Privacy

Privacy Policy

The current terms and notices governing Synara and the services made available through synara.co.uk.

This Privacy Policy explains the personal data Synara processes, why we process it, who may receive it, how long we keep it, and the rights available to you. We aim to collect what is reasonably necessary to run the website, accounts, Studio connection, support and subscriptions.

1. Who controls your data

For the personal data covered by this notice, the controller is Synara Technology, the operator of synara.co.uk. Our privacy contact is support@synara.co.uk.

This notice is written primarily with UK data-protection law in mind and is intended to provide information relevant to UK and EEA users where applicable. Additional rights may apply in your jurisdiction.

2. Data we collect

Account and identity information

When you create or verify an account, we may process your email address, account identifier, display name or other account profile information that you provide. We may also store a record showing when the account was created and the version of the legal terms you accepted.

Authentication information

For one-time email verification and account security, the service may process temporary verification codes, code hashes, timestamps, verification state, rate-limit state, sign-in state and related security metadata. We do not need to store your email password because the service uses verification rather than a traditional password flow.

Usage and service data

We may process credit balances, free-usage dates, subscription state, plan information, feature flags, plugin status, session identifiers, connection timestamps, task states and error information needed to operate the service.

Roblox Studio and project data

If you connect the Studio integration, information made available by the plugin can include Roblox object names, class names, hierarchy paths, service names, properties, selected or matching objects, source code, asset information, task state and other development metadata. The exact fields depend on the request, plugin version and features you use.

Prompts and conversations

Your prompts, conversation history and related structured context may be processed so Synara can answer your request, identify relevant targets, generate code, configure an asset, or continue a conversation. Some sessions can also contain snippets or metadata supplied by the connected Studio plugin.

Payment and subscription information

If you purchase Pro, we may receive and store subscription-related information such as a Stripe customer identifier, subscription identifier, plan state, billing status, payment event identifiers, invoice-related metadata and the email associated with the purchase. Stripe processes payment-card details directly. Synara is not intended to store your full card number.

Support communications

If you email support, we process the email address, message contents and attachments you choose to send, together with enough context to investigate the issue.

Technical information

Our infrastructure may process ordinary technical metadata associated with requests, such as timestamps, request paths, IP address, user agent, security signals, error logs and anti-abuse information. We use this type of information to provide, secure and troubleshoot the service.

Information from third parties

We may receive information from service providers such as Stripe or email providers, or from an administrator where an account is managed for an organisation. We may also receive information from the Roblox plugin when you explicitly connect it.

3. What we use personal data for

To provide the service. We use account, session, project and conversation data to authenticate you, maintain your workspace, connect the Studio plugin, prepare tasks, deliver generated output and keep the product functioning.

To provide AI-assisted features. We process prompts and relevant context through the AI infrastructure used to generate responses or structured task plans. The service may send selected project information and conversation context to the applicable AI provider so the requested feature can run.

To administer subscriptions. We use billing and subscription metadata to start, maintain, cancel and verify Pro access and to reconcile payment events.

To keep the service secure. We process security signals, authentication events, session state and service logs to detect abuse, investigate incidents and protect users.

To provide support. We use support messages and account information to answer questions, fix bugs, investigate billing issues and respond to legal or privacy requests.

To comply with law. We may retain or disclose information when necessary to comply with legal obligations, enforceable requests, court orders, tax/accounting obligations, or to establish, exercise or defend legal claims.

To improve reliability. We may use service metrics, aggregated information and limited diagnostic data to understand errors, performance and feature usage. We do not sell personal data.

4. Lawful bases

Where UK GDPR, EU GDPR or similar law applies, the lawful basis depends on the processing:

We may process more than one category of personal data for the same feature where the legal basis differs between purposes.

5. AI providers and model processing

Synara uses AI infrastructure to generate responses and structured development tasks. The current application code sends requests to Groq's API using configured server-side API credentials. A request can include your prompt, conversation context and project information necessary for the requested operation.

Do not treat the chat box as a place to submit passwords, secrets, private keys, financial credentials or information about other people that you do not have permission to process. You are responsible for ensuring that the information you submit is appropriate for the service.

Third-party AI providers can have their own processing terms and policies. We only send information needed for the applicable feature and use server-side credentials rather than exposing provider keys to the browser.

6. Roblox and connected project information

Synara is designed to assist with projects you control or are authorised to edit. When you connect the plugin, project data can leave the Studio process and be transmitted to Synara's servers so that Synara can search, reason about, configure or modify the requested target.

Because project source code and object metadata can themselves contain personal information, you should avoid placing unnecessary personal data into your game objects, scripts, comments, test fixtures or prompts.

Synara does not control Roblox's privacy practices. Data that stays within the Roblox platform or is processed by Roblox is governed by Roblox's own notices and terms.

