Sytoria

Privacy Policy

Last updated 2026-10-09

1. Controller

Oskar Baker – Sytoria, Silberstr. 42, 30655 Hannover, Germany. Email: support@sytoria.io · Phone: +49 151 29609383.

We are not required to appoint a data protection officer. For all privacy questions, contact us at the email address above.

2. Hosting and server logs

Our website runs on Vercel (Vercel Inc., USA) in the Frankfurt region; background processing runs on Railway (Railway Corporation, USA) in the EU West region. When you visit the site, the servers automatically process your IP address, date and time, the requested page, referrer and browser information in log files to deliver the site and keep it secure (Art. 6 (1) (f) GDPR). Log data is kept by the hosting providers only for a short period.

3. Account

To create an account we process your email address, an optional name and a hashed password (or, if you sign in with Google, the identifier and profile data Google provides). We use this data to provide your account and the contract (Art. 6 (1) (b) GDPR). Optional two-factor authentication data is stored encrypted.

4. Creations

When you generate content we process your prompts, uploaded files (images, video, audio), settings and the resulting outputs, and keep a history of your prompts. This is necessary to perform the contract (Art. 6 (1) (b) GDPR).

To generate, we transmit the prompt and the required input files to fal.ai (Features & Labels, Inc., USA). Depending on the model you choose, fal forwards the request to the developer of that model, who may be located outside the EU, including in the USA and in China. Do not include personal data of others in prompts or uploads unless you are allowed to.

Before a prompt reaches a model provider it is checked automatically for violations of our Acceptable Use Policy. For this check and, if you use it, for the prompt assistant and scene planning, the text is sent to Anthropic (Anthropic, PBC, USA) (Art. 6 (1) (b) and (f) GDPR). A blocked prompt is not generated and not charged; contact us if you think a block was wrong.

5. Public sharing

If you publish a creation in Explore or create a share link, the creation, its prompt and your display name become visible to anyone. You can unpublish it at any time (Art. 6 (1) (a) and (b) GDPR).

6. Payments

Payments are processed by Stripe (Stripe Payments Europe, Ltd., Ireland). Stripe receives your name, email address, billing address, payment details and, where provided, your VAT ID; we never see or store full card numbers. Stripe also processes data under its own responsibility to prevent fraud and comply with financial regulations. Legal basis: Art. 6 (1) (b) and (c) GDPR.

7. Emails

We send transactional emails (email verification, password reset, receipts, notifications about your creations and account) via Resend (Plus Five Five, Inc., USA), dispatched from the EU (Ireland) (Art. 6 (1) (b) GDPR). We do not send newsletters without your consent.

8. Abuse and fraud prevention

To prevent multiple free accounts, payment fraud and attacks, we store a salted hash of your IP address and of its network range at sign-up, apply rate limits, and may flag accounts for manual review. We do not store plain IP addresses for this purpose. Legal basis: our legitimate interest in a secure, fairly used service (Art. 6 (1) (f) GDPR).

9. Product analytics

We record usage events such as sign-ups, generations and purchases in our own database to understand and improve the product. We do not use third-party tracking or advertising tools and do not set analytics cookies. Legal basis: Art. 6 (1) (f) GDPR.

10. Cookies and referrals

We only use cookies that are necessary to provide the service you request — see our Cookie Policy. If you follow a referral or affiliate link, a cookie stores the referral code for 30 days so the referrer can be credited when you sign up.

11. Storage and database

Your data is stored in a PostgreSQL database by Neon (Neon, Inc., USA) in Frankfurt and your files in Cloudflare R2 (Cloudflare, Inc., USA) with EU data location. Files are private and only accessible through short-lived signed links.

12. Processors and third-country transfers

Vercel, Railway, Neon, Cloudflare, Resend, fal.ai, Anthropic and Stripe process data on our behalf under data processing agreements (Art. 28 GDPR). Where data is transferred to or accessed from countries outside the EU/EEA, the transfer is based on the EU–US Data Privacy Framework where the recipient is certified, or on the EU Standard Contractual Clauses (Art. 46 (2) (c) GDPR). Further model developers that fal works with may be located in countries without an adequacy decision, such as China.

13. Retention

Account data is kept for as long as your account exists. Generated media on the Free plan is deleted after 30 days, on paid plans when you delete it or your account. Uploaded input files are deleted after 90 days. When you delete your account, we delete your creations and personal data; invoices and payment records are kept for the statutory retention period of up to 10 years (§ 147 AO, § 257 HGB), and our credit ledger is kept in anonymised form.

14. Your rights

You have the right to access, rectification, erasure, restriction of processing, data portability and to object to processing based on legitimate interests (Art. 15–21 GDPR), and to withdraw consent at any time with effect for the future. You can export or delete your data yourself under Settings.

You also have the right to lodge a complaint with a supervisory authority, for example the authority responsible for us: Die Landesbeauftragte für den Datenschutz Niedersachsen, Prinzenstraße 5, 30159 Hannover, Germany.

15. Security

Sytoria uses encrypted connections (TLS), private storage with time-limited signed URLs, hashed identifiers for abuse prevention, role-based staff access and audit logs. Providing your data is required to use the service; without it we cannot conclude or perform the contract. We do not make automated decisions with legal effect within the meaning of Art. 22 GDPR.