Legal · Data
Privacy Policy
Last updated 20 August 2026
This Privacy Policy explains how Prithvi-Kalp, a sole proprietorship ("Prithvi-Kalp", "we", "us", "our") collects, uses, stores, and shares personal data when you use SynthMock (the "Service") at synthmock.com and any related websites, applications, or services.
For the purposes of applicable data protection law, including the UK GDPR and EU GDPR, Prithvi-Kalp is the data controller of your personal data.
By using the Service, you acknowledge the practices described in this Privacy Policy.
1. Scope
This Privacy Policy applies to personal data we collect when you:
- visit our website
- create an account
- subscribe to a paid plan
- use the Service
- upload content or generate outputs
- contact us
- interact with billing, support, or security systems
This Privacy Policy does not apply to third-party websites, products, or services that may link to or integrate with the Service.
2. Personal data we collect
2.1 Account data
When you create an account or sign in, we may collect:
- email address
- name
- profile image
- authentication provider identifiers
- account preferences
- account status
- subscription entitlement data
Some information may be provided by third-party login providers such as Google or other supported authentication providers.
2.2 Payment and billing data
Payments are processed by Polar as our authorised reseller and Merchant of Record. We do not receive or store full card numbers.
We may receive and store:
- billing name
- billing email
- country
- VAT or tax identifiers where applicable
- subscription plan
- renewal dates
- payment status
- transaction identifiers
- invoice metadata
- Polar customer and subscription IDs
2.3 Usage, device and analytics data
When you use the Service, we may automatically collect:
- IP address
- browser type
- device type
- operating system
- approximate location derived from IP
- pages visited
- feature usage
- timestamps
- referring URLs
- performance metrics
- crash logs
- diagnostic logs
- abuse-prevention signals
- rate-limit data
We may also use privacy-focused analytics and performance tools, including Vercel Analytics or similar providers, to understand product usage, traffic sources, page performance, and technical issues.
We use this information to operate the Service, secure accounts, prevent abuse, troubleshoot issues, and improve the Service.
2.4 Content you upload or create
We may process content you upload, import, edit, or generate through the Service, such as:
- screenshots
- images
- logos
- designs
- mockups
- exported assets
- project files
- prompts
- settings
- configuration data
We process this content solely to provide and improve the Service, store projects, generate outputs, and support requested features.
2.5 Communications
If you contact us by email, contact form, support channels, or social channels, we may collect:
- name
- email address
- message contents
- attachments
- support history
- related technical details needed to resolve issues
3. How we use personal data
We use personal data for purposes including:
- creating and managing accounts
- authenticating users
- processing subscriptions and payments
- providing paid and free features
- storing projects and outputs
- generating exports and renders
- customer support
- sending transactional emails
- fraud prevention and abuse detection
- enforcing limits and Terms of Service
- analytics and performance monitoring
- debugging and error resolution
- improving features and user experience
- complying with legal obligations
- responding to lawful requests
- protecting our rights, users, and systems
4. Legal bases for processing (UK GDPR / EU GDPR)
Where applicable, we rely on the following legal bases:
Contract
Where processing is necessary to provide the Service, manage subscriptions, authenticate access, process payments, or provide support.
Legitimate interests
Where necessary for:
- security
- fraud prevention
- abuse detection
- enforcing usage limits
- improving the Service
- internal analytics
- system administration
- defending legal claims
We balance these interests against your rights and freedoms.
Legal obligation
Where required to comply with tax, accounting, consumer protection, fraud prevention, or other legal obligations.
Consent
Where required by law for optional processing activities. You may withdraw consent at any time.
5. How we share personal data
We do not sell personal data.
We may share personal data with trusted service providers that help us operate the Service, including:
- payment processors
- hosting providers
- infrastructure providers
- database providers
- authentication providers
- email delivery providers
- analytics providers
- error monitoring providers
- customer support tools
- security and fraud prevention tools
Examples may include Polar, Vercel, Google, and other providers we use from time to time.
These providers process data on our behalf under contractual safeguards.
We may also disclose personal data:
- where required by law
- to enforce our rights
- to prevent fraud or security threats
- in connection with a merger, acquisition, financing, or sale of assets
6. International transfers
Some service providers may process personal data outside the UK, EEA, or your country of residence.
Where required by law, we use appropriate safeguards such as:
- Standard Contractual Clauses
- UK International Data Transfer Addendum
- adequacy regulations
- supplementary technical and organisational measures where appropriate
7. Cookies and similar technologies
We use cookies and similar technologies for purposes such as:
- authentication
- session management
- security
- remembering preferences
- fraud prevention
- essential product functionality
- limited analytics where permitted
Some cookies are strictly necessary and may not require consent under applicable law.
Where consent is legally required for non-essential cookies or similar technologies, we will request it through appropriate consent tools.
You can also manage cookies through your browser settings.
8. Data retention
We retain personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, including legal, operational, security, fraud-prevention, accounting, and contractual purposes.
Typical retention periods may include:
- account data: while your account remains active and for a reasonable period after closure
- billing and tax records: for periods required by law
- support records: for operational, dispute-resolution, and legal needs
- usage logs and diagnostics: for security, debugging, abuse prevention, and product improvement needs
- backups: until overwritten or deleted through normal backup cycles
Where reasonably practicable, we delete, anonymise, or de-identify personal data when no longer needed.
Some data may be retained longer where required by law, to resolve disputes, prevent abuse, enforce agreements, or protect legal rights.
9. Your privacy rights
Depending on your location, you may have rights regarding your personal data.
These may include the right to:
- access your data
- correct inaccurate data
- request deletion
- restrict processing
- object to certain processing
- withdraw consent
- receive a portable copy of your data
- complain to a supervisory authority
- appeal certain privacy decisions where applicable
To exercise a rights request, contact privacy@synthmock.com.
We may need to verify your identity before fulfilling requests.
We will respond in accordance with applicable law.
10. US state privacy rights
Residents of certain US states, including California, may have additional privacy rights under applicable law.
These may include rights to:
- know categories of data collected
- access specific data
- correct data
- delete data
- opt out of certain sharing or targeted advertising
- non-discrimination for exercising rights
- appeal denied requests where applicable
We do not sell personal data as commonly defined under applicable US privacy laws.
To make a request, contact privacy@synthmock.com.
11. Children
The Service is not intended for children under 16.
We do not knowingly collect personal data from children under 16.
If you believe a child has provided personal data, contact us and we will take appropriate steps.
12. Security
We use reasonable technical, administrative, and organisational safeguards designed to protect personal data.
These may include:
- encrypted connections (TLS)
- access controls
- credential management
- monitoring and logging
- least-privilege practices
- managed hosting safeguards
- secure payment processing through providers
No system is completely secure, and we cannot guarantee absolute security.
13. Changes to this Privacy Policy
We may update this Privacy Policy from time to time.
If we make material changes, we may notify users through email, in-product notice, or by updating the date at the top of this page.
Your continued use of the Service after changes take effect means you acknowledge the updated Privacy Policy.
14. Contact
For privacy-related questions or requests: privacy@synthmock.com
For legal or general enquiries: legal@synthmock.com