Privacy Policy
Your shopping data is guarded by the same hands that guard your money.
Last updated: September 6, 2026. Symy is built by Symbiotic Lab (Symbiotic Lab builds Symy and has no financial ties to any merchant or platform). This Policy describes what data we collect, why we collect it, and how you can control it.
1. Data We Collect
Account data: Email address, display name, authentication tokens (managed by Supabase Auth). Your password is never stored in plaintext — Supabase Auth uses bcrypt hashing.
Usage data: Chat messages with Symy, challenge results (saw it / bought anyway), spending reflections, Dream Fund goals and progress, Gacha story descriptions and outcomes, hourly rate setting, and buddy state (vitality, tokens, XP, streak, daily needs).
Blind-spot map data: Aggregated patterns derived from your challenges (e.g. time-of-day, amount tier, impulse rate) — used to show you your spending patterns. We do not store individual purchase receipts unless you connect email monitoring.
Email receipts (optional, only if you connect email): If you connect an email account, we scan for purchase-related emails (order confirmations, receipts, refund notices). We extract merchant name, item description, amount, and date. We do not store the full email body, attachments, or emails unrelated to purchases.
Device & usage analytics: Aggregated, anonymized usage statistics (page views, feature engagement, error rates) via Sentry. Sentry receives IP addresses and browser fingerprints for error diagnosis, but we configure Sentry to not store raw PII.
Referral data: If you sign up via a referral link, we store the referrer's code (an 8-character random string, not their email) on your account to credit the referrer if you complete your first challenge.
2. How We Use Your Data
Your data is used to:
- Provide the Symy companion experience — chat, challenges, Dream Funds, Gacha stories;
- Personalize AI reflections and stories (your challenge history is injected into AI context for continuity);
- Track your progress (vitality, streaks, savings, blind-spot map);
- Improve the Service anonymously — we may aggregate user data to identify common patterns (e.g. "40% of users struggle with late-night TikTok Shop") without exposing any individual's data;
- Send you service-related notifications (e.g. streak reminders, new feature announcements) — you can opt out from Settings;
- Detect and prevent abuse, fraud, and Terms violations.
3. AI Processing
Your chat messages and spending reflections are sent to our AI providers (Letta AI and GLM / Zhipu) for generating personalized responses. Each user has an isolated Letta Agent — your conversation memory is not shared with other users. The AI provider may temporarily process your data in memory to generate responses, but does not use your data for training their models (per Letta AI and Zhipu's enterprise agreements with us).
We inject relevant context (your recent challenges, hourly rate, blind-spot insights) into the AI prompt to make responses more personalized. This context is sent over HTTPS and not persisted on the AI provider's servers beyond the response generation window.
4. Data Storage & Security
Data is stored in Supabase (PostgreSQL, hosted in regulated cloud regions) with Row-Level Security (RLS) enabled. RLS ensures you can only read and write your own data — even Symy engineers cannot read individual user chats without explicit authorization. AI conversation history is stored in Letta's managed infrastructure, isolated per user agent.
Email credentials (if you connect email monitoring) are encrypted with AES-256 at rest and TLS 1.3 in transit. Access to decryption keys is restricted to a small number of authorized services, not individual engineers.
Authentication tokens (session JWTs) are stored in HTTP-only cookies (not localStorage) to reduce XSS risk. We use Supabase Auth's PKCE flow for OAuth.
5. Data Retention
Your data is retained as long as your account is active. An account is considered inactive after 24 months of no login activity; we will notify you before deleting inactive accounts. You can request a data export or account deletion at any time from Settings → Account. Your guardian records — challenge outcomes and Dream Fund deposits — remain yours. Account deletion removes all your data (including chat history, Dream Funds, blind-spot map) within 30 days. Some anonymized aggregate statistics may be retained for product improvement (e.g. "average user saves $X/month") — these cannot be linked back to you.
Letta AI retains conversation memory until you delete your account or clear agent memory. Sentry retains error events for 90 days, then automatically deletes them.
6. Your Rights (GDPR / CCPA / PIPL)
Depending on your jurisdiction (EU GDPR, California CCPA, China PIPL), you have the right to:
- Access — request a copy of all data we hold about you;
- Delete ("right to be forgotten") — request erasure of all your data;
- Correct — fix inaccurate data (e.g. wrong hourly rate, misspelled name);
- Object — object to specific processing activities (e.g. AI personalization);
- Data portability — receive your data in a machine-readable format (JSON);
- Withdraw consent — withdraw consent for email monitoring, AI processing, or marketing communications at any time.
To exercise these rights, use the in-app data export / deletion tools (Settings → Account) or email support@symy.ai. We respond to verified requests within 30 days (GDPR) or 45 days (CCPA).
7. Cookies & Local Storage
We use essential cookies for authentication (Supabase Auth session tokens, stored as HTTP-only cookies). We do not use third-party tracking cookies, advertising cookies, or analytics cookies that identify you across sites. We use localStorage for: language preference, theme (dark/light), referral code (until you sign up), and a streak-protected flag. We do not use localStorage for sensitive data.
8. Children's Privacy
The Service is not intended for users under 13 (or the age of digital consent in your jurisdiction, e.g. 14 in some EU countries). We do not knowingly collect data from children. If a parent or guardian believes their child has provided personal data, they can request immediate deletion at support@symy.ai. We will delete the data within 7 days of verification.
9. International Data Transfers
Your data may be processed in countries other than your own (e.g. Supabase servers in US/EU, Letta AI in US, GLM in China). We only transfer data to countries with adequate data protection laws (e.g. EU adequacy decisions) or under standard contractual clauses (SCCs) approved by the relevant regulator. For users in mainland China, we comply with PIPL cross-border transfer requirements.
10. Third-Party Services
We use the following third-party services, each with their own privacy policies:
- Supabase — authentication and database (data hosted in regulated regions);
- Letta AI — AI agent infrastructure (conversation memory, isolated per user);
- GLM / Zhipu — AI model inference (no training on your data, per enterprise agreement);
- Sentry — error monitoring (PII scrubbing enabled, 90-day retention);
- Vercel — hosting and edge network;
- Google APIs (if you connect Gmail) — email scanning for receipts, per Google's API Limited Use policy.
We do not sell your data to third parties. We do not share your data with advertisers.
11. Data Breach Notification
In the event of a data breach that poses a risk to your rights or freedoms, we will notify you via email within 72 hours of becoming aware of the breach, in accordance with GDPR Article 34. We will also notify the relevant data protection authority where required.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes (such as new data collection, new third-party processors, or changes to retention) will be notified via email or in-app notification at least 30 days before the changes take effect. Non-material changes (e.g. clarifications, contact info updates) take effect immediately upon posting.
13. Contact
Questions about privacy? Email us at support@symy.ai. For EU/UK data protection inquiries, you have the right to lodge a complaint with your local data protection authority.
Guard your wallet and your attention — buy a little less, live a little more.
Your data is exportable anytime — export it from Settings → Account.