Legal
Privacy Policy
This policy explains what data AgentSynth collects, where it goes, how long it is kept, and what you can do about it. It is written to be specific rather than generic — if something here is vague, that is a bug, and privacy@agentsynth.app will reach a human.
1. Who is responsible
The data controller is Tal Efronny, an individual trader based in Israel. Contact: privacy@agentsynth.app.
2. The short version
- Local mode sends no prompts or patches. If you run AI generation locally through Ollama, your prompts and patches never leave your computer, and we never see them.
- Hosted mode sends your prompt and your current patch to a third-party AI provider in the United States. This is the most important thing on this page — see §4.
- App usage statistics are off unless you turn them on. If you do, the app sends us a daily summary of your app version and platform and counts of the features and modules you used — never your patches, prompts, names, file paths or audio. See §12.
- We do not sell your data, and we do not use your prompts or patches to train AI models.
- We keep as little as we can get away with. The retention table in §7 is the honest version.
3. What we collect
| Category | What exactly | When |
|---|---|---|
| Account | Your Google account identifier, email address, and name | When you sign in |
| Authentication | Hashed refresh tokens, device authorization records, verification attempts | While you are signed in |
| AI requests | Your prompt text, your current patch data, the model used, token counts, timestamps | Each hosted generation |
| Technical logs | IP address, request path, response status, timestamp, error details | Every request to our service |
| Billing | Your subscription status and a customer identifier from our payment provider | While you have a paid plan |
| Product usage | Timestamps marking your first hosted AI request, hitting your quota, and upgrading, linked to your account or device identifier | As each milestone occurs |
| Product-learning prompt samples (opt-in) | Your prompt text and the patch it generated | Only if you opt in, each hosted generation |
| App usage statistics (opt-in) | A daily summary of app version, operating system and processor architecture, whether you run the standalone app or a plugin (VST3/AU), session count, active-time band, and counts of modules added and features used, stored under a random telemetry ID that is not linked to your account or to the device identifier above — details in §12 | Only if you turn on "Share anonymous usage statistics"; one summary for each day you use the app, sent the next time it starts |
| Newsletter | Your email address, subscription status and signup source | When you sign up for release-notes email in the site footer |
| Feedback | The category and free-text content of what you submit, linked to your account or device identifier | When you submit feedback in the application |
| Website | Aggregate, cookieless page-view statistics for agentsynth.app | When you visit the site |
What we never receive: your payment card details. Those go to our Merchant of Record and never touch our systems (§6).
Before you sign in. AgentSynth offers a limited anonymous trial. During it we process a device identifier and a request count to enforce the limit, plus the AI-request and log data above. No account and no email address is involved.
4. Hosted AI generation — where your prompts go
This is the disclosure that matters most, so it gets its own section.
When you use hosted AI generation, AgentSynth sends to our service, and our service forwards to a third-party inference provider:
- The text of your prompt.
- The JSON representation of your current patch — the modules, connections and parameter values in your project.
- A system prompt describing the available synthesizer modules.
The provider is Amazon Web Services, via Amazon Bedrock in the us-east-1 region. The model itself is an open-weight model (gpt-oss) served by AWS — your prompt never reaches OpenAI or Anthropic. AWS is named on our Subprocessors page along with what we have verified about its retention practices.
Amazon Bedrock does not store or log the content of your prompts or model outputs. Per AWS's own documentation, Data protection in Amazon Bedrock, Bedrock does not retain your prompt inputs or the model's outputs, does not use them to train any model, and does not share them with the underlying model provider. We do not use your prompts or patches to train any model, and our agreements do not permit our providers to do so on our behalf. The Subprocessors page has the detail and the source.
Practical advice: do not put anything confidential in a prompt. A prompt describing a bass sound is not sensitive. A prompt containing a client's unreleased track title, personal details, or anything you would not email to a stranger, is.
Local mode is the alternative. Running a model locally via Ollama keeps your prompts and patches on your machine. It is free, it stays free, and it is a first-class option rather than a crippled one.
