Privacy, plainly.
Here’s what happens when you use Syntexy.
Effective September 5, 2026
01. Your scripts
When you click “Obfuscate script” or call our API, your source code and protection settings travel over HTTPS to Syntexy’s server-side API. Our API forwards them to an external obfuscation processing service and returns the result to you. This processing is not performed locally in your browser.
Syntexy does not intentionally store source scripts, protected output, or script contents in application logs or a database. Input and output remain in your current browser tab until you clear them, reload, or leave. Uploaded files are read in your browser and are not submitted until you start obfuscation. Downloads are saved to your own device.
02. Infrastructure and processing providers
Cloudflare hosts this website and API, and the external processing service handles obfuscation. These providers receive the information required to deliver their services, including request metadata and, for the processing service, script content. Their own operational logging, retention, and privacy practices may apply. We cannot guarantee that providers never retain data.
03. Abuse prevention
We use your connection IP address to enforce request limits. Syntexy stores a time-windowed SHA-256 hash derived from that address, a request counter, and a minute timestamp in Cloudflare D1. Raw IP addresses are not stored in our application database. Counters older than 24 hours are eligible for deletion; cleanup runs when requests arrive during a scheduled cleanup minute, so actual retention may be longer during inactivity. Cloudflare may separately process connection metadata for security and operations.
04. Cookies and analytics
Syntexy does not set application cookies, use advertising trackers, or add analytics scripts. Infrastructure-level security cookies may be used by Cloudflare. We do not sell script contents or use them for advertising.
05. Use the service thoughtfully
Only submit scripts you own or have permission to process. Remove passwords, API tokens, personal data, and other sensitive information before submitting. Obfuscation is not encryption for secret storage and is not a substitute for secure server-side design.
06. Your choices
You can use the editor without submitting code. To avoid sharing code with the processing service, do not start obfuscation or call the API. Clear the editor or close the tab to remove its current contents from the interface. Keep a local copy of any code you want to retain.
07. Changes
This policy may be updated as the service changes. The effective date above identifies the current version. Review this page before submitting sensitive or business-critical work.
Back to Syntexy