Privacy Policy

What you share is used to simulate the person. Nothing more.

Effective date: August 26, 2026 · ArenaSynth, operated by Ereace

This policy explains exactly what data we process, what we store, and what we never store. It is written to be read, not to cover us.

A note on how ArenaSynth works: many counterparts require no personal data at all — you design the profile (role, sector, traits) and the engine generates the person. Providing source material is only needed when you want to simulate a specific real person, and that material can be anything you choose to share — a CV, a professional bio, your own notes. The rules below apply whenever you do.

The short version

What we process, and what happens to it

1. Profile text (CV, LinkedIn text, professional bio)

When you create a counterpart from a CV, the text you paste is sent — over TLS, in memory — to an AI language model that infers a psychometric profile (Big Five, Schwartz values, attachment style). On our side the text is then discarded: it is not written to our database, not retained in logs, and not sent to our persona simulation engine.

The inference step is performed by third-party AI model providers, which process the text to return the profile and may operate outside the EU under their own API terms. We may change the specific provider at any time. If you prefer not to have a given text processed this way, do not paste it — the archetype-based counterpart flow does not require any profile text.

2. The derived profile (what we actually store)

From the text we keep only: the psychometric vector (numeric scores), an inference confidence summary, and basic profile attributes the text states explicitly (such as name, age, gender, profession). These form the synthetic counterpart you practice against.

The vector and demographic attributes — never the original text — are sent to our persona simulation engine (StrataSynth, also EU-hosted, operated by Ereace) to generate the counterpart. Counterparts expire automatically (default: 30 days) and you can delete them at any time from the app.

3. Business context (optional)

If you provide situational context for a counterpart (deal background, role pressures), we store it with the counterpart so the simulation can use it. Delete the counterpart and it goes with it.

4. Simulation sessions

Conversation transcripts of your practice sessions and the post-session analysis are stored so you can review and compare sessions. They belong to your account and are not shared with other users.

9. Payments (only if you subscribe to a paid plan)

Paying is optional: the free plan needs no card. If you do subscribe, payments are handled by Stripe Payments Europe, Ltd., acting as our processor.

We never see or store your card number — it goes from your browser to Stripe. What we keep is a Stripe customer identifier, the subscription status and the plan.

Stripe processes your email, your billing name and address, and your VAT or tax ID when you provide one, because an invoice legally requires them. Stripe is a global company and may process data outside the EEA; that transfer is covered by Stripe's Data Processing Agreement and the European Commission's Standard Contractual Clauses.

Invoices are kept for as long as tax law requires. This is the one thing that survives deleting your account: we are legally obliged to keep it, and the right to erasure does not reach a record the law requires us to hold. Everything else about your account is deleted.

5. Account data

Your API key identity and usage data needed to operate the service. Authentication tokens live only in your browser's memory — never in localStorage or cookies.

6. Product analytics (how the platform is used)

We record which screens you open and which actions you take inside the app — for example “a session was started”, “an analysis was requested”, “the follow-up wizard was opened” — together with your user ID, the screen path and simple numbers such as how many turns a session had.

Three things this deliberately does not include: the content of your conversations, anything you type, and any name or free text. Event names come from a closed list and their properties can only be numbers or true/false values, so this data cannot become a store of your text even by mistake.

We use it to see where people get stuck and to improve the product; it is our own first-party data and is not shared with anyone. These events are deleted automatically after 180 days by the database itself — not by someone remembering to clean up.

7. The free rehearsal at /try (no account)

You can have a full rehearsal without signing up. Because there is no account, this is what happens instead.

We do not ask you for anyone's data. The counterpart in the free rehearsal is pre-built by us and is always the same. You never paste a CV, a name, or information about a real person — so nothing about a third party is processed at all.

We do not store your IP address. To stop one connection from using the free rehearsal endlessly, we count how many you have started today, against a one-way hash of your IP combined with a secret we hold — never the address itself. That counter deletes itself after three days. This anti-abuse counting rests on our legitimate interest in keeping a free service available.

