Effective date: 31 May 2026 Last updated: 31 May 2026 Version: 2.0
Plain-language summary (not a substitute for the policy below). SynergyAI is an orchestration layer. We collect the minimum needed to run the Service: your account identity, your usage and billing records, the prompts and content you create, and the credentials you connect (which we store encrypted and never return to your browser). To do what you ask, we route your prompts and inputs to AI model providers, and we act on the third-party accounts you connect — those third parties handle your data under their own policies. We do not sell your personal data, and we do not use your content to train our own AI models. This summary is qualified in its entirety by the full policy.
This Privacy Policy should be read together with our Terms of Service.
1.1 Who we are. SynergyAI ("SynergyAI", "we", "us", "our") operates the AI agent orchestration platform at synergyai.studio and its web app, APIs, and inbound chat surfaces (Telegram, Slack, and email). This policy applies to all Users of the Service worldwide.
1.2 Our dual role.
1.3 Model providers are independent controllers/processors. Foundation- and generative-model providers and the third-party services you connect determine their own processing under their own policies (Section 5 and the Processor Table). We are not responsible for their practices.
1.4 Contact. Privacy questions, requests, and complaints: contactus@synergyai.studio. We are based in Vadodara, Gujarat, India; our registered address and Grievance Officer details are in Section 14.
1.5 Governing law for this policy. This policy and any dispute relating to it are governed by the laws of India, and any proceeding shall be brought exclusively in India (Vadodara, Gujarat), to the maximum extent permitted by applicable law, consistent with Section 15 of the Terms of Service.
2.1 Account and identity data. When you sign in with Google OAuth (via Supabase Auth) we receive and store your name, email address, profile picture, and a stable account identifier. We use this to identify your account and communicate about the Service.
2.2 Prompts, inputs, and generated content. The instructions, prompts, messages, uploaded files and reference media, and the resulting outputs you create. Generated content and its associated prompt are stored together so you can access your work; deleting an item deletes its associated prompt. Conversational messages are retained as needed to provide context and history for your agents and may be deleted by you (see Section 6).
2.3 Connected-service credentials. The credentials you provide to connect third-party services — OAuth access/refresh tokens, bring-your-own-client OAuth client_id/client_secret, API keys, the Telegram bot token, IAM access keys/secrets/service-account JSON, and per-user MCP OAuth tokens. These are stored encrypted in our vault, referenced only by an opaque identifier, decrypted server-side only to perform actions you authorize, and never returned to your browser or written to logs (Section 8 and Terms §9).
2.4 Connected-service data in transit. When an agent acts on a service you connected (e.g. reading an email thread, a spreadsheet row, an ad metric, a file, or a CRM record), that data passes through our systems to fulfill your request and to return results to you. We retain only what is operationally necessary (e.g. short-lived caching, run context/history, or output you chose to save); it is not retained beyond what the feature requires and is flushed/rendered unusable on disconnect (Section 6).
2.4a Meta advertising connector — permissions. When you connect your Meta (Facebook/Instagram) advertising account to use the Ads Manager, you authorize, through Facebook Login, the Meta permissions you approve, which may include: ads_read (read your ad accounts, campaigns, ad sets, ads, and their performance metrics); ads_management (create, pause/resume, and edit the campaigns and budgets you direct, and create new campaigns in a paused state for your review); business_management (list and select the Business Manager ad accounts you own or have been granted access to); pages_read_engagement (read the Facebook Pages you manage and their basic identity/engagement information, so that ads can be correctly associated with and displayed under the right Page); and public_profile and Business Asset User Profile Access (your basic profile and the identity that links your connected ad accounts to your Synergy AI account). We use these permissions only to operate the Ads Manager for you, on accounts you own or are authorized to manage; we do not post to your Pages, and we do not use this data for any other purpose. Disconnecting the service (Section 6) revokes our access and renders the stored tokens unusable.
