Privacy Policy
Version 1.0 · Effective and last updated: August 9, 2026
1. Scope and data controller
This Privacy Policy explains how Synux Operator ("we," "us," or "our") collects, uses, shares, retains, and protects personal information when you visit the Synux website, sign in to the dashboard, create an API key, call a model, purchase credits, or contact us.
The data controller for Synux is Synux Operator. You can submit privacy and data-rights requests at team@synux.ai. We have not separately appointed a data protection officer. If applicable law requires one, we will make the appointment and update the contact details here.
2. Information we process
2.1 Account and identity information
Synux currently uses GitHub for sign-in. With your authorization, we receive and store your stable GitHub account identifier, username or display name, email address, avatar, and connection status. We also generate an internal customer ID and store account preferences such as language, time zone, and theme.
2.2 Security and technical information
We process sign-in sessions, IP addresses, user agents, browser and operating-system types, time zones, request times, request IDs, response statuses, latency, error types, and security audit events. API-key records may include a name, masked value, status, model or IP restrictions, credit limits, creation time, and most recent access time. Public pages and analytics tools never receive complete API keys.
2.3 Model requests and usage
To complete a model call, we process the prompts, messages, files, images, audio, video, tool parameters, and generated results that you submit through the API (collectively, "request content"). We route that content to the third-party provider you select or that the system matches to the requested model. Standard usage records include model ID, time, input and output token counts, number of calls, cost, latency, status, and request ID. Product analytics and billing pages do not need to store or display request bodies.
2.4 Payment and transaction information
We process the top-up amount, currency, expected and credited balance, order or transaction identifier, payment status and time, and the email address needed to match the payment to an account. Waffo Pancake processes complete card numbers, expiration dates, and security codes on its hosted checkout page; Synux does not store them.
2.5 Communications and requests
When you contact sales or support, request a refund, dispute a bill, report a security issue, submit feedback, or request account deletion, we process the contact details, message content, related order or request IDs, and follow-up records that you provide.
3. How we use information
- Performance of a contract: To create and maintain accounts, verify identity, provide the API, route model requests, measure usage, deduct credits, and process payments.
- Legitimate interests: To protect accounts and the platform, prevent fraud and abuse, diagnose problems, improve reliability, provide support, and maintain audit records.
- Legal obligations: To meet tax, accounting, sanctions, refund, chargeback, dispute, and regulatory requirements.
- Your consent: We use Google Analytics only after you allow it. You can withdraw consent at any time through Cookie settings or the Account page.
We do not sell personal information or use it for cross-site targeted advertising. We do not use your request content to train Synux-owned models without your explicit consent.
4. Cookies and Google Analytics
Strictly necessary cookies support sign-in sessions, security, and core functionality and cannot be disabled without affecting the service. Sign-in sessions generally last no more than 12 hours and may be renewed under our security rules while you continue to use the service. Your analytics choice is stored for 180 days in a first-party cookie named synux_analytics_consent.
Google Analytics is denied by default and loads only after you select "Allow." Once permitted, we send sanitized page locations, page titles, referrer sites, device and approximate-region information, and categorized events such as button clicks, sign-ins, API-key creation, model browsing, first calls, and checkout status. After sign-in, we may use an opaque internal customer ID as the Google Analytics User-ID to connect product journeys across pages.
We do not send email addresses, display names, OAuth identifiers, referral codes, complete API keys, prompts, model responses, checkout IDs, transaction IDs, or raw payment-provider payloads to Google Analytics. Ad storage, Google Signals, ad user data, and personalization always remain disabled. You can change your choice at any time through "Cookie settings" at the bottom of this page. See the Google Privacy Policy for information about how Google handles the data it receives.
5. Sharing and service providers
We share information only as needed to provide the service, meet legal obligations, or act with your consent:
- GitHub: To complete OAuth sign-in and account authentication. GitHub processes authorization and account data under its own policies.
- Waffo Pancake: As Merchant of Record and payment processor, to handle checkout, taxes, receipts, refunds, and disputes. Card data does not enter our servers.
