Privacy Policy.
Synthos handles two kinds of information, and they are not the same thing: data about you, our customer, and data about your customers, which you put into the platform. This page covers both, and is honest about which one we actually control.
We collect the minimum needed to run an account. Material you upload into a workspace is yours — we do not read it for our own purposes, we do not sell it, and we do not train models on it. Model providers process it to return a result and are contractually barred from training on it. You can export or delete a workspace at any time.
1. Who we are
Synthos is operated by John Hrzic. Contact: hello@getsynthos.com. For anything concerning your data specifically, use the same address and put “Privacy” in the subject line.
2. What we collect, and why
Account information
Name, work email, firm name, and — if you sign in with Google — the identity token that confirms the account is yours. We use it to authenticate you, contact you about the service, and bill you. That is all.
Usage and operational records
When a workflow runs we record what ran, when, which steps executed, what was approved or declined, by whom, and what it cost. This is not analytics — it is the audit trail, and it is a core feature rather than a byproduct. It exists so you can prove what happened, and so can we.
Workspace content
Documents you upload, notes in your vault, the criteria you write, and the material your agents produce. This is yours. See section 4.
What we do not collect
- We do not use advertising trackers or third-party analytics that follow you across the web.
- We do not buy data about our own customers from data brokers.
- We do not ask for information we have no use for.
3. Cookies
We use a session cookie to keep you signed in. That is a strictly necessary cookie and has no alternative. We do not use advertising or cross-site tracking cookies. If that changes, this page changes first and you will be asked.
4. Your workspace content — the part that matters
Most of what enters Synthos is not about you. It is a founder’s cap table, a customer’s conversation, a company’s financials. You are responsible for having the right to put it there; we are responsible for what happens to it afterwards.
- Isolation is enforced at the database, not the interface. Every workspace-scoped record carries its workspace, and access rules are checked on the server for every request. Our automated tests assert that a record belonging to another workspace and a record that does not exist are indistinguishable to a caller who should not see it.
- We do not train models on your content, and neither do the model providers we route to. That is a contractual term with them, not a preference.
- We do not read your workspace content for our own purposes. Support access to a specific workspace is a separate, logged action, and we will ask you first except where we are compelled not to.
- Encrypted in transit and at rest.
- Credentials you connect — mailbox tokens, model API keys — are stored server-side and are never returned to a browser, including yours.
5. Data about third parties in your workspace
The section above is about you. This one is about the people whose information you bring into a workspace — a founder who submits a data room, a contact in a list you upload, an investor you ask us to research. Different relationship, different rules, and worth separating rather than blurring.
You decide; we act on that instruction. Where you use enrichment or sourcing features, Synthos retrieves information about people and firms from public sources and licensed providers because you asked it to. You are the controller of that data. We process it for you and for no other purpose.
Every enriched record carries its provenance — which source it came from and when. If someone asks where their information came from, you can answer, and so can we. Most tools in this category cannot.
Sources are:
- Public filings and registries — regulatory records, corporate registries, and similar.
- Public web content — a firm's own site, published writing, public profiles.
- Licensed data providers, under contract, where you have enabled them.
We do not buy bulk personal data for our own use, and we do not aggregate across customers. What is retrieved into your workspace stays in your workspace.
If an individual asks to see or delete what you hold about them, that request goes to you — you decided to collect it. We will help you answer it, and deleting a record deletes what was enriched onto it.
You are responsible for having a lawful basis to enrich, and for outreach complying with the rules where your recipients are. That is not a formality: it is the reason these features are configurable rather than automatic.
6. Sub-processors
Running the service means other companies necessarily touch some data. The current list:
| Who | What they handle |
|---|---|
| Model providers (Anthropic, OpenAI, Google and others you may select) | The content of a request, to return a result. No training on your data. |
| Hosting and infrastructure providers | Storage and compute for the platform. |
| Payment processor | Billing details. We never see your full card number. |
| Email delivery | Service notifications sent to you. |
If you connect your own mailbox or your own model keys, that traffic goes to those providers under your agreement with them, not ours. We will give notice before adding a sub-processor that handles workspace content.
7. How long we keep things
- Account information — while your account is open, and for a limited period afterwards where we are required to keep records.
- Workspace content — until you delete it. Deleting a workspace removes its content within 30 days, including from backups as they rotate.
- Audit and billing records — retained after deletion where law requires it, or where they are the evidence for an invoice already issued. These are records of actions, not copies of your documents.
8. Your rights
Depending on where you are, you may have the right to access, correct, export, delete, or restrict processing of your personal data, and to object to it. We honour these requests regardless of whether a particular law compels us to.
Write to hello@getsynthos.com. We will respond within 30 days. We do not charge for this and we will not make it difficult.
Where you are our processor rather than our subject — that is, where the personal data is your customers’ and you decided to put it in — requests from those individuals should go to you. We will assist you in answering them.
9. Data location and transfers
Data is stored and processed in the United States and, depending on the model providers selected, may be processed elsewhere. Where transfers are subject to European or UK data protection law, they rely on Standard Contractual Clauses.
10. Security, stated honestly
We take security seriously and we will not claim more than we can demonstrate. What is true today: isolation enforced at the data layer and asserted by automated tests, encryption in transit and at rest, server-side credential storage, and an append-only record of what the system did.
What is not true today: we do not currently hold SOC 2 or ISO 27001 certification. If that matters to your firm, say so — it is a reasonable thing to require, and we would rather tell you now than be asked in a security review later.
If we discover a breach affecting your data we will tell you promptly and directly, with what we know and what we do not.
11. Children
Synthos is a business tool and is not directed at anyone under 18. We do not knowingly collect information from children.
12. Changes
If we change this policy in a way that materially affects how your data is handled, we will tell you before it takes effect — not by quietly updating a date at the top.
See also the Terms of Service.