2.5 Usage, billing, and ledger data. Your Vortex Coin balance and a ledger of purchases and deductions (action type, cost, timestamp, transaction reference), and payment-status metadata from Razorpay. We do not receive or store your full card details.
2.5a Voice and audio data. If you use voice features, we process audio you provide. In particular, the voice-cloning feature requires you to upload a short voice sample; we store that sample in our cloud storage and send it to our video/voice model provider (Kling AI / Kuaishou) to create a reusable voice model, which is then used to generate speech in your videos. Voice samples can be biometric/sensitive data. You must only upload a voice you own or have the documented consent of the person to use (Terms §6.6). Do not upload anyone's voice you are not entitled to use. You can delete stored voice samples and voice models from your account.
2.5b Live voice conversations (realtime audio). Some features let you talk with the Service in real time using your microphone — for example voice chat, the spoken modes of Live Debate/argue, coaching and interview practice, the Neural Network voice interview, and the autobiography/ghostwriter mode. When you start a live voice session, your live microphone audio is streamed directly from your browser to our realtime-voice provider, OpenAI (the OpenAI Realtime API), over an encrypted connection, where it is transcribed and answered in real time, and the spoken reply is streamed back to you. We mint a short-lived session token on the server; the audio itself flows between your browser and OpenAI and is processed under OpenAI's terms and policies. We do not record or store the raw audio of these live sessions on our own servers; depending on the feature, a text transcript or summary may be retained (for example, to score a coaching session, or to build your Neural Network profile if you have enabled it). These conversational and voice features are not a medical, mental-health, therapy, or crisis service (Terms §6.9); if you may be in crisis, contact local emergency services or a qualified professional. Only provide audio you are entitled to provide, and do not use another person's voice without their consent (Terms §6.6).
2.6 Agent configuration and memory. Agent definitions, routines, schedules, reminders, and the operational memory/observation records that let agents maintain context across runs.
2.6a Psychological and behavioral inferences (optional "Neural Network" mode). If — and only if — you turn on Neural Network mode, the Service builds and stores a model of you from your activity, which may include inferred psychological and behavioral attributes (for example, personality traits, communication style, preferences, goals, and similar signals drawn from frameworks such as the Big Five). This is an optional feature you control:
These inferences are used only to personalize your experience within the Service. We do not sell them, do not use them to train our own models, and do not share them other than with the infrastructure and model sub-processors needed to operate the feature for you. These inferences are not a clinical, psychological, or mental-health assessment (Terms §6.9) and should not be relied on as one. You can delete all of this at any time via the in-product wipe or the Delete my data control (Section 6.4).
2.7 Technical, analytics, and security data. Server-side logs including IP address, device/browser type, request timestamps, and diagnostic events, used for security, debugging, rate-limiting, and abuse prevention. We also collect first-party product analytics (such as page views, session-start events, and JavaScript-error reports) into our own systems to operate and improve the Service. We do not use third-party advertising or cross-site tracking SDKs.
2.7a Third parties in your Inputs. Your prompts and uploads may contain personal data about other people (for example, a photo, a voice recording, or contact details). Where they do, you are responsible for having a lawful basis and any required consent to provide that data to us and to the providers that process it (Terms §6.6); with respect to that data, you act as its controller and we act as your processor.
2.8 Inbound chat surface data. When you use Telegram, Slack, or email to talk to SynergyAI, we process the identifiers and message content needed to link the surface to your account and to act on your messages.
2.9 Support and communications. Information you provide when you contact us.
We do not intentionally collect special-category/sensitive personal data and ask that you not submit it unless necessary for a task you direct.
We use personal data to:
3.1 Autonomous agent processing. When you run an agent, your prompts, instructions, agent configuration, persistent agent memory, and the connected-service data needed for the task are processed by our autonomous agent runtime (the Hermes runtime, operated on our Modal compute) to plan and execute multi-step tasks. To carry out your instructions the runtime may, at your direction, search and browse the web, read/write/delete files, execute code in a sandbox, generate media, send messages, schedule runs, delegate to sub-agents, and invoke MCP servers and reusable "skills" (including third-party/community skills we do not control). Persistent agent memory (used to give agents continuity across sessions) is stored in our own systems and is deleted when you delete the relevant data or your account (Section 6.4). These processing activities occur only to deliver what you asked the agent to do.
