Synthetic Audience

Privacy Policy

Synthetic Audience — 1000heads Australia Tech Team

Last updated: 1 August 2026

This policy explains what personal information Synthetic Audience collects, why, and how it is handled. It covers both the Synthetic Audience web application (synth-aud.1000headsdev.com) and the Synthetic Audience — Benchmark Capture Chrome extension that works alongside it.

1. Who we are

Synthetic Audience is an internal tool built and operated by 1000heads. It is not a public product — access is restricted to 1000heads staff and is not offered to the general public or to clients directly.

2. Who this applies to

Synthetic Audience is an internal workplace tool. Sign-in is restricted to @1000heads.com accounts via Microsoft or Google single sign-on, so everyone whose data is processed by the platform is a 1000heads staff member acting in their working capacity. This policy does not apply to members of the public.

3. What we collect

3.1 Account & sign-in data

When you sign in via Microsoft or Google, we receive and store your name, work email address, profile photo/avatar, the identity provider used, and the time of your most recent login. We never see or store your Microsoft or Google password.

3.2 Usage & security audit data

Security-relevant actions — signing in, impersonation, sharing/permission changes, API key rotation, and similar — are written to an append-only audit log (retained 365 days) so we can investigate misuse and satisfy basic accountability requirements. Session records also capture your browser's IP address and user-agent string for the duration of your session.

3.3 Content you create or upload

The platform stores the audiences, evaluation jobs, and creative content (images, video, copy) you create or upload for evaluation. Synthetic personas are AI-generated fictional profiles — they do not represent, and are not derived from, real individuals. Any real people appearing in creative content you upload (e.g. a photo in an ad) are that content's subject matter, not data we collect about you.

3.4 Optional product analytics

We use PostHog for internal product analytics, but only when the analytics_posthog feature is switched on for the platform and for your account (default: off). When active, we identify you by your account ID and record your display name, SSO provider, and role — your email address is deliberately excluded, and session recording is disabled. Analytics data is processed in PostHog's EU region.

3.5 Chrome extension — Benchmark Capture

The Benchmark Capture extension is a separate, optional tool for staff who want to feed real social performance data into the platform. It only requests the browser permissions it needs:

  • Instagram and LinkedIn (read-only, on-page): while you are viewing one of your own published posts or its analytics, the extension can read the post's media, caption, and visible engagement stats (likes, comments, shares, saves, reach/impressions) directly from the page.
  • The Synthetic Audience app: the extension sends captured data to synth-aud.1000headsdev.com using your existing, authenticated app session — the same account and session as the web app, nothing separate.
  • Local storage: the extension stores only the app's base URL and minor UI state on your device. It does not store your credentials.

Nothing is sent automatically. Every capture is shown to you in a review screen first — you confirm (or edit) the fields before anything leaves your browser. The extension does not read your browsing history, cookies, or any page outside Instagram, LinkedIn, and the Synthetic Audience app, does not use tabs or webRequest permissions, and does not run remote code.

4. Why we process this data

We rely on our legitimate interest in operating a secure, working internal tool for your employer, and on the data being necessary to perform your role as a 1000heads employee using the platform. We use the data to:

  • authenticate you and enforce access control;
  • operate, secure, and troubleshoot the platform;
  • maintain an audit trail of security-relevant actions;
  • run the evaluations you request against the content you supply;
  • where enabled, understand feature usage so we can improve the product.

5. Who we share data with

We do not sell your personal information, and we do not share it for advertising purposes. We do share data with a small set of processors, strictly to run the service:

  • Microsoft / Google — as your chosen identity provider, to authenticate sign-in.
  • Amazon Web Services (AWS) — file storage (S3) and credential storage (Secrets Manager), primarily in the Sydney (ap-southeast-2) region.
  • Dreamhost — hosts the application and its database.
  • AI model providers (OpenAI, Google Gemini, Anthropic, Perplexity) — receive the content you submit for evaluation (and, if you use the extension, captured post content) in order to generate synthetic-audience evaluations. They do not receive your account profile data (name, email, etc.).
  • PostHog — only if product analytics is enabled for you (§3.4).

6. How long we keep data

Account and content data is retained for as long as your account is active. Deactivated accounts are soft-deleted (recoverable) rather than immediately erased, so a departing colleague's work isn't silently lost; a super-admin can permanently delete an account and its data on request. Security audit log entries are retained for 365 days.

7. Security

All traffic to the app and the extension is encrypted in transit (HTTPS/TLS). Provider API keys and other secrets are stored in AWS Secrets Manager, never in application code or config. Access within the platform is controlled by role- and ownership-based permissions, and security-relevant actions are logged (§3.2).

8. Your rights

You can ask us to access, correct, export, or delete the personal information we hold about you, or object to a particular use of it. As an internal tool, the fastest route is usually your manager or the Tech Team directly — you can also email us at the address below.

9. Children

Synthetic Audience is a workplace tool for 1000heads staff. It is not directed at, and we do not knowingly collect data from, children.

10. Changes to this policy

We'll update this page if what we collect or how we use it changes, and update the "Last updated" date above accordingly.

11. Contact us

Questions about this policy, or a request relating to your data, can be sent to privacy@1000heads.com.

Synthetic Audience is operated by 1000heads. For the privacy policy covering 1000heads' public website and client-facing services, see 1000heads.com/privacy-policy.

← Back to Synthetic Audience