Privacy Policy

SynthPrism Privacy Policy

Effective date: 2026-07-28

Last updated: 2026-08-06

1. Introduction & Scope

This Privacy Policy explains how Martello Systems, LLC ("Martello Systems," "we," "us," or "our") collects, uses, shares, and protects personal information when you use SynthPrism at synthprism.com and related applications and services (the "Service"). It applies to information we process about visitors and Account holders.

This Policy also describes how we handle information about your End Users — the people whose details you (as a business using the Service) import into, collect through, or otherwise submit to the Service, such as your contacts, customers, leads, or subscribers. For that End User information, you are the controller and we act as your processor (or "service provider"/"processor" under applicable law): we handle it on your behalf and under your instructions to provide the Service. You are responsible for having a lawful basis and any required consent to collect and use your End Users' information and to instruct us to process or message it.

By using the Service, you agree to the practices described in this Policy. This Policy is incorporated into and subject to our Terms of Service. If you do not agree with this Policy, please do not use the Service.

2. Information We Collect

  1. Account information. When you register, we collect information such as your name, email address, password (stored in hashed form), business name, and team/workspace details you provide.
  2. Customer Data you provide. We collect and store the information you enter or import to run your business through the Service, including any personal information about your End Users — for example names, email addresses, phone numbers, companies, notes, records, and form or intake submissions.
  3. Communications content. Where the Service sends or receives email, SMS/text, voice, or other communications on your behalf, we process the content of those communications along with related metadata (timestamps, delivery status, opt-out status) so we can deliver, organize, and display them for you.
  4. Payment information. Subscription payments are processed by a third-party payment processor (for example, Stripe, Inc.). We do not collect or store your full payment card numbers. The payment processor processes your payment details directly; we receive limited information such as a transaction identifier, the last four digits and card brand, subscription status, and billing metadata.
  5. Usage, device, and log data. We automatically collect information such as IP address, browser and device type, pages and features used, referring URLs, timestamps, and diagnostic/log data.
  6. Cookies and similar technologies. We use cookies and similar technologies as described in Section 8.
  7. Communications with us. If you contact us (for example, at support@synthprism.com), we collect the content of your messages and our correspondence.

We do not intentionally collect sensitive categories of personal information beyond what is needed to provide the Service, and we ask that you not submit sensitive information (such as government ID numbers, health data, or precise geolocation of End Users) unless a product-specific addendum expressly addresses that category.

3. How We Use Information

We use personal information to: provide, operate, and maintain the Service and your Account; store and organize your Customer Data; run the Automations and campaigns you configure; send and receive the communications you direct; provide AI-assisted features that draft, summarize, or analyze content at your request; process subscriptions, billing, and payments; send transactional and account communications to you; provide customer support; monitor, secure, debug, and improve the Service; detect and prevent fraud, abuse, and security issues; and comply with legal obligations and enforce our agreements. We do not sell your personal information, and we do not use your End Users' personal information for our own marketing.

4. Legal Bases for Processing (GDPR/UK GDPR)

Where the GDPR or UK GDPR applies, we process personal information on the following bases: performance of a contract (to provide the Service and process your Subscription); legitimate interests (to secure, improve, and analyze the Service and prevent fraud and abuse, balanced against your rights and freedoms); consent (for optional communications and certain non-essential cookies, which you may withdraw at any time); and legal obligation (to comply with applicable law, including tax and recordkeeping requirements). For personal information about your End Users, you are responsible for establishing the legal basis for collecting and using it and for instructing us to process it; we process it as your processor on your documented instructions.

5. How We Share Information

We share personal information only as described below. We do not sell your personal information, and we do not share it for cross-context behavioral advertising.

  1. Service providers / sub-processors. We use a limited set of third-party service providers to operate the Service, engaged as our sub-processors and bound by appropriate confidentiality and data-protection terms. These fall into the following categories: cloud infrastructure and hosting; database and file storage; payment processing and subscription billing; email delivery; SMS and voice delivery (where the Service supports messaging); AI/model providers (for AI-assisted features); and analytics providers (for privacy-respecting, consent-gated usage analytics). On the canonical SynthPrism service, our current sub-processors are: Anthropic, PBC (the in-app assistant); OpenAI, L.L.C., fal.ai and ElevenLabs Inc. (image, video, music, voice and lip-sync generation); Brevo (transactional email — sign-in codes, password resets, workspace invitations); Google LLC (Google Analytics 4, which is consent-gated; Google Sign-In; and Google Fonts, which receives your IP address on every page load); Neon (managed PostgreSQL hosting for our application and identity databases); Cloudflare and Martello Systems' own API gateway at keys.martelloyggdrasil.com, which broker our calls to several of the providers above; and our hosting and infrastructure providers. The social platforms you choose to connect receive the content you publish to them — today Bluesky and Meta Platforms (Facebook Pages and Instagram Business), with TikTok in preparation. Payment processing by Stripe, Inc. applies only if and when you purchase a paid plan through in-product checkout; no payment data is processed through the Service until then. Section 6 describes exactly what each AI provider receives.
  2. At your direction. When you send a message, run an Automation, or connect an integration, we share the necessary information with the relevant provider (for example, sending an End User's phone number to our SMS provider to deliver a message you sent) to carry out your instruction.
  3. Legal and safety. We may disclose information if required by law or legal process, or to protect the rights, property, or safety of Martello Systems, our users, or others, or to enforce our Terms.
  4. Business transfers. If we are involved in a merger, acquisition, financing, reorganization, or sale of assets, your information may be transferred as part of that transaction, subject to this Policy.
  5. Reseller or partner billing relationship. If you were referred to, or purchase, the Service through a reseller, agency, or channel partner, limited account and billing information may be shared with that party to administer your relationship with them, as described at the point of purchase.

