Legal
Privacy Policy
Desler Digital Enterprises LLC (“Company,” “we,” or “us”) operates Synchronex at synchronex.ai. This Privacy Policy describes what data we collect, how we use it, and the choices you have. We keep this plain and complete — no legalese traps.
1. Data We Collect
Account information. When you sign up we collect your email address and, optionally, your name. Your password is hashed; we never store it in plaintext.
Profile and brand data. We store the Identity Kernel, product context, decisions, worker configurations, and other content you create inside Synchronex. This is your operational data and stays yours.
Connected credentials. If you use Bring Your Own Key (BYOK), your API keys are stored encrypted using AES-256-GCM. We use them only to fulfill your requests and never expose them in plaintext.
Usage data. We collect product telemetry — feature interactions, session starts, worker run counts, and performance metrics — to improve the platform. This data is aggregated and used internally; it is not tied to ad profiles or sold.
Billing data. Payment processing is handled by Stripe. We store only the plan tier and Stripe customer ID — no raw card numbers.
Log data. Server logs capture IP addresses, timestamps, and request paths for security monitoring and debugging. Logs are retained for up to 90 days.
Cookies. We use session cookies required for authentication and local storage to preserve UI state (theme, panel positions). We do not use advertising or third-party tracking cookies.
2. How We Use Your Data
- To operate and deliver the Synchronex service.
- To authenticate you and maintain session security.
- To fulfill AI worker requests you initiate (your content is passed to AI providers on your behalf).
- To detect, investigate, and prevent fraud, abuse, and security incidents.
- To send transactional emails: password resets, billing receipts, and product-critical notices.
- To improve the platform using aggregated, non-identifying usage patterns.
We do not use your content to train AI models. We do not sell, rent, or broker your personal data to any third party for any purpose.
3. Data Storage and Security
Synchronex data is stored in Supabase (PostgreSQL on AWS). Every table is protected by Row-Level Security (RLS) so your data is scoped to your account and, where applicable, your team workspace. Tenant isolation is enforced at the database layer, not just at the application layer.
API keys and provider credentials are encrypted at rest with AES-256-GCM before storage. Access to production infrastructure is restricted to authorized personnel and logged.
We apply TLS in transit, regular dependency audits, and principle-of-least-privilege for all internal service accounts. No security system is perfect. If you discover a vulnerability, please report it to security@synchronex.ai.
4. AI Provider Data Sharing
When you run an AI worker, the relevant content (kernel context, your prompt, uploaded files) is sent to the AI provider processing that request — for example, Anthropic, OpenAI, or Google, depending on your configuration. Each provider has its own privacy policy and data handling terms. We pass only what is necessary for the task and do not share your account metadata with AI providers.
BYOK users route requests through their own provider credentials and should review their provider’s data retention policies directly.
5. Third-Party Services
We use a limited set of third-party processors to operate the service:
- Supabase — database and authentication infrastructure.
- Stripe — payment processing.
- Vercel — hosting and edge delivery.
- Axiom — internal observability and telemetry.
- Sendinel — email and notification delivery for Synchronex-initiated messages.
These processors handle your data only as directed by us and under contractual data processing agreements.
6. Data Retention
We retain your account data for as long as your account is active. Deleted accounts have their personal data purged within 30 days, except where retention is required by law (e.g., billing records may be kept for up to 7 years for tax compliance).
7. Your Rights
You have the right to:
- Access — request a copy of the personal data we hold about you.
- Correction — request correction of inaccurate data.
- Deletion — request deletion of your account and associated data. Submit a request from Settings → Account or email privacy@synchronex.ai.
- Portability — export your Identity Kernel and worker data from Settings → Memory.
- Opt out of non-essential communications — unsubscribe links are in every non-transactional email.
We will respond to verifiable requests within 30 days.
8. Children
Synchronex is not directed at anyone under 18. If we learn that we have collected personal data from a child under 13, we will delete it immediately. Contact us at privacy@synchronex.ai if you believe we have inadvertently collected such data.
9. Changes to This Policy
We may update this Privacy Policy. Material changes will be communicated by email or in-product notice at least 14 days before taking effect. The current version is always at synchronex.ai/legal/privacy.
10. Contact
Privacy questions or data requests: privacy@synchronex.ai. Desler Digital Enterprises LLC · Kaneohe, Hawaii.