Legal

Privacy Policy

Last updated: April 8, 2026

1. Who We Are

NanoSynthc is a product of Createnano LLC, a company registered in New Mexico, USA, located at 1209 Mountain Road Pl NE, Ste N, Albuquerque, NM 87110. ("Company," "we," "us," or "our").

For questions about this policy, contact us at privacy@createnano.com.

2. Data We Collect

Account Data: When you create an account, we collect your name, email address, and a hashed version of your password. We never store plaintext passwords.

Usage Data: We log API requests, generation parameters (row count, privacy level, format), and timestamps. We do not log the content of generated datasets.

Uploaded Data: If you upload a CSV for profiling, the file is processed to extract statistical properties (distributions, correlations, data types). The original file is stored temporarily on our servers and automatically deleted after 30 days, or immediately upon your request.

Payment Data: Payment processing is handled by Stripe. We do not store credit card numbers. We receive and store your Stripe customer ID and subscription status.

Technical Data: IP address, browser type, and device information are collected automatically for security and analytics purposes.

3. How We Use Your Data

  • To provide, maintain, and improve the NanoSynthc service
  • To authenticate your identity and manage your account
  • To process payments and manage subscriptions
  • To enforce plan limits and prevent abuse
  • To communicate service updates and security notices
  • To comply with legal obligations

We do not use your uploaded data to train any machine learning models. We do not sell, rent, or share your personal data with third parties for marketing purposes.

4. Synthetic Data & Privacy

The core function of NanoSynthc is generating synthetic data that contains zero personally identifiable information (PII). Synthetic records are mathematically generated and do not correspond to any real individual.

When you upload real data for profiling, we extract only statistical summaries (distributions, means, standard deviations, correlations). These summaries cannot be reverse-engineered to reconstruct individual records.

For Enterprise customers with on-premise deployments, no data — uploaded or generated — ever leaves your infrastructure.

5. Data Retention

  • Account data: Retained for the lifetime of your account, deleted within 30 days of account deletion request
  • Uploaded CSV files: Automatically deleted after 30 days, or immediately on request
  • Statistical profiles: Retained while your account is active
  • Generated datasets: Retained for 90 days, then automatically deleted
  • Usage logs: Retained for 12 months for billing and security purposes

6. Your Rights (GDPR & CCPA)

Depending on your jurisdiction, you have the right to:

  • Access: Request a copy of all personal data we hold about you
  • Rectification: Correct inaccurate personal data
  • Erasure: Request deletion of your account and all associated data
  • Portability: Receive your data in a machine-readable format
  • Restriction: Restrict processing of your personal data
  • Objection: Object to processing based on legitimate interests
  • Withdraw Consent: Withdraw consent at any time where processing is based on consent

To exercise any of these rights, email privacy@createnano.com. We will respond within 30 days.

California residents: Under CCPA, you have the right to know what personal information we collect, request deletion, and opt out of the sale of personal information. We do not sell personal information.

7. Security

We implement industry-standard security measures including:

  • AES-256 encryption at rest for all stored data
  • TLS 1.3 encryption in transit for all API communications
  • Bcrypt password hashing with per-user salts
  • SHA-256 API key hashing (we never store raw API keys)
  • JWT tokens with 24-hour expiration
  • Rate limiting to prevent abuse

8. Cookies

We use essential cookies only for authentication (JWT session token stored in localStorage). We do not use advertising cookies or third-party tracking cookies. See our Cookie Policy for details.

9. Third-Party Services

10. International Transfers

Our servers are located in the United States. If you access the service from outside the US, your data will be transferred to and processed in the US. For EU/EEA users, we rely on Standard Contractual Clauses (SCCs) as the legal basis for data transfers. Enterprise customers can request data residency in their preferred region.

11. Children's Privacy

NanoSynthc is not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us at privacy@createnano.com.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or by posting a prominent notice on our website at least 30 days before the changes take effect.

Createnano LLC · 1209 Mountain Road Pl NE, Ste N, Albuquerque, NM 87110 · privacy@createnano.com