Effective Date: January 17, 2025 | Last Updated: January 17, 2025
This Privacy Policy describes how Syntara AI, LLC ("Syntara AI," "we," "us," or "our") collects, uses, discloses, and protects personal information when you access or use our website, applications, and services (collectively, the "Services").
By accessing or using the Services, you acknowledge that you have read and understood this Privacy Policy.
This Privacy Policy applies to personal information collected when you:
This Privacy Policy does not apply to third-party websites, services, or platforms that may be linked from our Services. We are not responsible for the privacy practices of those third parties.
Syntara AI is a software-as-a-service ("SaaS") platform that provides real-time market activity alerts and contextual information derived from publicly available data sources. We do not provide investment advice, brokerage services, portfolio management, or trade execution.
We may collect personal information you voluntarily provide, including:
Note: We do not store full payment card numbers. Payment data is handled by our payment processors (e.g., Stripe) under their own privacy policies.
When you use the Services, we may automatically collect:
This data helps us operate, secure, and improve the Services.
We use cookies and similar technologies to:
You may control cookies through your browser settings, but disabling cookies may limit certain features of the Services.
We use personal information for the following purposes:
We do not use personal information to provide personalized investment advice or trading recommendations.
Where applicable, we process personal information based on:
We may share personal information only in the following circumstances:
We may share information with trusted third-party service providers that assist us with:
These providers are contractually obligated to protect your information and use it only for authorized purposes.
We may disclose information if required to:
If Syntara AI is involved in a merger, acquisition, financing, or sale of assets, personal information may be transferred as part of that transaction, subject to appropriate safeguards.
We retain personal information only for as long as necessary to:
Retention periods vary depending on the type of data and legal requirements.
We implement reasonable administrative, technical, and organizational measures designed to protect personal information. However, no system is completely secure, and we cannot guarantee absolute security.
We classify data based on sensitivity. OAuth access tokens, authentication credentials, and financial account identifiers are treated as highly sensitive. We store only the minimum data required for functionality and do not store raw credentials such as passwords, social security numbers, or bank account numbers.
User access is authenticated via a third-party identity provider with session-based authentication. All backend API endpoints are protected by authentication middleware. Database access is restricted to the application service layer only, with no direct human access in production. Sensitive financial operations require additional verification through a separate trading PIN.
All communications between clients and servers use TLS/HTTPS encryption. OAuth token exchanges with third-party services are conducted exclusively over HTTPS. Our database uses encryption at rest provided by our managed hosting infrastructure. All API calls between frontend applications and backend services are encrypted in transit.
Application dependencies are regularly updated. Our infrastructure is managed via a platform-as-a-service (PaaS) provider that handles OS-level patching and security updates. Application containers are rebuilt on each deployment with current base images.
Application logs are monitored for anomalies. Circuit breakers and rate limiting are implemented to prevent cascading failures. Database backups are automated. In the event of a security incident, affected tokens are immediately revoked, affected users are notified, and relevant third-party partners are informed.
All infrastructure is cloud-hosted with no on-premise servers. Physical security is managed by our hosting provider's data center facilities.
We use trusted third-party vendors for hosting, authentication, and brokerage services. All vendors are evaluated for security certifications and compliance standards before integration. Our hosting and authentication providers maintain SOC 2 compliance.
Your information may be processed and stored in the United States or other jurisdictions where we or our service providers operate. Where required, we implement appropriate safeguards for international data transfers.
Depending on your location, you may have rights to:
Requests may be submitted via our contact page.
We may need to verify your identity before responding.
If you are a resident of California or other U.S. states with privacy laws, you may have additional rights, including:
Syntara AI does not sell personal information.
The Services are not intended for individuals under 18 years of age. We do not knowingly collect personal information from minors. If we become aware that we have done so, we will delete such information.
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last Updated" date. Continued use of the Services constitutes acceptance of the updated policy.
Data Protection Notice: Syntara AI is committed to protecting your privacy and handling your personal information responsibly. We do not sell your data and only share it with trusted service providers as described in this policy.
If you have questions about this Privacy Policy or our data practices, please contact us.