SynthForge SynthForge SynthForge IO

Privacy Policy

Last Updated: May 9, 2026

1. Introduction

This Privacy Policy explains how SynthForge ("we", "us", or "the Service") collects, uses, and protects your information when you use our synthetic data generation platform. We are committed to protecting your privacy and being transparent about our data practices.

2. Information We Collect

Account Information

When you create an account, we collect:

  • Email address
  • Password (stored securely using industry-standard hashing)
  • Name (if provided)
  • OAuth provider user ID (if you sign up with Google or GitHub)

User-Generated Content

When you use the Service, we store:

  • Database schemas you create or generate
  • Generated datasets and export files
  • Natural language descriptions you provide for AI schema generation

Usage Information

We automatically collect:

  • API usage and token consumption for AI features
  • Last active timestamp
  • Generation job history and status
  • Theme preferences

3. How We Use Your Information

We use your information to:

  • Provide and operate the Service
  • Process your schema and data generation requests
  • Send only account-related emails (verification, password reset)
  • Enforce usage limits and prevent abuse
  • Improve the Service and fix issues
  • Respond to support requests

4. Third-Party Services

Important: To provide AI-powered features, we share certain data with third-party AI providers. You should be aware of these data flows:

AI Providers (OpenAI, Anthropic)

When you use AI features, the following may be sent to AI providers:

  • Natural language descriptions you provide for schema generation
  • Schema structures for validation and improvement
  • Prompts generated by our system based on your inputs

AI calls are routed through Cloudflare AI Gateway, which logs request/response metadata for observability. These providers process data according to their own privacy policies. We recommend reviewing their policies if you have concerns about AI data processing.

Email Service

We use Cloudflare Email Sending to deliver transactional emails (verification, magic-link sign-in, password reset). Your email address is shared with Cloudflare's email infrastructure for the purpose of delivering these messages.

Google and GitHub OAuth

If you sign up with Google or GitHub, we receive your email, name, profile image, and provider user ID from the chosen provider. We do not receive your password or access to other services on those platforms.

Cloud Storage

Generated datasets are stored encrypted on Cloudflare R2 (object storage) for a limited retention window (currently around 24 hours from generation time) so you can download them, then automatically deleted. Files are private and scoped to your account.

Bot Defense

We use Cloudflare Turnstile on signup and password-reset forms. Turnstile uses signals from your browser (no tracking cookies) to confirm you are human; the result is shared with Cloudflare for the purpose of issuing the verification token.

5. Data Retention

  • Account data: Retained as long as your account is active. Deleted upon account deletion. You may delete your account at any time.
  • Generated datasets: Automatically deleted roughly 24 hours after generation. Download important data promptly.
  • Usage logs: Retained for operational purposes and may be aggregated for analytics.

6. Data Security

We implement security measures to protect your data:

  • Passwords are hashed using industry-standard algorithms
  • API keys for third-party services are stored as Wrangler secrets, encrypted at rest by Cloudflare
  • HTTPS encryption for all data in transit
  • Authentication required for all API access
  • Session cookies are HTTP-only, Secure, and scoped to the .synthforge.io domain

However, no method of transmission or storage is 100% secure. We cannot guarantee absolute security of your data.

7. Your Rights

Depending on your location, you may have rights to:

  • Correction: Request correction of inaccurate data
  • Deletion: Request deletion of your account and associated data
  • Export: Download your schemas and generated data

To exercise these rights, please contact us or use the account settings in the Service.

8. Cookies and Sessions

We use a single session cookie (named __Secure-sf-session in production) to keep you signed in. It is HTTP-only, Secure, and SameSite=None scoped to .synthforge.io so the marketing site, the app, and the API can recognize your session. We do not use third-party analytics or advertising cookies.

9. Children's Privacy

The Service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe we have collected such information, please contact us immediately.

10. International Data Transfers

Your data may be processed in countries other than your own, including the United States, where our service providers operate. By using the Service, you consent to such transfers.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify users of material changes by posting the updated policy on the website. Your continued use of the Service after changes constitutes acceptance of the new policy.

12. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us at info@synthforge.io.