YOUR CODE IS YOUR BUSINESS

Privacy, plainly.

Here’s what happens when you use Syntexy.

Effective September 5, 2026

01. Your scripts

When you click “Obfuscate script” or call our API, your source code and protection settings travel over HTTPS to Syntexy’s server-side API. Our API forwards them to an external obfuscation processing service and returns the result to you. This processing is not performed locally in your browser.

Syntexy does not intentionally store source scripts, protected output, or script contents in application logs or a database. Input and output remain in your current browser tab until you clear them, reload, or leave. Uploaded files are read in your browser and are not submitted until you start obfuscation. Downloads are saved to your own device.

02. Infrastructure and processing providers

Cloudflare hosts this website and API, and the external processing service handles obfuscation. These providers receive the information required to deliver their services, including request metadata and, for the processing service, script content. Their own operational logging, retention, and privacy practices may apply. We cannot guarantee that providers never retain data.

03. Abuse prevention

We use your connection IP address to enforce request limits. Syntexy stores a time-windowed SHA-256 hash derived from that address, a request counter, and a minute timestamp in Cloudflare D1. Raw IP addresses are not stored in our application database. Counters older than 24 hours are eligible for deletion; cleanup runs when requests arrive during a scheduled cleanup minute, so actual retention may be longer during inactivity. Cloudflare may separately process connection metadata for security and operations.

04. Cookies and analytics

Syntexy does not set application cookies, use advertising trackers, or add analytics scripts. Infrastructure-level security cookies may be used by Cloudflare. We do not sell script contents or use them for advertising.

05. Use the service thoughtfully

Only submit scripts you own or have permission to process. Remove passwords, API tokens, personal data, and other sensitive information before submitting. Obfuscation is not encryption for secret storage and is not a substitute for secure server-side design.

06. Your choices

You can use the editor without submitting code. To avoid sharing code with the processing service, do not start obfuscation or call the API. Clear the editor or close the tab to remove its current contents from the interface. Keep a local copy of any code you want to retain.

07. Changes

This policy may be updated as the service changes. The effective date above identifies the current version. Review this page before submitting sensitive or business-critical work.

Back to Syntexy