Last updated: June 21, 2026
Your privacy matters. This policy explains what data Synaptic collects, how we use it, and the rights you have over your information.
We collect only what's needed to provide Synaptic. We don't sell your data, we don't train AI models on your conversations, and you can delete everything at any time.
When you create an account, we collect your email address, username, and encrypted password. If you sign in with Google or GitHub OAuth, we collect your name, email, and profile picture from those providers.
To provide the core service, we store the messages you send and responses you receive from AI models. This includes any files, images, or documents you upload.
Synaptic's persistent memory feature extracts and stores facts and context about you from your conversations (e.g. your role, preferences, ongoing projects). These memories are encrypted and accessible only to you.
When you connect integrations (Google, Slack, Notion, MCP servers), we store OAuth tokens encrypted at rest using Fernet symmetric encryption. We only access data on your behalf when you explicitly ask the AI to do so.
We log basic technical data for operations: API call counts, error rates, model usage, and feature usage. This helps us maintain service quality and detect abuse.
If you bring your own API keys (OpenAI, Anthropic, etc.), they are encrypted with Fernet before storage. We never log them in plaintext or share them with any third party.
We do not train AI models on your conversations. We do not sell your data to third parties. We do not show you ads. We do not share your data with advertisers, data brokers, or marketing companies.
Synaptic uses third-party services to deliver core functionality. Each service receives only the data needed to perform its function.
When you use a model (GPT-4o, Claude, Gemini, etc.), your message is sent to the relevant provider (OpenAI, Anthropic, Google, etc.). Each provider has its own data policies — most do not train on API requests by default. With BYOK, your data goes directly to the provider under your own account.
If you connect them: Google (Gmail/Drive/Calendar), Slack, Notion, GitHub, and any MCP-compatible server. You control which integrations are enabled.
You have full control over your data:
We retain your data while your account is active. When you delete your account, all personal data, chats, memories, and integrations are permanently removed within 30 days. Backups containing your data are purged within 90 days.
Synaptic uses essential cookies to keep you signed in (JWT session tokens). We do not use tracking or advertising cookies. We use privacy-respecting analytics (Plausible) that does not require cookies.
Synaptic complies with GDPR (Europe) and CCPA (California). EU and California residents have additional rights including data portability, the right to be forgotten, and the right to object to processing. Contact us to exercise these rights.
Synaptic is not intended for users under 16 years old. We do not knowingly collect data from children. If you believe we have, please contact us for removal.
We may update this policy as our service evolves. Material changes will be communicated via email or in-app notification. The "Last updated" date at the top reflects the most recent revision.
Questions about privacy, data requests, or this policy?