Back to Platform

Legal & Compliance

Review our policies, terms, and agreements. We prioritize zero data retention and client-side encryption.

Privacy Policy

Last Updated: August 13, 2026

SynthHires ("Company", "we", "our", "us") is committed to protecting your privacy. This Privacy Policy explains our stringent data handling practices, detailing what information we collect, how we process it, and most importantly, what information we explicitly refuse to store due to our Zero Data Retention architecture.

1. Core Architectural Principle: Zero Data Retention

Unlike traditional SaaS platforms that aggregate and store user data for model training or analytics, SynthHires is architected as an ephemeral orchestration layer.

1.1. Inference Data (Never Stored)

We do not collect, store, log, or process any Inference Data beyond volatile memory during active execution. Inference Data includes:

  • Prompts, instructions, or queries submitted to autonomous agents.
  • Context windows, chat histories, or file contents passed to the orchestration engine.
  • Responses, outputs, or artifacts generated by the foundation models. All Inference Data is immediately discarded upon the termination of the computational process.

1.2. Cryptographic API Keys (BYOK)

We operate on a Bring Your Own Key (BYOK) model. We do not store unencrypted API keys. All credentials are encrypted on the client side before transmission. The decryption keys are never persisted to disk on our servers; they exist solely in-memory during agent execution and are immediately purged.

1.3. Model Context Protocol (MCP) Traffic

Data retrieved from your enterprise systems via MCP servers is streamed directly through our orchestration engine to the foundation model. This data is never written to disk, logged, or retained by SynthHires.

2. Information We Do Collect (Account Metadata)

To legally and operationally provide the Services, we collect strictly necessary Account Metadata.

2.1. Personal Information Provided by You

  • Account Credentials: Name, email address, and authentication identifiers.
  • Billing Information: Company name, billing address, and payment method details (processed securely by our PCI-DSS compliant payment processor, e.g., Stripe; we do not store full credit card numbers).
  • Organizational Data: Role-Based Access Control (RBAC) configurations, team member invites, and workspace settings.

2.2. Automated Telemetry and Audit Logs

  • System Observability: We collect anonymous, aggregated telemetry (e.g., agent run durations, error rates, token count statistics, CPU/Memory utilization of sandboxes) necessary for system health monitoring and billing. This data contains no Inference Data or Personally Identifiable Information (PII).
  • Immutable Audit Logs: To satisfy enterprise compliance requirements (e.g., SOC2), we maintain logs of platform access, configuration changes, and RBAC modifications. These logs record who did what configuration change and when, but never contain the actual content of the agent tasks.

3. How We Use Your Information

We process your Account Metadata for the following legitimate business purposes:

  • Service Provisioning: To create and manage your account, authenticate your access, and facilitate billing.
  • Security and Compliance: To monitor for fraudulent activity, enforce our Terms of Service, and maintain our SOC2 Type II compliance posture.
  • Communication: To send administrative information, such as updates to our Terms, security alerts, and system status notifications. We do not use your Account Metadata for third-party marketing.

4. Subprocessors and Third-Party Disclosures

We use trusted third-party subprocessors to provide core infrastructure. We require all subprocessors to adhere to strict data protection standards (GDPR and CCPA compliant).

  • Cloud Infrastructure: AWS / Cloudflare (Hosting and Edge Compute).
  • Payment Processing: Stripe (PCI-DSS compliant billing).
  • Transactional Email: Resend (Administrative notifications).

Note on AI Providers: Because you utilize your own API keys (BYOK), the relationship regarding the processing of Inference Data by foundation models (e.g., OpenAI, Anthropic) is strictly between you and the respective model provider. SynthHires is not a subprocessor of Inference Data.

5. International Data Transfers

SynthHires operates globally. Your Account Metadata may be transferred to, stored, and processed in the United States or other countries where our subprocessors operate. For users in the European Economic Area (EEA), the United Kingdom, or Switzerland, we ensure appropriate safeguards are in place through the use of Standard Contractual Clauses (SCCs) approved by the European Commission.

6. Your Data Protection Rights (GDPR & CCPA)

Depending on your location, you may have the following rights regarding your Account Metadata:

  • Right to Access: Request copies of your personal data.
  • Right to Rectification: Request correction of inaccurate personal data.
  • Right to Erasure (Right to be Forgotten): Request the deletion of your account and associated metadata.
  • Right to Restrict Processing: Request restriction of processing under certain conditions.
  • Right to Data Portability: Request the transfer of your data to another organization.

To exercise any of these rights, please submit a formal request to synthhires@planobinario.com. We will respond to your request within 30 days.

7. Data Security

We implement commercially reasonable technical and organizational security measures to protect your Account Metadata, including AES-256 encryption at rest, TLS 1.3 for data in transit, strict RBAC, and regular penetration testing. However, no electronic transmission over the internet or information storage technology can be guaranteed to be 100% secure.

8. Contact Information

If you have questions or comments about this Privacy Policy, you may contact us at: Email: synthhires@planobinario.com