3.2 Automated decision-making. Agents act under your instruction and configuration, and you can review, limit, pause, or stop them at any time. We do not subject you to decisions producing legal or similarly significant effects about you that are based solely on automated processing without a lawful basis; where you direct agents to act on others, you are responsible for the lawfulness of that processing (Section 2.7a, Terms §6).
3.3 Automated child-safety screening. To keep child sexual content off the platform, every input you submit on every surface — prompts, chat messages, and uploaded images — is passed through an automated child-safety screen before it is processed. This screen uses OpenAI's moderation service (and, where configured, a known-CSAM image hash-match) solely to detect child sexual content; a positive detection is refused, recorded to a tamper-resistant log, preserved, and reported (Terms §4.2a). This applies even in Forget & Burn / zero-retention mode: while ordinary burn-mode content is never stored, a child-safety detection is the one exception — we record the account identity (the user who made the request), the time, and the offending input, in a log that Burn mode and "Delete my data" cannot erase, so the attempt is preserved for reporting. Burn mode is not a way to make such a request anonymous or unrecorded. This is the only content category we screen for ourselves — we do not screen for or restrict lawful adult, violent, or other mature creative content. The screen means your input text and images are transmitted to our moderation provider for this safety check in addition to the model provider that fulfills your request.
Legal bases (GDPR/UK GDPR, where applicable): performance of our contract with you (Art. 6(1)(b)); our legitimate interests in securing, improving, and protecting the Service (Art. 6(1)(f)); your consent where required, e.g. for any optional marketing or non-essential processing (Art. 6(1)(a)); and compliance with legal obligations (Art. 6(1)(c)). Under India's DPDP Act, we process on the basis of your consent and for legitimate uses as permitted by that Act.
4.1 No sale; no sharing for cross-context behavioral advertising. We do not sell your personal data, and we do not "share" it for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act as amended (CCPA/CPRA). We do not maintain advertising cookies or third-party ad trackers (Section 9). Accordingly there is nothing to opt out of in that sense, but you may still exercise your rights under Section 7, and you may submit a "Do Not Sell or Share My Personal Information" request to contactus@synergyai.studio; we will confirm our no-sale/no-share posture.
4.2 No training on your content by us. We do not use your prompts, inputs, connected-service data, or generated content to train, fine-tune, or improve our own AI models.
4.3 Third-party model providers. We cannot control whether a third-party model provider uses content you submit for its own purposes; each provider's policy governs, and we select providers and configurations with the aim of limiting such use where options exist. Review each provider's policy in the Processor Table.
4.4 Privacy by default — minimal sharing, no identity leakage. Our default posture is to share nothing about you with anyone you have not chosen to engage, beyond the infrastructure sub-processors strictly necessary to run the Service (Table A) and disclosures required by law. When we route a request to a foundation- or generative-model provider, we transmit only the content reasonably necessary to fulfill that request and, except where a feature technically requires it, we do not attach your account identity (such as your name or email) to that request — so, for example, a model provider processing your prompt does not receive your SynergyAI username or email from us. Data flows to a connected third-party service only because you connected it and instructed an action on it.
4.5 Our commitments cover our own systems. The protections and standards described in this policy apply to your data while it is within SynergyAI's own systems. Once data is transmitted to, or returned from, a third party at your direction — a model provider, a service you connected, an MCP server, or a sub-processor — that third party handles it under its own policy, and we are not responsible for how it receives, returns, stores, secures, or uses your data, or for the accuracy of what it returns. The links in the Processor Table are provided as a convenience to help you review those third parties' practices; they are not our representations about those third parties (see Terms §2.5).