5. Why we process it, and on what legal basis
| Purpose | Data | Legal basis (GDPR Art. 6) |
|---|---|---|
| Create and run your account | Account, authentication | Contract — Art. 6(1)(b) |
| Deliver AI generation | AI requests | Contract — Art. 6(1)(b) |
| Bill you and manage your subscription | Billing | Contract — Art. 6(1)(b) |
| Enforce quotas and the anonymous trial | Usage counters, device identifier | Contract, and legitimate interests in preventing abuse — Art. 6(1)(f) |
| Understand product conversion, to guide pricing and product decisions | Usage-milestone timestamps, account/device identifier | Legitimate interests — Art. 6(1)(f) |
| Keep the service secure and debug failures | Technical logs | Legitimate interests — Art. 6(1)(f) |
| Understand aggregate site traffic | Cookieless website statistics | Legitimate interests — Art. 6(1)(f) |
| Comply with tax and legal obligations | Billing records | Legal obligation — Art. 6(1)(c) |
| Improve prompts/product with real usage examples (opt-in only) | Prompt-learning samples | Consent — Art. 6(1)(a) |
| Understand, in aggregate, which app features, versions and platforms are used, to decide what to improve and support (opt-in only) | App usage statistics, random telemetry ID | Consent — Art. 6(1)(a) |
| Send you release-notes email you asked for | Newsletter | Consent — Art. 6(1)(a) |
| Review and act on bug reports and feature requests | Feedback | Legitimate interests — Art. 6(1)(f) |
We rely on consent for three things: the opt-in product-learning samples above, the opt-in app usage statistics (§12), and the newsletter (you only get it if you signed up for it). Everything else relies on contract, a legal obligation or our legitimate interests, as the table shows.
5a. Opt-in product learning
You can choose, in the application's settings, to help us improve AgentSynth by letting us keep a copy of your hosted-mode prompts. This is off by default and entirely optional.
What's collected. If you opt in, each hosted generation stores the text of your prompt and the JSON of the patch it produced.
What it's for. A person on our team reviews real prompts and the patches they generated to improve prompt engineering, the system prompt, and product features. This is never used to train or fine-tune any AI model — that promise from §4 is unchanged and this feature does not touch it. It is human review only.
How to opt in or out. Settings → the hosted-AI section of the application. You can change your choice at any time.
Revoking is immediate. Turning the toggle off deletes every sample already collected right away — there is no grace period and nothing lingers waiting for a retention job to catch up.
6. Who we share it with
We use a small number of service providers. Each is listed on our Subprocessors page with its role, what it receives and where it is located. That page is separate so we can keep it current, and we commit to updating it before adding a new provider.
Payments. Purchases are handled by Polar Software Inc. as Merchant of Record. Polar is the seller of record for your purchase and an independent controller of your payment data. We receive only your subscription status and a customer identifier. Polar engages its own subprocessors, including payment infrastructure — see Polar's privacy policy for their chain.
We do not sell personal data, and we do not share it for advertising.
We may disclose data if legally required, or to establish or defend legal claims.
7. How long we keep it
| Data | Retention |
|---|---|
| Account record | Until you delete your account |
| Refresh tokens | 60 days, or until revoked or rotated |
| Device authorization records | Short-lived; deleted after use or expiry |
| Verification attempts | Deleted on a short rolling window |
| Technical logs | 30 days |
| Billing records | As required by tax law — typically 7 years, held by our payment provider |
| Usage-milestone timestamps | Deleted with your account. Anonymous-trial (device-linked) records are retained indefinitely today — email privacy@agentsynth.app to have yours removed |
| Website statistics | Aggregate only, not linked to you |
| Conversation history (prompts & patches, signed-in users only) | 180 days after last activity, or until you delete it |
| Product-learning prompt samples (opt-in) | Until you revoke consent (Settings), then deleted immediately — no fixed retention period otherwise |
| App usage statistics (opt-in) | 12 months, then deleted. Turning the setting off deletes the telemetry ID and any unsent summaries on your device and stops collection, but does not delete summaries we have already received — see §12 |
| Newsletter | Until you unsubscribe (one-click link in every email) |
| Feedback | Retained indefinitely today — email privacy@agentsynth.app to have yours removed |
AI prompts and patches. If you are signed in, we store the text of your prompts and the JSON of the patches they generate, so you can list and resume past conversations across your devices. This is kept for up to 180 days after the conversation's last activity, or until you delete it yourself — you can list, export and delete your conversation history at any time (GET /v1/conversations, GET /v1/conversations/export, DELETE /v1/conversations/:id, or DELETE /v1/conversations to remove everything).
