Demosyne

Privacy Policy

Last updated 31 Jul 2026

What we collect

Account information. When you sign in — with Google or an emailed magic link — we receive and store your email address and an account identifier. Authentication is operated on our behalf by Supabase.

Organization and billing records.Your organization’s name, membership, credit balance, and ledger of charges and top-ups. Card payments are processed by Stripe; we never see or store card numbers.

Service usage. Operational records of what your account and API keys do on the platform — runs launched, API requests, and the model usage they consume — which are also what your ledger and usage views are built from.

Site analytics. demosyne.com uses Vercel Analytics and Speed Insights, which collect aggregate, non-identifying page performance and visit data. We run no advertising trackers.

Cookies. We set cookies to keep you signed in and to remember your light/dark theme choice. That is all.

How we use it

To operate the Service: authenticate you, meter and bill usage, show your organization its own activity, keep the platform secure, and communicate with you about your account. We do not sell personal data, and we do not use your scenarios or simulation outputs to train models for anyone else.

Where it lives and who touches it

Data is stored in our database and object storage hosted by Supabase, with the website served by Vercel. Payments run through Stripe, and Google provides sign-in if you choose it. These processors handle data only to provide their service to us. We may also disclose information if the law requires it, or as part of a financing, acquisition, or similar transaction with protections consistent with this policy.

Retention

Account and organization records are kept while your account is active. Ledger and billing records are kept as long as bookkeeping and tax obligations require. Operational run records are kept while they are useful to you and to the integrity of the platform, and are deleted or de-identified when they are not.

Security

Access to production data is restricted and role-based: reads are scoped to your own organization at the database level, API key secrets are stored only as hashes, and traffic is encrypted in transit. No system is perfectly secure; if a breach affects your data we will tell you promptly.

Your choices

You can see most of what we hold about your organization directly in the console. To access, correct, export, or delete your personal data — or to close your account — email contact@demosyne.com and we will respond within 30 days. Depending on where you live, you may have additional statutory rights, and we honor them.

Changes and contact

Material changes to this policy will be announced on this page with a new revision date. The Service is not directed at children under 16. Our Terms of Service govern use of the Service itself. Privacy questions go to contact@demosyne.com.