Official notice · Effective 30 July 2026

Privacy & GDPR Notice

This notice explains how Synderesis processes personal data when you use synderesis.eu, create an account, manage API keys, or call the Synderesis service. It is written for clarity; it is still a legal notice, not marketing copy.

Controller: Synderesis, the operator of synderesis.eu

Privacy contact: hello@synderesis.eu

Data Protection Officer: no DPO has been appointed at this stage; use the privacy contact above.

Related reading: Resources · Catholic AI FAQ · Home

1. Data we process

Account dataEmail address and, if supplied, name and organisation. We retain an irreversible password hash, never the password itself.
Waitlist and Beta invitationsWe retain waitlist join and update times. For email-bound invitations, we retain issue, preparation, operator-recorded sent, and claim times plus one-way hashes of the invitation code and email address. For one-time transferable Beta codes, we retain a code hash, a non-secret prefix, lifecycle times, and—until account deletion—the account identifier that claimed the code. Authenticated administrators receive plaintext codes only in transient no-store responses for out-of-band delivery; plaintext codes and invitation messages are not stored in the application database.
Security credentialsHashed browser-session identifiers, CSRF-protection values, API-key hashes, key prefixes, status, and expiry information. A plaintext API key is displayed only when created.
Service contentQuestions, instructions, source references, model responses, and conversation identifiers you send. Stored conversation content is retained only when the relevant request enables conversation storage.
Browser-local chat historyThe dedicated chat page can keep up to 20 completed text conversations in this browser's local storage. Each chat retains the newest complete user-and-assistant pairs within 100 messages and 100,000 text characters. A further 2,500,000-character serialized-storage limit across chat records may remove older chats. A bounded manifest of official and public web sources actually cited in an assistant response may be stored with that response so citations can be reopened and exported as a reading list. Uploaded files, filenames, extracted content, and uploaded-document citation metadata are never included. Ghost mode creates no saved chat.
Model contextThe full retained browser transcript is not sent wholesale with each request. The browser sends only the newest complete context within 12 messages and 12,000 text characters, together with the current question and any other context you explicitly enable or attach for that reply.
Task modeAnswer is the default. If you select Task in Spark or Pro, Synderesis runs a bounded read-only loop with no more than six controller decisions and four tool calls. The only tools are official-source search and, when you enable it, the fixed public-web search path. Task has no shell, arbitrary URL or file fetch, repository browser, or controller-selected provider tool. Task observations are request-scoped and are not added to saved conversation history.
Individual memoryIndividual memory is off by default. If you enable it, explicit preferences you ask Synderesis to remember and entries you add or edit are kept in this browser's local storage. Enabled entries are sent as bounded context with later requests but are not written to the Synderesis conversation database.
Organizational memoryAn administrator may manually assign your customer account to an organizational-memory group and maintain shared text entries for that group. Membership is based on an explicit server-side assignment, not the organization name entered in your public account profile.
Source and web-search dataOfficial-source settings and web-search choices are sent with a request. Web search is off by default. If you enable it, ordinary Answer mode sends one whitespace-normalised, at-most-2,000-character form of the current question through the fixed Exa-backed search path. Task may make up to four bounded queries derived from your request and prior request-scoped Task observations. Neither mode appends prior chat history, individual or organizational memory, attachments, uploaded filenames or content, document citation locations, or device/geolocation data to a web-search query. Anything you type in the current question can influence the query. When suitability review is enabled, each result batch is reviewed separately; the final deduplicated web evidence is capped at five records.
GitHub connectionIf you connect GitHub for Spark or Pro, we retain your GitHub user ID and login, the approved App installation ID, connection status, token expiries, and an encrypted OAuth token bundle. Repository, ref, and path choices remain only in the current browser tab. For each request where you enable the connection, Synderesis fetches only the exact selected bounded text files and passes them as untrusted model context. Raw repository bytes, names, paths, and transient file citations are request-scoped and are not directly added to saved chat records, memories, shares, downloads, or the Synderesis conversation database. Model output may reproduce repository material, and completed assistant text can then be saved in browser history or explicitly shared or downloaded by you.
Bring-your-own model keyIf you save an OpenRouter API key for Spark or Pro, Synderesis validates it with OpenRouter and stores only its last four characters plus an AES-256-GCM encrypted credential envelope. The plaintext key is not returned, placed in browser storage, or included in a chat request body. You choose whether it is session-scoped or remembered and separately opt in before using it for Catholic chat requests. Your key may fund selected-tier Answer calls and Task controller and final-answer model calls. Web search and suitability review remain funded by Synderesis, so a request can use mixed funding.
Theme preferenceYour System, Light, or Dark choice is stored in this browser's local storage. It contains no account identifier or conversation content.
Shared conversation snapshotsOnly when you choose Share, Synderesis stores a text-only capability-link snapshot using the newest complete context within 12 messages and 12,000 text characters, not the full retained browser transcript. Anyone with that high-entropy link can read the snapshot until you revoke it or it expires. Files and all citation/source manifests, including uploaded-document metadata, are excluded.
Usage and security dataRequest time, endpoint, model, token and request counts, cost estimates, response status, latency, and limited infrastructure logs such as IP address and user agent processed by hosting providers.
Optional aggregate product analyticsOnly after you choose Accept all, Synderesis counts fixed semantic interaction categories such as page views, navigation, form submissions, named controls, coarse API outcome and duration bands, and content-free client-fault categories. These hourly aggregates contain no account, user, device, session, or request identifier and no prompt, answer, title, form value, DOM text, URL, query string, filename, repository, citation, IP address, full user agent, or exception message. Ghost mode sends none of these optional events.
Consent recordThe time at which you explicitly consented to processing sensitive information you choose to submit, including information that may reveal religious beliefs.

