Last updated: 6 July 2026
This policy explains what personal information synthetic cfo ("we", "us") collects when you use synthetic cfo, why, and the choices you have. synthetic cfo generates forensic-grade synthetic ERP data from accounting rules; the datasets it produces are entirely synthetic and contain no real personal or company data. This policy is about the limited account and contact information we handle to run the service.
We do not sell your personal information, and we do not use it for automated decisions that produce legal effects about you.
We use a small number of processors to run the service: Railway (cloud hosting - runs the application and stores its data), Resend (email delivery - sends verification, reset, demo-code and account emails), and Google Fonts (serves the web fonts our pages use; your browser requests these from Google's servers, which receives your IP address for that request). If you choose a social sign-in (Google, Microsoft or GitHub), that provider authenticates you and shares your name and email address with us, and receives the sign-in request; we use only that name and email, exactly as we would from a form. They process data only on our instructions. We do not use analytics, advertising, or data-broker services. We may disclose information if required by law.
We keep account information for as long as your account is active. You can delete individual conversations and generated datasets at any time, and you can delete your entire account from the in-app menu, which erases your account and all the personal data tied to your email - including your conversations, generated datasets, and any demo or access-request records under that address. Demo and access-request records that never become an account are deleted automatically 24 months after your last interaction with us; you can ask us to delete them sooner at any time, and deleting an account on that email removes them immediately.
Depending on where you live (including under the GDPR/UK GDPR and South Africa's POPIA), you may have the right to access, correct, delete, or port your personal information, to object to or restrict certain processing, and to withdraw consent. You can delete your conversations, your generated datasets, and your entire account (and the personal data tied to it) yourself in the app. For access to, correction of, or a portable copy of your data, email us at info@syntheticcfo.com and we will help. You also have the right to complain to your data-protection regulator.
Passwords are stored only as salted PBKDF2 hashes, never in plain text. Traffic is encrypted in transit (HTTPS), sessions expire on inactivity, and access to each account's data is restricted to that account. No method is perfectly secure, but we work to protect your information.
Our providers may process data in countries other than yours. Where required, we rely on appropriate safeguards for such transfers.
We may update this policy; we will change the "last updated" date above. Questions? Email info@syntheticcfo.com.
← Back to synthetic cfo