Privacy policy
What data moves through the managed service.
This notice maps the current implementation: what is collected, why it is used, who can receive it, where it remains, and what deletion actually does.
Controller
Syntax Studios, Dennis Spannagel, c/o Postflex #10315, Emsdettener Str. 10, 48268 Greven, Germany
kontakt@syntax-studios.org
Version
3 August 2026
01 / Data journey
From collection to deletion
- 01
You provide data
Account details, orders, prompts, files, integration settings, and requests.
- 02
The portal records it
Production account, billing, legal-request, and platform state is stored in PostgreSQL.
- 03
The instance uses it
Runtime content, customer files, credentials, and backups live on the assigned managed node.
- 04
Selected providers receive it
Only the data needed for payment, email, inference, hosting, or a chosen integration.
- 05
It is deleted or retained
Operational deletion follows lifecycle jobs. Some records can remain while a legally approved retention schedule is still pending.
The application repository contains no advertising tracker or behavioural analytics integration. Server, reverse-proxy, payment, email, inference, hosting, and integration providers can still process request or service metadata as described below.
02 / Data categories
Concrete records, sources, and storage
| Category | Examples | Source | Primary location |
|---|---|---|---|
| Account and authentication | Email address, display name, salted password hash, verification status, roles, TOTP configuration, hashed recovery codes, session identifier and version, and authentication events. | You, your browser, and security events generated by the portal. | PostgreSQL in production; a signed session cookie is held in your browser. |
| Subscription and payment | Selected plan and runtime, instance name, PayPal customer, plan, subscription, transaction and webhook identifiers, amount, status, paid-through date, cancellation, refund, reversal, and dispute events. | You and verified PayPal API or webhook events. | Portal billing records in PostgreSQL and corresponding records at PayPal. The application does not receive card or PayPal login credentials. |
| Managed service and operations | Instance and node identifiers, runtime choice, provisioning and health state, resource measurements, AI budget usage, backup and patch metadata, audit events, errors, and correlation IDs. | The portal, Manager, assigned node, runtime, and infrastructure. | PostgreSQL for portal state; restricted Manager and node databases, files, and logs for operations. |
| Agent content and customer configuration | Chat messages, sessions, jobs, uploaded files, installed skills, integration settings, and customer-owned credentials. If configured for OpenClaw, a Telegram bot token is stored encrypted by the portal, delivered to the runtime, and may appear in node backups as customer configuration. | You, people who communicate with your agent, and the selected runtime or integration. | Primarily the assigned node and runtime volume; inference content is transmitted to OpenRouter when the managed model route is used. |
| Support and legal declarations | Name, email, contract or PayPal reference, requested date, optional reason, receipt and delivery state, and timestamps. The implemented refund workflow additionally records staff actor, note, status, and decision history; cancellation and withdrawal currently do not have that operator workflow. | You through support or the cancellation, withdrawal, and refund forms; staff adds review data only in the implemented refund workflow. | PostgreSQL in production and the configured email provider for receipts and operator notices. |
| Request and security metadata | Request time, route, method, correlation ID, authentication result, the raw trusted IP string used for rate limiting, and redacted security or error events. If no trusted proxy header is configured, the rate limiter uses the value "unknown". Hosting and proxy providers may also create access logs containing IP address and user-agent data. | Your device, network, portal, reverse proxy, and hosting infrastructure. | Process memory for the legal-form rate-limit bucket for up to one hour; restricted application or infrastructure logs for other events. |
03 / Purposes and bases
Why processing is intended to be lawful
These are intended bases, not a claim that the production legal assessment is complete. The deployed processing inventory, necessity test, legitimate-interest balancing, consent design, and statutory retention duties require counsel approval before launch.
Deliver the contract
Create and secure the account, process checkout, provision and operate the selected instance, route inference, maintain backups, provide support, and handle billing or termination.
GDPR Art. 6(1)(b), where necessary to take requested steps or perform the contract.
Meet legal duties
Keep and answer consumer declarations and retain records where accounting, tax, commercial, or other law requires it.
GDPR Art. 6(1)(c), once the applicable duty and retention period have been confirmed.
Protect and operate the service
Prevent abuse, rate-limit requests, investigate incidents, maintain security audit trails, recover service, and establish or defend legal claims.
GDPR Art. 6(1)(f), after documenting the purpose, necessity, and balancing of interests.
Optional consent-based processing
Only a separate optional activity that genuinely relies on consent. A selected integration may instead be necessary to deliver the feature you requested.
GDPR Art. 6(1)(a) only where the production flow obtains valid consent and offers withdrawal.
Official source: General Data Protection Regulation, including Articles 6 and 13.
04 / Recipients
Who can receive which data
Syntax Studios operations
Authorized staff can access account, billing, support, legal-request, and operational records when needed to provide, secure, or review the service. The implemented refund workflow attributes and timestamps staff decisions; cancellation and withdrawal currently only create an intake record and email attempts.
