Privacy policy

Last Updated: June 8, 2026

How to read this policy

Syntaxa builds developer tools that analyze source code. Section 6 below describes, in plain terms, what actually happens to your code when you run our products — including the fact that our primary deployment model (the Setsumei CLI) performs analysis entirely on your own infrastructure. If you only read one section before a security review, read that one.

Security Review Summary

Customer owns code. Syntaxa never claims ownership of Customer Content. Code stays on customer infrastructure under Setsumei’s primary (local CLI) deployment model. Scan results and findings stay on customer infrastructure under that same model. Syntaxa receives only limited operational telemetry — never source code, findings, or repository contents. AI-assisted steps use only the minimum context required for that specific step. Syntaxa does not train public or general-purpose foundation models on Customer Content without express authorization.

See Sections 5 and 6 for the full detail behind each of these statements.

1. Introduction

Syntaxa LLC (“Syntaxa,” “we,” “our,” or “us”) builds software that helps engineering teams understand, evaluate, and verify software systems. Our primary product is Setsumei, a static analysis and architecture intelligence engine, together with related offerings, websites, and documentation (collectively, the “Services”). Syntaxa is also developing additional products, including an AI agent behavior verification offering, which are referenced where relevant below.

This Privacy Policy explains what information we collect, how we use and disclose it, how long we retain it, and the choices and rights available to you. It applies whether you are evaluating Syntaxa as a prospective customer, participating in a pilot, using the Services under a paid agreement, or simply visiting our website.

Because Syntaxa’s products are developer tools that, by design, can process source code, this policy pays particular attention to how that code is handled — including the deployment models in which it never leaves your infrastructure at all.

By accessing or using the Services, you agree to the practices described in this Privacy Policy. If you are using the Services on behalf of an organization, you represent that you are authorized to accept this policy on that organization’s behalf, and references to “you” include that organization where the context requires.

2. Scope

This Privacy Policy applies to:

  • syntaxa.ai
  • setsumei.dev
  • Any other website, product, API, CLI tool, or application that we operate and that links to this Privacy Policy

This Privacy Policy does not apply to third-party websites, products, or services that may be linked from our Services, including any AI model providers, cloud infrastructure providers, or open-source tools that you separately choose to use. We encourage you to review the privacy practices of any third party before sharing information with them.

However, certain third-party providers, such as forms.app, may process information submitted through our Services on our behalf as service providers. Such processing is governed by our agreements with those providers and this Privacy Policy.

Where a customer agreement (such as a pilot agreement, order form, or master services agreement) contains data processing terms that conflict with this policy, the customer agreement governs for that customer’s use of the Services.

3. Information We Collect

3.1 Account and Business Contact Information

When you create an account, join a waitlist, register for a pilot, or otherwise engage with us commercially, we may collect:

  • Name
  • Business email address
  • Organization name and job title
  • Account credentials and authentication information
  • Information you provide in pilot agreements, NDAs, or onboarding forms

3.2 Website Information

When you visit our websites, our servers and analytics tools may automatically collect:

  • IP address and approximate location derived from it
  • Browser type and version, device type, and operating system
  • Referring URLs and pages visited
  • Session duration and general interaction information (e.g., pages viewed, links clicked)

3.3 Product Usage Information

When you use the Services, we may collect information about how the software is used, separate from the content it analyzes:

  • Feature usage and command invocation metrics
  • Diagnostic, performance, and error information
  • CLI version, installation environment (OS/architecture), and configuration settings unrelated to your codebase
  • API activity and authentication events

For the locally executed Setsumei CLI, product usage information is limited to the operational telemetry described above and does not include your source code, scan findings, or repository contents unless you explicitly choose to share them with us (for example, by sending us a bug report that includes a code snippet).

3.4 Customer Content

Depending on which Services you use and how you deploy them, we may process information that you or your organization provide for analysis, which we refer to collectively as “Customer Content.” This may include:

  • Source code, repositories, and version history
  • Dependency information, build manifests, and CI/CD configuration
  • Documentation and architecture metadata
  • Scan findings, smell vectors, AI investigation agent outputs, decision briefs, and other generated reports

As Syntaxa brings additional products to market, this section will be expanded to describe any new categories of Customer Content those products process. Any such update will be reflected in a revised “Last Updated” date.

Section 6 explains how Customer Content is handled, including the deployment models in which it is never transmitted to Syntaxa at all.

3.5 Communications

We may collect information you provide through:

  • Contact forms, sales inquiries, and pilot or demo requests
  • Support requests and related correspondence
  • Waitlist and event registrations
  • General email correspondence with our team

Forms and Lead Capture Services

We use a third-party form management provider, forms.app, to collect information submitted through contact forms, demo requests, waitlists, assessments, surveys, and similar forms available on our websites. Information submitted through these forms may include your name, email address, organization name, job title, responses you provide, and any other information you choose to submit.

forms.app processes this information on our behalf for the purpose of delivering submissions, managing inquiries, generating leads, and supporting our business operations.

