance, purchases, invoices, payment status, tax information, and transaction history. Payment providers may collect card or bank details directly.
  • Communications: support requests, feedback, survey responses, and business correspondence.

3. How we obtain data

We receive data directly from you, your organisation's administrators, your applications through the API, your authorised users, service providers, and automatically from use of the Services. A customer may also submit data about other people, including people shown or heard in reference media. That customer is responsible for having authority to do so.

4. Why we process personal data

We process personal data to:

  • create and administer accounts, tenants, sessions, and API credentials;
  • validate briefs, generate media, preserve character continuity, review quality, and deliver results;
  • route jobs to appropriate model, infrastructure, storage, and delivery providers;
  • meter usage, reserve and settle credits, issue invoices, and prevent duplicate charges;
  • provide job progress, webhooks, support, notices, and service communications;
  • protect tenants, investigate abuse, detect incidents, enforce terms, and maintain service reliability;
  • meet legal, tax, accounting, regulatory, and lawful government requirements; and
  • improve reliability, safety, and performance using operational and de-identified insights.

We do not use Customer Content for an unrelated purpose without an additional legal basis, notice, or agreement. Any separate use for model improvement will be disclosed and, where required, based on separate consent or written customer authorisation.

5. Grounds for processing

We process personal data for lawful purposes connected with providing the Services, responding to your requests, protecting the Services, complying with law, and operating our business. Where applicable law requires consent, we request specific and informed consent and provide a reasonably accessible way to withdraw it. We may also process data for uses expressly permitted without consent under applicable law.

6. How we share data

We share data only as reasonably necessary with infrastructure, storage, content delivery, AI model, payment, communications, customer support, security, analytics, and professional service providers. The current model stack may include fal-hosted video and image models, ElevenLabs for music, and language-model routing through OpenRouter. Providers can change as Synaptor routes for quality, reliability, and cost.

We may also share data with your organisation's administrators, in a business transfer, to protect rights and safety, or when required by a valid legal process. We do not sell personal data or share it for third-party targeted advertising.

7. International processing

Synaptor and its providers may process data in India and other countries where infrastructure or model providers operate. We use contractual, technical, and organisational safeguards appropriate to the processing and comply with restrictions or government requirements applicable to transfers of personal data outside India.

8. Retention and deletion

We retain personal data only for as long as needed for the stated purpose, account operation, contract performance, security, dispute handling, and legal compliance. Signed result links normally expire after a short period, but link expiry does not necessarily delete the stored asset. Customer Content and outputs follow the retention period configured for the account or stated in the applicable agreement.

Security and processing logs are retained for legally required minimum periods, including at least 180 days where the CERT-In Directions apply and longer periods when another applicable requirement does. Billing, tax, and transaction records may be kept for statutory recordkeeping. When retention is no longer necessary, we delete or de-identify the data and require processors to do the same, subject to backups and lawful holds.

9. Security

Synaptor uses tenant-scoped authorisation, test/live key separation, access controls, signed webhooks, expiring result URLs, logging, monitoring, backups, and other technical and organisational safeguards designed to protect confidentiality, integrity, and availability.

No system is completely secure. You must protect account credentials, keep API keys server-side, rotate exposed keys, and notify us promptly of suspected misuse.

10. Personal data breaches

We maintain incident response procedures. If a personal data breach occurs, we will investigate, contain, remediate, preserve required records, and notify affected people, customers, the Data Protection Board of India, CERT-In, or other authorities when and in the manner required by applicable law.

11. Your choices and rights

Depending on applicable law and our role, you may request information about processing, access available information, correct or update inaccurate data, request erasure, withdraw consent, nominate another individual, or raise a grievance. Withdrawal does not affect processing already lawfully completed and may prevent us from providing a service that needs the data.

Send a request from your registered business email to support@synaptor.io. We may verify your identity and authority before acting. We respond within the period required by applicable law. You should first use Synaptor's grievance process before escalating a complaint to the Data Protection Board where that process is required.

12. Children

Synaptor accounts and API access are not intended for people under 18. We do not knowingly create accounts for children or direct behavioural advertising to children.

Customers creating family, education, or children's media must obtain verifiable parental or guardian consent and meet all child-safety and notice obligations before submitting a child's personal data, photograph, voice, or likeness. Contact us if you believe child data was submitted without proper authority.

13. Cookies and similar technologies

The portal may use strictly necessary cookies or local storage for login, security, preferences, and session continuity. If optional analytics or marketing technologies are introduced, Synaptor will provide additional notice and choice where required. The API itself does not require browser cookies.

14. Indian data protection framework

This policy is designed around the Information Technology Act, applicable rules and CERT-In Directions, and the Digital Personal Data Protection Act, 2023 and Digital Personal Data Protection Rules, 2025 as their provisions take effect on the notified phased timeline. We will update practices and this notice as additional obligations commence or official guidance changes.

15. Changes and privacy contact

We may update this policy when the Services, providers, or law change. The effective date above shows the latest revision. Material changes will be communicated through the website, portal, or account contact where required.

For questions, rights requests, or grievances about personal data, contact the person responsible for privacy questions at support@synaptor.io.