Summary
- Your data stays in your account. Every task, document, comment, and decision is scoped to the account it belongs to. Nothing is shared across accounts.
- We do not train AI models on your data. Sintris does not train models on customer content, and the AI providers we use (Anthropic and OpenAI) are bound by API terms that exclude using customer data to train their models.
- The AI answers from your records, not the open internet. Retrieval is limited to your account and to what each user is permitted to see.
- We do not sell personal information. We share data only with the service providers listed below, and only to run Sintris.
- You can export or delete your data. Export is available in the app; deletion is available on request or by closing your account.
Who we are
Sintris is operated by Balanced Solutions (“Sintris”, “we”, “us”). This policy covers the Sintris web application and the sintris.com marketing site. Where a company (our customer) sets up a Sintris account and adds its own people and records, that company controls the content in its account and we process it on the company’s behalf.
What we collect
We collect the information needed to run the product and nothing beyond that.
- Account information. Name, work email address, password (stored as a hash, never in plain text), role, and the account(s) you belong to.
- Customer content. The companies, tasks, projects, templates, comments, documents, and custom fields that you or your team create or upload. This can include personal information about your own employees, clients, or vendors, which your company is responsible for.
- Activity and usage data. An activity log of who did what and when inside your account (this is a product feature, and part of your record), plus technical logs such as IP address, browser type, pages requested, and errors.
- AI usage data. The questions asked of the AI assistant, the answers returned, and the token counts used to meter AI usage against your plan.
- Billing information. Plan, billing contact, and payment status. Card details are collected and stored by Stripe; Sintris never sees full card numbers.
- Communications. Messages you send us through the contact form, support, or by email, including email sent to Sintris inbound addresses that file into your account.
- Marketing site analytics. Aggregate page-view data on sintris.com marketing pages through Google Analytics. This is not used inside the application.
How we use it
- To provide Sintris: run your tasks, store your documents, keep your activity history, and send reminders and notifications.
- To power AI features: answer questions from your records, generate dashboard insights, and extract tasks from documents you ask us to import.
- To bill you and manage your subscription.
- To respond to support requests and communicate about your account.
- To keep the service secure: detect abuse, investigate incidents, and enforce access controls.
- To improve the product, using aggregate usage patterns rather than the content of your records.
We do not sell personal information and we do not use customer content for advertising.
AI features and your documents
The Sintris AI assistant answers questions from your own account: your tasks, projects, comments, documents, and activity history. It does not search the open internet. Here is what happens to your data when you use it.
- Scoped to your account and your permissions. Every retrieval is filtered by account first, then by what the asking user is allowed to read. A user cannot get an answer drawn from records they could not open themselves.
- Sent to model providers only as needed. To answer a question, the relevant excerpts (and, when you ask about a specific document, that document’s text) are sent to Anthropic’s API to generate the answer. To make your records searchable, text is sent to OpenAI’s API to compute embeddings. Scanned PDFs may be sent to AWS Textract to extract text.
- Not used for training. Sintris does not train AI models on your content. Anthropic and OpenAI provide these services under API terms that exclude using customer inputs and outputs to train their models.
- Answers cite their source. Each answer references the task, document, or comment it was drawn from so you can open the record and check it.
- Usage is metered, not sold. We record token counts to meter AI usage against your plan. We do not share your questions or answers with anyone other than the providers above.
AI answers are grounded in the documents and records you provide, but they are still generated text. Review the source material before relying on an answer for decisions with legal, financial, or regulatory consequences.
Where your data lives
Sintris runs on Amazon Web Services in the United States. Your database records and uploaded files are stored there. Data moving between your browser and Sintris, and between Sintris and its service providers, is encrypted in transit using TLS. Passwords are stored as salted hashes. Access to production systems is restricted to the people who operate the service.
Service providers
We use the following providers to run Sintris. Each receives only the data needed for its purpose.
| Provider | Purpose | Data involved |
|---|
| Amazon Web Services (AWS) | Application hosting, database, file storage, and OCR for scanned documents (Textract) | All account and customer content, stored in the United States |
| Anthropic | AI assistant, dashboard insights, and document-to-task extraction (Claude models via API) | The specific tasks, comments, and document text needed to answer a request |
| OpenAI | Text embeddings that power semantic search over your records (via API) | Chunks of task, comment, and document text, for indexing |
| Stripe | Subscription billing and payments | Billing contact, plan, and payment details (card numbers are held by Stripe, not Sintris) |
| Resend | Transactional email (invitations, reminders, notifications) and inbound email to Sintris addresses | Email addresses and message content |
| Vercel | Hosting for the web application front end and marketing site | Request logs (IP address, browser, pages requested) |
| Google Analytics | Aggregate traffic measurement on the marketing site only | Pages visited and device information on sintris.com marketing pages; not used inside the application |
Who can see your data
- People in your account see what their role and permissions allow. Account administrators control who is invited, what role they have, and which categories and templates they can access.
- Sintris staff access customer content only to provide support you have asked for, to investigate a security or reliability problem, or as required by law.
- Service providers listed above receive data solely to perform their function for us.
- Legal requests. We may disclose information if required by law or to protect the rights, safety, or property of Sintris, our customers, or others. Where allowed, we will notify the affected customer.
- Business transfers. If Sintris is acquired or merges with another company, customer data may transfer to the new owner under this policy or one at least as protective.
Retention and deletion
- We keep your account data for as long as your account is active. Activity history is part of your record and is retained with it.
- When an account is closed or you ask us to delete it, we remove the account’s companies, tasks, documents, comments, and users from our production systems.
- Database backups that include deleted data expire on a rolling basis within 30 days of deletion.
- Technical and security logs are retained for a limited period to investigate incidents, then discarded.
- Billing records are retained as long as required for tax and accounting purposes.
Cookies and browser storage
The Sintris application stores your sign-in token and interface preferences in your browser’s local storage so you stay signed in. These are required for the product to work and are not used for advertising. Marketing pages on sintris.com use Google Analytics, which sets its own cookies to measure traffic in aggregate. We do not use advertising cookies or sell data to ad networks.
Your choices and rights
Depending on where you live, you may have rights to access, correct, export, restrict, or delete your personal information. In practice:
- Account administrators can export companies, tasks, and projects to CSV from inside the app, and download any uploaded document.
- You can update your name, email, and password in account settings.
- You can ask us to delete your account and its data by contacting us.
- You can opt out of Google Analytics on the marketing site with a browser extension or by blocking analytics cookies; the application itself does not run analytics.
If you are an employee, client, or vendor of a Sintris customer and your information appears in that customer’s account, contact that customer first; they control the content of their account. We will assist them in responding.
Children
Sintris is a business product and is not directed to children. We do not knowingly collect personal information from anyone under 16.
Changes to this policy
When we change this policy we will update the effective date at the top of this page. For material changes we will notify account administrators by email or in the application before the change takes effect.
Questions about privacy or this policy: reach us through the contact page.