Skip to content

Last updated July 22, 2026

Privacy policy

1. Controller

SyntarEngine Ltd, No. 3, Avenue des Orchidees, Quatre Bornes, Mauritius, is the controller of personal data processed through syntarengine.com and app.syntarengine.com (together, the "service"). Contact: info@syntarengine.com.

This policy covers visitors to our website and users of the platform. It does not cover the payment and buyer data processed by our merchant of record, which acts in its own right (section 4), or the personal data contained in the materials our business customers upload, for which the customer is the controller and we act as processor under our data processing addendum.

We are subject to the Mauritius Data Protection Act 2017. Where we offer the service to people in the EU, EEA, or UK, the GDPR and UK GDPR apply to that processing.

While we are established in Mauritius and do not maintain a physical presence within the European Union or the United Kingdom, we monitor our extraterritorial compliance obligations continuously. We are currently finalizing the formal appointment of our data protection representatives within both the EU and the UK pursuant to Article 27 of the GDPR and UK GDPR respectively. This section will be amended to publish their specific corporate identities and contact coordinates before the activation of customer registration interfaces and live payment transaction systems.

2. What we collect

Account data. Name, email address, organization, role, password hash, tier, and account settings.

Briefs and uploaded materials. The scripts, briefs, brand materials, and reference assets you upload. These may contain personal data, including images or recordings of real people; character assets built from a real person's likeness require that person's documented consent, which is held with the asset.

Generated output. The video, image, and audio output composed for you through the service, and the production history and decisions attached to your projects.

Usage and device data. Log data, IP address, browser and device information, feature usage, and diagnostic events, used to operate and secure the service.

Payment-related data. Payments are processed by our merchant of record (section 4). We do not receive your card number. We receive transaction metadata: tier purchased, amounts, currency, timestamps, country, and payment status, which we need for account provisioning and records.

Support communications. Messages you send to support and the context needed to resolve them.

Cookies and analytics data. Only as described in section 8, and for analytics only after your consent.

3. Purposes and legal bases

PurposeDataLegal basis
Providing the service: accounts, production pipeline, output delivery, supportAccount data, briefs and materials, output, support communicationsPerformance of a contract (GDPR Art. 6(1)(b))
Billing coordination and account provisioningPayment-related metadataPerformance of a contract (Art. 6(1)(b))
Securing the service: authentication, abuse and fraud prevention, diagnosticsUsage and device dataLegitimate interest (Art. 6(1)(f)): keeping the service secure and available
Preventing free-tier abuse by re-signup after erasureThe suppression token described in section 6Legitimate interest (Art. 6(1)(f)), documented in a legitimate interests assessment
Complying with legal obligations: accounting, tax, lawful requestsAccount and transaction recordsLegal obligation (Art. 6(1)(c))
Product analytics on the website and platformAnalytics dataConsent (Art. 6(1)(a)), via the banner in section 8
Service emails about your account, billing, and material changesAccount dataPerformance of a contract (Art. 6(1)(b))
Marketing emails, if you opt inAccount dataConsent (Art. 6(1)(a)); withdraw any time via the unsubscribe link

We do not use your briefs, uploaded materials, or generated output to train foundation models. Under our corporate agreements with the generative model providers listed in section 4, those providers do not use them to train their models either.

4. Processors and third parties

We share personal data with the following categories of recipients:

  • The merchant of record for all orders. Our designated merchant of record is the seller of record for your purchase and processes buyer and payment data in its own right, under its own terms and privacy policy, linked at checkout. We name the specific provider here once it is selected, before any transaction.
  • Google - foundation-model generation infrastructure that composes image, video, and audio output from your briefs and materials.
  • ElevenLabs - music, voice, and sound-effects generation that composes the audio tracks of your output.
  • Anthropic - the reasoning layer behind Cora, the AI Cinematographer, which processes your briefs and production instructions to direct the pipeline.
  • Vercel - hosting and deployment infrastructure for syntarengine.com and app.syntarengine.com.
  • Supabase - database and storage infrastructure for the platform, holding account data, briefs and uploaded materials, and generated output.
  • Railway - cloud compute infrastructure running the production pipeline and its workflow state, processing your briefs and materials into output.
  • Google Tag Manager and analytics - fires only after consent (section 8).
  • Professional advisers and authorities - shared where strictly required for regulatory compliance, professional auditing, the defense of legal claims, or corporate restructuring. These recipients process personal data as independent controllers under their own statutory and professional frameworks, limited strictly to what is necessary.

Except for the merchant of record and our professional advisers and authorities, which act as independent controllers, these recipients process personal data on our documented instructions as processors.

International transfers. We operate from Mauritius and use processors in other countries, so personal data is processed outside your country of residence. For personal data of people in the EU, EEA, or UK, we rely on the following safeguards: transfers to our processors are governed by the European Commission's Standard Contractual Clauses (and the UK addendum or IDTA, as applicable) together with transfer risk assessments, or by an adequacy decision where one covers the recipient; the transfer to us as controller in Mauritius, for account execution and core pipeline operations where you contract with us directly, relies on contractual necessity (Art. 49(1)(b)), while any non-essential transfer for product optimization or site analytics relies on your explicit consent (Art. 49(1)(a)) collected via our consent banner. Mauritius additionally regulates our handling of your data under the Data Protection Act 2017. You can request a copy of the relevant safeguards via info@syntarengine.com.

