// LEGAL / PRIVACY_POLICY
// PRIVACY_POLICY
Effective 26 July 2026. This policy describes the current public service.
1. Controller and scope
Syphio is operated by Ludovic Fournier in France. For privacy requests, contact contact@syphio.io.
This policy covers syphio.io, Syphio accounts, the authenticated application, Roadmap registrations and public report links. The public Demo contains labelled sample data and does not identify a real merchant.
2. Data and purposes
Account and authentication: email address, optional name and profile image, authentication provider identifiers, session records and security events. We use these data to create and protect your account, under the service contract and our legitimate interest in preventing abuse.
Workspace data: workspace membership, role and active-workspace preference. We use these data to provide authorized access and preserve application context.
Roadmap Feature Updates: normalized email, stable feature key, request source, consent time, subscription status and lifecycle timestamps. Consent is feature-specific; every confirmation includes a feature-specific unsubscribe link.
Contact and service messages: contact details and message content needed to answer a request or deliver transactional email.
Security and operations: request metadata, IP address, browser information and error logs where needed to operate, rate-limit and secure the service.
Historical billing: customer, subscription and transaction references required to administer earlier billing records and meet accounting obligations. Syphio does not store full card numbers.
3. Theme snapshots and Runtime reports
The current new-audit screen does not accept a theme archive. Before uploads are enabled, Syphio will publish and enforce the snapshot retention, deletion and processing rules that apply to that flow.
A report is publicly accessible only when it is explicitly published. Anyone who receives its URL may be able to open it. Do not publish a report containing personal data, secrets or material you are not authorized to share. Public reports are excluded from Syphio's public telemetry.
4. Legal bases
We process data to perform the service contract, comply with legal obligations, and pursue legitimate interests in security, fraud prevention and reliable operation. We rely on consent for each optional Roadmap notification; withdrawal does not affect earlier lawful processing.
5. Retention
Account: While the account is active, then for the period required to complete deletion and meet legal or security obligations.
Session: 30 days; magic-link verification: 10 minutes.
Roadmap: Until you unsubscribe or the selected feature programme ends. A minimal suppression record may be retained to honour the opt-out.
Contact: For the time needed to answer the request and handle reasonable follow-up.
Security: For the shortest period needed to prevent abuse, investigate incidents and meet legal obligations.
Billing: For statutory accounting, tax and dispute-resolution periods.
6. Processors and transfers
Neon: Managed PostgreSQL database infrastructure. Account, workspace, waitlist and application records.
Vercel: Application hosting, security delivery, cookieless Web Analytics and Speed Insights. Public telemetry is restricted to non-sensitive public routes.
Resend: Transactional email delivery. Magic links, waitlist confirmations and service messages.
Google: Optional social sign-in. Only when Google sign-in is selected.
Stripe: Historical billing and customer-portal records. No Pro checkout is currently offered.
Providers may process data outside France. Where required, Syphio uses contractual and legal transfer safeguards made available by the provider. Provider locations can change; we do not claim a storage region that has not been contractually configured.
7. Cookies and public telemetry
Syphio uses necessary authentication and workspace cookies. Public Web Analytics and Speed Insights are configured as cookieless telemetry and are blocked on authentication, application, unsubscribe and public-report routes. There is no advertising or cross-site tracking.
Names, purposes and durations are listed in the Cookie Policy.
8. Your rights
Depending on the processing, you may request access, rectification, erasure, restriction or portability, object to processing, or withdraw consent. We may need to verify your identity. We answer without undue delay and normally within one month, subject to the extensions and exceptions allowed by law.
Send a request to contact@syphio.io. You may also lodge a complaint with the Commission Nationale de l'Informatique et des Libertés (CNIL) or your local supervisory authority.
9. Security, changes and contact
Syphio applies access controls, encrypted transport, protected authentication cookies and token hashing where appropriate. No online service can promise absolute security.
Material policy changes will be dated and communicated when required. Legal terms are available in the Terms of Service. Privacy contact: contact@syphio.io.