Sections What We Mean by Personal DataInformation We CollectHow We Use Your InformationData Storage and SecurityHow We Share Your InformationInternational Data TransfersContact InformationData RetentionCookies and Local StorageYour Privacy RightsLinks to Other ServicesChanges to This PolicyQuestions and Contact Last updated
2 September 2026

Privacy Policy

Last Updated: 2 September 2026

Hiasynth AB (Org.nr 559538-3703, VAT SE559538370301) operates the Hiasynth service, which provides access to Humanity, our synthetic population model, via MCP server and API together with a web application for account management. We are committed to transparency and compliance with the EU General Data Protection Regulation (GDPR), Swedish data protection law, and other applicable privacy laws.

This Privacy Policy explains how Hiasynth collects, uses, shares, and protects personal information when you use our website, web application, API, and MCP server (collectively, our "Services"). By using our Services, you acknowledge this Policy. This Policy incorporates our Terms of Service by reference. If you do not agree with these terms, please discontinue use of our Services.

What We Mean by Personal Data

For purposes of this Policy, "personal data" means any information relating to an identified or identifiable natural person, as defined under the GDPR and Swedish data protection law.

The population data we provide is not personal data. Humanity is a synthetic population: it is generated, not collected. It is fit to published statistics — official statistical-agency tables and survey aggregates — and contains no individual-level source records. No record in the dataset corresponds to a real person, household, or address, and nobody in it can be identified, contacted, or matched back to a living individual. The Services never return individual records; every answer is an aggregate, such as a count, share, distribution, or comparison. Personas and example people in the product are statistical composites of a group, not records and not people. A minimum group size of 100 people is enforced on the server: smaller groups are withheld or rolled up to a larger area, and this cannot be switched off by any customer, client application, or AI assistant. Attributes touching special categories under Article 9 GDPR, such as religion, health, political opinion, sexual orientation, or ethnic and migration origin, are additionally never broken down at fine geographic detail.

The personal data this Policy is about is yours: your account, billing, and usage of the Services.

Hiasynth does not intentionally collect sensitive personal data such as health information, biometric identifiers, or precise geolocation. We instruct users not to include such information in their communications with us.

Information We Collect

Information You Provide Directly. When you create an account or purchase a subscription, you provide us with personal data including OAuth credentials from GitHub, Google, or Discord (user ID, email address, username, and avatar URL), payment information processed through Stripe (we never receive or store your card number), and any correspondence you send us. Sign-in tokens are verified on each request and discarded; they are not stored by the query service. API keys you generate are stored only as SHA-256 hashes — we cannot recover a key, and a lost key must be replaced.

Information Collected Automatically. To operate billing, we keep a usage log with one row per query: your account identifier, the tool called, a timestamp, and the credits charged. We also record the timestamp of last use per API key so you can see which keys are live. Separately, we collect technical telemetry for capacity planning and performance work: which tool was called, which attribute names and operators were filtered on, response size, and timings. This telemetry contains no account identifier and no filter values — it records the shape of a query, not its content.

What We Do Not Store. We do not store the content of your queries: not the question asked, not the values filtered on, not the results returned. We do not receive or store any conversation content from the AI assistant you connect to us; we only ever receive the structured parameters of an individual tool call. Your end users are never identified to us. We do not sell customer data, and we do not use customer usage data to train models.

We do not use third-party analytics services, tracking pixels, or advertising networks. We do not perform behavioral tracking or marketing profiling. [CONFIRM open item 3: Cloudflare and Fly.io retain their own platform request logs, which typically include IP addresses — confirm what is enabled and for how long, then state it here.]

Children's Data. Our Services are business tools intended for users aged 18 and older. We do not knowingly collect personal data from anyone under 18. If we discover we have inadvertently collected such information, we will delete it promptly. If you believe we may have collected data from a minor, please contact us at support@hiasynth.co.

How We Use Your Information

Hiasynth processes your personal data only where we have a valid legal basis under applicable privacy law. We rely on the following legal grounds:

Performance of a Contract. We process your data to provide, maintain, and support the Services you have requested under our Terms of Service, including authenticating you, serving your queries, maintaining your credit balance, managing your subscription, processing payments through Stripe, sending service notices such as low-credit alerts, and delivering customer support.

Legitimate Interests. We use personal data to secure our platform, detect fraud and abuse, enforce rate limits, prevent unauthorized access, and plan capacity and performance through the technical telemetry described above, which is not linked to your account. These interests are balanced against your privacy rights and do not override your fundamental freedoms. [CONFIRM open item 5: legal basis assignment, in particular for telemetry.]

