Sythe Labs
How it worksWhat's coveredCompliancePricingTeamCase StudiesResearchPressDocsBreached?Book a call (opens Google Calendar in a new tab)
Sythe Labs/Privacy policy

Privacy Policy

What we collect, why we collect it, how long we keep it, and what happens when you disconnect.

Document controlLast updated September 1, 2026
Related pagesPrivacyTermsEULASupport

1. Who we are and what this covers

Sythe LLC, doing business as Sythe Labs ("Sythe Labs", "we", "us"), operates sythelabs.com and the Sythe Labs platform. This policy applies when you visit our website, contact us, use the platform, or connect a third-party integration to it.

Where a customer uses the platform under a subscription or services agreement, that agreement governs how we handle the customer's data and controls over this policy if the two conflict. In that relationship the customer decides what data enters the platform and we process it on the customer's instructions.

2. What we collect

  • Contact and support details you give us: name, email address, company, phone number, the support category and topic you choose, and whatever you write in the message.
  • Website usage: page paths and query parameters, sent to Google Analytics when you browse sythelabs.com.
  • Account and platform records: your login identity, organization membership, role, and the actions you take in the platform, which we log for security and audit purposes.
  • Connection records for each integration: status, configuration metadata, timestamps, and the audit and error logs needed to keep the connection working.
  • Google Workspace, Vercel, Cloudflare, and Neon integration information, described in sections 3 through 6, when an authorized person in your organization connects that provider.

We do not sell personal information, and we do not use any of it for advertising. We do not knowingly collect information from anyone under 16.

3. Google Workspace integration data

When an authorized administrator connects Google Workspace we receive that administrator's Google account email address, the Google Workspace customer ID that ties the connection to the right organization, and an OAuth credential that keeps the connection alive. Credentials are stored encrypted.

The authorization requests basic Google account identity, the authorizing administrator's Google account email address, read-only access to Google Workspace directory user records, and read-only access to Google Workspace domain usage reports for authorized applications. It does not create, update, or delete data in Google Workspace.

Directory user records become Personnel records in your organization. Each may carry a stable Google identifier, primary email address, full name, job title, department, manager, suspension or archive status, mailbox setup status, and profile photo URL. We also read administrator and delegated-administrator status, 2-Step Verification enrollment and enforcement, and organizational unit path, because those fields are what your compliance controls are evaluated against. We do not use Google Workspace data for advertising.

We also read the customer usage report for authorized third-party applications. It gives us the authorized third-party application client identifiers, application names, report dates, and the number of accounts in your organization that authorized each one. We keep those as vendor discovery records scoped to your organization.

Google Workspace data is shared only with the service providers that host, operate, secure, and support the integration on our behalf, when you direct or consent to a disclosure, or when the law requires one.

The use of information received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Review the Google API Services User Data Policy.

4. Vercel integration data

When an authorized user connects Vercel we process the Vercel team ID; project IDs, names, framework labels, regions, and plan tiers; and domain names. We also receive a Vercel credential, stored encrypted, that keeps the connection alive. Vercel sets the integration's permissions in its Integration Console.

The connector only reads. It maintains a cloud-service inventory and compliance evidence for your organization and never deploys or changes anything in Vercel.

If an organization admin turns on audit-log ingestion, we also process the event identifier, action, timestamp, actor, delegated actors, request identifier, location, user agent, project identifier, and change context that Vercel delivers. We redact sensitive metadata values before storing the normalized event and do not keep the raw delivery body.

5. Cloudflare integration data

When an authorized administrator connects Cloudflare we receive the selected account ID and a customer-owned API token, and we read the account name to tie the connection to the right organization. The token is stored encrypted for as long as the connection is active.

We ask you to create a new account-owned token with only the four required Read permissions: account settings, public zones, DNS, and zone settings. The exact steps are in the customer setup guide. Cloudflare's token verification response does not list a token's full grants, so we can confirm the four reads are present but cannot detect extra permissions. Whatever the token can do, the integration performs only the seven documented read operations and never creates, edits, pauses, deletes, rotates, or revokes anything in Cloudflare.

From those reads we process the account ID and name, account-level two-factor authentication enforcement, and for each public zone its identifier, name, type, lifecycle status, paused state, DNSSEC status, Always Use HTTPS setting, and minimum TLS version. This feeds your cloud-service inventory and compliance evidence.

We also process account-member identity, status, assigned roles and policies, and privilege provenance: the Cloudflare membership ID, the user ID when Cloudflare returns one, the email address, and role and policy names, descriptions, permissions, access decisions, permission groups, and resource scopes. We keep this as a bounded access-review package scoped to your organization. Account members are never added to the cloud-asset inventory. We do not use Cloudflare integration data for advertising.

6. Neon integration data

When an authorized administrator connects Neon we receive a customer-owned API key and read the organization identifier and name to tie the connection to the right organization. The key is stored encrypted for as long as the connection is active.

