Privacy Policy
Effective Date: March 30, 2026
This Privacy Policy describes how Symage, Inc. (“Symage,” “we,” “us,” or “our”) collects, uses, and protects information when you access or use our platform at symagedocs.ai (the “Service”). By using the Service, you agree to the practices described in this policy.
1. Information We Collect
1.1 Information You Provide
When you register or sign in, we collect information depending on your chosen authentication method:
- Google OAuth: We receive your name, email address, and profile picture as authorized by you during the sign-in process.
- GitHub OAuth: We receive your name, email address, and avatar as authorized by you during the sign-in process.
- Credential-based signup: We collect your name, email address, company (optional), and a hashed version of your password. We never store your plaintext password.
1.2 Usage Information
We may collect information about how you interact with the Service, including pages visited, features used, data queries made, and access timestamps.
1.3 Technical Information
We may collect technical data such as IP address, browser type, device type, and operating system for security and performance purposes. We also derive your country from your IP address, using an offline database held on our own servers, to determine which cookie-consent rules apply to you and to record the country an account was created from. This lookup involves no third-party service and no outbound request. See Section 11 for how the resulting country code is used.
1.4 Payment Information
Payment processing is handled by Stripe. We do not directly collect or store credit card numbers or bank account details. We store a Stripe customer ID to associate your account with your payment history and manage subscriptions.
2. How We Use Your Information
We use the information we collect to:
- Authenticate your identity and provide access to the Service
- Manage your account and maintain platform security
- Process payments and manage subscriptions
- Communicate with you about your account, updates, or support requests
- Improve and develop our products and services
- Measure advertising effectiveness and attribute conversions
- Comply with legal obligations
3. Third-Party Authentication
We support authentication via Google OAuth 2.0 and GitHub OAuth. When you sign in with either provider, we do not receive or store your password for that service. The information we receive is limited to what you authorize during sign-in (typically your name, email address, and profile photo). We do not access your Google Drive, Gmail, GitHub repositories, or any other services beyond authentication.
4. Data We Do Not Collect or Sell
Symage does not sell your personal information to third parties. The synthetic and tabular datasets provided through our Service are generated data products and do not contain or derive from your personal information.
5. Data Sharing
We do not sell your personal information. We share data with third parties only in the following circumstances:
- AWS (Amazon Web Services): Cloud hosting and infrastructure for the Service
- Stripe: Payment processing and subscription management
- Mailchimp: Email marketing and drip campaigns for registered users
- Google Analytics: Website usage analytics and conversion tracking
- Meta (Facebook): Advertising attribution via the Meta Pixel and Conversions API
- When required by law, regulation, or valid legal process
- To protect the rights, property, or safety of Symage, our users, or the public
We may share data with Meta and Google for advertising attribution purposes, including hashed email addresses and conversion events, to measure the effectiveness of our advertising campaigns.
6. Data Retention
We retain your information according to the following schedule:
- Account data: Retained while your account is active
- Billing records: 7 years after the transaction (required for tax and legal compliance)
- Email logs: 90 days
- Analytics data: 26 months
You may delete your account at any time through your Account Settings page. Account deletion will remove your personal data, cancel active subscriptions, and anonymize your record. Certain billing records may be retained as required by law.
7. Security
We implement industry-standard security measures to protect your information, including encrypted connections (HTTPS) and access controls. However, no system is completely secure, and we cannot guarantee absolute security.
8. Your Rights
Depending on your jurisdiction, you may have specific rights regarding your personal data. Please see the GDPR and CCPA sections below for details. You can exercise your right to deletion directly via self-service account deletion in your Account Settings. For other requests, please contact us at support@symagedocs.ai.
9. Your Rights Under GDPR
If you are located in the European Union or European Economic Area, you have the following rights under the General Data Protection Regulation (GDPR):
- Right to access (Art. 15): You may request a copy of the personal data we hold about you.
- Right to rectification (Art. 16): You may request correction of inaccurate personal data.
- Right to erasure (Art. 17): You may request deletion of your personal data. This is now available via self-service account deletion in your Account Settings.
- Right to data portability (Art. 20): You may request your personal data in a structured, machine-readable format.
- Right to object (Art. 21): You may object to processing of your personal data for certain purposes.
Our lawful basis for processing your data includes consent (Art. 6(1)(a)) for optional features such as marketing emails and for any analytics or advertising cookies, and legitimate interest (Art. 6(1)(f)) for core service operation, security, and fraud prevention.
If you are in the European Economic Area, the United Kingdom, or Switzerland, we do not set analytics or advertising cookies, and do not load analytics or advertising scripts, unless and until you give consent — see Section 11. Determining that you are in one of those territories relies on deriving a country from your IP address, which we do on our own servers under legitimate interest (Art. 6(1)(f)) for the specific purpose of applying the correct consent rules to you. You may withdraw consent at any time via the “Cookie Preferences” link in the site footer; withdrawal does not affect the lawfulness of processing carried out before you withdrew it.
We will respond to data subject access requests (DSARs) within 30 days of receipt. To exercise any of these rights, contact us at support@symagedocs.ai.
