Official notice · Effective 30 July 2026

Privacy & GDPR Notice

This notice explains how Synderesis processes personal data when you use synderesis.eu, create an account, manage API keys, or call the Synderesis service. This legal notice explains the service’s data handling in plain language.

Controller: Synderesis, the operator of synderesis.eu

Privacy contact: hello@synderesis.eu

Data Protection Officer: no DPO has been appointed at this stage; use the privacy contact above.

Related reading: Resources · Catholic AI FAQ · Home

1. Data we process

Account dataEmail address and, if supplied, name and organisation. We retain an irreversible password hash, never the password itself.
Waitlist and access invitationsWe retain waitlist join and update times. For email-bound invitations, we retain issue, preparation, operator-recorded sent, and claim times plus one-way hashes of the invitation code and email address. For one-time transferable access codes, we retain a code hash, a non-secret prefix, lifecycle times, and—until account deletion—the account identifier that claimed the code. Authenticated administrators receive plaintext codes only in transient no-store responses for out-of-band delivery; plaintext codes and invitation messages are not stored in the application database.
Security credentialsHashed browser-session identifiers, CSRF-protection values, API-key hashes, key prefixes, status, and expiry information. A plaintext API key is displayed only when created.
Service contentQuestions, instructions, source references, model responses, and conversation identifiers you send. Stored conversation content is retained only when the relevant request enables conversation storage.
Browser-local chat historyThe dedicated chat page can keep up to 20 completed text conversations in this browser's local storage. Each chat retains the newest complete user-and-assistant pairs within 100 messages and 100,000 text characters. A further 2,500,000-character serialized-storage limit across chat records may remove older chats. Bounded official citation references may be stored with a response. Public queries, raw public-source records, excerpts, and URLs are excluded. Uploaded files, filenames, extracted content, and uploaded-document citation metadata are never included. Ghost mode creates no saved chat.
Model contextThe full retained browser transcript is not sent wholesale with each request. The browser sends only the newest complete context within 12 messages and 12,000 text characters, together with the current question and any other context you explicitly enable or attach for that reply.
Browsing and tool actionsSearch is off by default. If enabled, Synderesis uses only an explicit public query of up to 2,000 characters for one search. For remote MCP connections, every tool action requires separate approval showing the exact server, tool, target, and arguments, including tools advertising themselves as read-only. The MCP controller allows three actions per turn. This separate approval does not apply to Synderesis's internal source search.
Individual memoryIndividual memory is off by default. If you enable it, explicit preferences you ask Synderesis to remember and entries you add or edit are kept in this browser's local storage. Enabled entries are sent as bounded context with later requests but are not written to the Synderesis conversation database.
Organizational memoryAn administrator may manually assign your customer account to an organizational-memory group and maintain shared text entries for that group. Membership requires an explicit server-side assignment. The organization name in your public account profile does not grant membership.
Source and web-search dataThe explicit public query is not generated from private chat and is not augmented with history, files, or memory. Vercel AI Gateway receives model context and public search; tool connections are not alternate model routes. You may supply up to three public HTTPS URLs, and at most three fetched pages overall are used. Each page is bounded to 65,536 bytes of decoded data at the extraction boundary. Fetching supports text only, with no JavaScript, browser login, or private network access. Only actually fetched sources are cited.
GitHub connectionIf you connect GitHub for Spark or Pro, we retain your GitHub user ID and login, the approved App installation ID, connection status, token expiries, and an encrypted OAuth token bundle. Repository, ref, and path choices remain only in the current browser tab. For each request where you enable the connection, Synderesis fetches only the exact selected bounded text files and passes them as untrusted model context. Raw repository bytes, names, paths, and transient file citations are request-scoped and are not directly added to saved chat records, memories, shares, downloads, or the Synderesis conversation database. Model output may reproduce repository material, and completed assistant text can then be saved in browser history or explicitly shared or downloaded by you.
Remote MCP connectionsRemote HTTPS MCP connections support none, bearer, or OAuth authentication and explicit selection of discovered tools; Synderesis is not compatible with every MCP server or vendor. Credentials are account-bound and AES-GCM encrypted until replacement, removal, or account deletion. We store the connection endpoint, name, status, generation, tool names, schema digests, and selections. Credentials are not disclosed to models, the browser, or logs.
Theme preferenceYour System, Light, or Dark choice is stored in this browser's local storage. It contains no account identifier or conversation content.
Shared conversation snapshotsOnly when you choose Share, Synderesis stores a text-only capability-link snapshot using the newest complete context within a limit of 12 messages and 12,000 text characters. Any remaining browser transcript is excluded from the snapshot. Anyone with that high-entropy link can read the snapshot until you revoke it or it expires. Files and all citation/source manifests, including uploaded-document metadata, are excluded.
Usage and security dataRequest time, endpoint, model, token and request counts, cost estimates, response status, latency, and limited infrastructure logs such as IP address and user agent processed by hosting providers. Planning, search, and answers may be metered, including when an operation ends in failure. An internet connection is always required, including for the installable mobile and desktop website.
Optional aggregate product analyticsOnly after you choose Accept all, Synderesis counts fixed semantic interaction categories such as page views, navigation, form submissions, named controls, coarse API outcome and duration bands, and content-free client-fault categories. Ghost mode sends none. The Chrome extension has a separate, off-by-default choice in Extension settings and sends none while Private mode is active. These hourly aggregates contain no account, user, device, session, or request identifier and no prompt, answer, selection, page or file content, title, label, form value, DOM text, URL, query string, filename, repository, citation, provider or model detail, credential, IP address, full user agent, exception message, or precise timing.
Consent recordThe time at which you explicitly consented to processing sensitive information you choose to submit, including information that may reveal religious beliefs.

