Privacy Policy

Last updated 24 August 2026

This policy explains what Synthopia collects, why, and who else touches it. It covers synthopia.ai and app.synthopia.ai.

Pixelated Vectors LLC is the controller of the personal data described here. You can reach us at hello@synthopia.ai.

What we collect

  • Account details. Your name, email address, and the brand, outlet and country you enter when you sign up.
  • Billing details. Your subscription status and a Stripe customer reference. Card numbers are entered on Stripe and never reach our servers.
  • Content you upload. Product photographs, logos, brand assets and any text you write in a brief.
  • Uploads made before you have an account. If you try the product as a guest, the photos and brief are stored against a private claim link so you can claim them when you sign up.
  • Information about your brand. When you give us your website address we read its public pages. If you connect Instagram we read that account's public posts. We do not read anything behind a login unless you connect the account yourself.
  • Usage and device information. Pages viewed, actions taken, IP address and browser user agent.
  • Advertising identifiers. If you arrive from one of our ads, the click identifier and advertising cookies described below.

Why we use it

  • To run the service: to generate creative from your photos, store it, and publish it where you ask us to.
  • To take payment and manage your subscription.
  • To send service email, and lifecycle email you can unsubscribe from at any time.
  • To understand how the product is used, so we can improve it.
  • To measure our own advertising, so we know which ads bring people who find the product useful.
  • To keep the service secure and to prevent abuse and fraudulent signups.

Who else processes your data

We use the following providers. Each receives only what it needs for its purpose.

ProviderPurposeWhat it receives
SupabaseDatabase, authentication and file storageAccount data, uploaded images, generated assets
VercelWebsite and application hostingRequest logs, IP addresses
RailwayBackground job workerJob payloads for generation runs
StripePayments and subscriptionsBilling details. Card numbers go to Stripe directly and never reach our servers
fal.aiImage and video generation modelsThe photos and briefs you submit for a generation
AnthropicLanguage models for copy, briefs and analysisBrand information and text you provide
FirecrawlReading your public website when you give us its addressPublic pages of the site you name
ApifyCollecting your public Instagram content when you connect itPublic posts from the account you name
ResendTransactional and lifecycle emailEmail address, delivery and open events
PostHogProduct analyticsPseudonymous usage events, IP address
MetaAdvertising measurement (pixel and Conversions API)Cookie identifiers, IP, user agent, hashed email
GoogleAdvertising measurement (Google Ads)Click identifier, conversion events
bundle.socialPublishing to social accounts you connectThe posts you choose to publish, and the tokens for those accounts

Advertising and analytics

We use the Meta pixel and the Meta Conversions API to measure our advertising. These record that a visit or a signup happened, along with cookie identifiers, your IP address, your browser user agent, and where you have given it to us, a version of your email address that has been hashed so Meta cannot read it. We use Google Ads in the same way, and PostHog for product analytics.

You can refuse advertising cookies in your browser, and most browsers let you block them entirely. Doing so does not change what the product does for you.

We do not sell your personal data, and we do not share your photographs or generated assets with advertising platforms.

Where your data is held

Our database, file storage and hosting run on infrastructure in the European Union and the United States. Our providers are located in the European Union, the United States and the United Kingdom, so your data is transferred outside the United Arab Emirates and processed there.

Where a provider handles data originating in the European Economic Area or the United Kingdom, that transfer relies on the European Commission's standard contractual clauses or an equivalent mechanism.

How long we keep it

We keep your account, your uploads and your generated assets for as long as your account is open, and for as long afterwards as we need them to meet tax and accounting obligations.

Uploads made before you have an account are stored against your claim link. We do not currently delete them automatically. If you used the product as a guest and want those photographs removed, email us and we will delete them.

You can ask us to delete your account and its content at any time.

Your rights

You can ask us for a copy of your data, ask us to correct it, ask us to delete it, or object to how we use it. Email hello@synthopia.ai and we will respond within 30 days.

If you are in the European Economic Area or the United Kingdom you also have the right to complain to your data protection authority.

Security

Access to production data is restricted, traffic is encrypted in transit, and tenant data is separated at the database level so one customer's data cannot be read by another.

No system is perfect. If a breach affects your personal data we will tell you and the relevant regulator as the law requires.

Children

Synthopia is a business product and is not intended for anyone under 18. We do not knowingly collect data from children.

Changes

If we change this policy we will update the date at the top, and for material changes we will tell you by email before they take effect.

Contact

Pixelated Vectors LLC, Dubai, United Arab Emirates. hello@synthopia.ai.