PayPal
Receives order and subscription instructions and supplies payment, subscription, refund, dispute, and webhook identifiers and status. Payment credentials stay with PayPal.
OpenRouter
Receives model requests, including prompt or conversation content and technical metadata, when your instance uses the managed inference route. The runtime receives a scoped proxy token rather than the per-instance provider key.
Email delivery provider
Receives the destination address and message contents for verification, password reset, legal-request receipts, and operator notifications. Legal-request emails contain the submitted request details.
Hosting and managed nodes
Store and process portal state, runtime content, customer files, secrets, logs, and backups needed to operate the service.
Telegram and chosen integrations
Telegram processes bot messages and metadata only if you configure that channel. A separately configured operator alert bot can receive operational event details; agent conversations are not intended to be included in those alerts.
Authorities or professional advisers
Data may be disclosed where legally required or necessary to establish, exercise, or defend legal claims. No routine sale of personal data is intended.
05 / Access and security
Controls implemented, and their limits
Account controls
Passwords use salted scrypt hashes. Recovery codes are hashed. Sessions are signed and sent in HttpOnly cookies that are Secure in production and SameSite=Lax.
Managed secrets
The customer Telegram token is encrypted with AES-256-GCM in portal state. Per-instance OpenRouter keys remain encrypted on the node; runtimes use scoped proxy tokens.
Operational access
Access is limited to authorized operations and support work. The implemented refund workflow records the staff actor and decision history; cancellation and withdrawal do not yet have that workflow. Security logs are designed to redact secrets.
Backup limits
Node archives are permission-restricted and validated, but built-in at-rest archive encryption, off-host replication, legal holds, and independent expiry paging are not yet implemented.
The final archive is created with file mode 0600 and managed platform secrets are replaced. “Sanitized” does not mean customer content is removed: customer files, configuration, and a configured Telegram token can remain in that archive. No system can promise absolute security.
06 / Retention and deletion
What disappears when
Verification and reset
Email verification codes expire after 15 minutes. Password-reset codes expire after 10 minutes.
Portal session
The signed session can remain valid for up to 30 days, but logout, password or security changes, deletion, and administrative revocation can invalidate it earlier.
Active service
Account, subscription, instance, agent content, configuration, and operational data remain while needed to deliver and secure the subscribed service.
Active backups
Pro automatic snapshots default to one every 24 hours with 14 automatic snapshots retained. Manual, pre-patch, and pre-restore archives can also exist; their complete production rotation and legal-hold rules are not yet finalized.
Account deletion and paid access
After a verified deletion request, sessions are revoked and the account enters pending deletion. An already paid runtime remains available until the confirmed paid-through time, even though portal login is unavailable.
Final 30-day recovery window
At paid-through, the runtime is stopped, managed inference is disabled, and one validated final archive is created. Its expiry is exactly 30 days after paid-through, not 30 days after the request.
Final purge
At expiry, the data becomes due for deletion and the system attempts to remove the provider key, runtime project, managed-secret envelope, customer files, and entire node backup directory. A failed purge is marked as failed and retried, so completion can occur later than the exact expiry time. On successful purge, portal environment references and the encrypted Telegram token are cleared. Authentication data is anonymized only after all subscriptions are terminal.
Records without a finalized schedule
Billing, tax, audit, security, support, and legal-request records can remain after runtime deletion. Exact category-by-category periods and automated deletion jobs are not yet implemented and are a production launch blocker.
Important distinction
Deleting an account is not the same as immediately erasing every record. Runtime data follows the paid-through and 30-day final-backup sequence. Billing, consumer-declaration, audit, and claim records need separate, legally approved retention rules. A data-subject erasure request is assessed against those obligations.
07 / Your rights
Request access, correction, deletion, or restriction
Information and access
Correction
Deletion where applicable
Restriction
Data portability where applicable
Objection
Withdraw consent
Complain to an authority
Send a privacy request
Email kontakt@syntax-studios.org. Describe the right you want to exercise and the account email involved. We may request proportionate information to verify identity. Do not send passwords, payment credentials, recovery codes, or a Telegram token.
Account deletion
Authenticated customers can start account deletion in the portal. Password and a second factor are verified where enabled, PayPal subscriptions must be cancelled successfully, sessions are revoked, and the lifecycle above begins. For a GDPR request independent of account closure, use email.
For the controller address stated in North Rhine-Westphalia, the competent state authority is expected to be the State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia (LDI NRW); jurisdiction can differ in an individual case. You may also contact another supervisory authority where the GDPR permits. Refund decisions require staff review. The public cancellation and withdrawal forms do not make decisions and currently are not connected to an operator decision queue.
Production launch blocker
Before live processing, Syntax Studios must complete and approve the record of processing activities, named processor and subprocessor list, hosting locations, transfer safeguards, data-processing agreements, exact category retention schedule and deletion jobs, supervisory authority, incident and rights-request procedures, archive security decision, cookie inventory, and formal GDPR review against the deployed configuration. This page deliberately does not claim those open items are complete.