Consent. For any processing that requires your explicit consent under applicable law, such as certain marketing communications or optional features, we obtain your opt-in consent before proceeding. You may withdraw consent at any time without affecting the lawfulness of processing based on consent before withdrawal.

Legal Obligations. We retain and process information as necessary to comply with bookkeeping requirements, tax laws, court orders, law enforcement requests, export control and sanctions regulations, and other legal duties imposed by jurisdictions where we operate.

Automated Processing. Model outputs are synthetic aggregates about hypothetical groups. This processing does not evaluate or profile you or any identifiable real person, and Hiasynth does not engage in automated decision-making that produces legal or similarly significant effects on individuals under GDPR Article 22.

Data Storage and Security

Your account and usage data, and the population dataset itself, are hosted on Cloudflare's infrastructure. The query engine runs on Fly.io in Frankfurt, Germany, and is not reachable from the public internet. Your browser stores a session token and basic profile information in localStorage to maintain your logged-in session.

Payment processing is handled entirely by Stripe, a PCI DSS Level 1 certified service provider. We never store your full credit card number or CVV code. Stripe's data practices are governed by their privacy policy at stripe.com/privacy.

Transactional emails, such as service notices, are sent through Resend. Resend processes your email address solely to deliver these messages on our behalf.

We implement industry-standard security measures to protect your personal data from unauthorized access, disclosure, alteration, or destruction. All traffic is encrypted in transit using TLS, and data is encrypted at rest within our infrastructure. Every request requires a valid credential, and credentials are scoped to read-only population access and nothing else. Customers never send us database queries or code: the Services accept only a fixed set of structured parameters, which the server validates against an allow-list before use. Privacy thresholds on the population data are enforced server-side and cannot be overridden. You can revoke an API key at any time in your account settings, with immediate effect; if you believe a key or your account has been compromised, revoke the key and contact us at support@hiasynth.co.

How We Share Your Information

Hiasynth does not sell, rent, or trade your personal data. We share your information only in the following limited circumstances:

Service Providers. We engage trusted third parties to help us operate the Services: Cloudflare (application hosting, the account and usage database, and storage of the population dataset), Fly.io (the query engine, in Frankfurt, Germany), Stripe (payments), and Resend (transactional email). Each service provider is contractually required to protect your data and use it only for the specific services they provide to us. We maintain Data Processing Agreements with all service providers that handle personal data on our behalf.

Identity Providers. GitHub, Google, and Discord act as independent controllers when you sign in with them. Their handling of your data on their own platforms is governed by their respective privacy policies.

Your AI Platform. When you connect our MCP server to an AI assistant or agent of your choice, that platform processes your prompts and our responses under its own terms and privacy policy. We receive from it only the structured parameters of individual tool calls, and we are not responsible for its privacy practices.

Legal Requirements. We may disclose your information if required to do so by law or in response to valid requests by public authorities, such as to comply with a court order or similar legal process. Where legally permitted, we will notify affected users before producing data in response to government requests. We may also disclose information when we believe in good faith that disclosure is necessary to protect our rights, your safety or the safety of others, investigate fraud, or respond to a lawful request.

Business Transfers. If Hiasynth is involved in a merger, acquisition, asset sale, or bankruptcy proceeding, your personal data may be transferred as part of that transaction. We will provide notice before your data is transferred and becomes subject to a different privacy policy.

International Data Transfers

Hiasynth AB is based in Sweden. The query engine is pinned to Frankfurt, Germany. Our application layer runs on Cloudflare's edge network, which means a request may be processed at a location close to you rather than in a fixed region. [CONFIRM open item 4: region of the account/usage database and population storage bucket, and exact edge-network wording, before publishing.] Some of our service providers operate globally, which means your personal data may be transferred to and processed in countries outside the European Economic Area, including the United States, where data protection laws may differ from those in the EU. This includes Stripe.

We safeguard these transfers through legally recognized mechanisms under Chapter V of the GDPR, including the EU Standard Contractual Clauses (Commission Decision 2021/914) and, where the provider is certified, the EU–US Data Privacy Framework. You may request a copy of the safeguards we have in place by contacting us at support@hiasynth.co.

Contact Information

Data Controller:

Hiasynth AB
Org.nr 559538-3703
VAT SE559538370301
[Registered address — open item 8]

Email Contacts:

Privacy inquiries: support@hiasynth.co
General inquiries: hello@hiasynth.co

Supervisory Authority:

If you are located in the European Union, you have the right to lodge a complaint with your local data protection authority if you believe we have not handled your personal data in accordance with applicable law. For users in Sweden, the relevant authority is:

Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY)
Website: imy.se
Email: imy@imy.se

Data Protection Officer (DPO).

