Security & trust
What we can see, what we can't — in plain language
No legalese wall, no vague reassurances. Here's exactly how your information is accessed, who touches it, and how long we keep it.
Last updated: 17 July 2026
Access, honestly
You grant read-only access — and only to what you choose
When you connect an account, it's read-only by default. We can look at what we need to do the work; we can't change or post anything without your sign-off.
What we can see
- The accounts you choose to connect — and only those
- The metrics and content needed to do the work you asked for
- What we produce for you, so we can show you the results
What we can't
- Anything you haven't explicitly connected
- Your passwords — we never see or store them
- Permission to change or post anything without your approval
- The right to share your data with anyone for any other purpose
You can revoke any connection at any time — from your side, instantly, with no notice to us.
Who touches your data
The companies that help run the service
We use a small set of trusted providers to run the platform. Each handles a specific job, and only the data needed for it.
Cloud & storage
Amazon Web Services — EU region (Stockholm)
Hosting & delivery
Vercel (edge/CDN)
Sign-in & accounts
Clerk — we never see your password
Database
Supabase (Postgres)
Payments
Stripe — card data never touches our servers
AI processing
Scoped to your task; named on our Subprocessors page
Every provider, its purpose and its region is named on our Subprocessors page.
How it's protected
The controls that are actually in place
No aspirational claims — just what the platform is really configured to do.
- Encrypted in transit (TLS enforced) and at rest — every storage location refuses non-encrypted connections
- Your workspace data lives in the EU (AWS Stockholm region)
- Each client's data is kept in its own access-controlled location, and every request is scoped to your account server-side
- Least-privilege access: tightly-scoped permissions, no publicly-readable storage, a hard permission boundary on every role
- Account activity is audit-logged at the infrastructure level
- We never store your passwords — sign-in is handled by our auth provider, and connected accounts are read-only
- Card payments go straight to Stripe — card data never touches our servers
Found a security issue?
We welcome responsible disclosure. Email hello@roisynth.com with the details and we'll get back to you quickly. Please give us reasonable time to fix an issue before disclosing it publicly, and don't access or alter data that isn't yours.
How long we keep things
We keep your information only as long as we need it to do the work and meet our legal obligations. Ask us to delete your data and we will, wherever we're not legally required to retain it.
How it's protected
Data is encrypted in transit and at rest. Access is scoped to the task at hand, and payment details go straight to our payment processor — they never touch our servers.
Want the full detail? Read our Privacy Policy, Terms, Subprocessors, and Cookie Notice.
Trust is earned, not assumed.
Start with a free audit — read-only, no card, no commitment. See how we work before you connect anything.
The other two questions
Anyone deciding this properly asks all three.
Results or your money back · no card required