PRIVACY POLICY

Last updated: February 15, 2026

1. INFORMATION WE COLLECT

We collect information you provide directly: name, email address, company name, and role when you create an account or contact us. We also collect usage data automatically: API query metadata (endpoints called, timestamps, response codes), IP addresses, browser type, and referring pages. We do not collect, access, or store your training data, model weights, or proprietary datasets.

2. HOW WE USE YOUR INFORMATION

We use your information to: (a) provide and maintain the Services; (b) authenticate your API access; (c) monitor usage for rate limiting and abuse prevention; (d) communicate with you about your account, updates, and support; and (e) improve the Services through aggregate, anonymized analytics. We do not use your information for advertising or sell it to third parties.

3. DATA SHARING

We do not sell, rent, or share your personal information with third parties for their marketing purposes. We may share information with: (a) service providers who assist in operating the platform (hosting, analytics), bound by confidentiality obligations; (b) law enforcement when required by valid legal process; and (c) successors in the event of a merger, acquisition, or sale of assets.

4. API QUERY PRIVACY

Your API queries are processed to return results and are not stored beyond what is necessary for operational logging (rate limiting, error tracking). We do not analyze query patterns to infer your business strategy, training methodology, or competitive positioning. Query logs are retained for a maximum of 90 days and then permanently deleted.

5. COOKIES AND TRACKING

Our website uses essential cookies for session management and optional analytics cookies to understand site usage. Analytics data is aggregated and anonymized. You may disable non-essential cookies through your browser settings without affecting core functionality.

6. DATA SECURITY

We implement industry-standard security measures including encryption in transit (TLS), encryption at rest, access controls, and regular security reviews. API credentials are hashed and never stored in plaintext. While no system is perfectly secure, we take reasonable precautions to protect your information.

7. DATA RETENTION

Account information is retained for the duration of your account plus 30 days after deletion. API usage logs are retained for 90 days. You may request deletion of your account and associated data at any time by contacting us.

8. YOUR RIGHTS

You have the right to: (a) access the personal information we hold about you; (b) correct inaccurate information; (c) request deletion of your information; (d) export your account data in a portable format; and (e) withdraw consent for optional data processing. To exercise these rights, contact us at the address below.

9. INTERNATIONAL TRANSFERS

Your information may be processed in jurisdictions outside your country of residence. We ensure appropriate safeguards are in place for any international data transfers in compliance with applicable data protection laws.

10. CHANGES TO THIS POLICY

We may update this Privacy Policy from time to time. Material changes will be communicated via email or through the platform. Continued use of the Services after changes constitutes acceptance of the updated policy.

11. CONTACT

For privacy inquiries, data requests, or concerns, contact us at contact@syngraph.io.