4. How We Use Information

Provide the Services

  • Deliver, operate, and support the Services
  • Perform static analysis and generate smell vectors, findings, and decision briefs (Setsumei)
  • Support evaluation of AI agent behavior for customers piloting related Syntaxa offerings
  • Authenticate users and process transactions

Improve the Services

  • Diagnose and fix errors
  • Monitor performance and reliability
  • Develop new features and language/framework support
  • Improve detection accuracy and reduce false positives, consistent with Section 5

Communicate With You

  • Provide customer and pilot support
  • Respond to inquiries
  • Send service notifications, security alerts, and administrative communications
  • Share product updates, with an option to opt out of non-essential communications

Security, Trust, and Compliance

  • Detect, investigate, and prevent fraud or abuse
  • Protect the integrity and security of our systems and the systems of our customers
  • Enforce our agreements and terms of service
  • Comply with applicable legal obligations

5. AI and Automated Processing

Syntaxa’s products are built on a deliberate architectural principle: deterministic analysis comes first, and AI-generated explanation comes second. We believe this distinction matters enough to disclose plainly.

5.1 How AI Is Used in Setsumei

Setsumei’s core analysis — graph-based static analysis and the computation of smell vectors across security, complexity, reliability, maintainability, and performance categories — is performed using deterministic, rule- and graph-based methods, not AI inference. An AI investigation agent is layered on top of that deterministic output to verify or dismiss specific findings and to help generate human-readable explanations and decision briefs. The AI investigation agent does not independently originate findings; it evaluates findings that the deterministic engine has already produced.

5.2 General AI Disclosures

  • AI-generated outputs (including investigation agent conclusions, summaries, and recommendations) may contain inaccuracies, omissions, or errors.
  • Outputs are intended to assist, not replace, professional engineering judgment, and we recommend human review before relying on any AI-generated finding or recommendation in a decision with material consequences.
  • Syntaxa does not guarantee the accuracy, completeness, or fitness for a particular purpose of any AI-generated output.

Syntaxa does not use Customer Content to train public or general-purpose foundation models without your organization’s express authorization.

Where our AI investigation agent or other AI-assisted features rely on a third-party model provider (for example, to generate explanatory text from deterministic findings), Customer Content necessary to produce that specific output may be transmitted to that provider as a processor acting on our instructions, subject to the deployment-model limitations described in Section 6 and any contractual restrictions your organization has put in place.

6. Repository and Source Code Processing; Deployment Models

This is the section most relevant to engineering, security, and procurement teams evaluating Syntaxa, and we have written it to be read on its own.

6.1 You Own Your Code

Customers represent that they have the necessary rights and permissions to provide repositories, source code, documentation, configuration files, and related materials for analysis. Unless otherwise agreed in writing:

  • Customers retain full ownership of their Customer Content.
  • Syntaxa does not claim any ownership interest in Customer Content.
  • Syntaxa processes Customer Content only as necessary to provide the Services your organization has requested.

6.2 Setsumei’s Primary Deployment Model: Local CLI Execution

Setsumei’s primary deployment model today is a command-line tool that customers install and run within their own infrastructure (we refer to this internally as the local CLI deployment). In this model:

  • Static analysis, smell vector computation, and AI investigation agent processing all execute on infrastructure that you control — your laptop, your build server, or your private network.
  • Your source code, repository contents, and generated scan results are not transmitted to Syntaxa-operated servers as part of the scanning process.
  • Where the AI investigation agent step requires a call to a third-party model provider to generate explanatory text, the specific content sent for that step is the minimum necessary for that step, configurable in supported deployments, and is not retained by Syntaxa afterward; it is still subject to that provider’s own processing, which we describe further to customers under NDA or in a Data Processing Addendum where applicable.
  • Limited operational telemetry may be sent back to Syntaxa to support license validation, error reporting, and product improvement. Specifically, this telemetry is limited to: CLI version number, operating system and architecture, anonymized error codes, and license/authentication validation events.
  • This telemetry never includes: source code, repository contents, file names or paths from your codebase, scan findings, smell vectors, or decision brief content.

In plain terms: in our current pilot deployment model, your code stays on your infrastructure. Scan results, findings, and decision briefs are generated and stored locally unless and until you choose another deployment model.

