Synthesia
Graded against 804 verified platforms, from its own policy text. Automated assessment against a published rubric — not legal advice.
“It is in our interest to continuously improve our Platform for Users and enhance our models’ capabilities and safety.”
Partially verified: Privacy Policy assessed · Terms of Service pending. Everything below comes only from what was read in full.
Watch: Moderation and enforcement
Start here. These are the highest-risk verified clauses AIRIN found in the platform's own policy text.
Account termination and banning are explicitly reserved rights. The standard for triggering a ban is a 'breach of the Agreement,' which is defined elsewhere. This gives Synthesia broad enforcement discretion without transparent criteria in this document.
Broad sharing with affiliates and unaffiliated third-party service providers is permitted for routine business activities. The lack of specificity regarding which data categories are shared with which provider reduces user transparency and control.
Biometric data is disclosed to third-party subprocessors for identity verification. The open-ended list ('including but not limited to') means additional vendors may process biometric data without specific disclosure. Users have limited visibility into the full chain of biometric data processors.
How to read this page: Overall risk rates what Synthesia's own policy terms mean for your prompts, outputs, and data. The benchmark bands below grade those same verified terms relative to peers — a platform in a risky-by-default category can rate HIGH risk and still grade STRONG against its peer set. Both trace to the cited findings.
Policy benchmark
rubric v1.0 — how this is scoredIP/output assessment pending — terms of service not yet verified This lens receives a band only once its source document has been captured and read in full.
Know where this document lives? Point us to the URL or PDF and the pipeline will verify it.
Based on 94 verified, verbatim-cited findings below — read the citations.
Automated assessment against a published rubric — not legal advice.
Partially verified — Privacy Policy — Verified (read in full, 69 findings); Terms of Service — Capture pending. Findings below are from fully-read, verified documents only; remaining core documents are pending capture.
Capture blocked
A known core policy document could not be publicly captured after the available capture strategies were tried.
Blocked core document: Terms of Service
- Privacy PolicyVerified - read in full - 69 citationsstaticLast captured 2026-08-05
- Terms of ServiceCapture blocked - document not publicly capturablestatic
Only citation-backed plan differences are shown here; absent cells mean AIRIN has not verified a tier-specific claim.
Establishes that Customer Data is processed by Synthesia strictly in accordance with the Customer's instructions and the Agreement, confirming Synthesia's role as processor and the Customer's role as controller, and identifying that Other Information is used to operate the Platform and business.
" Customer Data will be processed by Synthesia in accordance with Customer's instructions, including any applicable terms in the Agreement, and as required by applicable law. As explained above, in general, Synthesia is a processor of Custom..."
Describes Synthesia's obligation to collect and process specific categories of personal data submitted through the Platform, including Customer Data and Other Information such as contact information and financial data, enumerating the data types and collection mechanisms that trigger processing obligations.
" Synthesia collects and receives the following information through the Platform and your other interactions with Synthesia. Customer Data . Customers or Authorized Users submit Customer Data to Synthesia when they use the Platform. Other..."
Describes procedures for exercising data subject rights including fee structure for copies (first copy free, further copies subject to reasonable fee), notification of consequences of stopping processing or deletion, and obligation to notify third parties of rectification, erasure, or restriction.
" Where we are required to provide a copy of your personal data, this will be free of charge; however, any further copies requested may be subject to a reasonable fee based on administration costs. Where we stop processing personal data or ..."
Establishes obligations to retain Customer Data per Customer instructions and applicable law, provides that Customer-initiated deletion may result in de-identification of associated information, and permits retention of other information for as long as necessary for described purposes including service provision.
" We will retain Customer Data in accordance with Customer’s instructions (including to perform any applicable terms in the Agreement and through Customer’s use of Platform functionality) and as required by applicable law. The deletion of Cu..."
Broad sharing with affiliates and unaffiliated third-party service providers is permitted for routine business activities. The lack of specificity regarding which data categories are shared with which provider reduces user transparency and control.
"Our affiliated companies - we will share your information with our affiliated companies in order to facilitate company business and as part of our regular reporting activities. Our service providers - we will share your information with af..."