6. AI Features & Model Providers

SynthPrism is an AI content product. Generating media, cloning a voice, or asking the in-app assistant a question all send some of your information to third-party AI providers. This Section states which providers, what actually reaches them, and what triggers it, so you can decide what to put into the Service. We do not operate any AI model ourselves — every model offered in the Service is run by the third party named below.

  1. Image, video, music and lip-sync generation — fal.ai. When you run one of these generations we send fal.ai the prompt text you wrote, any negative prompt, and the model parameters you chose, and it runs the model you selected (for example Flux, Kling, LTX, Stable Audio). For image-to-video, lip-sync and similar model types we also send the web address of the source image, video or audio you selected, which fal.ai fetches over the internet in order to run the model. Generating a character's avatar sends that character's appearance prompt, or its description if you left the appearance prompt empty.
  2. Image generation and text-to-speech — OpenAI. Where you choose a DALL·E 3 image model or the OpenAI voice, we send OpenAI, L.L.C. your prompt, or the text you asked to be spoken.
  3. Text-to-speech — ElevenLabs. Where you choose an ElevenLabs voice, we send ElevenLabs Inc. the text to be spoken and the identifier of the voice you picked. Previewing a character's voice sends a short line built from that character's name and the beginning of its description.
  4. Voice cloning and voiceprints — ElevenLabs. If you use voice cloning, the audio recordings you upload are sent to ElevenLabs, along with the name and description you give the voice. ElevenLabs creates and holds the resulting voiceprint; we store only the identifier it returns to us. Deleting a saved custom voice in SynthPrism also instructs ElevenLabs to delete it. The biometric-consent terms in the Terms of Service product addendum (Section A5) apply to this feature.
  5. The in-app assistant — Anthropic. When you ask the assistant a question we send your question and your recent conversation history to Anthropic, PBC (Claude models), together with the product name the assistant answers under and the name you gave the assistant. When the assistant uses one of its tools to answer, that tool's result is also sent. Those results can include: asset ids, types, filenames and dates; post ids, platform, status and scheduled/published dates; character names and descriptions; the text of your saved prompts (truncated); the platform and handle of your connected social accounts; and generation-spend totals. The body text of your posts, your uploaded files and images, and your stored social-platform access tokens are never sent to the assistant's model provider. The assistant is scoped to a single brand and cannot read another brand's data.
  6. How these calls are made. Calls to Anthropic and ElevenLabs are routed through an API gateway operated by us or our platform provider, which holds the provider credentials on our behalf; calls to OpenAI and fal.ai are made directly from our servers. Either way, what reaches the AI provider is what is described above.
  7. Training. We do not use your prompts, uploads, or generated output to train any model of our own, and we do not sell or license them to a provider for model training. What a provider may do with an API request is governed by that provider's own terms and privacy policy, which we encourage you to review before submitting sensitive material.
  8. Where your media actually lives, and who can reach it. Files you upload, and voice audio the Service generates for you, are stored on our servers and served from synthprism.com/uploads/, which is publicly readable and is not protected by your login. Images, video and music you generate are different: when you save one to your library we store the provider's own link to that file, so the file itself stays hosted by the AI provider that produced it (for example fal.ai or OpenAI) and is subject to that provider's retention — some such links expire on their own. Either way the file sits at an address that anyone holding the link can open. This is required: the social platforms you publish to, and some generation models, fetch the file directly over the internet and cannot sign in as you. Treat anything you upload, generate or save for publishing as reachable by anyone who has, or can work out, the link.
  9. Human review. AI features produce drafts and suggestions for you to review; we do not use them to make decisions about you without human involvement. See Section 15 (Automated Decision-Making).

7. International Data Transfers

We are based in the United States, and the Service is operated from and primarily processes data in the United States. If you or your End Users are located outside the United States, your information will be transferred to, stored, and processed in the United States and possibly other countries where our sub-processors operate, where data-protection laws may differ from those in your country. Where required by applicable law (for example, for transfers of personal information out of the EEA, UK, or Switzerland), we and our sub-processors rely on appropriate safeguards, such as Standard Contractual Clauses or an equivalent legal transfer mechanism, and take steps designed to ensure your information receives an adequate level of protection. By using the Service, you consent to this transfer and processing, subject to this Policy and applicable law.

