Privacy Policy
Synapse is a study tool that teaches from course material you provide. This policy explains what we hold, what never leaves your device, and who else is involved. It is written to be read rather than to be survived, and if anything here is unclear we would rather you asked.
1. The short version
Your account details live on our servers. Your course material does not. Documents you upload, the slides drawn from them, your conversations with the tutor, your quizzes, flashcards and progress all stay in your browser’s local storage, or in cloud storage you connect yourself. We cannot read any of it.
2. What we store about you
When you create an account we keep your username, your email address, a one way hash of your password, and a one way hash of your recovery phrase. A hash cannot be reversed, so a copy of our database does not reveal either secret.
We also keep a record of which sign in methods you have connected, the public half of any passkey you register, your active sessions with the rough device and network they came from, your leaderboard statistics, and a daily counter of how much AI usage you have spent. None of that describes what you are studying.
If you connect your own cloud storage, the credentials are encrypted in your browser using a key derived from your recovery phrase before they reach us. We store the encrypted block and have no way to open it, because the phrase itself is never sent to us in a form we keep.
3. What stays on your device
Everything you actually study. Uploaded files, extracted slides, generated questions, flashcards, notes, chat history and what the tutor has learned about how you learn are held in your browser and are not transmitted to us for storage.
The practical consequence is worth stating plainly: clearing your browser data deletes that material, and we cannot restore it. If a document matters to you, keep your own copy or connect storage you control.
4. When your material is sent somewhere
Asking the tutor a question sends the relevant part of your material to a model provider so the model can answer from it. That is the only time your content leaves your device on our initiative, it is sent for that single request, and we do not store it afterwards.
We route those requests under a zero retention policy, which means the provider is contractually required not to keep the content or train on it. Providers may be located outside your country, so this involves an international transfer of whatever is in that request.
5. Signing in with Google
If you choose to continue with Google, Google tells us three things: a stable account identifier, your email address, and your basic profile name and picture. We ask for nothing else, and specifically we request no access to your Gmail, Drive, contacts or calendar.
We store the identifier so that signing in again resolves to the same Synapse account, and the email address so you can be contacted about your account. We do not receive or store your Google password, and we do not post anything anywhere on your behalf. You can disconnect Synapse at any time from your Google account permissions page.
6. Who else processes your data
We use a small number of services to run Synapse: a database and hosting provider to store the account records described above, a model provider to answer tutoring requests, and an email provider to send account related messages such as a welcome note or a warning that a new device signed in. Each receives only what it needs for that job.
We do not sell your data, we do not share it with advertisers, and there are no advertising or analytics trackers in the product.
7. Cookies
Synapse sets two cookies and neither is used for advertising. One is a signed identifier that lets the tutor remember you between visits. The other is your session, which is what proves you are signed in. Both are set to be unreadable by scripts, and the session is removed when you sign out.
8. How long we keep things
Account records are kept for as long as the account exists. Sessions expire on their own after thirty days, or sooner if left unused, and a revoked session stops working immediately. Sign in requests from a new device expire within minutes whether or not anyone acts on them.
9. Your choices
You can ask us for a copy of the account data we hold, ask us to correct it, or ask us to delete the account entirely along with your leaderboard entry. Because your study material is on your device, you can remove it yourself at any time without involving us.
Depending on where you live you may have further rights over your personal data, including the right to object to processing or to complain to a data protection authority. Write to us first and we will try to resolve it.
10. Children
Synapse is not directed at children under 13, and we do not knowingly create accounts for them. If you believe a child has registered, tell us and we will remove the account.
11. Changes
If we change this policy in a way that materially affects you, we will say so before the change takes effect and update the date at the top of this page.
12. Contact
Questions about privacy, or a request about your data, can go to privacy@synaspe.space. We answer questions about data handling before anything else in the inbox.