Hiasynth AB is not currently required to appoint a formal Data Protection Officer under Article 37 GDPR. However, all privacy inquiries may be directed to support@hiasynth.co, where our privacy team will respond promptly.

Data Retention

We retain your personal data only as long as necessary to fulfill the purposes described in this Policy or as required by law. Active account data, including your email, linked OAuth accounts, and API keys, is retained for the duration of your account's active status. Usage logs and technical telemetry are retained for [OPEN ITEM 1: no automatic deletion exists today — a retention period must be decided AND implemented before this sentence can be published]. Payment and subscription records are retained for seven years from the date of the transaction in accordance with Swedish accounting law (Bokföringslagen).

When you delete your account, we will permanently erase your personal data within 30 days, apart from what we must keep by law. [OPEN ITEM 2: confirm what happens to the usage log on account closure and that an erasure request can be honoured today, before publishing this paragraph.] Some data may persist in system backups for up to [90 days — confirm], after which backups are overwritten.

If you wish to delete your account or request earlier deletion of your data, you may do so through the account settings in our web application or by contacting us at support@hiasynth.co. We will process your request in accordance with applicable law.

Cookies and Local Storage

Hiasynth does not use cookies for tracking or advertising. We rely on browser localStorage to maintain your authenticated session and store minimal information necessary for the Services to function. Specifically, we store a session token that identifies your session and basic profile information such as your username and avatar URL.

This use of localStorage is strictly necessary to provide the Services under Article 6(1)(b) GDPR (performance of contract) and does not require separate consent. You can clear localStorage at any time through your browser settings, but doing so will log you out and remove locally cached data.

Your Privacy Rights

Depending on your location, you have certain rights regarding your personal data. We respect these rights and will respond to verified requests in accordance with applicable law.

Right of Access. You have the right to request confirmation of whether we process your personal data and, if so, to receive a copy of that data along with information about how we use it. You can request access by contacting us at support@hiasynth.co.

Right to Rectification. If your personal data is inaccurate or incomplete, you have the right to request that we correct or complete it. You can update most of your information directly through your account settings in the web application.

Right to Erasure. You have the right to request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected, when you withdraw consent, or when you object to processing based on legitimate interests. You can delete your account through the web application or by contacting us at support@hiasynth.co. Note that we may retain certain information where required by law or for legitimate business purposes such as fraud prevention.

Right to Restriction of Processing. You have the right to request that we limit how we use your personal data in certain circumstances, such as when you contest the accuracy of the data or object to processing based on legitimate interests. During the period we assess your request, we will restrict processing of the data in question.

Right to Data Portability. You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller. We will provide your data in JSON format upon request.

Right to Object. You have the right to object to processing of your personal data based on our legitimate interests. If you object, we will stop processing your data unless we can demonstrate compelling legitimate grounds that override your interests or we need the data for legal claims.

Right to Withdraw Consent. Where we rely on your consent as the legal basis for processing, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before withdrawal.

Right to Lodge a Complaint. If you believe we have not handled your personal data appropriately, you have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY) or the supervisory authority in your EU Member State. Contact information is provided in the Contact Information section above.

To exercise any of these rights, please contact us at support@hiasynth.co. We will verify your identity before processing your request and respond within 30 days as required by applicable law. In some cases, we may need to extend this period, in which case we will notify you of the delay and the reason for it.

Links to Other Services

Our Services integrate with third-party platforms including GitHub, Google, Discord, Stripe, and the AI platforms through which you may access our MCP server. When you use these integrations, you are also subject to the privacy policies of those platforms. We encourage you to review their policies to understand how they handle your information. We are not responsible for the privacy practices of these third parties. Any data you provide directly to them is governed by their respective privacy policies.

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or the Services themselves. When we make changes, we will update the "Last Updated" date at the top of this document and post the revised Policy at hiasynth.co/privacy.

For material changes that significantly affect your rights or how we process your data, we will provide advance notice by email to your registered email address or through a prominent notice in the web application. We encourage you to review this Policy periodically to stay informed about how we protect your information.

Your continued use of the Services after the revised Policy takes effect constitutes your acceptance of the changes. If you do not agree with any changes, you may delete your account as described in this Policy. This Policy and any disputes arising from it are governed by the laws of Sweden.

Questions and Contact

If you have questions about this Privacy Policy or how we handle your personal data, please contact us at support@hiasynth.co or hello@hiasynth.co. We aim to respond to all inquiries within a reasonable timeframe and will work with you to resolve any concerns.

© 2026 Hiasynth AB
AboutPressDocsPrivacyTerms