Privacy & GDPR Notice
This notice explains how Synderesis processes personal data when you use synderesis.eu, create an account, manage API keys, or call the Synderesis service. It is written for clarity; it is still a legal notice, not marketing copy.
1. Data we process
2. Purposes and legal bases
- Provide your account, waitlist, Beta invitation and access, API access, responses, usage information, and support: performance of a contract or steps you ask us to take before entering one (GDPR Article 6(1)(b)).
- Protect accounts, prevent abuse, meter service use, diagnose failures, and establish or defend legal claims: our legitimate interests in operating a secure and reliable service (Article 6(1)(f)).
- Measure optional aggregate site and product interactions: your consent (Article 6(1)(a)), which you can withdraw through Cookie preferences. No optional interaction event is sent before consent or while Ghost mode is active.
- Process special-category information you voluntarily place in prompts or stored conversations: your explicit consent (Article 9(2)(a)). You may withdraw consent for future processing by stopping submission of that information and deleting stored conversations or your account.
- Meet tax, accounting, regulatory, or lawful authority requirements: compliance with a legal obligation where applicable (Article 6(1)(c)).
Providing an email address and password is necessary to create an account. Prompt content is necessary only when you ask the service to produce a response. You are not required to include sensitive personal data in a prompt.
3. Recipients and processors
We disclose data only as needed to operate the service. Current categories of recipients include cloud hosting and repository infrastructure (including Hugging Face), upstream model and inference providers selected for the Synderesis backend, and professional advisers or authorities where legally required. Prompt content may be sent to the configured model providers to generate a response.
If you are selected for Beta testing, the operational email provider or mailbox used by Synderesis processes your account email address and the invitation message, including its private email-bound code, so the invitation can be delivered. Do not forward that message or code.
If you enable web search, ordinary Answer mode sends one bounded, whitespace-normalised current-question query through OpenRouter's server-side web-search tool, which uses Exa. Task mode may send up to four bounded model-selected queries derived from your request and prior request-scoped Task observations. The feature does not append prior chat history, individual or organizational memory, attachments, uploaded filenames or content, file or citation locations, or device/geolocation data, but anything you type in the current question can influence a query. If the default suitability review remains enabled, each result batch's minimized query and bounded candidate fields—an opaque citation identifier, title, domain, and excerpt—are sent through OpenRouter to the configured review model solely to decide whether each candidate should be included. The final deduplicated web-evidence set is capped at five records. Turning review off skips that model review, but not deterministic URL, provenance, marker, citation, or final-answer checks.
If you connect GitHub for Spark or Pro, GitHub receives the installation, OAuth, identity, repository-list, and exact file requests required for the feature. Only repositories granted to the read-only Synderesis GitHub App are available. If you enable your own OpenRouter key for either tier, the context selected for the applicable Answer call or Task controller and final-answer calls—including any enabled conversation context, memory, attachments, or GitHub files—is processed under your OpenRouter account and billed there. Web search and suitability review remain Synderesis-funded, so the same request may use mixed funding. Your OpenRouter account may show the underlying billed provider and model route even though the assistant identifies in the workspace only as Synderesis Spark or Synderesis Pro.
Synderesis's browser-local and application-database retention limits do not by themselves determine an independent provider's operational, security, abuse-monitoring, backup, or legally required retention. Provider processing and retention are governed by the applicable processor arrangements, service terms, and policies. Contact us if you want current provider and transfer details before submitting sensitive content.
Where another organisation provides Synderesis to its staff, customers, or members, that organisation may be a separate controller or processor for its use of the API. Its own privacy notice may also apply.
4. International transfers
Some processors may operate outside the European Economic Area. Where personal data is transferred to a country without an EU adequacy decision, we use an applicable safeguard such as the European Commission's Standard Contractual Clauses and assess supplementary measures as required. You may request information about the safeguard through the privacy contact.
5. Retention
- Account profile, consent record, API-key metadata, usage events, and stored conversations remain until you delete the account or the data is no longer necessary.
- Waitlist and Beta-invitation lifecycle records remain with the account until account deletion or until they are no longer needed to operate the Beta. On account deletion, those records are erased. If a code was claimed, its one-way hash may remain without the account identifier or email hash solely to prevent the same code from being reused.
- Browser-local chat history is limited to the 20 most recently updated completed conversations. Each chat keeps the newest complete pairs within 100 messages and 100,000 text characters. Serialized chat records also have a 2,500,000-character limit; when necessary, the browser removes the oldest unpinned chats first while keeping the active chat where possible. A legacy v1 history record is removed only after it has been migrated successfully to v2. Bounded official/web citation records are retained and deleted with the local chat; raw uploaded-document and GitHub request context is not stored there. Assistant output may contain material derived from that context and is retained like other completed assistant text. You can delete individual chats, use Ghost mode, or clear the site's browser data.
- The browser theme preference remains until you change it or clear the site's browser data.