We ask you to create an organization API key, or a personal API key that belongs to exactly one Neon organization. Project-scoped keys are rejected. The exact steps are in the customer setup guide. We process the organization identifier and name and, for each project, its identifier, name, IP allowlist, public-connection settings, history retention, and default-branch backup schedule. This feeds your cloud-service inventory and compliance evidence.

The integration does not collect a Neon member roster and does not build an access-review package. Whatever the key can do, the integration performs only documented GET operations and never creates, mutates, or deletes anything in Neon. We do not use Neon integration data for advertising.

7. How we use it

  • To run, secure, and support the website, the platform, and each integration.
  • To keep an inventory of the cloud services connected to your organization.
  • To turn authorized Google Workspace directory data into Personnel records and the compliance evidence built from them.
  • To surface the third-party applications your Google Workspace accounts have authorized, so you can review them as vendors.
  • To answer support requests, tell you about the service, and fix problems.
  • To detect and investigate misuse, and to meet our legal obligations.

8. Retention, disconnection, and deletion

We keep integration credentials and connection metadata only while the integration is connected. We keep synchronized provider data while it is needed to operate the connection and support the compliance evidence built from it. An authorized user can disconnect any integration in the platform. Disconnecting stops scheduled synchronization and does the following for each provider:

  • Google Workspace. The saved Google authorization is removed. Imported Personnel stay in the platform but stop receiving directory updates. Discovered applications leave active vendor discovery views and stop receiving usage-report updates; reconnecting can restore any that a later report observes again. Imported Personnel are deleted when the tenant is deleted, or on request through our support page.
  • Vercel. The stored credential bytes are cleared, connection metadata is reset, and Vercel-discovered services leave active inventory views. Accepted audit-log events are unaffected and follow the platform audit-retention setting, which defaults to 365 days and can be set to 30 days, 90 days, 365 days, or no automatic expiry. Each event keeps the expiry assigned when it arrived, so a later change to the setting applies only to new events.
  • Cloudflare. When an organization disconnects Cloudflare, the platform deletes its encrypted API token, clears connection metadata, removes Cloudflare-discovered services from active inventory views, and invalidates the current account-member access-review package and its attestation.
  • Neon. When an organization disconnects Neon, the platform deletes its encrypted API key, clears connection metadata, and removes Neon-discovered services from active inventory views.

Disconnecting does not revoke the customer-owned Cloudflare token or Neon key at the provider. Revoke those yourself in the Cloudflare dashboard or Neon console.

Historical evidence versions may remain where they are needed for security, legal, or operational reasons, including to preserve an audit trail you have already relied on. To correct provider-sourced information, change it at the provider and synchronize again.

9. Who we share it with

We use Resend to deliver contact and support messages and Google Analytics to measure website traffic. We use other service providers to host, operate, secure, and support the service; each is bound by contract to process data only on our instructions. We disclose information when the law requires it, to protect people, systems, or rights, or as part of a merger, acquisition, or sale of assets, in which case the successor is bound by this policy. We never use Vercel, Cloudflare, or Neon integration data to deploy, change, or manage resources at the provider.

10. Security

Credentials are stored encrypted. Access is scoped to the organization that owns the data. OAuth connection steps are protected against interception. No system is perfectly secure, and we will notify affected customers of a security incident involving their data as the law and our agreements require.

11. Your rights

You can ask us to access, correct, or delete your personal information, or object to how we process it, through our support page. Select Other and describe the request. We may ask you to verify your identity first. If your data reached us through a customer's platform, we may direct the request to that customer, since they control the data. Where a privacy law such as the GDPR or CCPA gives you additional rights, we honor them within the time the law allows.

12. International transfers

We are based in the United States and process data there. If you use the service from elsewhere, your information is transferred to and stored in the United States, and we rely on contractual safeguards with our service providers for any onward transfer.

13. Changes

We update this policy when our services or practices change. The current version is always at this URL with its revision date. If a change materially reduces your rights, we will notify connected organizations before it takes effect.

Sythe Seconds

Security moves fast. Stay a step ahead.

Research from our team, practical compliance guidance, and the latest from Sythe Labs. Straight to your inbox.

By subscribing, you agree to receive Sythe Seconds. Unsubscribe anytime. Privacy policy
Sythe Labs

Your security team, on-demand. We do security, so you can ship.

Book a 30-minute call (opens Google Calendar in a new tab)

Company

AboutTeamContact

What's covered

PentestingIncident responseCompliance

Frameworks

SOC 2ISO 27001HIPAAPCI DSSGDPRAll frameworks

Resources

DocsIntegrationsVercel docsCase StudiesBlogNewsletterPressPrivacyTermsEULASupport
(c) 2026 Sythe LLCCut through the complexity.