Privacy Policy
Last updated 24 August 2026
This policy explains what Synthopia collects, why, and who else touches it. It covers synthopia.ai and app.synthopia.ai.
Pixelated Vectors LLC is the controller of the personal data described here. You can reach us at hello@synthopia.ai.
What we collect
- Account details. Your name, email address, and the brand, outlet and country you enter when you sign up.
- Billing details. Your subscription status and a Stripe customer reference. Card numbers are entered on Stripe and never reach our servers.
- Content you upload. Product photographs, logos, brand assets and any text you write in a brief.
- Uploads made before you have an account. If you try the product as a guest, the photos and brief are stored against a private claim link so you can claim them when you sign up.
- Information about your brand. When you give us your website address we read its public pages. If you connect Instagram we read that account's public posts. We do not read anything behind a login unless you connect the account yourself.
- Usage and device information. Pages viewed, actions taken, IP address and browser user agent.
- Advertising identifiers. If you arrive from one of our ads, the click identifier and advertising cookies described below.
Why we use it
- To run the service: to generate creative from your photos, store it, and publish it where you ask us to.
- To take payment and manage your subscription.
- To send service email, and lifecycle email you can unsubscribe from at any time.
- To understand how the product is used, so we can improve it.
- To measure our own advertising, so we know which ads bring people who find the product useful.
- To keep the service secure and to prevent abuse and fraudulent signups.
Who else processes your data
We use the following providers. Each receives only what it needs for its purpose.
| Provider | Purpose | What it receives |
|---|---|---|
| Supabase | Database, authentication and file storage | Account data, uploaded images, generated assets |
| Vercel | Website and application hosting | Request logs, IP addresses |
| Railway | Background job worker | Job payloads for generation runs |
| Stripe | Payments and subscriptions | Billing details. Card numbers go to Stripe directly and never reach our servers |
| fal.ai | Image and video generation models | The photos and briefs you submit for a generation |
| Anthropic | Language models for copy, briefs and analysis | Brand information and text you provide |
| Firecrawl | Reading your public website when you give us its address | Public pages of the site you name |
| Apify | Collecting your public Instagram content when you connect it | Public posts from the account you name |
| Resend | Transactional and lifecycle email | Email address, delivery and open events |
| PostHog | Product analytics | Pseudonymous usage events, IP address |
| Meta | Advertising measurement (pixel and Conversions API) | Cookie identifiers, IP, user agent, hashed email |
| Advertising measurement (Google Ads) | Click identifier, conversion events | |
| bundle.social | Publishing to social accounts you connect | The posts you choose to publish, and the tokens for those accounts |
Advertising and analytics
We use the Meta pixel and the Meta Conversions API to measure our advertising. These record that a visit or a signup happened, along with cookie identifiers, your IP address, your browser user agent, and where you have given it to us, a version of your email address that has been hashed so Meta cannot read it. We use Google Ads in the same way, and PostHog for product analytics.
You can refuse advertising cookies in your browser, and most browsers let you block them entirely. Doing so does not change what the product does for you.
We do not sell your personal data, and we do not share your photographs or generated assets with advertising platforms.
Where your data is held
Our database, file storage and hosting run on infrastructure in the European Union and the United States. Our providers are located in the European Union, the United States and the United Kingdom, so your data is transferred outside the United Arab Emirates and processed there.
Where a provider handles data originating in the European Economic Area or the United Kingdom, that transfer relies on the European Commission's standard contractual clauses or an equivalent mechanism.
How long we keep it
We keep your account, your uploads and your generated assets for as long as your account is open, and for as long afterwards as we need them to meet tax and accounting obligations.
Uploads made before you have an account are stored against your claim link. We do not currently delete them automatically. If you used the product as a guest and want those photographs removed, email us and we will delete them.
You can ask us to delete your account and its content at any time.
Your rights
You can ask us for a copy of your data, ask us to correct it, ask us to delete it, or object to how we use it. Email hello@synthopia.ai and we will respond within 30 days.
If you are in the European Economic Area or the United Kingdom you also have the right to complain to your data protection authority.
Security
Access to production data is restricted, traffic is encrypted in transit, and tenant data is separated at the database level so one customer's data cannot be read by another.
No system is perfect. If a breach affects your personal data we will tell you and the relevant regulator as the law requires.
Children
Synthopia is a business product and is not intended for anyone under 18. We do not knowingly collect data from children.
Changes
If we change this policy we will update the date at the top, and for material changes we will tell you by email before they take effect.
Contact
Pixelated Vectors LLC, Dubai, United Arab Emirates. hello@synthopia.ai.