To deliver the Service, your data is processed by three categories of third party, each listed with links in the Third-Party Processor Table at the end of this policy:
We disclose personal data only: (a) to these processors/recipients to operate the Service; (b) at your direction; (c) to comply with law or lawful process, or to protect rights, safety, and the integrity of the Service; or (d) in connection with a merger, acquisition, financing, or sale of assets, subject to this policy. We do not otherwise disclose your personal data.
5.1 Law-enforcement and legal requests. As an intermediary, we cooperate with valid legal process. In response to a court order, warrant, or a lawful request from an authorized government or law-enforcement authority (including under India's IT Act and the Bharatiya Nagarik Suraksha Sanhita / Code of Criminal Procedure), and as permitted by the DPDP Act, 2023 and other applicable law, we may preserve and disclose information we hold about an account — including the account's name and email, IP addresses and timestamps, prompts and generated content (and the associated metadata that links content to an account), connection metadata, and payment/transaction identity. We disclose only what the applicable law or process requires. Where we are legally permitted and not prohibited from doing so, we may notify the affected user. Suspected child sexual abuse material, or content indicating an imminent threat to life or serious harm, we may preserve, remove, and report to authorities proactively, without notice to the user.
5.2 Preservation and legal hold. If we receive a lawful preservation or production request, or become aware of an actual or potential legal claim, investigation, or proceeding, we may place the relevant data under legal hold and retain it notwithstanding any deletion request, "Delete my data" action, retention schedule, or auto-erase ("Burn") setting, for as long as reasonably necessary to comply with our legal obligations and to establish, exercise, or defend legal claims. You cannot use the Service's privacy or deletion features to defeat a lawful preservation obligation or to destroy evidence.
6.1 Where and how. Account, content, configuration, and ledger data are stored in our managed PostgreSQL database (Supabase) with row-level security; data in transit is protected by TLS; secrets are encrypted at rest in a pgsodium-backed vault (Section 8). Compute runs on Vercel and (for long-running agents) Modal.
6.2 Retention timelines.
| Data category | Retention |
|---|---|
| Account/identity data | For the life of the account; deleted within 30 days of verified account-closure request, except where law requires longer. |
| Prompts and generated content | Until you delete the item or close your account; deletion is permanent. In addition, generated media exceeding your plan's storage allowance may be deleted after a paid plan lapses, on at least 30 days' advance notice (Section 6.5). |
| Conversational/agent history | Retained to provide context while the account is active; deletable by you. |
| Connected-service credentials (vault) | Until you disconnect the service or close the account; deleted/rendered unusable on disconnect. |
| Connected-service data in transit | Only as long as operationally necessary to fulfill the request (short-lived cache / run context); flushed on disconnect. |
| Billing/transaction records | Retained for at least 8 years as required by Indian tax/financial-record law. On account/data deletion, retained as an anonymized financial archive for the remainder of that period. |
| Security/server logs | Up to 90 days, then purged or de-identified. |
6.3 Backups. Residual copies may persist in encrypted backups for a limited period after deletion and are overwritten on the ordinary backup cycle.
6.4 Self-service deletion. You can permanently delete your data at any time using the "Delete my data" control in My Account (Section 7.6). On confirmation we delete your profile, prompts, generated content, agent/routine configurations, conversational history, the files and media you uploaded or generated (including reference photos, voice samples, images, video, and music) stored in our cloud storage, and your connected-service credentials (erased from the encrypted vault), and we revoke the Service's ability to act on your connected accounts. The action is immediate and irreversible. We retain only the anonymized financial archive described above and any data placed under a legal hold (Section 5.2) — deletion does not override a lawful preservation obligation. We cannot delete data already held by third-party providers; request that from each provider directly.
