Syntra («we», «service») respects your privacy and complies with the General Data Protection Regulation (GDPR) and applicable Portuguese law.
1. Data controller
Controller: operator of the Syntra service (syntra.uno). Privacy contact: adaliosemedo@scobovault.org.
2. Data we collect
- Account: email, name (if provided), password (managed by Supabase Auth — not stored in plain text by us).
- Usage: chat and agent messages, sessions, credits consumed, routed model (technical metadata).
- Payments: billing data processed by Stripe; we do not store full card numbers.
- Technical: server logs, approximate IP address, essential session cookies, and consent preferences.
3. Cookies and similar technologies
We use cookies and local storage to operate the service and, only with your consent, for measurement and advertising.
- Essential: session authentication (Supabase), language preference, and your cookie choice. These are required for the service to work.
- Analytics (optional): Google Analytics 4 measures visits and events (e.g. sign-up) to improve the product. Enabled only if you accept non-essential cookies.
- Advertising (optional): Google technologies (e.g. Google Ads, Consent Mode) to measure campaigns and attribution. Enabled only with the same consent.
You can accept or reject non-essential cookies in the banner on your first visit. You can change your choice by clearing this site's cookies in your browser. For more on Google cookies: Google cookies policy.
4. Purposes and legal bases
- Service provision and contract performance (GDPR Art. 6(1)(b)).
- Billing and legal obligations (Art. 6(1)(c) and (1)(b)).
- Security, abuse prevention and product improvement (legitimate interest, Art. 6(1)(f)).
- Service communications (email confirmation, welcome).
- Website usage analysis and campaign measurement (consent, GDPR Art. 6(1)(a)), only if you accept analytics and advertising cookies.
5. AI processing
Content you send may be transmitted to AI model providers (e.g. OpenAI, Anthropic, Google, DeepSeek) only to generate responses. We configure requests not to use your data for model training when the provider supports it. We do not sell your prompts to third parties.
6. Processors and transfers
We use infrastructure in the EU or with adequate safeguards, including: Supabase (database and auth), Vercel (hosting), Stripe (payments), Resend (transactional email), Google (Analytics and advertising, if consented). An updated list can be requested by email.
7. Retention
We keep data while your account is active and for the legal period required for billing and claims. You may request account deletion on Delete account and data or by contacting us.
8. Your rights
You have rights of access, rectification, erasure, restriction, portability and objection, and may lodge a complaint with the CNPD (cnpd.pt). To exercise rights: adaliosemedo@scobovault.org.
9. Security
We apply reasonable technical and organizational measures (HTTPS, access control, database RLS). No system is 100% secure.
10. Minors
The service is not intended for users under 16. If you become aware of misuse, contact us.
11. Changes
We may update this policy. The date at the top indicates the current version. Material changes will be communicated by email or in the product.
