Privacy Policy
Effective date: September 14, 2026 · Version 1.0
This Privacy Policy explains how Synema.co, Inc. ("Synema," "we," "us") collects, uses, and shares information when you use our websites, applications, and services (the "Services"). Synema is a video library and AI editing platform for professional teams.
Questions or requests: privacy@synema.co.
Plain-language summaries appear in boxes like this throughout. They are for readability only — the full text controls.
1. Who this covers
- Customers and their teams — account owners, team members, and invited guests.
- Share-link visitors — people who view content via a share link without an account.
- Website visitors — people browsing synema.co.
- People appearing in customer footage — see §4; for their information we act on our customer's behalf.
Throughout this Policy, "you" means the person reading it in the role that applies to them — usually a customer, or a member of their team, using the Services. Where a passage instead speaks to someone who appears in a customer's footage without using Synema themselves, it says so explicitly (§4, §6), and "the customer" there means the workspace owner who uploaded the footage.
2. Information we collect
2.1 Account information. Name, email address, password (stored only as a salted hash), company/workspace name, role. If you sign in with Google, we receive your name, email address, and profile photo from Google.
2.2 Customer Content. The video, audio, images, and documents you or your team upload or import, and collaboration content (comments, labels, project structures, edits).
2.3 Derived Data. Data our systems generate from Customer Content to power the Services: transcripts and captions; scene descriptions, tags, and classifications; content embeddings for search; face and voice identifiers and the people index for your workspace (§6); edit histories and quality metrics.
2.4 Usage and device data. IP address, browser and OS, pages and features used, timestamps, and error/diagnostic logs. For share links we log access (IP address, user agent, time) so the content owner can see activity on what they shared and so we can enforce link passwords and expiration.
2.5 Website visitors. The synema.co website sets no cookies and uses no third-party analytics or trackers. We keep a first-party log of visits: approximate location (country, region, city), network, device type, page visited, referrer, and an anonymized identifier derived from your IP address using a salt that rotates daily — the IP address itself is not stored. If you request early access, we store the email address you provide and use it only to contact you about access. Fonts and icons load from content-delivery networks, which receive standard web-request data to serve those files.
2.6 Billing. Payments are processed by Stripe; we receive plan, transaction status, and the card's last digits — never full card numbers.
3. Our roles
For account, billing, usage, and website data, Synema is the data controller. For Customer Content and Derived Data — including personal data embedded in the content itself, such as the people who appear and speak in footage — Synema is a processor/service provider acting on the customer's instructions; the customer (the workspace's account owner or their organization) is the controller. One exception: in the optional global-improvement program (§7.2(b)), Synema acts as an independent controller for the personal data used in that program, under its supplemental notice, and handles applicable privacy requests for it directly. Business customers can request our Data Processing Agreement at privacy@synema.co.
4. People appearing in customer footage
Our customers upload footage that shows people — interview subjects, colleagues, event attendees. For that footage:
- We process it only on the customer's behalf to provide the Services described here (the one exception is the optional, separately noticed program in §7.2(b), for which Synema is the responsible controller). We do not use footage of you to identify you across other customers' workspaces, to build profiles, or for advertising — and we never sell it.
- The customer is responsible for having the rights and consents needed to film and upload you; our Terms of Service require this, including under biometric-privacy laws (§6.3).
- If you believe footage of you is in a customer's Synema workspace and you want it accessed, corrected, or deleted, contact that customer (the production team or organization that filmed you); we will assist them in honoring your request. You may also write to privacy@synema.co and we will route your request to the customer where we can identify them.
5. How we use information
5.1 To provide the Services. Store, organize, and stream your library; process content with AI (§5.2); enable search, review, sharing, and StoryCut editing; operate accounts, workspaces, and billing; send transactional email (verification, password resets, invites, share notifications).
5.2 AI processing of Customer Content. Uploading content triggers automated analysis:
- Transcription of speech to text, with word-level timing.
- Scene and content analysis — descriptions, classification, tags, quality metrics — using the AI providers named in §10.
- Face detection and person identification and voice/speaker identification, to build your workspace's people index (§6).
- Editorial analysis and generation to draft the edits you request.
Frames, audio, and transcripts are sent to the AI providers named in §10 for this processing. We use Anthropic's commercial API and Google's paid Gemini tier under terms that do not permit training on your content, and we maintain ElevenLabs' account-level training opt-out; we do not submit your content through provider configurations that permit training on it. Face and voice identifiers are computed by models running on Synema-operated servers — no third-party biometric service is used.
5.3 Google Drive import and Google user data. If you choose to import content from Google Drive, we request Google's read-only Drive scope (drive.readonly) and use that access only to display your available files and folders and to download the specific files or folders you select for import through Synema's interface — including the contents of a folder you expressly select. We do not modify, delete, create, move, or otherwise manage anything in your Drive.
We store an OAuth token only to perform imports you initiate. You can disconnect Google Drive at any time in Synema's settings or at myaccount.google.com/permissions; on disconnect or revocation we delete the stored token and stop all further Drive access. Disconnecting does not remove content already imported — imported copies are Customer Content in your workspace, stored and deletable exactly like directly uploaded content (§8, §9), and the workspace members, guests, and recipients you share with may access them through the sharing features you direct, like any other Customer Content.
Google user data — including imported content and data derived from it — is used only to provide or improve the user-facing import, storage, organization, search, editing, sharing, security, and support features you request through Synema, in accordance with Google's API Services User Data Policy, including its Limited Use requirements. It is not sold; not used for advertising; not used to build profiles unrelated to Synema's user-facing features; and never used to train, develop, fine-tune, or improve models or systems serving other customers — no workspace setting, customer opt-in, or other program overrides this restriction (§7.2). We do not transfer Google user data to third parties except: to processors necessary to provide the requested feature, bound by use restrictions (§10); with your affirmative consent for the specific transfer; for security or abuse prevention; to comply with applicable law; or in connection with a merger, acquisition, sale of assets, or other transfer of the relevant business, only after obtaining your explicit prior consent — notice alone is not sufficient. No person reads your specific Drive files or their contents unless you have given affirmative, documented permission for the specified files in connection with support you request, or access is necessary for security, legal compliance, or another use the Google policy expressly permits. This section controls over any broader permission elsewhere in this Policy.
5.4 To secure and improve the Services. Debugging, abuse and fraud prevention (including bot protection on sign-in), monitoring, and product analytics from usage data. Any improvement use of Customer Content is governed by §7.
5.5 To communicate. Service and account notices; separately, product news you can opt out of at any time.
5.6 Legal. To comply with law and to enforce our Terms.
We do not sell personal information or Customer Content, use either for third-party advertising, or use Customer Content for advertising of any kind.
6. Biometric identifiers (faces and voices)
6.1 What we create — and what we deliberately don't. The Services compute numerical representations of faces ("face embeddings") and voices ("voice prints") from Customer Content and link them into a people index for the workspace — so your team can search footage by person and the editor knows who is speaking. Under some laws these are "biometric identifiers."
This happens in two technically distinct stages. First, our systems detect the presence and approximate location of faces in footage solely to classify each as an intended subject of the shot or incidental to it (too small, in the background, out of focus, or passing through the frame — though a person speaking on camera is never treated as incidental, whatever their size in frame). For this classification step we retain only non-identifying bounding-box position and size — not facial landmarks, facial measurements, face crops, embeddings, templates, persistent identity tracks, or any other data designed or capable of identifying or matching an incidental person across content. Second, only after a face is classified as an intended subject in an upload where you have enabled people identification (§6.3) do we create a face embedding for workspace-limited person search and organization; we treat that embedding as a biometric identifier wherever applicable law does. If any detection process were to create or retain data capable of identifying or matching an individual, we would treat that data as biometric information and apply every control in this Section to it. Classification is automated and can be wrong: the per-file counts report the system's classifications rather than independently verifying them, and a person set aside as incidental in one appearance may still be enrolled from another appearance in which they are an intended subject. This intended-subject filtering applies to face processing; voice and speaker identification is a separate operation applied to speech in your content and does not use the face filter — the per-upload control (§6.3) lets you decline face and voice processing together. Voice prints have their own minimization rule: they are used only to match speech to people already in your workspace's index, and never to create a person entry. New person entries are created only for people who speak on camera. Your library shows, per file, how many faces were detected, how many were processed as intended subjects, and how many were set aside as incidental — so you can verify this behavior yourself.
6.2 Scope and purpose limits. Face and voice identifiers:
- are used solely to organize, search, and edit the workspace's own content — never for identity verification, authentication, advertising, surveillance, or law-enforcement purposes;
- are scoped to the workspace they were created in — we do not match people across different customers' workspaces — and are gated by that workspace's permissions: the people index and person search are available only to the members and guests you have authorized, under the roles you assigned them. Nothing biometric has a public surface: no share page or other no-login surface exposes the people index, face crops, or any identifier (§10);
- are computed on Synema-operated infrastructure and disclosed only to the infrastructure processors that store and secure the systems where they live, under written restrictions against any independent use (§10) — and, where biometric law requires the individual's consent for a disclosure, only where that consent or written release has been obtained or a specific statutory exception applies: a processor agreement does not replace required subject consent. Separately, we make disclosures legally required by law, warrant, or valid legal process — and none in any other case;
- are stored separately from names and account records — an identifier is linked to a named person entry only through the people index your workspace builds and can edit, and identifiers with no confirmed match remain unlinked;
- are encrypted at rest and are not made available for download, export, authentication use, or enrollment in any system, inside or outside the Services;
- are never sold, leased, or traded.
6.3 Consent and customer controls. Our customers are contractually required to provide any legally required notice to, and obtain any legally required consent from (including written consent where a law such as Illinois' Biometric Information Privacy Act requires it), individuals appearing in their footage before uploading it for processing. Where written consent is required, it must specifically cover biometric data collection — the collection of face and voice identifiers, its purpose, and the retention term (§6.4) — and a general appearance or model release may not be sufficient by itself. Customers confirm this authorization when creating an account or workspace; each upload then requires choosing either to confirm that the footage was not filmed in Illinois and does not depict Illinois residents AND that legally required written or electronic consent has been obtained from every individual depicted — deliverable on demand — or to decline face and voice processing for that upload entirely, and the choice is recorded. Face and voice identification is not offered for Illinois accounts or for footage filmed in Illinois or depicting Illinois residents. Customers must keep records sufficient to demonstrate the required notices and consents and provide them to us on reasonable request in connection with a complaint, regulator inquiry, or legal obligation. We may disable people-identification for particular content or workspaces where we reasonably believe the required authorization has not been obtained. Nothing in this allocation limits obligations that applicable law does not permit to be delegated.
6.4 Retention and destruction. This section is our written retention and destruction schedule for biometric identifiers. We permanently destroy a face or voice identifier at the earliest of: (i) when the purpose for which it was created has been satisfied — including deletion of the source content (§9), deletion of the associated person entry or workspace, the customer disabling people-identification for the relevant content, or — for any embedding not linked to a confirmed person entry, whether an unconfirmed candidate or an unassigned print — 180 days after its creation, with advance warnings to your team before removal; (ii) a verified deletion instruction from the customer; (iii) where the depicted individual has themselves used the Services, 3 years after their last interaction with the Services; or (iv) where the consent under which the footage was provided states a term, the end of that term. For individuals who have not themselves used the Services, the collection purpose — organizing and searching the customer's own library — continues only while the source footage remains in the customer's active workspace under the consent it was provided with: the identifier lives exactly as long as the footage does, and is destroyed with it. Continued activity on the customer's account never extends retention beyond these triggers, and we do not create or retain any biometric template for a face classified as incidental (§6.1). Where applicable law sets a shorter deadline, the shorter deadline applies — for identifiers subject to Texas law, destruction occurs no later than one year after the purpose for collection expires. These deadlines apply to every copy, including backup copies — backup rotation does not extend them.
7. Learning: your workspace vs. the global system
7.1 Learning that stays in your workspace (part of the service). Your workspace's results improve from your team's own activity: confirmed people tags, corrections to labels and transcripts, editing choices and preferences. This adapts only your workspace's search, people index, and editing behavior. It is service delivery, not model training.
7.2 Improving Synema for everyone. Different rules for different kinds of data:
(a) Editing-activity data — on by default, with an off switch. We use editing-activity data — the actions your team takes in the editor (edits made, story structures chosen, suggestions accepted or rejected, completion signals) — to improve the editorial systems that serve all customers. Before any such use we apply measures designed to remove direct identifiers and prevent the data from being reasonably linked back to a person, account, workspace, or specific content; we never use footage, audio, images, transcripts, face or voice identifiers, or people-index entries for this purpose; qualifying records carry action types, structural categories, and coarse measurements rather than free text, prompts, exact timecodes, or references to specific content; we do not attempt to re-identify the data and require the same of anyone who receives it. Only records satisfying both conditions — the limited content just described AND no reasonable linkability — enter this tier; a record failing either is excluded from it and remains governed by subsection (b). Subsection (a) is a limited exception to subsection (b) for qualifying records only, and the Google-data exclusion in (d) always controls. Turn it off any time in workspace settings; opting out never degrades your service.
(b) Customer Content — opt-in only. We do not use Customer Content — footage, audio, images, transcripts — or Derived Data to train, re-train, fine-tune, or otherwise improve the models and editorial systems that serve other customers unless the customer has expressly opted in through a workspace setting or written agreement. The consent states what would be used — for example, editorial-structure patterns rather than the underlying footage — and can be withdrawn for future use at any time. Participation is a separate, optional program in which Synema acts as an independent controller for the defined purpose, under a supplemental notice describing scope, purposes, retention, and withdrawal; a workspace opt-in does not by itself establish consent from the people depicted, and content containing identifiable people is eligible only where the legally required basis and subject notices exist (§4, §6.3).
(c) Face and voice identifiers — never used beyond your workspace (§6).
(d) Google Drive imports — never, regardless of settings. Content imported from Google Drive, and data derived from it, is excluded from every form of global learning; neither the editing-activity default nor a workspace opt-in overrides this (§5.3).
7.3 Aggregated data. We may use aggregated, de-identified data — data processed with reasonable measures so it is not reasonably linkable to an identified person or customer (feature usage counts, performance and reliability metrics) — to operate and improve the Services. We maintain and use such data in de-identified form, do not attempt to re-identify it except solely to test whether our de-identification measures work, and require any recipient to maintain the same protections. Security-incident investigations use separately governed identifiable records, not this data.
8. Where your content lives and how it's protected
- Storage. Customer Content is stored with Backblaze B2 in the United States, encrypted at rest with AES-256 server-side encryption and encrypted in transit with TLS.
- Compute. Application and processing servers run on Oracle Cloud Infrastructure in the United States. Media delivery uses Cloudflare's CDN.
- Access controls. Content is scoped to your workspace; role-based permissions govern team access; share links can carry passwords and expiration dates. Account passwords are stored hashed; sign-in and password reset are rate-limited and bot-protected.
- Personnel access to Customer Content is limited to support you request, abuse and security investigation, and legal compliance.
No system is perfectly secure; we work hard to protect your information but cannot guarantee absolute security. Keep independent backups of your original media.
9. Retention and deletion
| Data | Retention |
|---|---|
| Content you delete | 7 days in trash (restorable), then permanently deleted from our production systems by an automated purge — files and the data derived from them (transcripts, embeddings, face/voice identifiers) |
| "Empty trash" | Removed from your library immediately and purged from production systems by the next automated purge run, as above |
| Content after account closure | Export window of 30 days, then purged as above |
| Face/voice identifiers | §6.4's earliest applicable deadline, measured by the depicted individual — never by account activity. Applies to every copy, including backups; backup rotation does not extend it |
| Account records | Deleted or anonymized within 30 days of account deletion, except records we must keep (e.g., tax and billing: 7 years) |
| Server, access, and share-link logs | 12 months |
| Website visitor log | 12 months |
| Residual backup copies | Media files: no backup copies are kept, so the production purge is complete. Database records: encrypted nightly backups on a rolling cycle; residual copies overwritten within 30 days |
Legal holds, active investigations, and disputes can extend retention of specific data, only for as long as the necessity exists and only to the extent applicable law (including biometric-privacy law) permits the extension.
10. Who we share information with (subprocessors)
We share information only with the service providers below, only for the purposes shown, under contracts limiting their use of it. The current list is also maintained at synema.co/subprocessors, where we post notice of material changes.
| Provider | Purpose | What they receive | Location |
|---|---|---|---|
| Backblaze B2 | Content storage | Customer Content, Derived Data | US |
| Oracle Cloud | Hosting and processing | All service data | US |
| Cloudflare | CDN, DNS, bot protection | Traffic; delivery of media | Global edge |
| Google (Gemini API) | AI content analysis | Frames, audio, transcripts per request | US |
| Google (OAuth / Drive API) | Sign-in; Drive imports you initiate | OAuth identity; files you select | US |
| ElevenLabs | Transcription | Audio being transcribed | US |
| Anthropic (Claude API) | AI analysis/generation (alternate provider) | Text/analysis context per request | US |
| Stripe | Payments | Billing details | US |
| Resend | Transactional email | Name, email address, message content | US |
Verified deployment locations: the United States for Backblaze B2 storage and Oracle application compute; global edge for Cloudflare delivery. For the other providers, locations reflect the arrangements applicable to our accounts as recorded on the subprocessor page — this table does not independently promise US-only processing for them, and a provider's headquarters does not by itself establish data residency.
Separately from service providers, we disclose content at your direction when you share it: to the workspace members and project guests you authorize, and — for public links — to anyone who has the link, subject to the password and expiration you configure. Shared pages include the content and its transcript with speaker display names; they never expose the people index, face crops, or face/voice identifiers. Share only what you are authorized to disclose.
We also disclose information if required by law or valid legal process (we will notify the affected customer unless legally barred), to protect the Services and their users from harm, and in connection with a merger, acquisition, or asset sale — in which case this Policy's protections follow the data and we will notify you.
11. Security incidents
If a security breach affects your personal information or Customer Content, we will notify affected customers without undue delay with what we know, what it means for you, and what we are doing.
12. Your rights
12.1 Everyone, self-serve. You can access and update account information in settings and — to the extent your workspace role permits — export or delete content, at any time; you can always delete your own account. Deleting your individual account does not delete content controlled by a workspace you contributed to (ToS §4.2). Email preferences are managed in settings or via unsubscribe links.
12.2 Roles and routing. For account, billing, website, and usage data, Synema acts as the business/controller. For Customer Content and Derived Data, Synema acts as a service provider/processor for the workspace customer: if your request concerns content a customer uploaded (including footage you appear in), we will route it to that customer where we can reasonably identify them and assist as our contract and applicable law require (§4) — except for data in the optional program under §7.2(b), which we handle directly as its controller.