Establishes that Customer Data sharing is controlled by the Customer and that Synthesia shares Customer Data only per Customer instructions and applicable agreement terms, while identifying affiliated companies as a permissible disclosure recipient category.
" The policies and practices for sharing and/or disclosure of Customer Data to third parties is determined by the Customer. Synthesia has no control over the Customer's or any other third parties' choice to share and/or disclose Customer Dat..."
Permits the sale, transfer, or sharing of personal data including user data as part of mergers, acquisitions, asset sales, bankruptcy, or related due diligence processes, constituting a business transfer exception to standard data sharing restrictions.
" Other entities as part of a business transfer - if Synthesia undertakes or is involved in any merger, acquisition, reorganisation, sale of assets, bankruptcy, or insolvency event, then we may sell, transfer, or share some or all of our as..."
Evidence appendix
Showing priority citations first. The full appendix is available for audit trails; not every citation is a severe risk.
"delete your Synthesia account, at your request or in accordance with the Agreement. We may take steps to ban your account if there is a breach of the Agreement."
Account termination and banning are explicitly reserved rights. The standard for triggering a ban is a 'breach of the Agreement,' which is defined elsewhere. This gives Synthesia broad enforcement discretion without transparent criteria in this document.
AI-generated interpretation, not legal advice.
"Our affiliated companies - we will share your information with our affiliated companies in order to facilitate company business and as part of our regular reporting activities. Our service providers - we will share your information with affiliated and unaffiliated service providers which assist us in carrying out the processing activities described in this Privacy Policy. Our service providers include payment processing providers, IT service providers, our auditors, and our legal, accounting and other professional advisors."
Broad sharing with affiliates and unaffiliated third-party service providers is permitted for routine business activities. The lack of specificity regarding which data categories are shared with which provider reduces user transparency and control.
AI-generated interpretation, not legal advice.
"In order to effectively verify the authenticity of submissions, we may use a third-party verification systems or vendors, including but not limited to Amazon Web Services EMEA SARL."
Biometric data is disclosed to third-party subprocessors for identity verification. The open-ended list ('including but not limited to') means additional vendors may process biometric data without specific disclosure. Users have limited visibility into the full chain of biometric data processors.
AI-generated interpretation, not legal advice.
"Customer Data excludes the Services, any content that Synthesia makes generally available to Customers through the Services (“ Synthesia Content ”) and Non-Synthesia Products. The Customer (e.g., your employer or another entity or person) that entered into the Agreement with Synthesia for the purchase of Services controls its instance of the Services and any associated Customer Data. If you have any questions about specific settings and privacy practices, please contact the Customer whose Service you use. "
Defines 'Customer Data' by exclusion (excluding Synthesia Content and Non-Synthesia Products), identifies the Customer as the controller of Customer Data, and establishes that the Customer (e.g., an employer) controls the instance of Services and associated data, directing users to contact the Customer for privacy questions — creating a clear allocation of data-control responsibility.
AI-generated interpretation, not legal advice.
" It is in our interest and in the interest of Synthesia Users to prevent and address fraud, unauthorised use of Synthesia, violations of our Terms and policies, or other harmful or illegal activity. It is in our interest to protect ourselves (including our rights, personnel, property or products), our Users or others, including as part of investigations or regulatory inquiries; or to prevent death or imminent bodily harm."
States the legitimate interests relied upon for sharing personal data with law enforcement — preventing fraud, unauthorized use, policy violations, harmful or illegal activity, protecting the company and users, and preventing death or bodily harm — establishing the legal basis for voluntary data sharing with authorities.
AI-generated interpretation, not legal advice.
" We rely on our legitimate interests or the legitimate interests of a third party, where they are not outweighed by your interests or fundamental rights and freedoms. "
Establishes the legal basis of legitimate interests for processing personal data, imposing a balancing requirement that the controller's interests must not be outweighed by the data subject's interests or fundamental rights and freedoms.
AI-generated interpretation, not legal advice.
" process the information relating to your use and interaction with the Services, and the performance and quality of the Services resulting from such use "
Specifies that information relating to user interaction with Services and the performance/quality of Services is processed for platform improvement and internal research, which encompasses model training and capability enhancement.
AI-generated interpretation, not legal advice.
" To promote safety, integrity and security in limited circumstances outside of the performance of our contract with you. Our Platform is delivered to ensure the safety, integrity and security of the Platform and those Users who use it. We apply automated processing to Technical data so we can scan it and prevent malicious signs such as too many password failures, seeking exploits, and similar, to maintain the integrity of our Platform and to promote safety, integrity and security."
Describes the automated processing of Technical data to detect and prevent security threats (excessive password failures, exploit attempts) in order to maintain platform integrity and promote safety, establishing this as an ongoing security-related data processing obligation.
AI-generated interpretation, not legal advice.
"Sample is considered Customer Data and a separate agreement may govern its use and processing. Cookie information : We use a variety of cookies and similar technologies in our Websites and Services to help us collect Other Information. For more details about how we use these technologies, and your opt-out controls and other options, please visit our Cookie Policy . Other information you choose to provide . We also receive Other Information when submitted to our Platform or in other ways, such as responses or opinions you provide if you participate in a focus group, contest, activity or event, feedback you provide about our products or services, information you provide if you apply for a job with Synthesia, enrol in a certification program or other educational program hosted by Synthesia or a vendor, request support, interact with our social media accounts or otherwise communicate with Synthesia. Generally, no one is under a statutory or contractual obligation to provide any Customer Data or Other Information (collectively, “ Information ”). However, certain Information is collected automatically and, if some Information, such as Account information, is not provided, we may be unable to provide the Services. "
Identifies 'Sample' as Customer Data subject to a separate agreement, discloses the use of cookies to collect Other Information, and references the Cookie Policy for opt-out controls, creating an obligation to process cookie data and an incorporation by reference of the Cookie Policy's terms.
AI-generated interpretation, not legal advice.
"To analyse and develop technical improvements to the Platform we: Collect information about your use of the Platform (for example, when and how often you use the Platform and visit our Sites. Collect and process any User feedback provided to us. Collect information to monitor the performance and reliability of our Platform. Collect information to resolve issues with the Platform or outages, technical User issues, to troubleshoot, run diagnostics and debug the Platform."
Processing user feedback and usage data for platform diagnostics and improvement is a common and generally low-risk practice. The legitimate interests basis is plausible, though users retain an GDPR right to object.
AI-generated interpretation, not legal advice.
" Synthesia collects and receives the following information through the Platform and your other interactions with Synthesia. Customer Data . Customers or Authorized Users submit Customer Data to Synthesia when they use the Platform. Other Information . Synthesia also collects, generates and/or receives the following categories of personal data (" Other Information "): Contact information: When you contact us or otherwise communicate with us, we will process your name, email address, phone number, and any additional information which you may provide such as your title and employer. Financial data: When you purchase our Services, we will collect the following transaction information: payment card details if payment is done using a payment card, bank account details is payment is done using a wire transfer or ACH, details of the amounts paid or refunded, dates of payments and the services purchased. Account information: When you create an account on our services or Customer creates an account for you, we will process your email address, first and last name and depending on the log-in method, your password. You may also customize your user profile by adding a profile picture and changing the account settings. Usage information: During your interactions with the Platform, we will collect and process information about how Users use or interact with the Site and features and functionality of the Services and Software. "
Describes Synthesia's obligation to collect and process specific categories of personal data submitted through the Platform, including Customer Data and Other Information such as contact information and financial data, enumerating the data types and collection mechanisms that trigger processing obligations.
AI-generated interpretation, not legal advice.
" To send you marketing communications, depending on your preferences, to introduce you to new Services, or provide general news about our Platform. We will obtain your consent to send you marketing communications where required by law."
Describes the permissible use of personal data for sending marketing communications to users about new services and news, conditioned on user preferences and consent where required by law, establishing a consent-based processing permission.
AI-generated interpretation, not legal advice.
"To protect the integrity and security of our systems and Platform we process your personal data to: Verify accounts and activity. Find and address violations of the Agreement or our policies. Investigate suspicious activity. Detect, prevent and combat unlawful behavior."
Processing personal data for fraud detection, security investigations and policy enforcement is a recognised legitimate purpose. This clause confirms that user activity is monitored for compliance with the Agreement and applicable law.
AI-generated interpretation, not legal advice.
" We reserve the right to change our Privacy Policy at any time. The current version of the Privacy Policy is available on the Website, indicating the effective date in the heading. We will notify you of any material changes, as appropriate, and update the effective date in the heading of this Privacy Policy. You are encouraged to check our Privacy Policy periodically. "
Reserves the platform's right to change the Privacy Policy at any time, imposes an obligation to notify users of material changes and update the effective date, and encourages periodic review by users.
AI-generated interpretation, not legal advice.
"We will retain Customer Data in accordance with Customer’s instructions (including to perform any applicable terms in the Agreement and through Customer’s use of Platform functionality) and as required by applicable law. The deletion of Customer Data and other use of the Services by the Customer may result in the deletion and/or de-identification of certain associated Other Information."
Retention of Customer Data follows customer instructions and legal requirements. However, deletion of Customer Data only 'may result' (not 'will result') in deletion of associated Other Information, leaving some residual retention risk.
AI-generated interpretation, not legal advice.
" We will retain Customer Data in accordance with Customer’s instructions (including to perform any applicable terms in the Agreement and through Customer’s use of Platform functionality) and as required by applicable law. The deletion of Customer Data and other use of the Services by the Customer may result in the deletion and/or de-identification of certain associated Other Information. We may retain Other Information pertaining to you for as long as necessary for the purposes described in this Privacy Policy (such as to provide the Services, including any optional features you use, and to provide customer support). This may include keeping your Other Information after you have deleted your account for the period of time needed for us to pursue legitimate business interests, conduct audits, comply with (and demonstrate compliance with) legal obligations, resolve disputes, and enforce our agreements."
Establishes obligations to retain Customer Data per Customer instructions and applicable law, provides that Customer-initiated deletion may result in de-identification of associated information, and permits retention of other information for as long as necessary for described purposes including service provision.
AI-generated interpretation, not legal advice.
" Where we are under an obligation to disclose personal data such as, for example, if we receive a valid legal request for certain personal data (such as a search warrant), we will access, preserve and/or share your personal data with regulators, law enforcement or others. The way in which the personal data will be processed depends on the specific circumstances."
Specifies that when legally compelled (e.g., by search warrant), the platform is obligated to access, preserve, and/or share personal data with regulators, law enforcement, or others, and that the manner of processing depends on the specific circumstances of the legal request.
AI-generated interpretation, not legal advice.
" We process personal data to comply with a legal obligation including, for example, to access, preserve, or disclose certain personal data if there is a valid legal request."
Describes the processing activity carried out under legal obligation — accessing, preserving, or disclosing personal data in response to valid legal requests — establishing this as a mandatory processing activity distinct from legitimate interest processing.
AI-generated interpretation, not legal advice.
Common questions about Synthesia's policies
- Does Synthesia train its AI models on your data?
- No training on your content by default — based on 2 verified findings from Synthesia's published policy. Informational only, not legal advice.
Clause detail — protections, your obligations, and coverage
Every clause below is a verbatim quote from Synthesia's own published policy, read in full and linked to its exact location. Protections and user obligations are reported separately from risk because they are different kinds of clause — an obligation on you is not a risk to your data. Informational only, not legal advice.
✅ Protections found
16 verified clausesClauses in Synthesia's policies that work in your favour — commitments the platform made to you.
- Audit rights, DPA & residency
“Certain jurisdictions distinguish between a "controller" or "processor" of personal data. A controller is the decision-maker and exercises overall control over how and why personal data is collected and used. In general, the Customer is the controller of Custo…”
Defines the legal roles of 'controller' and 'processor' under applicable data-protection law, assigns the Customer as controller of Customer Data and Synthesia as processor of Customer Data and controller of Other Inform…
📍 Privacy Policy › “Identifying the Data Controller and Data Processor”Jump to exact text → - Privacy & data use
“We process all personal data in accordance with the principles of GDPR and especially having in mind your data protection rights, in particular your right, in certain circumstances, to: Request access to any data held about you by Synthesia and information re…”
Enumerates data subject rights under GDPR including the right to access personal data, receive information about processing, and obtain data portability in structured machine-readable format where processing is based on…
- Designated security contact: support@synthesia.io
📍 Privacy Policy › “User's Rights”Jump to exact text → - Audit rights, DPA & residency
“We may transfer your personal data to recipients located outside of the United Kingdom (“ UK ”) and European Economic Area (“EEA”). When we transfer your personal data outside of the UK or EEA, we ensure it benefits from an adequate level of data protection b…”
Imposes an obligation to ensure personal data transferred outside the UK or EEA benefits from adequate protection, identifying adequacy decisions and standard contractual clauses as the approved transfer mechanisms relie…
📍 Privacy Policy › “International Data Transfers”Jump to exact text → - Audit rights, DPA & residency
“We may transfer your personal data to recipients located outside of the United Kingdom (“ UK ”) and European Economic Area (“EEA”). When we transfer your personal data outside of the UK or EEA, we ensure it benefits from an adequate level of data protection b…”
The platform relies on EU-approved transfer mechanisms (adequacy decisions and SCCs) for cross-border personal data transfers outside the UK/EEA. This represents standard compliance posture under GDPR Article 45/46. User…
📍 Privacy Policy › “International Data Transfers”Jump to exact text → - Privacy & data usesale/sharing of personal data
“Where we are required to provide a copy of your personal data, this will be free of charge; however, any further copies requested may be subject to a reasonable fee based on administration costs. Where we stop processing personal data or delete your personal…”
Describes procedures for exercising data subject rights including fee structure for copies (first copy free, further copies subject to reasonable fee), notification of consequences of stopping processing or deletion, and…
📍 Privacy Policy › “User's Rights”Jump to exact text → - Data retentiondeletion rights & post-termination survival
“We and our vendors will store and use the Biometric Data described above only until it is no longer needed for the achievement of the above listed purposes. For the creation of an Avatar, Biometric Data is stored and used as long as the Avatar is available on…”
Retention of biometric data for the lifetime of the avatar means data could persist indefinitely. Furthermore, the controlling party for deletion decisions is the Customer (e.g., an employer), not the individual whose bi…
📍 Privacy Policy › “Avatar submissions and Biometric Data”Jump to exact text →
+ 10 more verified clauses of this kind on this platform, cited in full in the report.
📋 Rules you must follow
0 verified clausesWhat Synthesia requires of YOU. These are your obligations, not risks to your data or IP, so they are cited here and excluded from this platform's risk rating.
No user-conduct rule has been verified in Synthesia's published policies yet.
What the policies actually cover
9 topics- Product telemetry & usage tracking19 clauses
- Advertising & tracking1 protective4 clauses
- Sale or sharing of personal data2 protective2 clauses
- Sensitive data (biometric, location, health)1 protective2 clauses
- Children's data1 protective1 clause
- Government & law-enforcement disclosure5 clauses
- Terms can change at any time1 protective1 clause
- Deletion rights & post-termination survival1 protective3 clauses
- Breach-notification promises1 clause
31 further verified clauses are cited on this page but not yet assigned a topic.
Cross-clause notes
Two verified clauses intersect on the same subject matter: the Privacy Policy, Privacy Policy › “Retention of personal data” addresses how long content is retained, and the Privacy Policy, Privacy Policy › “Usage information” addresses use of content in connection with model training or service improvement. Both clauses are in force at the same time — read them together.
Automated cross-reference against the published rubric — not legal advice.
Clause intelligence
Canonical clauses and stance patterns extracted from the same gate-verified citations shown on this page.
The clause allows indefinite, perpetual, or necessity-based retention.
“We will retain Customer Data in accordance with Customer’s instructions (including to perform any applicable terms in the Agreement and through Customer’s use of Platform functionality) and as required by applicable law. The deletion of Customer Data and other use of the Services by the Customer may result in the deletion and/or de-identification of certain associated Other Information. We may retain Other Informa...”Open source citation
The clause allows indefinite, perpetual, or necessity-based retention.
“We may retain Other Information pertaining to you for as long as necessary for the purposes described in this Privacy Policy (such as to provide the Services, including any optional features you use, and to provide customer support). This may include keeping your Other Information after you have deleted your account for the period of time needed for us to pursue legitimate business interests, conduct audits, compl...”Open source citation
The clause allows indefinite, perpetual, or necessity-based retention.
“We will retain Customer Data in accordance with Customer’s instructions (including to perform any applicable terms in the Agreement and through Customer’s use of Platform functionality) and as required by applicable law. The deletion of Customer Data and other use of the Services by the Customer may result in the deletion and/or de-identification of certain associated Other Information. We may retain Other Informa...”Open source citation
The clause allows indefinite, perpetual, or necessity-based retention.
“We will retain Customer Data in accordance with Customer’s instructions (including to perform any applicable terms in the Agreement and through Customer’s use of Platform functionality) and as required by applicable law. The deletion of Customer Data and other use of the Services by the Customer may result in the deletion and/or de-identification of certain associated Other Information. We may retain Other Informa...”Open source citation
The clause allows indefinite, perpetual, or necessity-based retention.
“We will retain Customer Data in accordance with Customer’s instructions (including to perform any applicable terms in the Agreement and through Customer’s use of Platform functionality) and as required by applicable law. The deletion of Customer Data and other use of the Services by the Customer may result in the deletion and/or de-identification of certain associated Other Information. We may retain Other Informa...”Open source citation
Tier matrix
Plan-level conditions detected from citation-backed clauses. Empty tiers mean AIRIN has not captured decisive tier language yet.
| Tier | Surface | Verdict | Risk | Citations |
|---|---|---|---|---|
| All applicable tiers | commercial use | worsens | HIGH | 6 |
| All applicable tiers | data retention | conditional | MEDIUM | 5 |
| All applicable tiers | privacy data use | worsens | HIGH | 4 |
| All applicable tiers | prompt ownership | conditional | MEDIUM | 2 |
| All applicable tiers | subprocessors data sharing | worsens | HIGH | 2 |
| Free | data retention | worsens | HIGH | 3 |
| Free | privacy data use | worsens | HIGH | 1 |
| Team / Business | data retention | conditional | MEDIUM | 5 |
| Team / Business | privacy data use | worsens | HIGH | 6 |
| Team / Business | subprocessors data sharing | worsens | HIGH | 4 |
Policy evolution
Open full timelineBefore/after stance changes across captured policy versions. When no material delta exists yet, AIRIN shows the latest citation-backed stance events instead.
data sharing worsened from medium/third party or vendor sharing to high/sale or sell.
“We and our vendors will store and use the Biometric Data described above only until it is no longer needed for the achievement of the above listed purposes. For the creation of an Avatar, Biometric Data is stored and used as long as the Avatar is available on the Platform or as otherwise instructed by our Customer. For authenticating the Avatar submission, Biometric Data is stored and used only until we confirm the results of the samples comparison which usually occurs within few minutes of the submission. After the relevant processing has been completed or where instructed by our Customer, we permanently destroy your Biometric Data, unless otherwise required by law or legal process to retain the data. We require our vendor(s) to similarly delete or destroy Biometric Data. You will be asked whether you consent to the use of your Biometric Data as described above. If you do not consent, or if we cannot otherwise complete the validation checks (for example, if you close the browser without completing all necessary steps), we will not extract Biometric Data from your recordings, process your Biometric Data, or verify or authenticate your identity. This will also prevent you from generating an Avatar. If you do not want to consent to this processing of your Biometric Data you may utilize our Studio Avatar feature in which the validation check happens manually. In order to effectively verify the authenticity of submissions, we may use a third-party verification systems or vendors, including but not limited to Amazon Web Services EMEA SARL.”Before citation
“Where we are required to provide a copy of your personal data, this will be free of charge; however, any further copies requested may be subject to a reasonable fee based on administration costs. Where we stop processing personal data or delete your personal data, it will possibly mean that you are unable to continue using or contributing to the provision of some of our Services, and you will be notified accordingly. Where we rectify or erase your personal data or restrict any processing of such personal data, we may be required to notify certain third-parties to whom such personal data has been disclosed. You have the right to lodge a complaint with the Information Commissioner's Office at 0303 123 1113 or via live chat at ico.org.uk/livechat or with your local supervisory authority . We do not sell or rent personal information to any third-party.”After citation
Latest stance: sale or sell on commercial use
“In addition to our third-party vendors acting on our behalf, we will only disclose, redisclose or otherwise disseminate Biometric Data in the following circumstances: As instructed by the Customer as a data controller; As required by applicable State or federal law or municipal ordinance; As required pursuant to a valid warrant or subpoena issued by a court of competent jurisdiction; or As expressly consented to by you or your legally authorized representative. We will not sell, lease, trade, or otherwise profit from Biometric Data and will not permit its vendor(s) to sell, lease, trade, or otherwise profit from the Biometric Data.”Open timeline citation
Latest stance: third party or vendor sharing on commercial use
“In addition to our third-party vendors acting on our behalf, we will only disclose, redisclose or otherwise disseminate Biometric Data in the following circumstances: As instructed by the Customer as a data controller; As required by applicable State or federal law or municipal ordinance; As required pursuant to a valid warrant or subpoena issued by a court of competent jurisdiction; or As expressly consented to by you or your legally authorized representative. We will not sell, lease, trade, or otherwise profit from Biometric Data and will not permit its vendor(s) to sell, lease, trade, or otherwise profit from the Biometric Data.”Open timeline citation
Latest stance: third party or vendor sharing on privacy data use
“The policies and practices for sharing and/or disclosure of Customer Data to third parties is determined by the Customer. Synthesia has no control over the Customer's or any other third parties' choice to share and/or disclose Customer Data. Synthesia may share and disclose Customer Data in accordance with a Customer's instructions, including any applicable terms in the Master Subscription Agreement and Data Processing Addendum. In certain circumstances we may share and/or disclose the personal data described in this Privacy Policy. Our affiliated companies - we will share your information with our affiliated companies in order to facilitate company business and as part of our regular reporting activities. Our service providers - we will share your information with affiliated and unaffiliated service providers which assist us in carrying out the processing activities described in this Privacy Policy. Our service providers include payment processing providers, IT service providers, our auditors, and our legal, accounting and other professional advisors. Regulators, law enforcement, public or government authorities, or courts - we will share your information if and to the extent we are required or permitted to do so by law or where disclosure is reasonably necessary to (i) comply with applicable law; (ii) comply with a valid legal request or respond to claims against Synthesia; (iii) respond to a valid legal request relating to a criminal investigation to address alleged or suspected illegal activity, or to respond to or address any other activity that may expose us, you, or any other of our Users to legal or regulatory liability; (iv) enforce and administer our Terms of Service; (v) respond to requests for or in connection with current or”Open timeline citation
Latest stance: sale or sell on privacy data use
“Other entities as part of a business transfer - if Synthesia undertakes or is involved in any merger, acquisition, reorganisation, sale of assets, bankruptcy, or insolvency event, then we may sell, transfer, or share some or all of our assets, including your personal data, in connection with such transaction or in contemplation of such transaction, such as due diligence.”Open timeline citation
Capture recency
- Privacy Policy:Last captured 2026-08-05· verified 2026-08-05
- Terms of Service:Last captured 2026-08-05
Dates state when our pipeline captured and verified each document — not when the vendor last changed it. Documents are re-scanned on a recurring cadence; a document verified once says so until a re-scan confirms it again.
↓ 25 fewer findings this quarter vs last (112 vs 137). First scan: June 2026.
Compare and stack are saved in your browser. Open compare · View your stack. A correction triggers an automated re-read of Synthesia's policies — no human edits the data.
Need this for procurement or legal diligence?
Free shows today's risk. A Stack Audit gives you a citable, verbatim-sourced PDF across your whole AI stack — and flags the moment a vendor's terms change.
Know where the missing document lives?
We haven't yet verified Synthesia's Terms of Service. Point us at the official page and our pipeline will attempt to capture and read it in full. Submissions are candidates only — nothing is published until it passes the same verification gates as every other document on this site.
Every finding above is a verbatim quote from Synthesia's own published policy, captured to an immutable snapshot and read in full through a two-gate verification pipeline. Confidence labels and any analysis are AI-generated and informational only — not legal advice.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.