- Model providers: To send request content to the provider for the selected model, including OpenAI, Anthropic, Google, DeepSeek, and other providers listed in the dashboard model catalog. The list changes as models become available or are retired.
- Google Analytics: To receive the limited analytics data described in Section 4, and only after you consent.
- Infrastructure and support providers: To provide hosting, databases, networking, monitoring, email, or customer support under confidentiality and security obligations.
- Legal and business events: To comply with lawful requests, protect rights and safety, or support a merger, acquisition, or restructuring with appropriate notice and continued safeguards.
Third-party model providers and Waffo Pancake may also determine some processing independently under their own legal obligations. Review the relevant third-party policies before selecting a model or making a payment.
6. International transfers
Synux provides services globally. GitHub, Waffo Pancake, Google Analytics, hosting facilities, and model providers may be located outside your country or region. Where required by applicable law, we use contractual safeguards, standard contractual clauses, adequacy decisions, or other lawful mechanisms, and we aim to transfer only the data needed for each specific purpose.
7. Retention
- Account, identity, and preferences: Retained while the account is active, then deleted or anonymized within 90 days after account deletion, except for records we must retain by law.
- Model request bodies: Standard access logs in the Synux gateway do not record request bodies. Request content is transmitted and processed temporarily only to complete a call. Model providers may retain content under their own policies.
- API usage and billing metadata: Generally retained for no more than 24 months, then deleted, anonymized, or kept only in aggregate form. Data connected to financial records follows the next retention period.
- Transaction, refund, and tax records: Generally retained for seven years, or longer when required by applicable accounting, tax, anti-fraud, or dispute rules.
- Support, complaint, and deletion requests: Retained for two years after closure to support follow-up and document our response.
- Security and audit logs: Generally retained for no more than 12 months. Records related to a security incident, fraud, or legal dispute may be kept until the matter is resolved and the legal retention period expires.
- Analytics data: The consent cookie is stored for 180 days. Google Analytics data is retained for the period configured in our administration settings. We stop sending new data after you withdraw consent.
8. Data security
We use encryption in transit, access controls, least-privilege permissions, HttpOnly session cookies, OAuth-token encryption, network isolation, signed payment notifications, log redaction, and backup and recovery measures. No internet service can guarantee absolute security. You should also protect your GitHub account and API keys, and revoke a key and contact us immediately if you discover a compromise.
If a security incident may affect your rights, we will investigate it, contain the risk, and notify regulators and affected users within 72 hours of confirmation when applicable law requires us to do so.
9. Your rights and choices
Depending on the laws where you live, you may have the right to be informed, access or correct information, request deletion, restrict or object to processing, receive a portable copy, withdraw consent, and complain to a competent data-protection authority. Withdrawing consent does not affect the lawfulness of processing that occurred before withdrawal.
You can view account, usage, and transaction information in the dashboard. On the Account page, you can adjust preferences, withdraw analytics consent, or submit an account-deletion request. Submit other requests to team@synux.ai. To protect your account, we may need to verify your identity. We generally respond within 30 calendar days and will explain any extension allowed by law or needed for a complex request.
10. Marketing communications
Using the service does not automatically subscribe you to marketing emails. If we send product or event information with your consent in the future, every message will include a way to unsubscribe. Unsubscribing from marketing will not affect necessary security, billing, service-change, or policy notices.
11. Children
The service is intended for users who are at least 18 years old. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us with information, contact us. After verification, we will delete it as soon as applicable law permits.
12. Third-party links and services
The website may link to GitHub, Waffo Pancake, model providers, or other third parties. Those websites and services have their own terms and privacy policies, and we do not control their independent processing. Review the relevant policy when you leave Synux for a third-party service.
13. Policy updates
We may update this policy as our product, providers, legal requirements, or security practices change. We generally provide at least 15 days' notice of material changes through your registered email address, a dashboard notice, or a website announcement, and update the date at the top of this page. Urgent security or legal requirements may require a change to take effect sooner, in which case we will explain why.
14. Contact us
Data controller: Synux Operator. For questions about this policy, personal information, or your rights, contact team@synux.ai.