Synth (synth.net.au) is committed to protecting your privacy. This policy explains what data we collect, how we use it, and your rights.
1. Data We Collect
- Account information — email address, display name, profile picture, and username provided during sign-up.
- Authentication data — we use Google Sign-In (via Clerk) for authentication. Clerk may store session tokens, OAuth tokens, and related metadata on our behalf.
- Usage data — pages visited, features used, browser type, operating system, referral URL, and interaction timestamps. We use PostHog for product analytics.
- Payment information — purchase history, amounts, and Stripe payment identifiers. See “Payment Processing” below for important details.
- Content you create — code snippets, app kits, comments, reviews, and other user-generated content submitted to the platform.
- Commission and intake data — when you use Synth Assist (AI-assisted intake) or request customisation via upgrade packs, the conversation messages, structured briefs, and acceptance checklists are stored to fulfil the commission. Do not share API keys, credentials, or personal secrets in intake chats.
2. Payment Processing
All payment processing is handled by Stripe. We do not store your credit card number, CVC, or full card details on our servers. Stripe is a PCI-DSS Level 1 certified payment processor. We only retain transaction metadata (payment intent IDs, amounts, timestamps) for record-keeping and dispute resolution.
3. How We Use Your Data
- To provide, operate, and improve the Synth platform.
- To process payments and prevent fraud.
- To communicate with you about your account, purchases, and platform updates.
- To enforce our Terms of Service and protect the integrity of the marketplace.
- To generate aggregated, anonymous analytics to improve the product.
4. Data Sharing
We do not sell your personal data to third parties.
We share data only with the following categories of service providers, solely for the purposes described in this policy:
- Stripe — payment processing.
- Clerk — authentication and session management.
- Supabase — database hosting and file storage.
- AI providers — Synth Assist sends intake conversation context to third-party AI models (OpenAI, Google, Anthropic) to generate structured briefs. Conversations are not used to train these models.
- PostHog — product analytics (anonymised where possible).
- Vercel — application hosting and edge delivery.
5. Cookies & Tracking
Synth uses essential cookies for authentication and session management. We also use analytics cookies (PostHog) to understand how the platform is used. You can disable non-essential cookies through your browser settings.
6. Data Retention
We retain your account data for as long as your account is active. If you delete your account, we will remove your personal data within 30 days, except where we are required to retain records for legal or regulatory purposes (e.g. payment audit logs).
7. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate data.
- Request deletion of your data.
- Object to or restrict certain processing of your data.
- Request a portable copy of your data.
To exercise any of these rights, contact us at the address below.
8. Security
We implement industry-standard security measures including HTTPS encryption, secure session management, and regular access reviews. No system is 100% secure; if you become aware of a vulnerability please report it to security@synth.net.au.
9. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, the “Last updated” date above will be revised. We encourage you to review this page periodically.