10. Your Rights Under CCPA/CPRA
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
- Right to know: You may request information about the categories and specific pieces of personal information we have collected about you.
- Right to delete: You may request deletion of your personal information. You can do this directly via the self-service account deletion feature in your Account Settings.
- Right to opt-out of sale: We do not sell your personal information to third parties.
- Right to non-discrimination: We will not discriminate against you for exercising any of your CCPA/CPRA rights.
11. Cookies and Tracking
We use cookies and similar tracking technologies for the following purposes:
- Essential cookies: NextAuth session cookies required for authentication and security, a CSRF token cookie, and a cookie recording your cookie choice. These cannot be disabled.
- Analytics: Google Analytics (GA4) to understand how visitors use the Service and improve the user experience.
- Advertising: Meta Pixel, the LinkedIn Insight Tag, and Google Ads conversion tracking, used to measure the effectiveness of our advertising campaigns on Facebook, Instagram, LinkedIn, and Google.
- Advertising attribution: first-party cookies prefixed with _pl_ (for example _pl_gclid, _pl_fbclid, _pl_li_fat_id) that store the ad click identifier appended to the URL when you arrive from an ad, so we can tell which campaign led to a sign-up. These expire after 90 days.
- Acquisition attribution: a first-party cookie named pl_attribution recording how you first reached us — the campaign tags in the link you followed (utm_source, utm_medium, utm_campaign, utm_term, utm_content), the site that referred you, the page you landed on, and any ad click identifier. It expires after 90 days, and if you create an account we keep this first visit on your account record so we know which channel it came from. Only your first visit is recorded; later visits do not overwrite it.
- Payment: Stripe cookies for secure payment processing and fraud prevention.
How we decide whether to ask you first
Whether we ask for your consent before setting analytics and advertising cookies depends on where you are, which we determine from your IP address using an offline geolocation database. We do not store your IP address for this purpose; we store only the resulting two-letter country code, in a cookie named pl_region that expires after 30 days.
- European Economic Area, United Kingdom, and Switzerland: we ask first. No analytics or advertising cookies are set, and no analytics or advertising scripts are loaded, until you choose “Accept All.” Choosing “Necessary Only” means none are ever set.
- Everywhere else, including the United States: analytics and advertising cookies are set by default when you first visit, and you may opt out of them at any time using the “Cookie Preferences” link in the site footer.
- If we cannot determine your location, we treat you as being outside the European Economic Area, the United Kingdom, and Switzerland.
What we record either way
Whichever of the above applies to you, and whether or not you have made a cookie choice, we record first-party usage events describing how the Service is used — which pages were viewed and which features were exercised, as described in Section 1.2. These events stay on our own servers, are not shared with advertising partners, and are used to operate and improve the product. Declining optional cookies stops the analytics and advertising technologies listed above; it does not stop this first-party record.
Global Privacy Control
We honor the Global Privacy Control (GPC) signal. If your browser or extension sends GPC and you have not made an explicit choice on this site, we do not load advertising or cross-site measurement technologies (Meta Pixel, LinkedIn Insight Tag, Google Ads conversion tracking) and we do not store advertising attribution cookies. First-party analytics still runs so we can measure how the Service is used. If you subsequently choose “Accept All” on this site, that later, site-specific choice takes precedence over the browser-wide GPC signal.
Changing your mind
Your choice is stored in a cookie named pl_cookie_consent, which expires after 365 days, and it always overrides the regional default described above. You can review or change it at any time using the “Cookie Preferences” link in the site footer, which is available in every region. If you are signed in, your choice is also saved to your account: on a different device it applies once you have signed in there, and it is synced shortly after the page loads, so the very first pageview on a new device may still follow the regional default described above. Choosing “Necessary Only” stops analytics and advertising scripts from loading, instructs Google to deny all Consent Mode signals, withdraws consent from the Meta Pixel, and deletes any _pl_ advertising-attribution cookies and the pl_attribution cookie already on your device; clearing your browser cookies resets the choice.
This control governs cookies and the measurement scripts that run in your browser. It does not switch off the server-side conversion measurement described in “How We Share Your Information” above: when you complete an action such as creating an account or making a purchase, we report that event to our advertising partners from our own servers, and that report may include advertising identifiers already stored on your device from an earlier visit. If you want that data removed, contact us using the details at the end of this policy.
12. Children's Privacy
The Service is not directed to children under the age of 13. We do not knowingly collect personal information from children. If you believe we have inadvertently collected such information, please contact us immediately.
13. Changes to This Policy
We reserve the right to update this Privacy Policy at any time. Changes will be posted on this page with an updated effective date. Continued use of the Service after changes constitutes acceptance of the revised policy.
14. Governing Law
This Privacy Policy is governed by the laws of the Commonwealth of Massachusetts, without regard to conflict of law principles.
15. Contact Us
If you have any questions about this Privacy Policy, please contact us at:
Symage, Inc.Email: support@symagedocs.ai
Website: symagedocs.ai
Symage, Inc.
March 30, 2026