If you are not signed in (local trial or anonymous use), nothing about your prompts or patches is stored on our servers — see §2 and §4.
When you delete your account we delete your account record and authentication data. App usage statistics are not linked to your account, so deleting it does not affect them; they are deleted after 12 months (§12). Billing records held by our payment provider are retained under their own tax obligations and are outside our control.
8. Where your data goes — international transfers
Our servers and database are in the United States. We operate from Israel.
GDPR does not require EU data to stay in the EU. It requires a valid mechanism for transferring it, and we rely on:
- Israel's adequacy decision — the European Commission recognises Israel as providing an adequate level of data protection, so data reaching us in Israel needs no additional safeguards.
- The EU–US Data Privacy Framework for providers certified under it — Google, Databricks (Neon), Amazon Web Services and Cloudflare are certified participants — and Standard Contractual Clauses for those that are not. AWS processes hosted-mode prompts and patch data in
us-east-1(United States) via Amazon Bedrock.
See the Subprocessors page for the full list of providers and what each one receives.
9. Your rights
If you are in the EU, UK or another region with equivalent law, you have the right to:
- Access the personal data we hold about you.
- Correct it if it is wrong.
- Delete it ("right to be forgotten").
- Export it in a portable format.
- Object to or restrict processing based on legitimate interests.
- Withdraw consent where we rely on it — the opt-in product-learning samples in §5a, the opt-in app usage statistics in §12, and the newsletter (unsubscribe link in every email). Turn the product-learning toggle or the usage-statistics setting off in Settings at any time. Withdrawing consent does not affect processing that took place before you withdrew it.
How to exercise them. Email privacy@agentsynth.app. We will respond within 30 days. There is no charge. We may ask you to confirm you control the email address on the account.
Account deletion is also available in the application.
App usage statistics are deliberately not linked to your account or email address, so deleting your account does not delete them, and requests about them work differently — see §12.
Complaints. You may lodge a complaint with your national data protection authority. We would rather you told us first, but you are not obliged to.
10. How we protect it
- All data in transit is encrypted with TLS 1.2 or higher. Database connections require TLS.
- Data at rest is encrypted with AES-256 by our hosting and database providers.
- Refresh tokens and device codes are hashed, never stored in readable form. Refresh tokens rotate on use, and reuse of a retired token revokes the whole token family.
- Application credentials are held only as encrypted secrets in our infrastructure configuration — never in source control, and never in a log.
- Desktop credentials are stored in your operating system keychain, not in a plain configuration file.
- Access to production systems is limited to the operator and protected by multi-factor authentication.
No system is perfectly secure. If a breach occurs that is likely to risk your rights, we will notify the relevant supervisory authority within 72 hours and tell you directly where required.
11. Children
AgentSynth is not intended for children under 13, or the higher minimum age of digital consent where your country sets one, and we do not knowingly collect their data. If you believe a child has given us personal data, contact privacy@agentsynth.app and we will delete it.
12. Cookies, tracking and usage statistics
The AgentSynth desktop application sets no cookies and contains no third-party analytics or advertising SDKs. It offers optional first-party usage statistics, off by default, which are sent only to our own service — see Telemetry below.
