Privacy Policy
Last updated: April 19, 2026
Your privacy is important to us. This Privacy Policy explains how Syntropic, operated by Bert Software Inc. ("we", "us", or "our") collects, uses, shares, and protects information in relation to our services. By using our services, you agree to the collection and use of information in accordance with this policy.
1. Customer Content
Your Sensitive Data and Database Information
Database Connection Credentials: To provide our services, we require you to provide connection details for your data sources. This may include credentials for services like Snowflake, Databricks, MotherDuck, Amazon S3, and others.
Table Metadata: We automatically collect information about your database tables including column names, data types, whether columns are null or distinct, and row counts. This metadata is necessary to provide our data management services.
Row-Level Data via Integrations: When you use our API or a user-directed integration (such as our Model Context Protocol server, which allows you to connect LLM clients like Claude Code or Claude Desktop to Syntropic), row-level table data and change history may be transmitted to the endpoint you have connected. We transmit this data only in response to requests initiated by you or by software acting on your behalf.
Important Commitment: We use your Customer Content solely to provide the services you have requested. We do not use this data for marketing, advertising, product development, or any other purpose beyond delivering our core data management services to you. Your database credentials and metadata are handled with the highest level of security as detailed in Section 4.
2. User Information
Information About You and Your Account
Account Information: When you register, we collect your email address. You may also provide a password if you choose to create an account directly with us, or you can sign up using third-party authentication providers like Google. For enterprise accounts, we may also collect additional business-related information such as your full name, company or organization name, professional title, business phone number, and geographic location (country and state/province) to establish and manage the enterprise relationship.
Payment Information (Processed by Stripe): When you subscribe to a paid plan, our payment processor, Stripe, will collect your payment information. We do not store or have access to your payment information.
Communications: When you contact us with inquiries, for support, or for other purposes, we may store copies of your communications (including emails).
Analytics Data: We use Cloudflare Web Analytics, a privacy-first analytics service, to collect aggregated information about how you interact with our services. This service does not use cookies or track you across other sites.
Essential Cookies: We use only essential cookies that are necessary to operate and administer our services, including maintaining your session and verifying your authentication to your workspaces. Please see our Cookie Policy below for more details.
3. How We Use Your Information
Use of Customer Content
We use your Customer Content solely to provide the services you have requested, including securely connecting to your specified data sources on your behalf, performing data management operations as instructed by you, and ensuring service stability and security.
We do not use your Customer Content for marketing, advertising, product analytics, or any other purpose beyond delivering our core services to you.
Use of User Information
We use your User Information (account details, usage analytics, communications) for providing, operating, and maintaining our services; processing payments and sending transaction-related information; sending technical notices, updates, security alerts, and support messages; responding to inquiries and providing customer service; monitoring and analyzing usage patterns to improve our services; detecting and preventing fraudulent, abusive, or illegal activities; and complying with legal obligations, resolving disputes, and enforcing agreements.
4. How We Share Your Information
We do not sell your personal information. We may share information with third parties under the following circumstances:
Service Providers: We share information with third-party vendors and service providers who assist in our business operations, such as payment processing (Stripe), cloud hosting (Amazon Web Services), and analytics (Cloudflare). These providers are contractually obligated to protect your data and are restricted from using it for any other purpose.
Professional Advisors: We may share information with our lawyers, accountants, and other professional advisors as necessary to obtain advice or otherwise protect and manage our business interests.
Legal Compliance and Protection: We may disclose information if required to do so by law or in the good faith belief that such action is necessary to comply with a legal obligation, protect and defend our rights or property, or in urgent circumstances to protect the personal safety of users or the public.
With Your Consent: We may share your information with other parties with your explicit consent.
User-Directed Integrations: When you connect Syntropic to a third-party tool you control (for example, via our Model Context Protocol server or our API), information you request—including row-level table data—is transmitted to that endpoint. Syntropic does not control how the receiving third party (such as an LLM provider) stores, processes, retains, or uses that data for model training. You are responsible for reviewing the privacy and data-handling practices of any integration you authorize.
In connection with any merger, sale of company assets, financing, or acquisition of all or a portion of our business by another company, your information may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on our website of any change in ownership or uses of your personal information.
5. Our Commitment to Data Security
We understand the sensitivity of the data you entrust to us and make its security our highest priority. We implement a multi-layered security architecture:
Encryption in Transit: All data transferred between your browser and our servers is encrypted using Transport Layer Security.
Encryption at Rest: All underlying databases and storage, including your personal information and cached data, are encrypted at rest using industry-standard encryption.
Envelope Encryption for Credentials: We use envelope encryption to provide an advanced layer of security for your database credentials. Your credentials are first encrypted with a unique Data Encryption Key (DEK). This DEK is then, in turn, encrypted by a master Key Encryption Key (KEK) stored in AWS Key Management Service. This ensures that even in the unlikely event of a database breach, your credentials remain unreadable.
Strict Access Controls: Access to your personal information and credentials by our personnel is strictly limited on a need-to-know basis to a small number of authorized individuals who require it to perform their job functions (e.g., providing customer support).
6. Your Data Rights and Choices
General Rights
Access: You can request a copy of the personal information we hold about you.
Correction: You have the right to request that we correct any inaccurate or incomplete information.
Deletion: You can request to delete your account and all associated data. When you do so, we will permanently and irrevocably delete your personal information and database credentials from our production systems, subject to any legal retention requirements.
Data Portability: You can request an export of your account information in a machine-readable format.
Opt-out of Marketing: You can opt-out of receiving marketing communications from us at any time by following the unsubscribe link in the email.
