Start with 25 free Setup Credits to set up your business and AI workforce.

Privacy Notice

Last updated: October 3, 2026

Who we are

SynaBot Inc., a Delaware corporation (registration number 10420285) with its registered office at 16192 Coastal Highway, Lewes, Delaware 19958, County of Sussex, USA ("SynaBot", "we", "us"), operates the SynaBot platform and website at synabot.ai. We are the data controller for the personal data described in this notice. You can reach us at privacy@synabot.ai.

What personal data we collect and why

  • Account data — name, email address, password (hashed), display name and avatar. Used to create and secure your account and to provide the Service. Legal basis: performance of contract.
  • Business and preferences — membership status, selected business, Business DNA, saved teams, favorites, and referral code. Used to personalise the Service. Legal basis: performance of contract and legitimate interests.
  • Content you submit — requests, uploaded files, forum posts, and Business DNA. Used to provide AI responses and features you request. Legal basis: performance of contract.
  • Usage and telemetry — pages viewed, features used, Credit usage, device and browser information, IP address, and approximate location derived from IP. Used to operate, secure, debug and improve the Service and to prevent fraud. Legal basis: legitimate interests.
  • Support and communications — messages you send us and email interactions. Used to respond to you and improve support quality. Legal basis: legitimate interests and consent where required.
  • Marketing preferences — newsletter subscription status and unsubscribe tokens. Legal basis: consent; you may withdraw consent at any time.

Payment card details are collected directly by our payment processor, Stripe, and are never seen or stored on our servers.

How we share personal data

We share personal data with the following categories of recipient:

  • Stripe (Stripe, Inc. and its affiliates) — our payment processor. Stripe processes all payments, subscription billing, invoicing and refund handling on our behalf. See Stripe's Privacy Policy.
  • Infrastructure and service providers — hosting, database, email delivery, analytics, error monitoring and AI model providers who process data on our behalf under contract.
  • Professional advisers — legal, accounting and compliance advisers where necessary.
  • Authorities — where we are required to disclose by law, court order, or to protect our rights or the safety of others.

We do not sell your personal data.

International transfers

SynaBot is based in the United States and some of our providers process data outside the US, UK and EEA. Where transfers involve personal data of UK or EEA residents, we rely on appropriate safeguards such as Standard Contractual Clauses, the UK International Data Transfer Addendum, or adequacy decisions where available.

How long we keep personal data — data retention & deletion

  • AI chat content and prompts — kept for up to 12 months, then deleted or irreversibly anonymised.
  • Usage and telemetry — kept for up to 12 months in identifiable form; longer-term aggregates are anonymised.
  • Account data — kept while your account is active and for up to 24 months after closure to handle billing queries, disputes and legal obligations, after which it is deleted or anonymised.
  • Billing records — retained by Stripe and by us for the periods required by tax and accounting law (typically 6–7 years).
  • Deletion requests — email privacy@synabot.ai at any time to request deletion of your account and associated personal data. We will action verified requests within 30 days. Some records may be retained where the law requires (e.g. billing records) and will be securely disposed of at the end of the required period.

Your rights

Depending on where you live, you may have the right to access, correct, delete, restrict or object to the processing of your personal data, to data portability, and to withdraw consent. To exercise any of these rights, email privacy@synabot.ai. If you are in the UK or EEA, you also have the right to complain to your local data protection authority. If you are a California resident, you have rights under the CCPA/CPRA including the right to know, delete and correct, and to opt out of the "sale" or "sharing" of personal information — we do not sell personal information.

Security

We use appropriate technical and organisational measures including encryption in transit, encrypted storage, access controls and row-level security to protect your personal data. No system is perfectly secure; please report suspected vulnerabilities to security@synabot.ai — see our Security & Vulnerability Reporting page.

Cookies and analytics

We use essential cookies to keep you signed in and secure. We use limited analytics cookies to understand aggregate usage of the Service. You can manage cookies through your browser settings.

Children

The Service is not directed at children under 16 and we do not knowingly collect personal data from them.

Changes to this notice

We may update this notice from time to time. We will notify you of material changes through the Service or by email.

Contact

SynaBot Inc., 16192 Coastal Highway, Lewes, Delaware 19958, USA — privacy@synabot.ai.

Google services and Limited Use

SynaBot only requests Google access needed for features you choose to connect. Analytics and Search Console access is read-only. Gmail access can read permitted mailbox context and create drafts using compose permission; SynaBot does not request Gmail send permission. Calendar access can create approved events, and Drive file access is limited to files SynaBot creates or that you explicitly select, including supported Google Sheets records.

Google data is used only to provide and improve the user-facing features you request. Its use and transfer comply with the Google API Services User Data Policy, including the Limited Use requirements. Connection credentials are encrypted, kept on the server, and removed locally when you disconnect; SynaBot also requests revocation from Google. External actions remain subject to SynaBot approval controls.