6.3 Other Deployment Models

As Syntaxa’s product offerings expand, we expect to support additional deployment models, which may include:

  • Self-hosted or private cloud deployments, where Customer Content remains within infrastructure you control or designate
  • On-premises deployments
  • A Syntaxa-hosted Decision Workspace or software-as-a-service offering, for customers who choose to sync scan results, annotations, and resolutions to infrastructure operated by Syntaxa

Where a deployment model involves Syntaxa hosting or storing Customer Content, this Privacy Policy and the applicable customer agreement will govern that processing, and we will provide clear notice of what is collected, why, and for how long before any such offering becomes generally available. This policy reflects our currently available deployment models as of the date above; we will update it as new products and deployment models ship.

6.4 Data Processing Addendum

Enterprise customers with specific data processing, security review, or regulatory requirements may request a Data Processing Addendum (DPA) by contacting [email protected]. A DPA can supplement this policy with terms specific to your organization’s deployment, including sub-processor lists and audit rights where applicable.

7. Legal Bases for Processing

Where required by applicable law (including the EU/UK GDPR), we process personal information on one or more of the following legal bases:

  • Performance of a contract with you or your organization
  • Our legitimate business interests, such as securing and improving the Services, balanced against your rights
  • Compliance with a legal obligation
  • Protection of vital interests or the rights, property, or safety of Syntaxa, our customers, or others
  • Your consent, where consent is the applicable basis (for example, certain marketing communications), which you may withdraw at any time

8. Sharing Information

We do not sell personal information. We may share information in the following circumstances:

Service Providers

We work with third-party providers that support:

  • Cloud hosting and infrastructure
  • Security and fraud prevention
  • Analytics
  • Authentication
  • Customer support tooling
  • AI model inference, limited to the specific outputs described in Section 5 and subject to the deployment-model boundaries in Section 6
  • Form hosting and submission processing services (including forms.app)

These providers are authorized to use information only as necessary to provide services to us and are bound by appropriate confidentiality and data protection obligations.

When you submit information through a form hosted or embedded on our websites, that information may be processed by forms.app as a service provider acting on our behalf. For more information about forms.app’s privacy practices, please refer to their forms.app Privacy Policy.

Corporate Transactions

We may disclose information in connection with a financing, investment transaction, acquisition, merger, or sale of assets, including during due diligence, subject to appropriate confidentiality protections.

Legal Requirements

We may disclose information where we believe in good faith that disclosure is required to comply with law, protect our rights or the rights of others, respond to a lawful request from public authorities, or enforce our agreements.

9. Data Retention

We retain information only for as long as reasonably necessary to provide the Services, maintain security, resolve disputes, comply with legal obligations, and enforce our agreements. Retention periods vary depending on:

  • The category of data (for example, account information versus Customer Content)
  • The terms of your specific customer or pilot agreement
  • The deployment model in use — for locally executed Setsumei CLI deployments, scan data and findings are retained on your infrastructure under your own retention policies, not ours
  • Applicable legal requirements

Where Syntaxa does hold Customer Content (for example, content voluntarily shared in a support request, or content processed under a hosted deployment model you have selected), we will delete or anonymize it in accordance with the retention schedule set out in the applicable customer agreement, or upon a reasonable deletion request where no such schedule applies.

10. Security

We maintain administrative, technical, and organizational safeguards designed to protect information against unauthorized access, disclosure, alteration, and destruction, which may include encryption, access controls, audit logging, network protections, authentication controls, and monitoring systems.

No security measure can guarantee absolute security, and we encourage customers evaluating Setsumei’s local CLI deployment to treat infrastructure-level security — since analysis occurs on your own systems — as governed primarily by your own security controls, with Syntaxa’s safeguards applying to the limited telemetry and account data we do hold.

11. International Data Transfers

Information may be processed in the United States and other countries where Syntaxa or its service providers operate. Where required by law, we use appropriate safeguards (such as standard contractual clauses) for international transfers of personal information.

12. Privacy Rights

Depending on your location, you may have the right to:

  • Access the personal information we hold about you
  • Correct inaccurate information
  • Delete your information, subject to legal and contractual exceptions
  • Restrict or object to certain processing
  • Receive a portable copy of your information
  • Withdraw consent, where processing is based on consent

Requests may be submitted to [email protected]. We may need to verify your identity before fulfilling a request. If your organization’s Customer Content is processed entirely within infrastructure your organization controls (Section 6.2), requests concerning that content should generally be directed to your own organization’s data administrator, as Syntaxa may not hold a copy.

13. Children’s Privacy

The Services are intended for business use and are not directed to, and may not be used by, individuals under the age of 18. We do not knowingly collect personal information from children.

14. Changes to This Policy

We may update this Privacy Policy from time to time, including as our deployment models, product architecture, and AI processing practices evolve. The “Last Updated” date above reflects the most recent revision. Material changes affecting how we handle Customer Content will be communicated to active customers in addition to being reflected here.

15. Contact Information

Syntaxa LLC

San Jose, California, United States

[email protected] | [email protected]