To exercise your rights, please contact us at [email protected].
Note: Depending on your location, you may have additional rights as detailed in the jurisdiction-specific sections below.
7. Data Retention
We retain your information for as long as required to provide you services or to comply with legal obligations, including:
We retain your information while your account is active and you are using our services, to fulfill any legal obligations, resolve disputes, and enforce agreements, and in anonymized form for analytics purposes to improve our services.
8. International Data Transfers
Our services involve international data transfers in the following ways:
Primary Servers: Our primary servers are located in Canada, a country that the European Commission has recognized as providing an adequate level of data protection. This means that personal information transferred from the European Economic Area (EEA) to our Canadian servers is protected under standards deemed adequate by the EU.
Content Delivery Network (CDN): We use Cloudflare's global CDN network to improve performance and reliability. This means your data may be temporarily processed and cached on servers in various countries where Cloudflare operates edge locations.
Third-Party Service Providers: Some of our service providers (such as payment processors, analytics providers, and cloud hosting services) may process your data in countries other than your own.
User-Authorized Integrations: Third-party tools you connect to Syntropic (such as LLM providers reached via our Model Context Protocol server) may process data in their own regions, which may differ from where Syntropic operates.
Your Consent: By using our services, you acknowledge and consent to these international data transfers as described in this policy.
9. Children's Privacy
Our services are not directed to individuals under the age of 16, and we do not knowingly collect personal information from children. If you are a parent or guardian and believe that your child has provided us with personal information, please contact us at [email protected]. If we become aware that we have collected personal information from a child in violation of applicable law, we will take steps to delete that information.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by sending an email to the address associated with your account, by posting a notice on our website, or as otherwise required by law, prior to the change becoming effective. We encourage you to review this policy periodically. Your continued use of our services after any changes or revisions to this Privacy Policy shall indicate your agreement with the terms of such revised policy.
11. Jurisdiction-Specific Privacy Rights
European Economic Area (EEA), United Kingdom, and Switzerland
Legal Basis for Processing: We process your personal information under the following legal bases:
- Performance of a Contract: To provide the services you have requested and maintain your account
- Legitimate Interest: To improve our services, ensure security, and communicate with you about service-related matters
- Consent: Where you have provided explicit consent for specific processing activities, including transmissions to third-party tools you connect via our API or Model Context Protocol server
- Legal Obligation: To comply with applicable laws and regulations
Your Rights Under GDPR: If you are located in the EEA, UK, or Switzerland, you have the following rights:
- Right of Access: Request confirmation of whether we process your personal data and obtain a copy
- Right to Rectification: Request correction of inaccurate or incomplete personal data
- Right to Erasure (Right to be Forgotten): Request deletion of your personal data under certain circumstances
- Right to Restrict Processing: Request limitation of processing under certain circumstances
- Right to Data Portability: Receive your personal data in a structured, commonly used format
- Right to Object: Object to processing based on legitimate interests or for direct marketing
- Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent
- Right to Lodge a Complaint: File a complaint with your local supervisory authority
To exercise these rights, contact us at [email protected]. We will respond within one month of receiving your request.
12. California Privacy Rights (CCPA/CPRA)
For California Residents
Categories of Personal Information: We collect the following categories of personal information as defined by the California Consumer Privacy Act:
- Identifiers (email address, account credentials, and for enterprise accounts: full name, business phone number)
- Commercial information (subscription details, payment history)
- Internet/electronic activity (usage analytics, website interactions)
- Professional information (for enterprise accounts: company or organization name, professional title)
- Geolocation data (for enterprise accounts: country and state/province)
Your California Privacy Rights: If you are a California resident, you have the following rights:
- Right to Know: Request disclosure of the categories and specific pieces of personal information we collect, use, disclose, and sell
- Right to Delete: Request deletion of personal information we have collected about you
- Right to Correct: Request correction of inaccurate personal information
- Right to Opt-Out of Sale/Sharing: We do not sell or share personal information for cross-context behavioral advertising
- Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights
Sale and Sharing of Personal Information: We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising purposes.
Sensitive Personal Information: We do not collect or process sensitive personal information as defined by the CCPA.
To exercise your rights, contact us at [email protected].
13. Canadian Privacy Rights (PIPEDA)
For Canadian Residents
As a Canadian company, we are subject to Canada's Personal Information Protection and Electronic Documents Act (PIPEDA).
Your Rights Under PIPEDA:
- Right to Access: Request access to your personal information in our custody or control
- Right to Correction: Request correction of personal information that is inaccurate or incomplete
- Right to Withdraw Consent: Withdraw consent for the collection, use, or disclosure of personal information, subject to legal or contractual restrictions
- Right to File a Complaint: Lodge a complaint with the Office of the Privacy Commissioner of Canada
Accountability: We are accountable for personal information in our possession or custody, including information transferred to third parties for processing.
Consent: We obtain meaningful consent for the collection, use, and disclosure of personal information, except where inappropriate.
To exercise your rights under PIPEDA, contact us at [email protected]. For complaints that cannot be resolved directly with us, you may contact the Office of the Privacy Commissioner of Canada at www.priv.gc.ca.
14. Contact Us
For privacy-related questions:
Email: [email protected]
Cookie Policy
We use only essential cookies that are strictly necessary for the operation of our service. These cookies are used exclusively to maintain your user session and verify your authentication to your workspaces.
Essential cookies are small data files that enable core functionality such as keeping you logged in and ensuring secure access to your account and workspace data.
Since these cookies are essential for the basic functionality of our service, they cannot be disabled. If you choose to disable cookies in your browser, you will not be able to use our service.