Privacy Policy
Syntha collects only what is needed to operate the platform. We do not sell personal data.
effective June 22, 2026 GDPR · CCPA posture no data salesPolicy changelog
- June 22, 2026 — Initial Privacy Policy published.
1. Who We Are
Syntha is operated by VaultSpark Studios LLC (“VaultSpark,” “we,” “us,” “our”). Our primary domain is syntha.music. For privacy questions, contact us at legal@syntha.music.
2. Information We Collect
Automatically collected
- Usage events — anonymized
syntha_*analytics events (page views, play start, play duration). Events are stripped of personal identifiers before processing. No cross-site tracking. - IP addresses — Cloudflare handles infrastructure; IP addresses are processed briefly for routing, rate limiting, and abuse prevention. We do not store raw IP addresses in long-term logs.
- HTTP headers — browser type, referrer, and request metadata used to diagnose errors and serve the platform correctly.
Information you provide
- Artist applications — when you apply to join the Syntha catalog, we collect the information in your application form (name, contact details, catalog links, rights information). This data is used solely to evaluate and administer your application.
- Rights and disclosure records — artists uploading content provide rights, AI (Artificial Intelligence) origin disclosure, and provenance metadata. This information is retained to support moderation, takedowns, and legal compliance.
- Payment data — purchases are processed by Stripe (see §4). We receive and store an operational ledger record (amount, product, timestamp, Stripe transaction reference) but never your card number, expiry, or CVV.
3. How We Use Information
- Operate, maintain, and improve the platform.
- Process purchases, issue download entitlements, and maintain the support ledger.
- Review rights, AI disclosure, and moderation submissions from artists.
- Investigate and respond to takedown requests and abuse reports.
- Comply with legal obligations, including DMCA (Digital Millennium Copyright Act) requirements.
- Detect fraud and prevent abuse of the platform.
We do not use personal information to serve targeted advertising, and we do not sell, rent, or share personal data with third parties for their own marketing purposes.
4. Third-Party Services
- Stripe
- Payment processing. Card data is never transmitted to or stored by Syntha. Stripe’s privacy practices are available at stripe.com/privacy.
- Cloudflare
- Content delivery, DDoS (Distributed Denial of Service) protection, and Worker runtime. Cloudflare processes requests on our behalf and is subject to Cloudflare’s privacy policy. No personal data is intentionally transmitted to Cloudflare beyond what is inherent in serving web requests.
- Supabase
- Database hosting (when configured). Operational records (track catalog, ledger, moderation cases) are stored in a Supabase-hosted PostgreSQL database. Data is processed in accordance with Supabase’s sub-processor terms.
5. Cookies and Tracking
Syntha uses localStorage (not cookies) to remember your color theme preference (syntha-theme). This data never leaves your browser and is not transmitted to any server.
We do not use tracking cookies, cross-site tracking pixels, or third-party advertising trackers. If you block localStorage, the platform continues to work and your theme preference will reset to the system default.
6. Data Retention
- Analytics events — retained in aggregated, anonymized form. Individual event payloads do not contain personal identifiers.
- Rights and moderation records — retained for the life of the content on the platform and for a reasonable period after removal, to support takedown responses, dispute resolution, and legal compliance.
- Payment ledger records — retained as required by applicable financial regulations and for dispute and chargeback response.
- Artist applications — retained while an application is under review and for a reasonable period after a decision is made, to maintain audit records.
To request deletion of your personal data, contact us at legal@syntha.music.
7. Your Rights
General Data Protection Regulation (GDPR) — EU/EEA/UK residents
If you are located in the European Union (EU), European Economic Area (EEA), or United Kingdom (UK), you have rights under the General Data Protection Regulation (GDPR): access personal data we hold about you; correct inaccurate data; request deletion of your data (subject to legal hold requirements); restrict or object to processing; and receive a portable copy of your data. Contact legal@syntha.music to exercise these rights. We will respond within 30 days.
California Consumer Privacy Act (CCPA) — California residents
If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA): know what personal information we collect and how it is used; request deletion of your personal information; opt out of the sale or sharing of your personal information (we do not sell or share personal information); and not be discriminated against for exercising your rights. Contact legal@syntha.music to exercise these rights.
8. Children’s Privacy
Syntha is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected information from a child under 13, please contact legal@syntha.music and we will delete it promptly.
Users who wish to make purchases or engage in financial transactions must be at least 18 years of age or have verifiable parental consent.
9. Changes to This Policy
We may update this Privacy Policy periodically. When we do, we will update the effective date at the top of this page. If changes are material, we will provide a prominent notice on the platform. Continued use of Syntha after the effective date of any update constitutes your acceptance of the revised policy.
10. Contact
- legal@syntha.music
- Operator
- VaultSpark Studios LLC