Privacy Policy

Last updated: March 18, 2026

← Back to homeRead our Terms of Service

1. Who We Are

Synthsize is a product of Cold Start Lab, a sole proprietorship based in California. We build tools that help founders clarify and act on their business strategy.

Questions about this policy: hello@synthsize.io

2. Information We Collect

Account information

When you register, we collect your email address. Your name is optional and only stored if you provide it.

Business information

The core of Synthsize is a structured conversation about your business. Everything you share — your market, customers, revenue, goals, challenges — is stored as your business profile and used to generate your strategic artifacts. This is the data you intentionally give us to do the job.

Usage data

We log which pages you visit, features you use, and when sessions occur. This helps us improve the product and understand how it's being used.

IP address and approximate location

We collect your IP address when you use the Service. We use IP geolocation (resolved locally on our servers — we do not send your IP to a third-party geolocation service) to derive your approximate city and country. This is used for profile view analytics (e.g., “your public profile was viewed from Austin, TX”). We do not track precise location.

Payment information

Payments are processed by Stripe. We do not store your card number, CVV, or full billing address. We do store your Stripe customer ID, subscription status, and subscription period dates in our database to manage your account tier and billing history.

Public profile data

If you have a public business profile page (at synthsize.io/co/your-slug), we record when that page is viewed, including the viewer's approximate location and referral source. You can see this data in your account. Profile pages are opt-in and can be unpublished at any time.

3. How We Use Your Information

  • Provide and operate the Service — generating your business documents and artifacts
  • Manage your account, subscription, and billing
  • Send transactional emails: magic link sign-in, account confirmations
  • Send product emails: summaries of new artifacts generated in your sessions, re-engagement reminders if you haven't visited in a while, upgrade prompts when you approach usage limits. You can opt out of these at any time via the unsubscribe link in any email.
  • Show you analytics about your public profile page views
  • Detect and prevent abuse, fraud, and security incidents
  • Improve the product using aggregated, anonymized usage patterns
  • Comply with legal obligations

We will not use your data for purposes materially different from those listed above without notifying you first.

4. AI Processing

Your business information is sent to Anthropic's Claude API to power the AI conversation and artifact generation. Specifically:

  • We do not use your data to train our own AI models
  • Anthropic processes API requests under their Privacy Policy and Usage Policy. Under their API terms, data sent via the API is not used to train their models by default.
  • The “operator intelligence” layer — our internal scoring, question sequencing, and artifact selection logic — is never exposed to users or third parties

5. Data Storage and Security

Your data is stored in the following places:

  • Primary database: PostgreSQL (with TimescaleDB) hosted on a private VPS in the United States. Accessible only over an encrypted private network.
  • Generated PDF artifacts: Stored in Backblaze B2 object storage (US East region). PDFs are accessed via time-limited signed URLs (24-hour expiry).
  • Email delivery: Transactional and product emails are sent via DreamHost SMTP infrastructure.
  • Payments: Stripe (US-based). Subject to Stripe's Privacy Policy.

All data is transmitted over TLS. We maintain regular backups. Access to production systems is restricted to authorized personnel only.

6. Data Retention

We retain your account and business data for as long as your account is active.

Account deletion is handled as a soft delete: your data is marked inactive and hidden from all product surfaces within 24 hours of your request. Complete purge of personal data occurs within 30 days, except for:

  • Billing records, which are retained for up to 7 years as required by law
  • Anonymized, aggregated data (not linkable to you) retained indefinitely to improve the Service

To request account deletion, email hello@synthsize.io.

7. Sharing Your Information

We do not sell your personal data. We share it only in these circumstances:

  • Anthropic — to process AI requests on your behalf (see Section 4)
  • Stripe — to process payments and manage your subscription
  • Backblaze — to store and serve your generated PDF artifacts
  • DreamHost — to deliver email to you
  • Legal requirements — when required by law, court order, or government authority
  • Business transfers — in the event of a merger or acquisition, we will notify you by email before your data is transferred to a different privacy policy

All processors listed above are contractually bound to protect your data and use it only as directed.

8. Your Rights

You have the right to:

  • Access — request a copy of the data we hold about you
  • Correction — request that we fix inaccurate or incomplete data
  • Deletion — request deletion of your account and personal data
  • Portability — request an export of your business profile and artifacts
  • Opt-out of marketing email — unsubscribe at any time via the link in any email we send, or by emailing us directly
  • Unpublish your profile page — remove your public /co/ page at any time from your account settings

Contact us at hello@synthsize.io to exercise any of these rights. We will respond within 30 days.

9. Cookies and Session Storage

We use a minimal set of browser storage mechanisms:

  • Session cookie: Required for authentication. Set by NextAuth, cleared on sign-out.
  • Local storage: Used to persist your in-progress session state between page loads (e.g., your last conversation response). Cleared when you sign out.

We do not use tracking cookies, advertising cookies, or third-party analytics that share your data with external ad networks. We run our own self-hosted analytics (Umami) which collects anonymized, aggregate page view data only.

10. Children

Synthsize is not directed at users under 18. We do not knowingly collect data from minors. If you believe a minor has created an account, contact us at hello@synthsize.io and we will delete the account promptly.

11. Changes to This Policy

We may update this policy as the product evolves. For material changes, we will notify you by email at least 14 days before they take effect. The “last updated” date at the top of this page always reflects the current version.

12. Contact

Questions, concerns, or requests: hello@synthsize.io

Cold Start Lab · El Dorado County, California

← Back to homeTerms of Service