2. Purposes and legal bases

Providing an email address and password is necessary to create an account. Prompt content is necessary only when you ask the service to produce a response. You are not required to include sensitive personal data in a prompt.

3. Recipients and processors

We disclose data only as needed to operate the service. Current categories of recipients include cloud hosting and repository infrastructure (including Hugging Face), upstream model and inference providers selected for the Synderesis backend, and professional advisers or authorities where legally required. Prompt content may be sent to the configured model providers to generate a response.

If you are selected for Beta testing, the operational email provider or mailbox used by Synderesis processes your account email address and the invitation message, including its private email-bound code, so the invitation can be delivered. Do not forward that message or code.

If you enable web search, ordinary Answer mode sends one bounded, whitespace-normalised current-question query through OpenRouter's server-side web-search tool, which uses Exa. Task mode may send up to four bounded model-selected queries derived from your request and prior request-scoped Task observations. The feature does not append prior chat history, individual or organizational memory, attachments, uploaded filenames or content, file or citation locations, or device/geolocation data, but anything you type in the current question can influence a query. If the default suitability review remains enabled, each result batch's minimized query and bounded candidate fields—an opaque citation identifier, title, domain, and excerpt—are sent through OpenRouter to the configured review model solely to decide whether each candidate should be included. The final deduplicated web-evidence set is capped at five records. Turning review off skips that model review, but not deterministic URL, provenance, marker, citation, or final-answer checks.

If you connect GitHub for Spark or Pro, GitHub receives the installation, OAuth, identity, repository-list, and exact file requests required for the feature. Only repositories granted to the read-only Synderesis GitHub App are available. If you enable your own OpenRouter key for either tier, the context selected for the applicable Answer call or Task controller and final-answer calls—including any enabled conversation context, memory, attachments, or GitHub files—is processed under your OpenRouter account and billed there. Web search and suitability review remain Synderesis-funded, so the same request may use mixed funding. Your OpenRouter account may show the underlying billed provider and model route even though the assistant identifies in the workspace only as Synderesis Spark or Synderesis Pro.

Synderesis's browser-local and application-database retention limits do not by themselves determine an independent provider's operational, security, abuse-monitoring, backup, or legally required retention. Provider processing and retention are governed by the applicable processor arrangements, service terms, and policies. Contact us if you want current provider and transfer details before submitting sensitive content.

Where another organisation provides Synderesis to its staff, customers, or members, that organisation may be a separate controller or processor for its use of the API. Its own privacy notice may also apply.

4. International transfers

Some processors may operate outside the European Economic Area. Where personal data is transferred to a country without an EU adequacy decision, we use an applicable safeguard such as the European Commission's Standard Contractual Clauses and assess supplementary measures as required. You may request information about the safeguard through the privacy contact.

