Privacy Policy
Syphonr is built so your records never reach an AI model. This policy says what we collect, why, who else touches it and what you can ask us to do with it.
The controller is Syphonr. Contact: hello@syphonr.com.
This website and the waitlist
- Waitlist. When you join, we collect the email address and anything else you type into the form. We use it to send your invite and occasional launch news, on the basis of your consent. You can withdraw at any time by replying or writing to us. The form is run by Tally.
- Server logs. Our host records IP address, browser and pages requested for security and to keep the site running (legitimate interest). Logs are deleted after 30 days.
- Fonts. Pages load fonts from Google Fonts, which receives your IP address.
- Cookies. This site sets no cookies and runs no analytics or ad trackers. The embedded Tally form may set its own cookies, covered by Tally's policy.
The product
- Account data. Name, email, workspace and billing details, used to run your account and bill usage (contract).
- Your data. Files you upload and databases you connect are stored in storage kept separate for your organisation. We process them only to answer your questions. We never sell them and never use them to train models.
- What the AI model sees. Your question, your schema as column names and types, and notes you write. It returns a query; we run it; the rows go to you and never into a prompt, a log or a trace.
- One exception, only when you ask. If you ask Syphonr to analyse charts on screen, we first show you exactly what will be sent (at most 8 charts, 50 points each, never a table). Nothing leaves until you approve.
- Usage records. Questions asked, credits used and error logs, kept to bill you and keep the service reliable.
Who else processes data
We use a small number of providers, each bound by a data processing agreement:
- DigitalOcean: hosting, database and file storage
- OpenAI: language models (questions, schemas and notes only, as above)
- Tally: waitlist form
- Google: web fonts
Some providers are outside the UK and EEA. Where they are, transfers rely on adequacy decisions or standard contractual clauses.
How long we keep it
Waitlist entries: until you launch an account or ask us to remove you. Account data and your data: for as long as your account is open, then deleted within 30 days of closing it, except records we must keep by law (such as invoices).
Your rights
You can ask to access, correct, delete, restrict or export your personal data, or object to how we use it. Write to hello@syphonr.com; we answer within one month. You can also complain to your data protection authority.
Changes
If this policy changes in a way that matters, we will email account holders before it takes effect. The date at the top always shows the current version.