Privacy Policy
Effective: 2026-08-10 · Version: 1.0
This policy explains what data AgentSynth collects, where it goes, how long it is kept, and what you can do about it. It is written to be specific rather than generic — if something here is vague, that is a bug, and privacy@agentsynth.app will reach a human.
1. Who is responsible
The data controller is Tal Efronny, an individual trader based in Israel (Netanya, Israel). Contact: privacy@agentsynth.app.
2. The short version
- Local mode sends nothing. If you run AI generation locally through Ollama, your prompts and patches never leave your computer, and we never see them.
- Hosted mode sends your prompt and your current patch to a third-party AI provider in the United States. This is the most important thing on this page — see §4.
- We do not sell your data, and we do not use your prompts or patches to train AI models.
- We keep as little as we can get away with. The retention table in §7 is the honest version.
3. What we collect
| Category | What exactly | When |
|---|---|---|
| Account | Your Google account identifier, email address, and name | When you sign in |
| Authentication | Hashed refresh tokens, device authorization records, verification attempts | While you are signed in |
| AI requests | Your prompt text, your current patch data, the model used, token counts, timestamps | Each hosted generation |
| Technical logs | IP address, request path, response status, timestamp, error details | Every request to our service |
| Billing | Your subscription status and a customer identifier from our payment provider | While you have a paid plan |
| Website | Aggregate, cookieless page-view statistics for agentsynth.app | When you visit the site |
What we never receive: your payment card details. Those go to our Merchant of Record and never touch our systems (§6).
Before you sign in. AgentSynth offers a limited anonymous trial. During it we process a device identifier and a request count to enforce the limit, plus the AI-request and log data above. No account and no email address is involved.
4. Hosted AI generation — where your prompts go
This is the disclosure that matters most, so it gets its own section.
When you use hosted AI generation, AgentSynth sends to our service, and our service forwards to a third-party inference provider:
- the text of your prompt,
- the JSON representation of your current patch — the modules, connections and parameter values in your project,
- a system prompt describing the available synthesizer modules.
The provider is Cerebras, and it is named on our Subprocessors page along with what we have verified about their retention practices.
Cerebras does not retain the content of your prompts. Their published policy is that prompt content, API requests and responses, and model outputs are not stored. We do not use your prompts or patches to train any model, and our agreements do not permit our providers to do so on our behalf. The Subprocessors page has the detail and the sources.
Practical advice: do not put anything confidential in a prompt. A prompt describing a bass sound is not sensitive. A prompt containing a client's unreleased track title, personal details, or anything you would not email to a stranger, is.
Local mode is the alternative. Running a model locally via Ollama keeps everything on your machine. It is free, it stays free, and it is a first-class option rather than a crippled one.
5. Why we process it, and on what legal basis
| Purpose | Data | Legal basis (GDPR Art. 6) |
|---|---|---|
| Create and run your account | Account, authentication | Contract — Art. 6(1)(b) |
| Deliver AI generation | AI requests | Contract — Art. 6(1)(b) |
| Bill you and manage your subscription | Billing | Contract — Art. 6(1)(b) |
| Enforce quotas and the anonymous trial | Usage counters, device identifier | Contract, and legitimate interests in preventing abuse — Art. 6(1)(f) |
| Keep the service secure and debug failures | Technical logs | Legitimate interests — Art. 6(1)(f) |
| Understand aggregate site traffic | Cookieless website statistics | Legitimate interests — Art. 6(1)(f) |
| Comply with tax and legal obligations | Billing records | Legal obligation — Art. 6(1)(c) |
We do not rely on consent for anything above, because none of it is optional to providing the service you asked for. If we ever add something that does need consent — marketing email, non-essential tracking — we will ask first and it will be genuinely optional.
6. Who we share it with
We use a small number of service providers. Each is listed on our Subprocessors page with its role, what it receives and where it is located. That page is separate so we can keep it current, and we commit to updating it before adding a new provider.
Payments. Purchases are handled by Polar Software Inc. as Merchant of Record. Polar is the seller of record for your purchase and an independent controller of your payment data. We receive only your subscription status and a customer identifier. Polar engages its own subprocessors, including payment infrastructure — see Polar's privacy policy for their chain.
We do not sell personal data, and we do not share it for advertising.
We may disclose data if legally required, or to establish or defend legal claims.
7. How long we keep it
| Data | Retention |
|---|---|
| Account record | Until you delete your account |
| Refresh tokens | 60 days, or until revoked or rotated |
| Device authorization records | Short-lived; deleted after use or expiry |
| Verification attempts | Deleted on a short rolling window |
| Technical logs | 30 days |
| Billing records | As required by tax law — typically 7 years, held by our payment provider |
| Website statistics | Aggregate only, not linked to you |
AI prompts and patches. We do not store the content of your prompts or patches on our servers.
When you delete your account we delete your account record and authentication data. Billing records held by our payment provider are retained under their own tax obligations and are outside our control.
8. Where your data goes — international transfers
Our servers and database are in the United States. We operate from Israel.
GDPR does not require EU data to stay in the EU. It requires a valid mechanism for transferring it, and we rely on:
- Israel's adequacy decision — the European Commission recognises Israel as providing an adequate level of data protection, so data reaching us in Israel needs no additional safeguards.
- The EU–US Data Privacy Framework for providers certified under it — Google, Databricks (Neon) and Cloudflare are certified participants — and Standard Contractual Clauses for those that are not.
Which mechanism applies to which provider is noted on the Subprocessors page.
9. Your rights
If you are in the EU, UK or another region with equivalent law, you have the right to:
- access the personal data we hold about you,
- correct it if it is wrong,
- delete it ("right to be forgotten"),
- export it in a portable format,
- object to or restrict processing based on legitimate interests,
- withdraw consent where we rely on it (currently, nowhere).
How to exercise them. Email privacy@agentsynth.app. We will respond within 30 days. There is no charge. We may ask you to confirm you control the email address on the account.
Account deletion is also available in the application. <!-- Do not publish this sentence until DELETE /v1/account exists — see 00-checklist.md §D.1 -->
Complaints. You may lodge a complaint with your national data protection authority. We would rather you told us first, but you are not obliged to.
10. How we protect it
- All data in transit is encrypted with TLS 1.2 or higher. Database connections require TLS.
- Data at rest is encrypted with AES-256 by our hosting and database providers.
- Refresh tokens and device codes are hashed, never stored in readable form. Refresh tokens rotate on use, and reuse of a retired token revokes the whole token family.
- Application credentials are held only as encrypted secrets in our infrastructure configuration — never in source control, and never in a log.
- Desktop credentials are stored in your operating system keychain, not in a plain configuration file.
- Access to production systems is limited to the operator and protected by multi-factor authentication.
No system is perfectly secure. If a breach occurs that is likely to risk your rights, we will notify the relevant supervisory authority within 72 hours and tell you directly where required.
11. Children
AgentSynth is not intended for children under 16, and we do not knowingly collect their data. If you believe a child has given us personal data, contact privacy@agentsynth.app and we will delete it.
12. Cookies and tracking
The AgentSynth desktop application sets no cookies and contains no third-party analytics or advertising SDKs.
The website uses cookieless, aggregate traffic statistics that do not identify you and set nothing on your device. There is no advertising, no cross-site tracking, and no consent banner because there is nothing to consent to.
13. Changes
We may update this policy. For material changes we will give notice by email or in the application before they take effect. The version and effective date are at the top of this page.
14. Contact
Tal Efronny · Netanya, Israel · privacy@agentsynth.app