SYNTH ID

Privacy Policy

Draft template โ€” not yet reviewed by a lawyer. The data inventory below matches what the software actually stores. Replace the bracketed items and have counsel complete the legal sections (legal bases, transfers, regulator contacts) before public launch.

Last updated: [DATE]. Controller: [LEGAL ENTITY NAME], [ADDRESS]. Contact: [PRIVACY EMAIL].

What we store about account holders

What is public

Each asset has a public provenance record showing your name as registrant, the registration time, the image fingerprints and your rights settings. It contains a hash of your email address, not the address itself. Anyone can upload a file to the Identify page to see whether it matches a registered asset; a match shows the asset title and registrant name. If you turn on open licensing for an asset, its public page also shows your listed prices. The controlled image URL is public unless you restrict it.

What we store about other people

Who we share data with

Platforms and AI services that integrate with the registry send it files to check and receive the matching work's title, registrant name and permissions; they may report back the address where a work appeared. Otherwise, only the providers the operator has enabled: [PAYMENT PROCESSOR] for license payments; [EMAIL PROVIDER] to deliver notices and account email; [REVERSE IMAGE SEARCH PROVIDER], which receives the protected copy of an image to search for matches; [HOSTING / STORAGE PROVIDER]; and public domain-registration (RDAP) services, which receive a website's hostname when you look up its abuse contact. We do not sell personal data.

How long we keep it

Account and asset data is kept until you delete the asset or your account, which removes the files, evidence, notices and audit trail for those assets. Expired sessions and used sign-in links are purged automatically. [BACKUP RETENTION PERIOD.]

Your choices

You can delete any asset or your whole account from the app. To access, correct or export your data, or to object to processing, contact [PRIVACY EMAIL]. If you received a notice and want your details removed, use the same address. [RIGHTS UNDER GDPR / CCPA AND HOW TO COMPLAIN TO A REGULATOR โ€” to be completed by counsel.]

Security

Passwords are hashed, session tokens are stored only as hashes, state-changing requests are restricted to this site's origin, sign-in is rate limited, and the registry signing key can be encrypted at rest. No system is perfectly secure; we will notify affected users of a breach as the law requires.

Back to Synth ID ยท Terms of Service