Privacy Policy
Last updated: 1 July 2026
You pour your team's real thinking into Symphonate, so this policy is deliberately concrete about what we collect, where it goes, and what we will never do with it. The one-line version: your content is yours, we don't train AI models on it, we don't sell it, and you can export or delete it at any time.
1. Who we are
Symphonate operates the service at app.symphonate.ai and this website. For
your account data, we are the data controller; for the content your workspace creates, we
process it on your team's behalf. Contact:
founder@symphonate.ai.
2. What we collect
- Account data: email address, display name, hashed password (bcrypt — we never store or see the plaintext), optional avatar.
- Workspace content: the messages, decisions, artifacts, lists, and file uploads you and your team create.
- Usage telemetry: product events (sign-up, workspace created, decision logged, …) via PostHog, in production only. Events identify your account so we can measure activation — they never include message bodies.
- Operational logs: server logs and error reports (Sentry). Error reports exclude message bodies.
- Marketing-site analytics: when enabled, this website uses Plausible — cookieless, aggregate page-view counts, no personal profiles.
3. How we use it
- To run the Service: store and sync your workspace, deliver messages, generate AI responses, send transactional email (invites, verification, digests).
- To keep it working and safe: error tracking, abuse and rate-limit enforcement, security auditing (an append-only audit log of high-value actions in your workspace, visible to your workspace admins).
- To improve the product: aggregate usage funnels (which steps new teams get stuck on).
- Never: to train AI models, to advertise to you, or to sell or rent to anyone.
4. AI processing
When an AI teammate participates in a thread, the relevant workspace context (recent messages, decisions, artifacts) is sent to that AI's provider to generate the response — that's the feature working as designed. We only send what the response needs. Every AI provider is called under its commercial API terms with training disabled: your content is not used to train their models, and it is never used to train ours.
5. Sub-processors
- Anthropic — AI inference for the primary AI teammate (commercial API terms, training disabled).
- Google Gemini — inference for the optional second AI teammate, when enabled (paid API tier, training disabled).
- AWS — hosting and storage (ap-southeast-2, Sydney).
- Sentry — error tracking (no message bodies).
- PostHog — product analytics (production only; no message bodies).
- Resend — transactional email.
- Plausible — cookieless marketing-site analytics, when enabled.
- Stripe — payments (only once paid tiers launch).
We'll update this list before adding a sub-processor that handles workspace content.
6. Cookies and local storage
The app keeps your session token and UI preferences in your browser's local storage — no advertising cookies, no cross-site trackers. This marketing site sets no cookies.
7. Sharing you control
- Your workspace content is visible only to your workspace's members and the sub-processors above.
- If a member creates a public share link (for example, sharing a decision), that specific item becomes visible to anyone with the link until the link is revoked. Nothing is ever public unless someone on your team explicitly shares it.
- We disclose data to authorities only when legally compelled, and we'll tell you unless prohibited.
8. Retention and deletion
- Workspace content is kept for as long as your workspace exists — durability is the product.
- Deleting a thread or workspace (an owner action) removes its content.
- Account deletion: email founder@symphonate.ai; we process requests within 30 days. Backups age out within a further 30 days.
- Export first, any time: in-app CSV/JSON decision exports, workspace zip export, and the read-only API.
9. Where data lives
The Service is hosted on AWS in Sydney, Australia (ap-southeast-2). AI providers and some operational sub-processors process data in the United States. Where transfer rules (like GDPR) apply, transfers rest on the providers' standard contractual clauses.
10. Your rights
Depending on where you live (GDPR, UK GDPR, Australian Privacy Act, CCPA), you may have the right to access, correct, export, delete, or restrict processing of your personal data, and to complain to your local regulator. Exercise any of them via founder@symphonate.ai — export and deletion are also available directly, as above. We don't discriminate against anyone for exercising their rights.
11. Children
Symphonate is a workplace tool for adults — you must be 18 or older to use it. We don't knowingly collect data from anyone under 18; if you believe we have, email us and we'll delete it.
12. Changes
We'll update this policy as the product evolves and note the date at the top. For material changes — especially anything touching workspace content — we'll give at least 14 days' notice in-app or by email.