Policy
Privacy
Symfo runs on your machine. That is why the list of what we store is short, and the list of what never reaches us is the one that matters.
In force since
The policy in four lines
The policy in four lines
- Your code, your AI keys and everything you say to the agents stay on your machine.
- We store what an account and a subscription need: email, plan and payment history.
- Card details never pass through us — Stripe handles them.
- This site has no tracking cookies, no ad pixel and no analytics.
On this page
Who handles your data
Symfo is the controller of the data described here. Requests to see, correct or delete it go to [email protected], and that is the same address for any question about this page.
This policy covers symfo.net, our API and the Symfo app. It does not cover the AI provider you contract, nor the tools the agent runs on your machine: those have policies of their own.
TO FILL IN: “Symfo” is the name of the product, not of the company. The legal name, the CNPJ and the address of the controller still have to be added, and so does the name of the person responsible for data protection — today the only published contact is the shared email address.
What never reaches us
This is the most important part of the policy, and it is short because the architecture already settles it. The app runs on your machine and talks directly to the AI provider you chose. There is no server of ours in that conversation.
Code, project files, AI keys, CLI credentials, prompts and agent responses: none of it is uploaded to us.
We cannot read your repository, we do not know which project you are working on, and we do not keep what you asked the agent to do. This is not a promise about our behaviour: it is how the product is built, and it does not change without a new version of this page saying so.
What we store
Only what an account and billing need in order to exist:
- Account
- Your email, the name your sign-in provider sent us (when it sends one) and your phone number, if you add one. The phone is optional and gives you one more way in.
- Sign-in
- Which door you come through — Google, GitHub or an email code — and the identifier that provider uses for you. Symfo has no passwords, so there is no password stored.
- Access codes
- The six-digit code sent to your email is stored as a hash, never as text. It is valid for a few minutes and can be used only once.
- Session
- The record that you signed in, and hashes of that session’s renewal tokens. Ending the session kills all of them at once.
- Subscription
- Which plan you have, in which status, since when and until when, and whether renewal is on. Previous subscriptions stay: they are what answers “why was I charged this”.
- Payments
- Amount, currency, date and type of every billing event, plus your Stripe customer identifier and any coupon you used.
We store no card details, ask for no tax or identity document to subscribe, and collect no postal address.
Payment
Your card details go from your browser straight to Stripe. They never pass through our servers.
Checkout and the subscription portal are Stripe pages, and what you type there is handled under Stripe’s privacy policy. What comes back to us is only the outcome: paid, how much, when, and your customer identifier at Stripe.
We also keep the body of the event Stripe sends us for each charge. That is what lets us audit an invoice years later without querying Stripe customer by customer.
AI providers
The key is yours and the provider account is yours. When an agent works, the request goes from your machine to the provider you configured, with your key, under their data policy.
Symfo does not resell tokens, does not proxy the call and receives no copy of what was sent or answered. It is worth reading the policy of whichever provider you choose: that document decides whether your prompts are used for training, not this one.
Why we handle each piece
Data protection law asks for a lawful basis behind every use. We have three:
- Performing the contract
- Account, sign-in, session and subscription. Without them you cannot get in and Symfo cannot know your access is active.
- Legal obligation
- The payment history, which tax law requires us to keep.
- Legitimate interest
- Security: detecting a replayed token, limiting code attempts and responding to an incident. It is the minimum needed to keep someone’s account from being taken.
We run no behavioural advertising, and no automated decision affects your access.
How long we keep it
- Account and subscription
- While the account exists. Once it is closed we delete or anonymise whatever we are not required to keep.
- Payment history
- For as long as tax law requires, including after the account is closed. That history cannot be deleted on request, and should not be: it is the proof of what was charged.
- Access codes
- They expire within minutes and cannot be used again.
- Sessions
- Until you sign out, revoke them, or the token expires.
Your rights
About your own data, you can:
- Ask whether we hold any, and which.
- Get a copy, in a format you can read and take elsewhere.
- Correct anything wrong or incomplete.
- Ask us to delete whatever we are not required to keep.
- Find out who we shared it with.
- Withdraw consent where consent was the basis for using it.
Email [email protected] from your account address. We answer within 15 days, and we charge nothing for it.
Today the request goes by email: there is no button in your account yet to export or erase everything yourself. We are building it, and until it exists a person answers you inside that deadline.
Security
What we actually do, instead of adjectives:
- Symfo has no passwords, so there is no password to leak.
- Access codes and renewal tokens are stored as hashes, never as text.
- Each session renewal spends the previous token. If the same token shows up twice, the whole session is dropped — that is how a stolen one is caught.
- All traffic between you, the site and the API runs over TLS.
- The database denies reads by default: only the API, connecting as the owner of the tables, sees anything.
If an incident could put you at meaningful risk, we tell you and the Brazilian data protection authority what happened, which data was affected and what to do about it.
Under-18s
Symfo is not for people under 18, and we do not knowingly collect their data. If we find such an account, we close it and delete the data.
Changes to this policy
When this policy changes, we change the date at the top of the page. If the change affects what we collect or who we share it with, we email you before it takes effect.
Questions, requests or complaints: [email protected]. You can also complain directly to the data protection authority where you live.