6.5 Storage allowances and deletion of content over the limit. Your subscription determines how much content we store for you, measured across files you upload or save and media you generate (currently 5 GB on Free, 50 GB on Pro, and 100 GB on Studio; current figures are shown in the Service). If a paid plan ends or lapses, your account reverts to the Free allowance. Where your stored content then exceeds that allowance, we retain it and give you at least 30 days' advance notice by email and within the Service before any deletion. If your account remains over the allowance after that period, we may permanently delete content to bring it within the allowance. We currently delete only generated media for this purpose and retain files you have saved; we reserve the right to delete other content, including saved files, on the same basis (at least 30 days' notice and a separate cure period). Re-subscribing before deletion occurs cancels it. This process is separate from your deletion rights (Section 6.4) and the retention periods in Section 6.2.
Depending on where you live, you have some or all of the following rights. We honor these rights for all Users where feasible.
7.1 GDPR / UK GDPR (EEA/UK). Rights of access, rectification, erasure ("right to be forgotten"), restriction, data portability, objection (including to processing based on legitimate interests), and the right to withdraw consent at any time without affecting prior processing. You may lodge a complaint with your supervisory authority (Section 14).
7.2 CCPA/CPRA (California). Rights to know/access, to delete, to correct, to data portability, to opt out of sale/sharing (we do neither — Section 4), to limit use of sensitive personal information (we do not use sensitive PI for inferred profiling), and the right not to be discriminated against for exercising your rights. You may use an authorized agent.
7.3 India DPDP Act, 2023. Rights to access a summary of your personal data and processing, to correction and erasure, to grievance redressal, and to nominate another individual to exercise your rights in the event of death or incapacity. Contact our Grievance Officer (Section 14).
7.4 Other jurisdictions. We extend comparable rights to Users in other regions to the extent local law applies.
7.5 How to exercise. Email contactus@synergyai.studio. We will verify your identity and respond within 30 days (extendable where the law permits and we notify you). Exercising these rights is free except where a request is manifestly unfounded or excessive. Withdrawing consent or requesting erasure of essential data may prevent you from using the Service.
7.6 One-click deletion. You do not have to email us to erase your data: use the "Delete my data" control in My Account. It permanently and irreversibly deletes your personal and content data and your stored credentials, subject only to the anonymized financial archive we must keep by law (Sections 6.2 and 6.4).
We use commercially reasonable technical and organizational measures, including: pgsodium-backed Supabase Vault encryption at rest for all connected-service secrets, written through a security-definer wrapper and referenced only by an opaque secret_id (plaintext never returned to the client, never logged); TLS in transit; OAuth for authentication and connections; PKCE for MCP connections; scoped tokens; row-level security in the database; and audit logging. Payment card data is handled by Razorpay under PCI-DSS; we do not store full card numbers.
No system is perfectly secure. We do not warrant that the Service or its data stores are impenetrable. You provide content and credentials at your own risk and are responsible for your own account, device, and OAuth-grant hygiene (Terms §9).
SynergyAI operates globally and engages sub-processors and model providers located in multiple countries, including the United States, the European Union, the United Kingdom, India, Singapore, and elsewhere. As a result, your personal data may be transferred to, stored in, and processed in countries other than your own, whose data-protection laws may differ.
Where we transfer personal data out of the EEA/UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK Addendum/IDTA), or an adequacy decision where one applies. Many of our major providers maintain their own transfer mechanisms and Data Processing Agreements; links to provider DPAs, where available, are in the Processor Table. You may request information about the safeguards applicable to a specific transfer at contactus@synergyai.studio.
We use only strictly necessary mechanisms — primarily browser localStorage and essential first-party cookies — to maintain your session, preferences, and cached state. We do not use advertising cookies, cross-site trackers, or third-party advertising/analytics SDKs for behavioral profiling. Where required by law, we obtain consent for any non-essential cookies before setting them.
The Service is for Users 18 and older. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us data, contact contactus@synergyai.studio and we will delete the account and associated data.
If a personal-data breach occurs that is likely to affect you, we will notify the relevant supervisory authority and affected Users as and to the extent required by applicable law and within the timeframes it prescribes (for example, without undue delay and, where required, within 72 hours of becoming aware under the GDPR; and as required by the CCPA, the DPDP Act, and other applicable laws). Our notice will describe the nature of the incident, likely consequences, and measures taken or proposed, to the extent known.