What you type is processed to give you the rehearsal you asked for: it goes to our persona simulation engine (StrataSynth, EU/Ireland, operated by Ereace) so the counterpart can reply. As everywhere else in the product, the AI inference behind that reply is performed by third-party model providers that may operate outside the EU.

The whole conversation is deleted automatically two hours after it starts. Not archived, not anonymised for later use: removed. We do not need it, so we do not keep it.

The report you get is computed, not written by a model: the signals it shows are counted directly in the words you used. And if you later create an account, that is a separate step with its own data — nothing from the free rehearsal is carried over or linked to it.

8. The waiting list (optional, and only if you type your email)

At the end of the free rehearsal you can leave an email address to be told when ArenaSynth opens. It is optional and nothing else on the page depends on it.

We keep only the address and, if you pick one, the area of work you are interested in — chosen from a fixed list. There is no free-text field on that form, by design: we do not want you telling us about a real colleague, and we do not want to hold that.

We use it for one thing: to write to you about ArenaSynth becoming available. Not for newsletters, not for anything else, and it is never shared or sold. Leaving your address is your consent to be contacted for that purpose, and you can withdraw it at any time.

Ask us to remove it and it is gone, at the address in “Your rights” below. You do not need an account to ask.

7. Voice mode (optional, off by default)

Voice mode is a deliberate choice. It is disabled unless you switch it on for a session, and everything below happens only after you do. Practice sessions work fully in text, so declining costs you nothing but the microphone.

What you say: your microphone audio is sent over TLS to our servers and forwarded to a third-party speech-to-text provider, which returns the text of what you said. The audio is then discarded — not written to our database, not stored in a file, not retained in our logs.

What the counterpart says: its reply is sent to a third-party speech synthesis provider, which returns audio that is played to you and then discarded. The counterpart's voice is synthetic — it is not a recording of a real person, and it is not cloned from anyone's voice.

What we keep: only the text of the conversation, exactly as if you had typed it (covered in point 4 above). No audio, in either direction, is ever stored.

These speech providers act on our instructions and may operate outside the EU under their own API terms, and we may change the specific provider at any time. If that is not acceptable to you, leave voice mode off — it is off unless you turn it on, and the product does not need it. Turning it off stops any further processing immediately, and there is nothing to delete afterwards because nothing was kept.

Your responsibility when pasting someone else's CV

You may use ArenaSynth to simulate a real counterpart — for example, a person you will negotiate with. If you paste text about another person, you confirm you are lawfully entitled to use it (for instance, publicly available professional information used for legitimate preparation). The same guarantees apply: the text is never stored, only the derived profile, which you can delete.

What we never do

Who we are (data controller)

ArenaSynth is operated by Ereace (a sole trader; full registered details will be published once incorporated). Infrastructure hosted in the EU (Ireland). Contact: hello@arenasynth.com.

Legal bases (GDPR art. 6)

How long we keep data

International transfers

Our core infrastructure is in the EU. Some processing — AI inference and analytics — may involve providers outside the EEA; those transfers rely on Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework. We are working to move AI inference to EU-hosted models to remove the transfer.

Processors we rely on

Cookies

We use only necessary cookies plus Google Analytics, and analytics loads only after you consent. You can change or revoke your choice anytime via “Cookie settings” in the footer. Full detail in our Cookie Policy.

Your rights (GDPR)

You have the right to access, rectification, erasure (“right to be forgotten”), objection, restriction and portability, and to withdraw consent at any time. In practice: deleting a counterpart removes its derived profile; deleting your account removes everything tied to it. You can also request erasure by email. Contact: hello@arenasynth.com (we respond within the legal time limit, one month, extendable).

If you believe the processing is not lawful, you may lodge a complaint with your data protection authority — in Spain, the Agencia Española de Protección de Datos (AEPD, www.aepd.es).

Changes

If we change how data is processed — a new provider category, a new stored field — we update this policy and its effective date before the change goes live.