01Introduction
Synthesis Intelligence, Inc. ("we," "us," or "our") operates the Synthesis platform ("Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.
02Information We Collect
Account Information. When you create an account, we collect your email address, name, and organization name.
Brand Data. When you connect data sources (Amazon, Shopify, Meta, etc.), we access and process your business data including sales, orders, advertising metrics, and customer analytics. This data is used solely to provide the Service to you.
Usage Data. We collect information about how you interact with the Service, including queries, session data, and feature usage.
Third-Party Platform Data. We access data from platforms you connect, including:
- Amazon Seller Central (orders, revenue, inventory, customer analytics)
- Shopify (orders, customers, products)
- Meta / Facebook (advertising performance, ad creative data)
- Google Ads (campaign and keyword performance — see below)
- Google Analytics (GA4 sessions, traffic sources and conversions — see below)
- Google Search Console (search queries, impressions and clicks — see below)
- Google Sheets and Google Drive (only the files you choose to share with Synthesis — see below)
- Google Trends (search interest data)
- Other marketplaces, storefronts, advertising, email, subscription, support, creator and finance platforms you connect. The full list is on our Integrations page.
Google services. Each Google connection asks for one read-only permission and nothing more:
- Google Ads —
https://www.googleapis.com/auth/adwords. We read campaign and keyword performance only — campaign name, status and channel type; ad group and keyword text and match type; and the metrics impressions, clicks, cost, conversions, all conversions and conversion value, segmented by day. We never create, edit, pause, bid on, or otherwise modify any campaign, ad, keyword or budget, and we perform no mutate operations of any kind. - Google Analytics —
https://www.googleapis.com/auth/analytics.readonly. We read aggregated GA4 reports for the property you choose: sessions, users, new users, conversions, transactions and purchase revenue by day and by traffic channel. We do not read or store individual visitor identifiers. - Google Search Console —
https://www.googleapis.com/auth/webmasters.readonly. We read search performance for the site you choose: queries, pages, device and country, with impressions, clicks and average position by day. - Google Sheets and Google Drive —
https://www.googleapis.com/auth/drive.file. This permission only covers the files or folders you pick in the Google file chooser, or a folder you share with the Synthesis service address shown on your Connections page. We read the contents of those files, and re-read a shared folder on a schedule so new files in it are picked up; we cannot see, list or open anything else in your Drive.
How we handle Google user data. Data obtained through any Google API is used solely to provide reporting and analytics back to the customer who authorized the connection. It is stored in that customer's dedicated, isolated Google BigQuery dataset in the United States, encrypted in transit (TLS) and at rest. It is never sold, rented, or used for advertising or targeting. It is never used to develop, improve or train any machine-learning or AI model, generalized or otherwise, and it is excluded from the answer review described in Section 03. It is not combined with, or disclosed to, any other customer. OAuth refresh tokens are stored encrypted in Google Cloud Secret Manager. You may revoke our access at any time from the Connections page in Synthesis, or from your Google Account permissions page at myaccount.google.com/permissions; on revocation we stop syncing immediately. On request or on account termination, all Google-sourced data is deleted within 30 days. Synthesis Intelligence's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
03How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the Service
- Generate strategic intelligence, analytics, and recommendations for your brand
- Process and store your business data in secure cloud infrastructure
- Improve and personalize your experience
- Communicate with you about the Service
How we improve Synthesis. When you flag or rate an answer, our team reviews that answer and the reasoning behind it — which sources were read, which checks were run, and where the reasoning went wrong — to improve how Synthesis reasons for every customer. In that review your figures stay in your own workspace and are never shown to another customer, and nothing built from it can reveal your data to anyone else. No third-party model provider trains on your data. Data obtained from Google services is excluded from this review entirely (see Section 02).
04Data Isolation & Security
We implement industry-standard security measures to protect your data:
- Tenant Isolation. Each organization's data is stored in separate, isolated database containers. No organization can access another organization's data.
- Authentication. All API access requires cryptographic JWT tokens verified on every request.
- Encryption. Data is encrypted in transit (TLS/SSL) and at rest (Google Cloud encryption).
- Access Control. Role-based access control limits data access within organizations.
- Secret Management. API credentials and secrets are stored in Google Cloud Secret Manager, not in application code.
- SQL Validation. All database queries are validated against authorized datasets before execution to prevent cross-tenant data access.
05Data Storage
Your data is stored on Google Cloud Platform infrastructure in the United States. We use:
- Google BigQuery for business analytics data
- Google Firestore for application data (sessions, settings, memory)
- Google Cloud Run for application hosting
06Data Sharing
We do not sell, trade, or rent your personal or business data to third parties. We may share data only:
- With your explicit consent
- With service providers who assist in operating the Service (e.g. cloud infrastructure providers), bound by confidentiality agreements
- To comply with legal obligations or protect our rights
07Third-Party Services
Our Service integrates with third-party platforms and AI providers:
- Anthropic (Claude). AI language model for analysis and recommendations. Your queries and brand context are processed by Anthropic's API. See Anthropic's Privacy Policy.
- OpenAI. Secondary AI model for analysis. See OpenAI's Privacy Policy.
- Advertising data and AI providers. Where you have connected Google Ads, Google Ads performance data may be included in the brand context processed by these AI providers in order to generate your analytics. These providers act as our service providers under confidentiality obligations and do not use your data to train their models.
- Google Cloud. Infrastructure and data storage. See Google Cloud Privacy.
- Firebase. Authentication services. See Firebase Privacy.
- Stripe. Payment processing for subscriptions. Stripe receives your billing details directly; we never see or store your card number. See Stripe's Privacy Policy.
- Sentry. Error monitoring, so we find faults before you report them. Personal-data reporting is disabled. See Sentry's Privacy Policy.
- Cal.com. Demo scheduling. Receives only the name, email and time you enter when you book. See Cal.com's Privacy Policy.
- Google Workspace. The email we send you — reports, alerts and replies to your requests — is sent and stored through Google Workspace.
This list is the current set of sub-processors. Where another policy of ours refers to “the list maintained in our Privacy Policy”, this is that list.
07bThe AI assistant you connect
Synthesis is designed to be used from inside an AI assistant you choose and control — Claude, ChatGPT, Perplexity, Slack and others that speak the Model Context Protocol. This matters for your privacy, so we state it plainly:
- When you connect Synthesis to one of those assistants and ask it a question, that assistant sends the question to us, we answer from your data, and the answer — including the figures in it — is delivered into that assistant.
- Once it arrives there, it is held under that vendor's terms and privacy policy and your own account settings with them, not ours. If you are on a consumer plan that trains on your conversations, that is a setting on their side and we cannot change it for you.
- You decide which assistants are connected, and you can revoke a connection at any time from your Synthesis account. We never connect one on your behalf.
- We do not send your data to any AI assistant you have not connected.
This is separate from the model providers listed above, which we use ourselves to generate your analysis and which do not train on your data.
08Data Retention
We retain your data for as long as your account is active or as needed to provide the Service. You may request deletion of your data at any time by contacting us. Upon account termination, we will delete your data within 30 days, except as required by law.
09Your Rights
You have the right to:
- Access your personal and business data
- Request correction of inaccurate data
- Request deletion of your data
- Disconnect third-party data sources at any time
- Export your data in a machine-readable format
10Children's Privacy
The Service is not intended for individuals under the age of 18. We do not knowingly collect information from children.
11Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the updated policy on this page with a revised "Last updated" date.
12Contact Us
If you have questions about this Privacy Policy or our data practices, contact us at: