Privacy Policy

This Privacy Policy explains how Synema.co, Inc. ("Synema," "we," "us") collects, uses, and shares information when you use our websites, applications, and services (the "Services"). Synema is a video library and AI editing platform for professional teams.

Questions or requests: privacy@synema.co.

Plain-language summaries appear in boxes like this throughout. They are for readability only — the full text controls.

1. Who this covers

Throughout this Policy, "you" means the person reading it in the role that applies to them — usually a customer, or a member of their team, using the Services. Where a passage instead speaks to someone who appears in a customer's footage without using Synema themselves, it says so explicitly (§4, §6), and "the customer" there means the workspace owner who uploaded the footage.

2. Information we collect

2.1 Account information. Name, email address, password (stored only as a salted hash), company/workspace name, role. If you sign in with Google, we receive your name, email address, and profile photo from Google.

2.2 Customer Content. The video, audio, images, and documents you or your team upload or import, and collaboration content (comments, labels, project structures, edits).

2.3 Derived Data. Data our systems generate from Customer Content to power the Services: transcripts and captions; scene descriptions, tags, and classifications; content embeddings for search; face and voice identifiers and the people index for your workspace (§6); edit histories and quality metrics.

2.4 Usage and device data. IP address, browser and OS, pages and features used, timestamps, and error/diagnostic logs. For share links we log access (IP address, user agent, time) so the content owner can see activity on what they shared and so we can enforce link passwords and expiration.

2.5 Website visitors. The synema.co website sets no cookies and uses no third-party analytics or trackers. We keep a first-party log of visits: approximate location (country, region, city), network, device type, page visited, referrer, and an anonymized identifier derived from your IP address using a salt that rotates daily — the IP address itself is not stored. If you request early access, we store the email address you provide and use it only to contact you about access. Fonts and icons load from content-delivery networks, which receive standard web-request data to serve those files.

2.6 Billing. Payments are processed by Stripe; we receive plan, transaction status, and the card's last digits — never full card numbers.

3. Our roles

For account, billing, usage, and website data, Synema is the data controller. For Customer Content and Derived Data — including personal data embedded in the content itself, such as the people who appear and speak in footage — Synema is a processor/service provider acting on the customer's instructions; the customer (the workspace's account owner or their organization) is the controller. One exception: in the optional global-improvement program (§7.2(b)), Synema acts as an independent controller for the personal data used in that program, under its supplemental notice, and handles applicable privacy requests for it directly. Business customers can request our Data Processing Agreement at privacy@synema.co.

4. People appearing in customer footage

Our customers upload footage that shows people — interview subjects, colleagues, event attendees. For that footage:

5. How we use information

5.1 To provide the Services. Store, organize, and stream your library; process content with AI (§5.2); enable search, review, sharing, and StoryCut editing; operate accounts, workspaces, and billing; send transactional email (verification, password resets, invites, share notifications).

5.2 AI processing of Customer Content. Uploading content triggers automated analysis:

Frames, audio, and transcripts are sent to the AI providers named in §10 for this processing. We use Anthropic's commercial API and Google's paid Gemini tier under terms that do not permit training on your content, and we maintain ElevenLabs' account-level training opt-out; we do not submit your content through provider configurations that permit training on it. Face and voice identifiers are computed by models running on Synema-operated servers — no third-party biometric service is used.

5.3 Google Drive import and Google user data. If you choose to import content from Google Drive, we request Google's read-only Drive scope (drive.readonly) and use that access only to display your available files and folders and to download the specific files or folders you select for import through Synema's interface — including the contents of a folder you expressly select. We do not modify, delete, create, move, or otherwise manage anything in your Drive.

We store an OAuth token only to perform imports you initiate. You can disconnect Google Drive at any time in Synema's settings or at myaccount.google.com/permissions; on disconnect or revocation we delete the stored token and stop all further Drive access. Disconnecting does not remove content already imported — imported copies are Customer Content in your workspace, stored and deletable exactly like directly uploaded content (§8, §9), and the workspace members, guests, and recipients you share with may access them through the sharing features you direct, like any other Customer Content.

Google user data — including imported content and data derived from it — is used only to provide or improve the user-facing import, storage, organization, search, editing, sharing, security, and support features you request through Synema, in accordance with Google's API Services User Data Policy, including its Limited Use requirements. It is not sold; not used for advertising; not used to build profiles unrelated to Synema's user-facing features; and never used to train, develop, fine-tune, or improve models or systems serving other customers — no workspace setting, customer opt-in, or other program overrides this restriction (§7.2). We do not transfer Google user data to third parties except: to processors necessary to provide the requested feature, bound by use restrictions (§10); with your affirmative consent for the specific transfer; for security or abuse prevention; to comply with applicable law; or in connection with a merger, acquisition, sale of assets, or other transfer of the relevant business, only after obtaining your explicit prior consent — notice alone is not sufficient. No person reads your specific Drive files or their contents unless you have given affirmative, documented permission for the specified files in connection with support you request, or access is necessary for security, legal compliance, or another use the Google policy expressly permits. This section controls over any broader permission elsewhere in this Policy.

5.4 To secure and improve the Services. Debugging, abuse and fraud prevention (including bot protection on sign-in), monitoring, and product analytics from usage data. Any improvement use of Customer Content is governed by §7.

5.5 To communicate. Service and account notices; separately, product news you can opt out of at any time.

5.6 Legal. To comply with law and to enforce our Terms.

We do not sell personal information or Customer Content, use either for third-party advertising, or use Customer Content for advertising of any kind.

6. Biometric identifiers (faces and voices)

6.1 What we create — and what we deliberately don't. The Services compute numerical representations of faces ("face embeddings") and voices ("voice prints") from Customer Content and link them into a people index for the workspace — so your team can search footage by person and the editor knows who is speaking. Under some laws these are "biometric identifiers."

This happens in two technically distinct stages. First, our systems detect the presence and approximate location of faces in footage solely to classify each as an intended subject of the shot or incidental to it (too small, in the background, out of focus, or passing through the frame — though a person speaking on camera is never treated as incidental, whatever their size in frame). For this classification step we retain only non-identifying bounding-box position and size — not facial landmarks, facial measurements, face crops, embeddings, templates, persistent identity tracks, or any other data designed or capable of identifying or matching an incidental person across content. Second, only after a face is classified as an intended subject in an upload where you have enabled people identification (§6.3) do we create a face embedding for workspace-limited person search and organization; we treat that embedding as a biometric identifier wherever applicable law does. If any detection process were to create or retain data capable of identifying or matching an individual, we would treat that data as biometric information and apply every control in this Section to it. Classification is automated and can be wrong: the per-file counts report the system's classifications rather than independently verifying them, and a person set aside as incidental in one appearance may still be enrolled from another appearance in which they are an intended subject. This intended-subject filtering applies to face processing; voice and speaker identification is a separate operation applied to speech in your content and does not use the face filter — the per-upload control (§6.3) lets you decline face and voice processing together. Voice prints have their own minimization rule: they are used only to match speech to people already in your workspace's index, and never to create a person entry. New person entries are created only for people who speak on camera. Your library shows, per file, how many faces were detected, how many were processed as intended subjects, and how many were set aside as incidental — so you can verify this behavior yourself.

6.2 Scope and purpose limits. Face and voice identifiers:

6.3 Consent and customer controls. Our customers are contractually required to provide any legally required notice to, and obtain any legally required consent from (including written consent where a law such as Illinois' Biometric Information Privacy Act requires it), individuals appearing in their footage before uploading it for processing. Where written consent is required, it must specifically cover biometric data collection — the collection of face and voice identifiers, its purpose, and the retention term (§6.4) — and a general appearance or model release may not be sufficient by itself. Customers confirm this authorization when creating an account or workspace; each upload then requires choosing either to confirm that the footage was not filmed in Illinois and does not depict Illinois residents AND that legally required written or electronic consent has been obtained from every individual depicted — deliverable on demand — or to decline face and voice processing for that upload entirely, and the choice is recorded. Face and voice identification is not offered for Illinois accounts or for footage filmed in Illinois or depicting Illinois residents. Customers must keep records sufficient to demonstrate the required notices and consents and provide them to us on reasonable request in connection with a complaint, regulator inquiry, or legal obligation. We may disable people-identification for particular content or workspaces where we reasonably believe the required authorization has not been obtained. Nothing in this allocation limits obligations that applicable law does not permit to be delegated.

6.4 Retention and destruction. This section is our written retention and destruction schedule for biometric identifiers. We permanently destroy a face or voice identifier at the earliest of: (i) when the purpose for which it was created has been satisfied — including deletion of the source content (§9), deletion of the associated person entry or workspace, the customer disabling people-identification for the relevant content, or — for any embedding not linked to a confirmed person entry, whether an unconfirmed candidate or an unassigned print — 180 days after its creation, with advance warnings to your team before removal; (ii) a verified deletion instruction from the customer; (iii) where the depicted individual has themselves used the Services, 3 years after their last interaction with the Services; or (iv) where the consent under which the footage was provided states a term, the end of that term. For individuals who have not themselves used the Services, the collection purpose — organizing and searching the customer's own library — continues only while the source footage remains in the customer's active workspace under the consent it was provided with: the identifier lives exactly as long as the footage does, and is destroyed with it. Continued activity on the customer's account never extends retention beyond these triggers, and we do not create or retain any biometric template for a face classified as incidental (§6.1). Where applicable law sets a shorter deadline, the shorter deadline applies — for identifiers subject to Texas law, destruction occurs no later than one year after the purpose for collection expires. These deadlines apply to every copy, including backup copies — backup rotation does not extend them.

7. Learning: your workspace vs. the global system

7.1 Learning that stays in your workspace (part of the service). Your workspace's results improve from your team's own activity: confirmed people tags, corrections to labels and transcripts, editing choices and preferences. This adapts only your workspace's search, people index, and editing behavior. It is service delivery, not model training.

7.2 Improving Synema for everyone. Different rules for different kinds of data:

(a) Editing-activity data — on by default, with an off switch. We use editing-activity data — the actions your team takes in the editor (edits made, story structures chosen, suggestions accepted or rejected, completion signals) — to improve the editorial systems that serve all customers. Before any such use we apply measures designed to remove direct identifiers and prevent the data from being reasonably linked back to a person, account, workspace, or specific content; we never use footage, audio, images, transcripts, face or voice identifiers, or people-index entries for this purpose; qualifying records carry action types, structural categories, and coarse measurements rather than free text, prompts, exact timecodes, or references to specific content; we do not attempt to re-identify the data and require the same of anyone who receives it. Only records satisfying both conditions — the limited content just described AND no reasonable linkability — enter this tier; a record failing either is excluded from it and remains governed by subsection (b). Subsection (a) is a limited exception to subsection (b) for qualifying records only, and the Google-data exclusion in (d) always controls. Turn it off any time in workspace settings; opting out never degrades your service.

(b) Customer Content — opt-in only. We do not use Customer Content — footage, audio, images, transcripts — or Derived Data to train, re-train, fine-tune, or otherwise improve the models and editorial systems that serve other customers unless the customer has expressly opted in through a workspace setting or written agreement. The consent states what would be used — for example, editorial-structure patterns rather than the underlying footage — and can be withdrawn for future use at any time. Participation is a separate, optional program in which Synema acts as an independent controller for the defined purpose, under a supplemental notice describing scope, purposes, retention, and withdrawal; a workspace opt-in does not by itself establish consent from the people depicted, and content containing identifiable people is eligible only where the legally required basis and subject notices exist (§4, §6.3).

(c) Face and voice identifiers — never used beyond your workspace (§6).

(d) Google Drive imports — never, regardless of settings. Content imported from Google Drive, and data derived from it, is excluded from every form of global learning; neither the editing-activity default nor a workspace opt-in overrides this (§5.3).

7.3 Aggregated data. We may use aggregated, de-identified data — data processed with reasonable measures so it is not reasonably linkable to an identified person or customer (feature usage counts, performance and reliability metrics) — to operate and improve the Services. We maintain and use such data in de-identified form, do not attempt to re-identify it except solely to test whether our de-identification measures work, and require any recipient to maintain the same protections. Security-incident investigations use separately governed identifiable records, not this data.

8. Where your content lives and how it's protected

No system is perfectly secure; we work hard to protect your information but cannot guarantee absolute security. Keep independent backups of your original media.

9. Retention and deletion

DataRetention
Content you delete7 days in trash (restorable), then permanently deleted from our production systems by an automated purge — files and the data derived from them (transcripts, embeddings, face/voice identifiers)
"Empty trash"Removed from your library immediately and purged from production systems by the next automated purge run, as above
Content after account closureExport window of 30 days, then purged as above
Face/voice identifiers§6.4's earliest applicable deadline, measured by the depicted individual — never by account activity. Applies to every copy, including backups; backup rotation does not extend it
Account recordsDeleted or anonymized within 30 days of account deletion, except records we must keep (e.g., tax and billing: 7 years)
Server, access, and share-link logs12 months
Website visitor log12 months
Residual backup copiesMedia files: no backup copies are kept, so the production purge is complete. Database records: encrypted nightly backups on a rolling cycle; residual copies overwritten within 30 days

Legal holds, active investigations, and disputes can extend retention of specific data, only for as long as the necessity exists and only to the extent applicable law (including biometric-privacy law) permits the extension.

10. Who we share information with (subprocessors)

We share information only with the service providers below, only for the purposes shown, under contracts limiting their use of it. The current list is also maintained at synema.co/subprocessors, where we post notice of material changes.

ProviderPurposeWhat they receiveLocation
Backblaze B2Content storageCustomer Content, Derived DataUS
Oracle CloudHosting and processingAll service dataUS
CloudflareCDN, DNS, bot protectionTraffic; delivery of mediaGlobal edge
Google (Gemini API)AI content analysisFrames, audio, transcripts per requestUS
Google (OAuth / Drive API)Sign-in; Drive imports you initiateOAuth identity; files you selectUS
ElevenLabsTranscriptionAudio being transcribedUS
Anthropic (Claude API)AI analysis/generation (alternate provider)Text/analysis context per requestUS
StripePaymentsBilling detailsUS
ResendTransactional emailName, email address, message contentUS

Verified deployment locations: the United States for Backblaze B2 storage and Oracle application compute; global edge for Cloudflare delivery. For the other providers, locations reflect the arrangements applicable to our accounts as recorded on the subprocessor page — this table does not independently promise US-only processing for them, and a provider's headquarters does not by itself establish data residency.

Separately from service providers, we disclose content at your direction when you share it: to the workspace members and project guests you authorize, and — for public links — to anyone who has the link, subject to the password and expiration you configure. Shared pages include the content and its transcript with speaker display names; they never expose the people index, face crops, or face/voice identifiers. Share only what you are authorized to disclose.

We also disclose information if required by law or valid legal process (we will notify the affected customer unless legally barred), to protect the Services and their users from harm, and in connection with a merger, acquisition, or asset sale — in which case this Policy's protections follow the data and we will notify you.

11. Security incidents

If a security breach affects your personal information or Customer Content, we will notify affected customers without undue delay with what we know, what it means for you, and what we are doing.

12. Your rights

12.1 Everyone, self-serve. You can access and update account information in settings and — to the extent your workspace role permits — export or delete content, at any time; you can always delete your own account. Deleting your individual account does not delete content controlled by a workspace you contributed to (ToS §4.2). Email preferences are managed in settings or via unsubscribe links.

12.2 Roles and routing. For account, billing, website, and usage data, Synema acts as the business/controller. For Customer Content and Derived Data, Synema acts as a service provider/processor for the workspace customer: if your request concerns content a customer uploaded (including footage you appear in), we will route it to that customer where we can reasonably identify them and assist as our contract and applicable law require (§4) — except for data in the optional program under §7.2(b), which we handle directly as its controller.

12.3 What we collect, from where, and why. In the preceding 12 months we have collected these categories: identifiers and professional contact information; account credentials; commercial and billing information; internet, device, and usage information; audio, visual, and electronic information contained in Customer Content; biometric information, where face or voice identifiers are processed to identify a person within a workspace (sensitive personal information under some laws, used only as §6 describes and only to provide the Services and for security); and Derived Data and inferences generated to provide the Services. Sources: you, your workspace and its members, integrations you connect, your device or browser, and our service providers. Purposes: §5. Recipients: the service providers listed in §10 and — at your direction — the workspace members, project guests, and share-link recipients described there (content, transcripts, and speaker display names may reach them; raw biometric identifiers never do). We do not sell personal information and do not share it for cross-context behavioral advertising.

12.4 Retention by category. §9 states our retention schedule. For categories not separately listed there: account and contact data are kept while the account is active, then deleted or anonymized within 30 days; billing and tax records, 7 years; biometric identifiers, per §6.4. Identifiable editing and product-usage records follow the retention of their source records and are not kept longer for improvement purposes; data qualifying as de-identified is maintained as such (§7.3).

12.5 Exercising your rights. Depending on your location (e.g., EEA/UK GDPR; California CCPA/CPRA and other US state privacy laws), you may have the right to access, correct, delete, or receive a copy of your personal information, to restrict or object to its processing, and to withdraw consent — without being discriminated against for exercising these rights. Submit requests through your account or to privacy@synema.co. We verify requests using information proportionate to their sensitivity — for account holders, ordinarily through the authenticated account — and respond within the legally required time.

12.6 Authorized agents and appeals. Where your state's law provides, an authorized agent may submit a request on your behalf — no Synema account is needed — with proof of your authorization (we may confirm directly with you). If we deny a request, we will explain why and how to appeal: write to privacy@synema.co with the subject "Privacy Rights Appeal" and we will respond within the period your state's law requires, including identifying the regulator with whom you may lodge a complaint. You may also complain to your local supervisory authority.

12.7 Preference signals. Where the law requires, we honor opt-out preference signals such as Global Privacy Control. Because we do not sell personal information or share it for advertising, such a signal does not change our current practices — and we never treat one as consent. A preference signal also does not control the separate editing-activity setting (§7.2(a)), which you manage in workspace settings.

12.8 International transfers. We are a US company and process data in the United States. Where we receive personal data from regions with transfer restrictions (e.g., the EEA/UK), we rely on appropriate safeguards such as Standard Contractual Clauses.

12.9 GDPR legal bases. Where the GDPR applies: we rely on contractual necessity for account and billing processing needed to perform a contract with the individual concerned; where our customer is an organization, we process its representatives' account and billing-contact information for our legitimate interests in administering that relationship; usage and security data likewise rest on our legitimate interests in operating, improving, and protecting the Services; records we must keep rest on our legal obligations; and optional processing rests on the basis identified at the point of consent. For biometric identification, our customers must establish the required legal basis — including any Article 9 condition — for the people in their footage before enabling it; accepting our Terms is not itself biometric consent (§6.3).

13. Cookies

We use first-party cookies strictly for sign-in sessions, security, and remembering interface preferences. We do not use third-party advertising or analytics cookies. Because these cookies are essential to operating the Services, there is no tracking-consent banner; you can clear them in your browser, which signs you out.

14. Children

The Services are for professionals 18 and over, and we do not knowingly collect personal information from children under 13. Customer footage may depict minors (for example, documentary subjects); responsibility for consent lies with the customer (§4), and such footage receives the same protections as all Customer Content.

15. Changes to this Policy

We will post updates here with a new effective date and version number. For material changes we will notify you by email or in the Services at least 30 days before they take effect, following the acceptance procedure in our Terms (§2.3). Data collected earlier remains subject to the commitments in effect when it was collected unless we obtain any separately required permission for a new use — and acceptance required to keep using the Services is never treated as an opt-in to global learning.

16. Contact

Synema.co, Inc. 1711 Carpenter St., Philadelphia, PA 19146 privacy@synema.co · support@synema.co