8. Cookies & Analytics

We use strictly necessary cookies to keep you logged in, secure your session, and remember your preferences — these are always active because the Service cannot function without them. Where we use analytics, we use privacy-respecting, consent-gated analytics tools that load only after you accept a cookie-consent banner; if you decline, or have not yet chosen, no non-essential analytics cookies are set. We do not use advertising cookies and do not use cookies to sell your data or track you across unrelated websites for advertising. You can control cookies through your browser settings and, where applicable, through our consent banner; disabling some cookies may affect functionality.

9. Data Retention

We retain personal information for as long as your Account is active and as needed to provide the Service, then for a reasonable period afterward to comply with legal, tax, accounting, and recordkeeping obligations, resolve disputes, and enforce our agreements. We also retain opt-out and suppression records as needed to honor unsubscribe and STOP requests. When information is no longer needed, we delete or anonymize it. You may request deletion as described in Section 11; certain records (such as billing records) may be retained where required by law, and some information may persist for a limited period in routine backups before being overwritten on their normal cycle.

10. Security

We use reasonable administrative, technical, and organizational measures designed to protect personal information, including encryption in transit, hashed passwords, encryption of sensitive stored credentials, access controls, and reputable infrastructure and payment providers. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your Account credentials confidential. One deliberate exception to our access controls is described in Section 6, under "Where your media actually lives, and who can reach it": your media sits at public URLs that your login does not protect — and generated images, video and music remain hosted by the AI provider that produced them — because the social platforms you publish to must be able to fetch those files without signing in as you. If we become aware of a breach affecting your personal information, we will notify you and applicable authorities as required by law.

11. Your Privacy Rights

Depending on where you live, you may have rights to: access a copy of the personal information we hold about you; correct inaccurate information; delete your personal information; port/export your data; object to or restrict certain processing; withdraw consent where processing is based on consent; and non-discrimination for exercising your rights.

California residents (CCPA/CPRA). You have the right to know what personal information we collect, access, correct, and delete it, and to opt out of any "sale" or "sharing" of personal information — note that we do not sell or share personal information as those terms are defined under California law, so there is generally nothing to opt out of, but we will honor a request if you make one. You also have the right not to be discriminated against for exercising your rights.

EEA/UK/Swiss residents (GDPR/UK GDPR). You have the rights listed above and the right to lodge a complaint with your local data protection supervisory authority.

Other U.S. state privacy laws. If another applicable U.S. state privacy law grants you rights similar to those above, we will honor requests to exercise those rights in accordance with that law.

If your request concerns information that one of our business customers controls (for example, you are an End User of a business that uses SynthPrism), please contact that business directly; we will assist them as their processor where appropriate and as required by law. To exercise any right with us directly, email support@synthprism.com. We will verify your request and respond within the timeframes required by applicable law.

12. SMS / Phone Data Handling

Where the Service supports SMS or voice communications, phone numbers and messaging content are processed to deliver the communications the relevant business directs. We share a recipient's phone number with our SMS/voice provider only to deliver the messages and calls sent through the Service, and we maintain opt-out and suppression records to honor STOP requests. We do not sell phone numbers, and mobile opt-in/opt-out data collected through the Service is not shared with third parties for their own marketing purposes. Message frequency depends on usage, and message and data rates may apply to recipients per their carrier plans. See any SMS/Messaging Policy posted alongside this Policy for further detail.

13. Children's Privacy

The Service is intended for business users who are at least 18 years old (or such other minimum age as stated in a product-specific addendum) and is not directed to children. We do not knowingly collect personal information from anyone under 13 (or, where a product-specific addendum sets a different threshold consistent with applicable law, that threshold — for example, some products require parental consent for users between 13 and 16). If we learn that we have collected personal information from a child in violation of this Section, we will delete it. If you believe a minor has provided us information, contact support@synthprism.com.

14. Third-Party Links & Services

The Service may contain links to, or integrate with, third-party websites, platforms, and services that we do not control. This Policy does not apply to those third parties. We encourage you to review the privacy practices of any third-party site or service before providing it with information.

15. Automated Decision-Making

We do not use your personal information, or your End Users' personal information, to make decisions that produce legal or similarly significant effects concerning you or them without human involvement. AI-assisted features in the Service generate drafts, suggestions, or analyses for your review; you decide whether and how to act on them.

16. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date and may provide additional notice (for example, by email or an in-product notice). Your continued use of the Service after the changes take effect constitutes acceptance of the updated Policy.

17. Contact

If you have questions or requests regarding this Privacy Policy or your personal information, contact Martello Systems, LLC — SynthPrism, at support@synthprism.com (synthprism.com).