- Browser-local individual memories remain until you edit or clear them, delete the account from that browser, or clear the site's browser data. Turning memory off retains the entries but stops using or learning them.
- Shared conversation snapshots become unavailable when revoked and expire automatically after 30 days. Expired and revoked snapshots are deleted from the active application database.
- Browser sessions expire after seven days and can be ended earlier by signing out. A session-scoped model key expires within one hour and is deleted when you sign out. A remembered model key remains encrypted until you remove it or delete the account.
- A GitHub connection remains encrypted until you disconnect it, GitHub revokes or disables it, or you delete the account. Repository selections live only in the current tab, and fetched repository content is request-scoped.
- Revoked key hashes remain with the account so status and metering records can be understood; they are erased with account deletion.
- The Synderesis browser-chat service does not add the web-search query, Task observations, or returned web-source records to a server conversation-history database. Cited official/web records may remain in the browser-local chat. One usage event covers the browser request, including search and review usage or failures. Operational question/answer improvement records are collected only when that separate server-side feature is expressly enabled and are normally limited to 30 days.
- First-party optional product-interaction counters are hourly aggregates and are deleted after 30 days. Withdrawing analytics consent stops future collection and clears the in-memory browser queue; there is no persistent browser telemetry queue.
- Security and infrastructure logs are normally retained for no more than 30 days, except where a longer period is necessary to investigate an incident or comply with law. Independent provider retention follows the applicable processor arrangements, terms, and policies; it is not controlled by these Synderesis application-retention periods. Processor-controlled backup copies, if any, are removed or overwritten under the relevant processor retention schedule.
6. Account deletion and your rights
The account dashboard includes a self-service Delete account action. Password confirmation immediately fences access and revokes sessions, API keys, encrypted provider credentials, the encrypted GitHub connection, OAuth flows, and device grants. Application PII—including the active account profile, waitlist entry, Beta-invitation lifecycle record, usage audit details, conversation and prompt-improvement content, private shares, and unshared organizational memory—is erased in the initial deletion transaction. A claimed invitation's one-way code hash may remain after its account and email identifiers have been removed solely to prevent reuse.
Already-accepted meter units are separated into an opaque cleanup ledger before Stripe subscription cancellation and customer deletion. If a remote step fails, deletion may return HTTP 202 pending and retain only the minimal retry state needed to finish safely. After cleanup, only a one-way hashed tombstone remains locally to prevent account resurrection and billing replay.
The initiating browser clears that account's chat history, retained public-source citation records, and individual memory. Browser-local copies on another device or browser must be removed there or by clearing that site's browser data. The non-account theme preference remains until you change it or clear site data. Stripe may retain legally required billing records, including invoice and tax records. Stripe meter aggregation is asynchronous, so an immediate final invoice is not guaranteed to include usage that was just submitted.
Subject to the conditions in the GDPR, you may ask for access, rectification, erasure, restriction, portability, or object to processing based on legitimate interests. You may withdraw consent at any time without affecting processing already carried out lawfully. Contact hello@synderesis.eu. We will respond without undue delay and normally within one month.
You also have the right to lodge a complaint with the data-protection authority in the EU/EEA country of your habitual residence, place of work, or the place of the alleged infringement.
7. Security
We use transport encryption, Argon2id password hashing, hashed API keys and session tokens, authenticated encryption for connected external credentials, HttpOnly cookies, CSRF protection, rate limiting, OAuth state and PKCE controls, webhook-signature verification, access controls, and data minimisation. No internet service is risk-free; please do not submit personal data that is unnecessary for your request.
8. Cookies
Under EU rules, non-essential cookies require your consent. When you first visit, a banner lets you choose Accept all or Necessary only. You can change that choice later with the button below.
Necessary (always on when you use the feature): authenticated browser session and CSRF protection cookies for account security (about seven days, or until you sign out); and the home-page free-demo cookie synderesis_demo, used only to count your three free preview questions if you use the demo.
Optional analytics (only if you accept): Google Analytics 4 (measurement ID G-BSHNJ7NBWG) for aggregate site usage, plus Synderesis's first-party anonymous semantic interaction counters described above. Google Analytics receives only the origin and path as the page location; query strings and fragments are excluded. Optional analytics are not activated until you choose Accept all. We do not use advertising cookies or sell personal data.
Your banner choice is stored in your browser (localStorage) so we do not show the banner on every page load. The optional Synderesis interaction queue is memory-only. Choosing Necessary only, changing preferences, entering Ghost mode, or clearing site data stops optional collection and clears that queue.
9. Automated decision-making and children
Synderesis generates text using automated models, but the consumer account service does not make decisions producing legal or similarly significant effects about you. The service is not directed to children, and account holders must be at least 18 years old or have authority under applicable law.
10. Changes
We may update this notice when the service, processors, or legal requirements change. The effective date at the top identifies the current version. Material changes will be communicated through the service where appropriate.