The website uses cookieless, aggregate traffic statistics that do not identify you and set nothing on your device. There is no advertising, no cross-site tracking, and no consent banner because there is nothing to consent to.
Telemetry
Versions of the application that include the Share anonymous usage statistics setting (Settings → Preferences) can send us a short daily summary of how the app is used. It is off by default: nothing is recorded or sent unless you turn it on. The app may ask you once, on its Welcome screen, whether you want to share; saying no leaves it off. Sharing is optional: the app works the same whether or not you turn it on. Versions without the setting do not collect or send these statistics at all.
What "anonymous" means here. When you turn the setting on, the app creates a random identifier — the telemetry ID — on your device, and sends it with each summary so we can count how many installations use a feature without knowing whose they are. The telemetry ID is new and random: it is not your account identifier, email address or licence, and it is not the device identifier used for the anonymous trial, feedback and product-usage records in §3. It is never sent together with your sign-in credentials, and we do not link it to any of those. The statistics are not designed to tell us who you are, and we do not try to find out. But because the same ID is sent with each day's summary, the summaries from one installation can be linked to each other, so we treat them as personal data and you have the rights described below.
What's collected. For each day on which you use the app, we store one summary containing:
- The telemetry ID, the date, and the time our service received the summary.
- The app version, your operating system and processor architecture, and whether you are running the standalone app or the VST3 or AU plugin.
- How many sessions you started, and roughly how long the app was active, in broad bands (under 15 minutes, 15–60 minutes, 1–3 hours, or more than 3 hours).
- How many modules of each type you added (for example, oscillators or filters). If you load third-party plugins, we count them, but never record which ones.
- How many times you used certain features: creating macros, using the timeline, making AI requests, saving and loading presets, and opening projects.
What is never collected. The contents of your patches, presets or projects; any names you give to them; file paths; anything you type, including your AI prompts; and audio. AI requests are counted, not recorded.
Where it goes and how long we keep it. Summaries are sent to our own service, not to a third-party analytics provider. If a summary cannot be sent, the app keeps it on your device and tries again the next time it starts; it keeps at most 14 days' worth of unsent summaries and discards older ones. We store the summaries in our database in the United States (see §8 and our Subprocessors page) and delete them after 12 months. We may keep totals calculated from them after that — for example, how many installations used the timeline on a given day, by app version and operating system — but those totals do not include the telemetry ID. We do not sell the statistics or use them for advertising.
IP addresses. Sending a summary, like any request over the internet, reveals your IP address to our hosting provider, Google Cloud, which uses it to deliver the request. We do not store your IP address with your usage statistics, and our own application does not record it. Google Cloud's standard request logs for our service do record the IP address of every request, including these: they are the technical logs described in §3, kept for 30 days, and we do not use them to connect an IP address to a telemetry ID.
Legal basis, and turning it off. We rely on your consent (GDPR Art. 6(1)(a)), which also covers creating and keeping the telemetry ID on your device. You can withdraw it at any time by switching the setting off. When you do, the app stops recording and sending summaries, and deletes from your device the telemetry ID and any summaries it has not yet sent. Withdrawing consent does not affect processing that took place before. Summaries we have already received are not deleted at that point — they stay in our database until the 12-month deletion — but once the ID is gone from your device, neither you nor we can tell which of them came from your installation. If you turn the setting on again later, the app creates a new, unrelated ID.
Your rights and these statistics. Because we deliberately do not link the telemetry ID to you, we cannot find your summaries from your name, email address or account, and so we cannot act on an access or deletion request that identifies you only in those ways (GDPR Art. 11). We can act on a request that gives us your telemetry ID: we will provide or delete the summaries stored under it. Turning the setting off deletes the ID, so if you want the summaries already sent to us provided to you or deleted, email privacy@agentsynth.app before you turn the setting off, and we will help you find the ID on your device.
13. Changes
We may update this policy. For material changes we will give notice by email or in the application before they take effect. The version and effective date are at the top of this page.
14. Contact
Tal Efronny · Israel · privacy@agentsynth.app