7. Payments and Stripe

Pro purchases are handled through Stripe. Stripe can process payment-card information, billing details, payment authentication information and fraud-prevention signals under Stripe's own privacy documentation and contractual terms.

Synara stores enough information to know that a payment or subscription exists and to provide the corresponding access. This can include Stripe customer and subscription identifiers, plan status and billing event metadata.

We do not ask you to send card numbers or security codes to support. Do not include full payment-card information in an email to us.

8. Cookies, local storage and similar technologies

Synara can use browser storage such as localStorage and sessionStorage for necessary product state, including remembering the signed-in user representation, pending navigation state, and session-related UI preferences. These mechanisms are part of the web application's normal operation.

Where we introduce non-essential cookies or similar technologies for analytics, advertising or optional functionality, we will provide the notices and choices required by applicable law. The site currently includes an ads.txt endpoint for the advertising ecosystem, but the existence of that file does not by itself mean the browser is given an advertising cookie.

9. How we share data

We may disclose personal data to:

We do not sell your personal data to data brokers or provide it to advertisers for their own unrelated purposes.

10. International transfers

Some suppliers used to operate Synara may process information outside the UK or EEA. Where a transfer is subject to a restricted-transfer regime, we aim to use an appropriate legal mechanism, such as an adequacy decision or approved contractual safeguards, where required.

Because third-party infrastructure can change, the exact country of processing can change over time. We will update this notice when a change materially affects the information we are required to provide.

11. Retention

We keep personal data only for as long as reasonably necessary for the purpose for which it was collected, subject to legal, accounting, security and dispute requirements.

Specific retention can vary because security logs, backups and legal records may need a longer period than normal operational data.

12. Security

We use reasonable technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse and alteration. Examples include server-side API credentials, authentication checks, access controls, restricted secret handling and measures intended to limit unauthorised service use.

No internet service can guarantee absolute security. You are also responsible for using secure devices, protecting your account, reviewing Studio tasks before execution, and avoiding unnecessary secrets in prompts or project data.

13. Your data-protection rights

Depending on where you live and the law that applies, you may have the right to request access to personal data, correction of inaccurate information, deletion, restriction of processing, data portability, or objection to certain processing. You may also have a right to withdraw consent where consent is the legal basis.

You may object to processing based on legitimate interests in circumstances provided by law. You can also ask us to explain a decision where data-protection law gives you a right concerning solely automated decision-making or profiling.

These rights are not absolute. We may need to retain some information to comply with law, prevent fraud, preserve evidence, or defend legal claims.

14. How to make a request

Email support@synara.co.uk and state which right you want to exercise. Please send the request from the email associated with your account where possible. We may need reasonable information to verify your identity before releasing or changing data.

We aim to respond within the period required by applicable law. If we need more time because a request is complex or numerous, we will explain that where the law requires it.

15. Complaints

We want to resolve privacy concerns directly. You can contact us first at support@synara.co.uk.

If UK GDPR applies to you, you may also complain to the UK's Information Commissioner's Office (ICO). If EU GDPR applies to you, you may have the right to complain to the data-protection supervisory authority in the EU/EEA country where you live, work or believe an infringement occurred.

16. Children's privacy

Synara is a development tool, not a service designed specifically for children. We do not knowingly request more information from children than is necessary to operate the service. If you believe a child has provided personal data without appropriate authorisation, contact us and we will assess the request.

17. Your responsibilities

You are responsible for making sure that information you upload or submit is lawful to share with Synara. You should not send us another person's private information unless you have a lawful basis and authority to do so.

For team projects, the person connecting the project should ensure that the team has appropriate notices or permissions for the processing of source code, project data and any personal information contained in that project.

18. Data relating to other people

Roblox experiences can contain usernames, player identifiers, test accounts, developer identities, analytics data or other information about other people. Do not intentionally submit that information to Synara unless you are permitted to do so. If you are a studio or organisation using Synara on behalf of others, you remain responsible for meeting any transparency and lawful-processing obligations that apply to your project.

19. Automated processing

Synara uses automated systems to generate answers, identify likely targets, prepare tasks and process service state. The system is not intended to make decisions about your legal rights, employment, creditworthiness, healthcare, or similarly significant matters. It is a development assistant and the output is reviewed by you before use.

20. Changes to this Policy

We may update this Privacy Policy when our processing changes, when suppliers change, or when legal requirements change. The effective date and version are shown at the top. We will take any additional notice or consent steps required by law for material changes to how we process personal data.

21. Contact and controller information

Synara Technology
Website: https://synara.co.uk
Privacy and support: support@synara.co.uk

Please do not send passwords, one-time codes, API keys, recovery codes or full payment-card details in a privacy request.