Privacy Policy
This policy explains how SynFabula (EU sole trader / individual operator for MVP) processes personal data under the GDPR.
Controller
You (the operator) are the data controller. Contact: support@example.com.
Data we process
- Account data: email, display name, password hash, magic-link and email-verification tokens, language preference
- Project content: README, prompts, proposals, reports
- Credits ledger and Stripe payment references (card data stays with Stripe)
- Technical logs: IP, user agent (security / abuse prevention)
- Generated media stored to deliver the service
Purposes & legal bases
- Provide the service (contract)
- Payments and fraud prevention (contract / legitimate interest)
- Safety moderation and illegal content handling (legitimate interest / legal obligation)
- Account deletion / export requests (legal obligation)
Processors
Typical processors: hosting (e.g. Vercel, Railway/Fly), PostgreSQL host, Redis host, Stripe, Replicate, OpenRouter, email (Resend), object storage, moderation GPU host.
Retention
Account data until deletion request or inactivity policy; ledger retained as needed for accounting; reports retained for abuse handling.
Your rights
Access, rectification, erasure, restriction, portability, and objection where applicable. Use Account → Export / Delete in the product, or contact the operator. You may lodge a complaint with your EU supervisory authority. support@example.com.
Cookies
MVP uses localStorage for the auth token (`sf_token`) and a language cookie (`sf_locale`); no advertising cookies. This carries residual XSS risk compared to httpOnly cookies.
International transfers
Some processors may be outside the EEA; use appropriate safeguards (SCCs) with your vendors.