5. Retention

6. Account deletion and your rights

The account dashboard includes a self-service Delete account action. Password confirmation immediately fences access and revokes sessions, API keys, encrypted provider credentials, the encrypted GitHub connection, OAuth flows, and device grants. Application PII—including the active account profile, waitlist entry, Beta-invitation lifecycle record, usage audit details, conversation and prompt-improvement content, private shares, and unshared organizational memory—is erased in the initial deletion transaction. A claimed invitation's one-way code hash may remain after its account and email identifiers have been removed solely to prevent reuse.

Already-accepted meter units are separated into an opaque cleanup ledger before Stripe subscription cancellation and customer deletion. If a remote step fails, deletion may return HTTP 202 pending and retain only the minimal retry state needed to finish safely. After cleanup, only a one-way hashed tombstone remains locally to prevent account resurrection and billing replay.

The initiating browser clears that account's chat history, retained public-source citation records, and individual memory. Browser-local copies on another device or browser must be removed there or by clearing that site's browser data. The non-account theme preference remains until you change it or clear site data. Stripe may retain legally required billing records, including invoice and tax records. Stripe meter aggregation is asynchronous, so an immediate final invoice is not guaranteed to include usage that was just submitted.

Subject to the conditions in the GDPR, you may ask for access, rectification, erasure, restriction, portability, or object to processing based on legitimate interests. You may withdraw consent at any time without affecting processing already carried out lawfully. Contact hello@synderesis.eu. We will respond without undue delay and normally within one month.

You also have the right to lodge a complaint with the data-protection authority in the EU/EEA country of your habitual residence, place of work, or the place of the alleged infringement.

7. Security

We use transport encryption, Argon2id password hashing, hashed API keys and session tokens, authenticated encryption for connected external credentials, HttpOnly cookies, CSRF protection, rate limiting, OAuth state and PKCE controls, webhook-signature verification, access controls, and data minimisation. No internet service is risk-free; please do not submit personal data that is unnecessary for your request.

8. Cookies

Under EU rules, non-essential cookies require your consent. When you first visit, a banner lets you choose Accept all or Necessary only. You can change that choice later with the button below.

Necessary (always on when you use the feature): authenticated browser session and CSRF protection cookies for account security (about seven days, or until you sign out); and the home-page free-demo cookie synderesis_demo, used only to count your three free preview questions if you use the demo.

Optional analytics (only if you accept): Google Analytics 4 (measurement ID G-BSHNJ7NBWG) for aggregate site usage, plus Synderesis's first-party anonymous semantic interaction counters described above. Google Analytics receives only the origin and path as the page location; query strings and fragments are excluded. Optional analytics are not activated until you choose Accept all. We do not use advertising cookies or sell personal data.

Your banner choice is stored in your browser (localStorage) so we do not show the banner on every page load. The optional Synderesis interaction queue is memory-only. Choosing Necessary only, changing preferences, entering Ghost mode, or clearing site data stops optional collection and clears that queue.

9. Automated decision-making and children

Synderesis generates text using automated models, but the consumer account service does not make decisions producing legal or similarly significant effects about you. The service is not directed to children, and account holders must be at least 18 years old or have authority under applicable law.

10. Changes

We may update this notice when the service, processors, or legal requirements change. The effective date at the top identifies the current version. Material changes will be communicated through the service where appropriate.

Subscription billing and usage accounting

When subscription billing is enabled, Stripe processes hosted checkout, subscription, invoice, and tax information. Synderesis sends customer-wide accepted and advisory usage totals for billing; withheld outcomes are excluded, and browser and API-key activity are combined for the verified billing period.

Usage overages normalize Synderesis-funded provider costs to a true 50% provider-cost contribution margin. Customer-funded BYOK generation excludes the Synderesis provider-cost component but incurs the configured platform fee (25% by default) on trusted reference cost; separately funded search or review work may also remain billable. Provider routes and internal cost details are never exposed in the account page.

Account deletion immediately blocks new usage and begins remote cancellation and customer deletion. The interface continues to show deletion as pending while cleanup is incomplete. Retry and terminal writeoff records retain only opaque operational identifiers and counts, never account content or credentials; the completed local tombstone is a one-way hash used for replay safety. Stripe may retain invoice and tax records for legally required retention periods.