5. Retention

DataRetention
Account dataLife of the account, then deleted within 90 days of closure, except records we must keep for legal obligations
Briefs, uploaded materials, generated outputPer the asset-retention terms of your tier while the account is active; deleted within 90 days of account closure, subject to the export window in the terms of service
Trial content90 days after Production completion or last activity, then read-only; deleted within 90 days of account closure
Usage and device logs12 months
Support communications24 months after the ticket closes
Transaction recordsAs required by Mauritian accounting and tax law (typically 7 years), held as records, not for any other purpose
Erasure-suppression token (section 6)12 months, with a technically enforced time-to-live; the token cannot outlive the window
Analytics dataPer the configured analytics retention, not exceeding 14 months

Where we anonymize data so it can no longer be linked to you, we may retain it in that form.

6. Erasure and your rights

Erasure. When you ask us to erase your personal data, we erase it immediately. Erasure runs at the time your request is confirmed, not on a schedule. It covers your account, your briefs and uploaded brand materials, your generated output, and your Asset Library. Residual copies in encrypted backups expire on the backup rotation cycle and, if a backup is ever restored, the erasure is re-applied.

The suppression token. One narrow record survives erasure: a suppression token. It is a keyed cryptographic code derived from your email address. The key is stored separately in a hardened key-management system, the token contains no readable personal data, and it cannot be reversed into your email address. Its only purpose is anti-abuse: it lets us recognize that an email address recently went through erasure, so that a free-tier account cannot be immediately re-created on the same address to obtain another free Production. It is not used for anything else - not for marketing, not for analytics, and not for profiling - and it never affects a paid subscription. Once the token expires, or if you sign up on a paid tier, it does not stand in your way.

We keep the token for 12 months, on the legal basis of legitimate interest (Article 6(1)(f) GDPR: keeping the right to erasure effective and protected from abuse), documented in a legitimate interests assessment. Deletion after 12 months is enforced by the system itself, not by a manual process. You can object to this processing at any time; see "Objecting to processing" below.

Some records sit outside this erasure process because statutory corporate, financial, and tax laws require their continuous preservation: specific transaction metadata, invoicing details, and corporate accounting summaries are held securely by us and our merchant of record for our respective statutory retention periods (typically up to 7 years under Mauritian corporate law).

Objecting to processing. You can object at any time to processing we base on legitimate interest. In this policy, that is one thing: the suppression token described above.

To object, write to privacy@syntarengine.com with "objection" in the subject line. We respond within one month.

Our default is to uphold the objection: unless the specific token is tied to an active investigation into free-tier abuse, we delete it early and confirm the deletion to you. If we believe compelling legitimate grounds require keeping it, we will explain those grounds in our response, and you can lodge a complaint with your supervisory authority.

Your rights. If you are in the EU, EEA, or UK, or where Mauritian law grants equivalent rights, you can:

  • Access the personal data we hold about you and receive a copy;
  • Rectify inaccurate or incomplete data;
  • Erase your data, as described above;
  • Restrict processing while a dispute about the data is resolved;
  • Port the data you provided to us in a structured, commonly used, machine-readable format;
  • Object to processing based on legitimate interest, including the suppression token, as described under "Objecting to processing" above;
  • Withdraw consent at any time where processing is based on consent, without affecting processing before withdrawal.

To exercise any right, contact privacy@syntarengine.com. We respond within one month, extendable by two further months for complex requests, and we will tell you if we extend. We may need to verify your identity before acting.

Complaints. You can lodge a complaint with your local supervisory authority: in the EU/EEA, the data protection authority of your country of residence; in the UK, the Information Commissioner's Office; in Mauritius, the Data Protection Office. We would appreciate the chance to address your concern first, but you are not required to contact us before complaining.

7. Security

We protect personal data with technical and organizational measures appropriate to the risk, including encryption in transit and at rest, role-based access controls and least-privilege access for staff, separation of the suppression-token key in a key-management system, logging and monitoring of production access, and tested backup and recovery procedures. No system is perfectly secure; if a breach occurs that risks your rights and freedoms, we will notify the competent authority and, where the risk is high, notify you directly, in the timeframes applicable law requires.

8. Cookies and consent

When you first visit, a consent banner offers accept and decline with equal prominence. Essential cookies run without consent because the site cannot function without them; everything else waits for your choice. Analytics, loaded via Google Tag Manager, fires only after you consent. We run no marketing or advertising pixels at launch. You can change your choice at any time via the cookie settings link in the footer.

Cookie categoryExamplesPurposeDuration
EssentialSession and authentication cookies, consent stateSign-in, security, remembering your consent choiceSession, or up to 12 months for the consent record
Analytics (consent only)Google Tag Manager, analytics identifiersUnderstanding how the site and platform are used, in aggregateUp to 14 months

The specific cookies in each category at launch:

CookieProviderCategoryPurposeDuration
_gaGoogle AnalyticsAnalytics (consent only)Distinguishes visitors, in aggregateUp to 2 years
_ga_<container-id>Google Analytics 4Analytics (consent only)Persists GA4 session stateUp to 2 years
Consent state (syntar-*)SyntarEngineEssentialRemembers your accept or decline choiceUp to 12 months
Session and authenticationSyntarEngine, SupabaseEssentialSign-in and securitySession

The _ga cookies persist up to 2 years but carry only aggregate analytics identifiers; the analytics data they feed is retained for at most 14 months (section 5). Cookie names and exact durations are confirmed against the built site before launch.

9. Changes and contact

We will update this policy as the service and the law evolve. Material changes are announced by email to account holders and by a notice on the site at least 14 days before they take effect; the "updated" date above always reflects the current version. General questions: info@syntarengine.com. Privacy rights and objections: privacy@syntarengine.com. Postal address: SyntarEngine Ltd, No. 3, Avenue des Orchidees, Quatre Bornes, Mauritius.