Synapse
Privacy Policy
Synapse stores your organization's institutional memory. This policy explains exactly what we collect, why we hold it, who can process it, and how you get it back or delete it.
Last updated: September 1, 2026
1. Who we are
Synapse ("Synapse", "we", "us") provides an institutional memory and AI knowledge retrieval platform at mysynapseai.com. For customer content submitted to the service we act as a data processor; for account and billing records we act as a data controller.
Privacy contact: privacy@mysynapseai.com
2. Data we collect
- Account data — name, work email, password hash, company name, industry, company size, role and department.
- Customer content — everything you or your team put into your company brain: memories, decisions, SOPs, documents and their extracted text, client and team records, ghost-employee knowledge, and chat questions and answers.
- Derived data — vector embeddings generated from your content so it can be searched semantically.
- Billing data — plan, subscription status and billing period. Card details are entered directly with Stripe and never touch our servers.
- Technical data — authentication events, IP address, browser type and error diagnostics used to keep the service secure and available.
3. How we use it
- To operate the service: store, index, retrieve and display your company's knowledge.
- To generate AI answers grounded in your own content, with permission filtering applied before anything reaches a model.
- To authenticate users, enforce access permissions and prevent abuse.
- To process subscriptions and provide support.
- To meet legal, tax and security obligations.
We do not sell personal data. We do not use your customer content for advertising, and we do not use it to train our own or any third party's foundation models.
4. AI processing
When you ask a question, Synapse retrieves only the records your permissions allow and sends the relevant excerpts, together with your question, to our AI provider (OpenAI) to compose an answer. Content is sent over encrypted connections for the purpose of that single request. Under OpenAI's API terms, API content is not used to train their models. Document text and memories are also sent for embedding generation so they can be searched.
5. Sub-processors
- Supabase — database, authentication and encrypted file storage.
- OpenAI — AI answer generation and embeddings.
- Stripe — subscription billing and payment processing.
- Cloudflare — application hosting, delivery and DDoS protection.
We will give notice of material changes to this list. Sub-processors are bound by confidentiality and data-protection terms.
6. Data location and transfers
Data is hosted in our providers' cloud regions and may be processed in the United States and other countries where those providers operate. Where personal data leaves the EEA or UK, transfers rely on Standard Contractual Clauses or an equivalent lawful mechanism.
7. Security
Data is encrypted in transit (TLS 1.2+) and at rest. Access to company data is enforced at the database level by row-level security tied to your verified session, and privileged fields such as roles, admin status and billing plan can only be changed by our servers. File downloads use short-lived signed URLs. Full detail is on our Security page.
8. Retention and deletion
We retain customer content for as long as your account is active. You can delete individual records at any time. When an account is closed, customer content and associated embeddings and files are deleted within 30 days, except where we must keep limited billing and audit records to satisfy legal obligations. Encrypted backups age out within 90 days.
9. Your rights
Depending on where you live (including under GDPR, UK GDPR and the CCPA/CPRA), you may request access to your personal data, correction, deletion, a portable copy, restriction of processing, or object to processing. You may also opt out of the "sharing" or "sale" of personal information — a right that is trivially satisfied here because we do neither.
Email privacy@mysynapseai.com and we will respond within 30 days. If we process data on behalf of your employer, we will route your request to them as the controller. You may also lodge a complaint with your local supervisory authority.
10. Cookies
We use strictly necessary cookies and local storage to keep you signed in and to remember interface preferences. We do not use third-party advertising or cross-site tracking cookies.
11. Children
Synapse is a business product and is not directed to anyone under 16. We do not knowingly collect data from children.
12. Changes
We will update this page when our practices change and revise the date above. Material changes will be notified by email or in-app before they take effect.