Privacy Policy
Effective July 24, 2026 · Version 2026-07-24
1. Scope
This Policy explains how SypherDyne Systems collects, uses, stores, and shares information when you use its website, account workspace, email research workflow, reports, and billing features.
2. Information we process
- Account data: email address, password hash, verification status, sessions, plan, legal acceptance, and account settings.
- Research data: email subjects and bodies, prompts, constraints, report content, sources, research events, and enabled or disabled research memories.
- Usage data: query counts, timestamps, plan entitlements, job states, delivery events, and feature interactions.
- Billing data: Stripe customer, subscription, price, invoice, payment-status, and cancellation identifiers. Full card details are processed by Stripe rather than stored by SypherDyne.
- Technical data: IP address used for security and rate limiting, browser and request information, server logs, and diagnostic errors.
3. How information is used
Information is used to create and secure accounts; verify authorized email senders; perform and deliver research; build the member’s report catalog and research memories; enforce daily compute limits; manage subscriptions and invoices; prevent abuse; diagnose failures; communicate service information; comply with law; and improve reliability and research quality.
SypherDyne does not sell personal information or use private member research to deliver third-party behavioral advertising.
4. Email research and automated processing
Research requests are initiated through email. The Service matches the sender to a verified account and may transmit account identifiers, plan entitlement, and prompt content to SypherDyne’s research infrastructure. When a worker policy enables it, bounded plain-text attachments can be included as research input; unsupported formats are ignored. Automated systems search, analyze, organize, and generate reports. Research can involve third-party websites and source providers whose own logging practices apply when their services are accessed.
5. Service providers and disclosures
Information may be disclosed to vendors that provide payment processing, transactional email, mailbox access, hosting, storage, security, networking, and research infrastructure, only as reasonably necessary for those functions. Information may also be disclosed to comply with valid legal process, protect people or systems, investigate abuse, enforce agreements, or complete a business reorganization subject to appropriate safeguards.
6. Retention
Account and billing records are retained while an account is active and as needed for accounting, dispute, fraud-prevention, and legal obligations. Research emails, reports, report files, events, and memories are retained to provide the member’s catalog and continuity features until deleted under available controls or a valid request, subject to backups and required retention. Expired sessions, verification material, and password-reset tokens are periodically removed.
7. Security
SypherDyne uses access controls, password hashing, authenticated member routes, signed Stripe webhooks, and account-scoped data queries. No internet service can guarantee absolute security. Members must protect their email and account credentials and report suspected compromise promptly.
8. Your choices and rights
You can review account, subscription, invoice, usage, and research information from the workspace; change your password; manage research-memory influence; and cancel billing. Depending on applicable law, you may request access, correction, export, restriction, objection, or deletion of personal information. Identity verification may be required, and some records may be retained where legally permitted or required.
9. International processing
Providers and research sources may process information in countries other than your own. Those locations can have different data-protection laws. SypherDyne uses reasonable contractual and operational safeguards appropriate to the services involved.
10. Children
The Service is not directed to children who cannot legally consent to this processing or enter the Terms. Do not create an account for a child without lawful authority.
11. Changes and contact
Material changes will be communicated through the account, email, or an updated acceptance request. Privacy questions and rights requests may be sent to [email protected].