SYNK

Privacy policy

This policy covers the SYNK Radio API at api.synkradio.co.uk and this documentation site at docs.synkradio.co.uk. It is plain English and short on purpose.

Last updated: 15 Sep 2026.

What we collect

When you call the API, we receive what every HTTP server receives:

  • Your IP address.
  • The User-Agent header you send, which includes the contact email you put in it.
  • The request path, query string and timestamp.
  • The response status and approximate latency.

We do not require accounts, we do not issue API keys and we do not set cookies on the API domain.

What we do with it

  • Operate the service. Logs are used to debug failures and to size capacity.
  • Enforce fair use. Rate limits are counted per IP and per email so that a single misbehaving client does not affect everyone else.
  • Contact you if something goes wrong. If your traffic pattern is going to get you blocked, the email in your User-Agent is how we reach you first. See authentication for why this is the model.

We do not sell logs, we do not share them with advertisers and we do not use them for marketing.

How long we keep it

  • Request logs, including the IP and the User-Agent (with its contact email): kept indefinitely. Unlike most services that bin logs after a few days, we keep ours so we can track long-term API health, look at year-on-year patterns and catch slow-burning problems. The legal basis is our legitimate interest in running the service, keeping it up and preventing abuse.
  • Aggregated counters (requests per route, errors per day): kept indefinitely with no identifying fields.
  • Abuse-related records, including blocked IPs and User-Agents: kept indefinitely, because a block only works if it sticks.

You can ask us to delete the logs that contain your contact email at any time. See "Your rights" below.

What we do not do

  • No tracking pixels, no analytics on the API itself.
  • No third-party scripts on this docs site beyond the font CDN that loads the wordmark.
  • No selling, renting or sharing of request data with anyone outside SYNK Radio.

Your rights

You can ask us to delete any logs that contain your contact email by sending a request to the address below. We will action it within 30 days. Because we keep logs indefinitely, this does not happen on its own: if you want your data removed, you need to ask, and we may keep records tied to a block where we have a legitimate interest in preventing further abuse.

Browsers and CORS

CORS is open on every route, but the User-Agent restriction means browser fetches will fail. Server-to-server only. Your end users never hit the API directly, so their data does not enter this system.

AI endpoints

Endpoints under /ai/ (for example /ai/is-radio-safe, /ai/track-insights, /ai/artist-summary, /ai/similar-because, /ai/lyrics-explain) run your query through a language model to generate the response.

  • We send the model only the track details it needs to answer, usually the artist name, the title and, where we have it, the ISRC. For the endpoints that reason about lyrics we also include the lyrics we already hold for that track.
  • We do not attach your IP, your User-Agent, your contact email or anything else that identifies you when we do this.
  • Responses are cached on our side so the same question does not get processed twice.
  • We do not use your queries or the answers to train, fine-tune or evaluate any model of our own.

Treat anything sent to an /ai/ endpoint as something a language model will process to build a reply. Do not send anything you would not be comfortable with that.

Contact

Privacy queries: [email protected]. Replies inside two working days.