SynnStudio

App Privacy Policy

SynnStudio AI Marketolog — content automation service · 26 August 2026

SynnStudio operates a social media content automation service for small businesses. Our clients connect their own Instagram professional accounts, review AI-generated marketing content, and approve it for publishing to their own accounts. This policy explains what data we process, why, who else is involved, and how you can have it deleted.

1. Controller

The controller responsible for the processing described here is:

  • Maksym Synytskyi
  • SynnStudio (trade name of Maksym Synytskyi)
  • Semmelländerweg 10, 13593 Berlin, Germany

Privacy matters: privacy@synnstudio.de · General contact: contact@synnstudio.de · Phone: +49 179 435 8779

2. Scope of this policy

This document covers the SynnStudio content automation service — the product our clients use under a service contract. It does not cover visits to our website, enquiries sent through the website contact form, or our marketing communication.

For website visits a separate privacy policy applies: Website Privacy Policy

3. Instagram data we access

We use the Instagram API with Instagram Login. Access is granted by you through Instagram's own authorization screen and is limited to the following permissions:

  • instagram_business_basic — your Instagram account ID, username, account type and basic profile fields. Used to identify the connected account and to display it to you in our interface.
  • instagram_business_content_publish — creating media containers and publishing content to your account. Used exclusively to publish content you have approved.

4. What we explicitly do not access

We do not request the permissions that would be required for any of the following, and we therefore cannot access:

  • your direct messages
  • comments on your posts
  • your follower list or any data about individual followers
  • insights, analytics or audience demographics
  • any content on accounts other than the one you connect

We do not use your data for advertising, we do not sell it, and we do not combine it with data from other sources.

5. Access token

Authorizing the connection produces an access token. We store it in our database in Germany and use it solely to publish approved content to your account and to keep the connection alive.

  • Lifetime: 60 days, refreshed automatically on a schedule so the connection does not lapse.
  • The token is never passed on to third parties.
  • If you revoke access in your Instagram settings, the token stops working immediately and no further publishing is possible.
  • The stored token is deleted when you ask us to delete your data, and on termination of the service contract.

6. Business profile and content we store

To generate content that fits your business we store the information you provide during onboarding and the material the service produces:

  • Business profile: company name, industry, brand description, tone of voice, target audience, language, location names, logo files and uploaded media.
  • Messenger contact: your Telegram chat ID, used to send you content for approval and service notifications.
  • Generated content: prompts, generated images and videos, caption texts, approval history, and the IDs of published posts.
  • Topic history: which topics have already been used, so the same subject is not proposed twice.

7. Face photos and personalized image models

If you want to appear in the generated material, you can voluntarily upload photographs of yourself. This is optional and the service works without it.

  • Purpose: training a personalized image model (a so-called LoRA) so that generated pictures show a recognisable likeness.
  • Processors involved: fal.ai (model training and image generation) and Cloudinary (storage of the source photos and the trained model).
  • The photos and the trained model are never used for facial recognition, identity verification, or matching against any other person.
  • Retention: for as long as the service relationship lasts. On disconnection or on a deletion request, the source photos and the trained model are deleted together with your other data.

If photographs show people other than yourself, you confirm when uploading that those people have consented, as agreed in the data processing agreement.

Special categories of personal data within the meaning of Art. 9 GDPR are not part of this processing, and you undertake not to submit any.

8. Topic research

To choose subjects that are currently working in your field, the service analyses publicly available content in your niche through an external data provider. The only information we send is the keyword describing your niche.

No data about your followers, your account's audience, or any content of yours is involved in this step.

9. Sub-processors

We use the following processors, each receiving only the minimum data required for its task. Transfers outside the EU/EEA are based on the EU Standard Contractual Clauses (Implementing Decision (EU) 2021/914) and, where the provider is certified, additionally on the EU-US Data Privacy Framework.

ProcessorPurposeRegistered seatProcessing locationTransfer basis
Hetzner Online GmbHServers, database, backupsGermanyGermany— (EU/EEA)
Anthropic PBCText generation (Claude)USAUSASCC
fal.ai (Features and Labels Inc.)Image and video generation, image model trainingUSAUSASCC
ElevenLabs Inc.Voice synthesisUSAUSASCC
Cloudinary Ltd.Media storage and processingIsrael / USAUSASCC, EU-US DPF
Meta Platforms Ireland Ltd.Publishing to InstagramIrelandEU / USASCC, EU-US DPF
Telegram FZ-LLCApproval communicationUAEUAESCC
Google Ireland LimitedBusiness email (Google Workspace)IrelandEU / USASCC, EU-US DPF

Cloudinary: the default storage region on the plan in use is the USA; storage inside the EEA is not available on that plan. Meta: publishing takes place on your own account, and your own relationship with Meta applies to Meta's processing.

We inform clients four weeks before a sub-processor is added or replaced, and clients may object within two weeks, as set out in the data processing agreement.

10. AI-generated content and labelling

Content is created wholly or predominantly by artificial intelligence systems — this covers text, images, video and synthetic speech.

  • Nothing is published until you have approved it. You can also enable scheduled publishing for your own account: you switch it on yourself, content is then published on the schedule agreed with you, and you can switch it off again at any time with one message in the chat.
  • Generated material is labelled as artificially generated in accordance with Art. 50 of Regulation (EU) 2024/1689 (EU AI Act), visibly in the image and in the accompanying text, where this is activated for your account.
  • Under the terms of the AI providers we use, data we submit is not used to train their models.

11. Legal bases

  • Art. 6(1)(b) GDPR — processing necessary to perform the service contract with you. This covers the account connection, content generation, the approval workflow and publishing.
  • Art. 6(1)(f) GDPR — our legitimate interest in the technical security and reliability of the service, in error diagnosis, and in anonymised technical statistics.
  • Art. 6(1)(c) GDPR — compliance with statutory retention obligations for invoices and accounting records.

12. Retention

  • Account connection, business profile, generated content and approval history: for the duration of the service relationship.
  • On termination or on a deletion request: deleted within 30 days. This covers records in the production database, media stored in Cloudinary, and the Instagram access token, which is additionally revoked.
  • Encrypted backups follow their own 90-day rotation and are then deleted automatically. Removing a single record from an existing backup is technically not possible.
  • Invoices and accounting records: retained for 10 years under § 147 AO, regardless of a deletion request.
  • Content already published on Instagram remains on your account and under your control; it is not affected by deletion on our side.

13. Deletion

There are two ways to have your data removed:

  • Revoke access in Instagram — Settings → Apps and Websites → SynnStudio → Remove. This takes effect immediately: our access ends and no further publishing to your account is possible.
  • Request deletion of the stored data — email privacy@synnstudio.de with the subject "Data Deletion Request". We confirm within 3 business days and complete deletion within 30 days. Revoking access ends our access but does not by itself remove the records we already hold, so send the request as well if you want them gone.

Step-by-step instructions: Data Deletion Instructions

14. Your rights

Under the GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21). To exercise any of these, write to privacy@synnstudio.de.

You also have the right to lodge a complaint with a supervisory authority. The authority responsible for us is:

  • Berliner Beauftragte für Datenschutz und Informationsfreiheit
  • Alt-Moabit 59-61, 10555 Berlin, Germany