We may update this policy from time to time. If we make material changes, we will provide notice through the Service and update the "Last updated" date. Continued use after the effective date constitutes acceptance of the updated policy.
Synergy AI Web: synergyai.studio Privacy / data-subject requests: contactus@synergyai.studio Legal entity: Kayarsh Homawalla, sole proprietor trading as SynergyAI Grievance Officer (DPDP Act, 2023): Kayarsh Homawalla, contactus@synergyai.studio Registered address: SynergyAI, FP 44, TP 2, Vasna/Bhayli, behind Pratham Citadel, Vadodara 391410, Gujarat, India EU/UK representative under GDPR Art. 27: Not currently appointed. Synergy AI is established in India. If you are in the EEA or UK and wish to raise a data-protection matter, contact us at contactus@synergyai.studio; we will respond directly. (We will appoint an EU/UK representative if and when our user base there makes one required.)
If you are in the EEA/UK, you may also lodge a complaint with your local data-protection supervisory authority. If you are in India, you may escalate to the Data Protection Board of India after first using our grievance-redressal process.
This table lists the third parties involved in delivering the Service. It is grouped into (A) infrastructure sub-processors, (B) AI model providers, (C) inbound chat surfaces, and (D) services you connect at your direction. "Data shared" describes the maximum category of data that may flow to that party in connection with the relevant function; the actual data depends on the features and connections you use. Region reflects the provider's principal processing locations and may include global infrastructure.
URL verification note. All provider privacy-policy links in this policy — infrastructure sub-processors (Table A), AI-model providers (Table B), chat surfaces (Table C), and every connector in the integration catalog (Table D) — were verified against the providers' live legal pages in May 2026. DPA links are given where a public DPA exists. Providers occasionally relocate these pages; we keep them current and recommend a periodic re-check.
| Processor | Purpose | Data shared | Region | Privacy Policy | DPA |
|---|---|---|---|---|---|
| Supabase | Authentication, PostgreSQL database, pgsodium credential vault | Account/identity, content, configuration, ledger, encrypted secrets | US / EU (global) | https://supabase.com/privacy | https://supabase.com/legal/dpa |
| Vercel | Application hosting, serverless compute, delivery | All web traffic and request data | US (global edge) | https://vercel.com/legal/privacy-policy | https://vercel.com/legal/dpa |
| Modal | Serverless compute that runs our autonomous agent runtime (Hermes, a self-hosted agent model) — the agent's reasoning/orchestration runs here, not at a separate third-party model provider | Prompts, agent context, persistent agent memory, and connected-data in transit during a run | US | https://modal.com/legal/privacy-policy | https://modal.com/legal/dpa |
| Composio | Connector OAuth + tool-execution layer for managed/BYOC integrations | OAuth tokens/metadata, action requests and responses for connected services | US (global) | https://composio.dev/privacy | https://composio.dev/legal/dpa |
| Resend | Transactional email delivery | Recipient email address, message content | US | https://resend.com/legal/privacy-policy | https://resend.com/legal/dpa |
| Razorpay | Payment processing (primary, INR) | Order amount, currency, your user/account identifier, payment status (no full card data to us) | India | https://razorpay.com/privacy/ | https://razorpay.com/terms/ (request executed DPA via dashboard) |
| Processor | Purpose | Data shared | Region | Privacy Policy | DPA |
|---|---|---|---|---|---|
| Anthropic | Language/reasoning models (Claude) for chat and agents | Prompts, conversation/context, relevant connected-data | US | https://www.anthropic.com/legal/privacy | https://privacy.claude.com/en/articles/7996862-how-do-i-view-and-sign-your-data-processing-addendum-dpa |
| OpenAI | Language models, image generation, audio transcription, real-time voice conversations (live audio via the OpenAI Realtime API), text embeddings (memory features), prompt enhancement, and automated child-safety moderation of all inputs | Prompts, images, live microphone audio (during voice sessions), audio (if used), context | US | https://openai.com/policies/privacy-policy | https://openai.com/policies/data-processing-addendum |