12.3 What we collect, from where, and why. In the preceding 12 months we have collected these categories: identifiers and professional contact information; account credentials; commercial and billing information; internet, device, and usage information; audio, visual, and electronic information contained in Customer Content; biometric information, where face or voice identifiers are processed to identify a person within a workspace (sensitive personal information under some laws, used only as §6 describes and only to provide the Services and for security); and Derived Data and inferences generated to provide the Services. Sources: you, your workspace and its members, integrations you connect, your device or browser, and our service providers. Purposes: §5. Recipients: the service providers listed in §10 and — at your direction — the workspace members, project guests, and share-link recipients described there (content, transcripts, and speaker display names may reach them; raw biometric identifiers never do). We do not sell personal information and do not share it for cross-context behavioral advertising.
12.4 Retention by category. §9 states our retention schedule. For categories not separately listed there: account and contact data are kept while the account is active, then deleted or anonymized within 30 days; billing and tax records, 7 years; biometric identifiers, per §6.4. Identifiable editing and product-usage records follow the retention of their source records and are not kept longer for improvement purposes; data qualifying as de-identified is maintained as such (§7.3).
12.5 Exercising your rights. Depending on your location (e.g., EEA/UK GDPR; California CCPA/CPRA and other US state privacy laws), you may have the right to access, correct, delete, or receive a copy of your personal information, to restrict or object to its processing, and to withdraw consent — without being discriminated against for exercising these rights. Submit requests through your account or to privacy@synema.co. We verify requests using information proportionate to their sensitivity — for account holders, ordinarily through the authenticated account — and respond within the legally required time.
12.6 Authorized agents and appeals. Where your state's law provides, an authorized agent may submit a request on your behalf — no Synema account is needed — with proof of your authorization (we may confirm directly with you). If we deny a request, we will explain why and how to appeal: write to privacy@synema.co with the subject "Privacy Rights Appeal" and we will respond within the period your state's law requires, including identifying the regulator with whom you may lodge a complaint. You may also complain to your local supervisory authority.
12.7 Preference signals. Where the law requires, we honor opt-out preference signals such as Global Privacy Control. Because we do not sell personal information or share it for advertising, such a signal does not change our current practices — and we never treat one as consent. A preference signal also does not control the separate editing-activity setting (§7.2(a)), which you manage in workspace settings.
12.8 International transfers. We are a US company and process data in the United States. Where we receive personal data from regions with transfer restrictions (e.g., the EEA/UK), we rely on appropriate safeguards such as Standard Contractual Clauses.
12.9 GDPR legal bases. Where the GDPR applies: we rely on contractual necessity for account and billing processing needed to perform a contract with the individual concerned; where our customer is an organization, we process its representatives' account and billing-contact information for our legitimate interests in administering that relationship; usage and security data likewise rest on our legitimate interests in operating, improving, and protecting the Services; records we must keep rest on our legal obligations; and optional processing rests on the basis identified at the point of consent. For biometric identification, our customers must establish the required legal basis — including any Article 9 condition — for the people in their footage before enabling it; accepting our Terms is not itself biometric consent (§6.3).
13. Cookies
We use first-party cookies strictly for sign-in sessions, security, and remembering interface preferences. We do not use third-party advertising or analytics cookies. Because these cookies are essential to operating the Services, there is no tracking-consent banner; you can clear them in your browser, which signs you out.
14. Children
The Services are for professionals 18 and over, and we do not knowingly collect personal information from children under 13. Customer footage may depict minors (for example, documentary subjects); responsibility for consent lies with the customer (§4), and such footage receives the same protections as all Customer Content.
15. Changes to this Policy
We will post updates here with a new effective date and version number. For material changes we will notify you by email or in the Services at least 30 days before they take effect, following the acceptance procedure in our Terms (§2.3). Data collected earlier remains subject to the commitments in effect when it was collected unless we obtain any separately required permission for a new use — and acceptance required to keep using the Services is never treated as an opt-in to global learning.
16. Contact
Synema.co, Inc. 1711 Carpenter St., Philadelphia, PA 19146 privacy@synema.co · support@synema.co