AgentSynth

Privacy Policy

Effective: 2026-08-10 · Version: 1.0

This policy explains what data AgentSynth collects, where it goes, how long it is kept, and what you can do about it. It is written to be specific rather than generic — if something here is vague, that is a bug, and privacy@agentsynth.app will reach a human.


1. Who is responsible

The data controller is Tal Efronny, an individual trader based in Israel (Netanya, Israel). Contact: privacy@agentsynth.app.

2. The short version

3. What we collect

CategoryWhat exactlyWhen
AccountYour Google account identifier, email address, and nameWhen you sign in
AuthenticationHashed refresh tokens, device authorization records, verification attemptsWhile you are signed in
AI requestsYour prompt text, your current patch data, the model used, token counts, timestampsEach hosted generation
Technical logsIP address, request path, response status, timestamp, error detailsEvery request to our service
BillingYour subscription status and a customer identifier from our payment providerWhile you have a paid plan
WebsiteAggregate, cookieless page-view statistics for agentsynth.appWhen you visit the site

What we never receive: your payment card details. Those go to our Merchant of Record and never touch our systems (§6).

Before you sign in. AgentSynth offers a limited anonymous trial. During it we process a device identifier and a request count to enforce the limit, plus the AI-request and log data above. No account and no email address is involved.

4. Hosted AI generation — where your prompts go

This is the disclosure that matters most, so it gets its own section.

When you use hosted AI generation, AgentSynth sends to our service, and our service forwards to a third-party inference provider:

The provider is Cerebras, and it is named on our Subprocessors page along with what we have verified about their retention practices.

Cerebras does not retain the content of your prompts. Their published policy is that prompt content, API requests and responses, and model outputs are not stored. We do not use your prompts or patches to train any model, and our agreements do not permit our providers to do so on our behalf. The Subprocessors page has the detail and the sources.

Practical advice: do not put anything confidential in a prompt. A prompt describing a bass sound is not sensitive. A prompt containing a client's unreleased track title, personal details, or anything you would not email to a stranger, is.

Local mode is the alternative. Running a model locally via Ollama keeps everything on your machine. It is free, it stays free, and it is a first-class option rather than a crippled one.

5. Why we process it, and on what legal basis

PurposeDataLegal basis (GDPR Art. 6)
Create and run your accountAccount, authenticationContract — Art. 6(1)(b)
Deliver AI generationAI requestsContract — Art. 6(1)(b)
Bill you and manage your subscriptionBillingContract — Art. 6(1)(b)
Enforce quotas and the anonymous trialUsage counters, device identifierContract, and legitimate interests in preventing abuse — Art. 6(1)(f)
Keep the service secure and debug failuresTechnical logsLegitimate interests — Art. 6(1)(f)
Understand aggregate site trafficCookieless website statisticsLegitimate interests — Art. 6(1)(f)
Comply with tax and legal obligationsBilling recordsLegal obligation — Art. 6(1)(c)

We do not rely on consent for anything above, because none of it is optional to providing the service you asked for. If we ever add something that does need consent — marketing email, non-essential tracking — we will ask first and it will be genuinely optional.

6. Who we share it with

We use a small number of service providers. Each is listed on our Subprocessors page with its role, what it receives and where it is located. That page is separate so we can keep it current, and we commit to updating it before adding a new provider.

Payments. Purchases are handled by Polar Software Inc. as Merchant of Record. Polar is the seller of record for your purchase and an independent controller of your payment data. We receive only your subscription status and a customer identifier. Polar engages its own subprocessors, including payment infrastructure — see Polar's privacy policy for their chain.

We do not sell personal data, and we do not share it for advertising.

We may disclose data if legally required, or to establish or defend legal claims.

7. How long we keep it

DataRetention
Account recordUntil you delete your account
Refresh tokens60 days, or until revoked or rotated
Device authorization recordsShort-lived; deleted after use or expiry
Verification attemptsDeleted on a short rolling window
Technical logs30 days
Billing recordsAs required by tax law — typically 7 years, held by our payment provider
Website statisticsAggregate only, not linked to you

AI prompts and patches. We do not store the content of your prompts or patches on our servers.

When you delete your account we delete your account record and authentication data. Billing records held by our payment provider are retained under their own tax obligations and are outside our control.

8. Where your data goes — international transfers

Our servers and database are in the United States. We operate from Israel.

GDPR does not require EU data to stay in the EU. It requires a valid mechanism for transferring it, and we rely on:

Which mechanism applies to which provider is noted on the Subprocessors page.

9. Your rights

If you are in the EU, UK or another region with equivalent law, you have the right to:

How to exercise them. Email privacy@agentsynth.app. We will respond within 30 days. There is no charge. We may ask you to confirm you control the email address on the account.

Account deletion is also available in the application. <!-- Do not publish this sentence until DELETE /v1/account exists — see 00-checklist.md §D.1 -->

Complaints. You may lodge a complaint with your national data protection authority. We would rather you told us first, but you are not obliged to.

10. How we protect it

No system is perfectly secure. If a breach occurs that is likely to risk your rights, we will notify the relevant supervisory authority within 72 hours and tell you directly where required.

11. Children

AgentSynth is not intended for children under 16, and we do not knowingly collect their data. If you believe a child has given us personal data, contact privacy@agentsynth.app and we will delete it.

12. Cookies and tracking

The AgentSynth desktop application sets no cookies and contains no third-party analytics or advertising SDKs.

The website uses cookieless, aggregate traffic statistics that do not identify you and set nothing on your device. There is no advertising, no cross-site tracking, and no consent banner because there is nothing to consent to.

13. Changes

We may update this policy. For material changes we will give notice by email or in the application before they take effect. The version and effective date are at the top of this page.

14. Contact

Tal Efronny · Netanya, Israel · privacy@agentsynth.app