| Google (Gemini / Vertex AI / Veo) | Language, image, and video generation; reasoning | Prompts, inputs, context | US / EU (global) | https://policies.google.com/privacy | https://cloud.google.com/terms/data-processing-addendum |
| Kling AI (Kuaishou) | Video generation | Prompt text, reference images you select | China / Singapore | https://klingai.com/global/docs/privacy-policy | (none public) |
| BytePlus ModelArk (ByteDance) | Video generation — Seedance engine | Prompt text, reference image(s) | Singapore (operated by ByteDance) | https://docs.byteplus.com/en/docs/legal/docs-privacy-policy | https://docs.byteplus.com/en/docs/ModelArk/BytePlus_ModelArk_Data_Processing |
| ElevenLabs | Music + audio generation and text-to-speech | Text prompts for audio | US / EU | https://elevenlabs.io/privacy | https://elevenlabs.io/dpa |
| DeepInfra | Hosted open-weight language/reasoning models offered in Agent Mode — DeepSeek V4 Pro, Qwen 3.7 Max, Kimi K2.7, GLM 5.2 | Prompts, conversation/context | US | https://deepinfra.com/privacy | (none public) |
| xAI | Grok language models (chat) and Grok Imagine (image / video generation) | Prompts, reference image(s) you select | US | https://x.ai/legal/privacy-policy | https://x.ai/legal/data-processing-addendum |
Because Kling AI is materially different from our other providers, we disclose its data handling separately and explicitly. SynergyAI's video-generation features are powered in part by Kling AI, operated by Kuaishou (a company headquartered in China). When you generate video using a Kling-powered engine:
If you wish to avoid Kling entirely, do not use the video-generation engines that are powered by Kling. By choosing to use a Kling-powered engine, you acknowledge and consent to the data flow described above.
| Processor | Purpose | Data shared | Region | Privacy Policy | DPA |
|---|---|---|---|---|---|
| Telegram | Inbound chat surface (SynergyAI bot) | Message content, Telegram user/chat identifiers | Global / UAE | https://telegram.org/privacy | n/a (consumer) |
| Slack (Salesforce) | Inbound chat surface + connected workspace | Message content, workspace/user identifiers | US (global) | https://slack.com/trust/privacy/privacy-policy | https://slack.com/terms-of-service/data-processing |
Data flows to these only when you connect them, and only as you instruct. You hold the direct relationship with each provider under its own terms. The "Connect method" reflects how credentials are handled (see Terms §5). Most of the OAuth-based connectors below (those marked "Managed OAuth" or "BYOC OAuth") are brokered through our connector layer, Composio (Table A) — so your OAuth tokens and the action requests/responses for those services also pass through Composio, which processes them under its own policy and DPA. Connectors marked "API key", "IAM credentials", or "Bot token" are called directly by us using credentials in our encrypted vault and do not pass through Composio. All privacy-policy links below were verified against the providers' live pages in May 2026.
The Service lets you connect your own Model Context Protocol (MCP) servers — whether an official vendor MCP server or one you operate or choose. We do not curate, host, vet, or endorse these servers. When you add one, you supply its address and (where needed) your own credentials, which we store in our encrypted vault; thereafter, when you instruct an agent to use it, your prompts and the relevant data are sent to that MCP server at your direction, and that server processes your data under its own terms and privacy policy, entirely outside our control. You are solely responsible for the trustworthiness, security, lawfulness, and data handling of any MCP server you connect (Terms §5.4). The only vendor MCP server we integrate as a built-in connector is Meta Ads (listed in Table D); all other MCP servers are ones you bring yourself.
If we add, remove, or change a processor, we will update this policy. The current version is always available at the published Privacy Policy URL.
Synergy AI · Privacy Policy v2.0 · Effective 31 May 2026. Read together with the Terms of Service.