Legal
Privacy Policy
Last updated 26 July 2026
What we collect, why, who sees it, and how to get it back or delete it.
Before anything else
This document is a plain-language template written to describe how the service actually behaves. It has not been reviewed by a lawyer and is not legal advice. Before relying on it commercially, have it reviewed for your jurisdiction.
What we collect
Three categories, and nothing else:
- Account data: your name, email address, hashed password, and workspace membership.
- Content: the projects, research, sources, claims, scripts, shot lists and packaging you create.
- Operational data: sign-in times, a salted one-way hash of your IP address, request logs, error reports, and aggregate usage counts.
What we deliberately do not collect
We do not send your content to analytics. Product events record that something happened, whether a project was created or a step was applied or a limit was hit, and never what it contained. Project titles, script text, research notes and source material are transmitted only to the AI provider whose key you have connected, only when you run a step, and to nowhere else.
We do not store raw IP addresses, and we do not use third-party advertising or cross-site tracking.
AI providers
We hold no AI provider account ourselves. Generation runs on the key you connect, currently Anthropic or OpenAI, which makes that provider a processor of your content under your own agreement with them, not ours. Your content reaches them only when you run a step, and only the material that step needs. See the AI Disclosure page for what each step sends.
Other processors
We use a small number of vendors to run the service: a database and hosting provider, an object-storage provider, a payment processor, a transactional email provider, and an error-monitoring provider. Each processes only what its function requires.
Retention
Content is kept while your account is active. When you delete your account we delete your content within 30 days, except where we must keep billing records for tax and accounting purposes.
Audit logs are kept for 12 months. Operational logs are kept for 30 days.
Your rights
You can export everything you have created at any time, in a machine-readable format, from account settings, with no request needed.
You can delete your account from account settings, which removes your content on the timetable above.
Depending on where you live you may also have rights to correction, restriction and objection. Email us and we will action them.
Security
Passwords are hashed with a memory-hard function. Session tokens are stored only as hashes, so a database read does not yield usable sessions. Data is encrypted in transit, and at rest by our infrastructure providers. Access to production data is limited and logged.
We do not claim any formal certification. See the Security section of the product documentation for what is actually implemented.
Cookies
We set one essential cookie for your session and one for your currently-selected workspace. Neither is used for tracking, so no consent banner is required for them. If analytics are enabled on this deployment, they are configured without cross-site identifiers.
Questions about this document?
Email synxparth@gmail.com, or read the other policies.