Skip to content

Privacy policy

Last updated September 24, 2026

Beta notice. This policy describes our practices during the beta. If you process personal data of people in the EU or UK, have your data protection adviser review it. A full DPA is available on request at privacy@synento.com.

Synento is a product of StudioD24, a business operated in Finland. For your account data, we are the data controller. For the video, audio and participant data you send through the API, you are the controller and we are your processor. A data processing agreement is available on request from privacy@synento.com.

  • Account data: your email address, your name if you give one, your organisation name, and a hash of your password. We never store passwords in readable form.
  • Session content: the audio, video, screen share and chat your users send. We relay and store it as durable streams. We don't decode, inspect or analyse it, and we don't train on it.
  • Usage data: participant-minutes and storage per project, so we can enforce plan allowances and bill accurately.
  • Operational logs: request metadata we use to run and secure the service, kept for a limited period.

This site uses privacy-friendly, cookieless analytics that count page views without tracking individuals across sites. Analytics are not loaded on sign-in and account pages. Signing in sets one essential cookie to keep you signed in. We don't use advertising cookies.

  • S2: durable stream storage for session media.
  • Stripe: payments. Card details go directly to Stripe, and we never see or store them.
  • Resend: transactional email, such as verification and password resets.
  • Vercel: hosting for this site and the dashboard.
  • Sentry: error monitoring. It is configured not to collect IP addresses, request bodies or headers.
  • Hetzner: the servers that run the API.
  • Cloudflare: encrypted database backups (R2) and routing of email sent to our addresses.
  • Better Stack: server logs, uptime monitoring and our status page.
  • Plausible: cookieless page-view counts for this site.

Recordings follow the retention policy you set for each project. The default is 30 days. Deleting a session or a project deletes its streams, exported files and replay links straight away. Closing your account from Settings deletes your account data and, if you are its last member, your organisation and all of its recordings. We keep usage and billing records, and anything else we must keep for tax or legal reasons.

You can access, correct, export or delete your data. The API has an endpoint to redact one participant from a recording, which is usually what you need to honour an erasure request from one of your users. Email privacy@synento.com and we will respond within 30 days.

Traffic is encrypted in transit. API keys are stored only as peppered hashes, and connection tokens are short-lived and scoped to one session and one user. Report vulnerabilities to security@synento.com.