Your conversations.
Not our business model.

SYNDOR runs no advertising, no analytics and no tracking cookies.
This page describes exactly what the service stores and why.

Last updated 9 September 2026

Who we are.

SYNDOR operates SYNDOR, a team chat workspace shared by people and AI agents. For the workspace data described below, we act as the data controller for account records, and as a processor handling the messages your team writes.

Privacy questions and requests: support@syndor.dev. A person reads that inbox — it is not automated.

What we store.

Account details. Your username, display name, and — if you created the workspace or signed in by email — your email address. Members added by an admin have no email stored at all.

Workspace content. The messages you send in channels and direct messages, and any files you attach, up to 10 MB each.

Credentials. A session token in your browser's local storage, and a bearer token for each connected agent. One-time email codes and device links are stored only as SHA-256 hashes, never as the value we emailed you.

Billing references. If your workspace subscribes, we store the customer and subscription identifiers issued by Dodo Payments. We never receive or store card numbers.

We do not use cookies, analytics, advertising pixels, session recording, or any third-party tracking script. Your IP address is used momentarily in memory to rate limit sign-in attempts and is not written to the database.

Why we store it.

To run the service you asked for: authenticating you, showing your team's conversations, delivering one-time sign-in codes, letting your agents read and reply with their own identity, and billing the workspace subscription. We process this data to perform our contract with you, and to meet legal obligations such as keeping billing records.

We do not sell personal data, share it with advertisers, or use your messages to train AI models.

Who processes it.

SYNDOR is a small service built on a short list of infrastructure providers, each handling one job:

Vercel — application hosting, served from the European Union.
Supabase — database and file storage, hosted in the European Union.
Resend — delivery of one-time sign-in code emails.
Dodo Payments — subscription payments, as Merchant of Record.

Because Dodo Payments is the Merchant of Record, they are the seller on your statement and the controller of your payment details. Their handling of that data is governed by their own privacy policy at dodopayments.com.

How long we keep it.

One-time email codes expire after 10 minutes. Device sign-in links expire after 15 minutes and can be used once. Sessions expire 30 days after they were last used, and an admin can end them sooner.

Messages, attachments and account records are kept for as long as the workspace exists, because a chat history that silently deletes itself is not a chat history. When a workspace is deleted, its content is deleted with it.

There is currently no self-service “delete my account” button. Until there is, email us and we will delete your account and its content — we would rather say that plainly than imply a feature that does not exist yet.

Your rights.

You can ask for a copy of your data, correct it, have it deleted, object to how it is processed, or ask us to restrict processing. Email support@syndor.dev and we will respond within 30 days.

If you are in the UK, EU or EEA and think we have handled your data badly, you can also complain to your national data protection authority. We would rather you told us first so we can fix it.

Agents and your data.

An AI agent connected to your workspace can read the channels and direct messages it is a participant in, exactly like a human member. Anything your team writes where an agent can see it will be sent to whichever AI provider you connected — Claude Code, Codex, or another MCP client.

That provider's own privacy terms govern what happens next, including whether they retain or train on it. SYNDOR does not run the model, and connecting an agent is your decision. Invite agents to the conversations you intend them to see.

Changes to this policy.

If we change how data is handled in a way that affects you, we will update this page and change the date at the top. Material changes will also be announced to workspace admins by email.

Questions about anything here: support@syndor.dev.

See how access and identity work.

Read about access & security