Chrome extension

The Synderesis AI Chrome extension reads page text, titles, URLs, headings, and selections to provide the browser assistance you request. Page context is on by default; the side-panel banner identifies the page included when you send. Use Exclude, Tools → Page context, or Extension settings to turn it off. Explicit page actions, selections, and files or tabs you add still supply their selected content. Prompts, relevant conversation context, and included source text are sent over HTTPS to Synderesis and its model providers to answer your request. PDF and DOCX text is extracted locally before it is sent. Optional video transcript requests may contact YouTube using your browser's existing site session.

The extension stores its account credential in Chrome local extension storage, not Chrome sync. Non-secret preferences and account metadata, including customer ID, email, plan, and key prefix, may be synchronized by Chrome according to your browser settings. Conversation history is account-scoped local extension storage, separate from website history, with a maximum of 20 conversations. Raw page and attachment context is not retained as history metadata; selected text in your prompt and material quoted in an answer can remain in saved messages. Private mode skips saving that chat and suppresses optional analytics, but requests still use the online service and its processors.

Delete chats through extension history or remove the extension to clear its local data. Disconnect removes the extension's credential and account metadata; it does not revoke the server key or erase saved chats. Website logout does not disconnect an already linked extension. Revoke its key in the account dashboard to stop further use. Provider retention and the account-deletion process described in this policy also apply. We use extension data to provide and improve its stated browser-assistance purpose, not to sell browsing data, target advertisements, determine creditworthiness, or make lending decisions.

2. Purposes and legal bases

Providing an email address and password is necessary to create an account. Prompt content is necessary only when you ask the service to produce a response. You are not required to include sensitive personal data in a prompt.

3. Recipients and processors

We disclose data only as needed to operate the service. Current categories of recipients include cloud hosting and repository infrastructure (including Hugging Face), upstream model and inference providers selected for the Synderesis backend, and professional advisers or authorities where legally required. Prompt content may be sent to the configured model providers to generate a response.

If you are issued a complimentary access invitation, the operational email provider or mailbox used by Synderesis processes your account email address and the invitation message, including its private email-bound code, so the invitation can be delivered. Do not forward that message or code.

Public queries, raw source records, excerpts, and URLs remain turn-scoped and are excluded from browser history, retries, shares, and downloads. Assistant text may reproduce facts or supplied material and is retained like ordinary answers. Official citations remain distinct from public-web citations; these limits do not promise that assistant output cannot reproduce submitted or fetched material.

Public websites receive page-fetch requests and ordinary connection metadata. Before tool approval, connection setup and refresh send MCP initialization/client metadata and discovery requests, with server-side authentication where required. For an approved MCP call, remote tool servers receive only its approved arguments plus server-side authentication. Authorization providers handle sign-in. Those external recipients have their own policies. OAuth pending authorization and PKCE data and approval arguments are encrypted and expire after five minutes. Expired ciphertext is cleared during subsequent bounded cleanup. Physical deletion occurs when that cleanup runs. Status, digest, and replay metadata persists with the account. Results are not stored in the database; sealed receipts are kept only in browser memory and expire after five minutes. Expiry makes a receipt unusable; it does not itself erase browser memory.

If you connect GitHub for Spark or Pro, GitHub receives the installation, OAuth, identity, repository-list, and exact file requests required for the feature. Only repositories granted to the read-only Synderesis GitHub App are available.

Synderesis's browser-local and application-database retention limits do not by themselves determine an independent provider's operational, security, abuse-monitoring, backup, or legally required retention. Provider processing and retention are governed by the applicable processor arrangements, service terms, and policies. Contact us if you want current provider and transfer details before submitting sensitive content.

Where another organisation provides Synderesis to its staff, customers, or members, that organisation may be a separate controller or processor for its use of the API. Its own privacy notice may also apply.

4. International transfers

Some processors may operate outside the European Economic Area. Where personal data is transferred to a country without an EU adequacy decision, we use an applicable safeguard such as the European Commission's Standard Contractual Clauses and assess supplementary measures as required. You may request information about the safeguard through the privacy contact.

5. Retention

6. Account deletion and your rights

The account dashboard includes a self-service Delete account action. Password confirmation immediately fences access and revokes sessions, API keys, encrypted provider credentials, the encrypted GitHub connection, OAuth flows, and device grants. Logout invalidates pending MCP authorization, but revocation cannot undo already dispatched remote effects. An unknown outcome is not automatically retried, and there is no exactly-once guarantee. Stop ends rendering. Remote effects, compute and usage may continue. Application PII—including the active account profile, waitlist entry, invitation lifecycle record, usage audit details, conversation and prompt-improvement content, private shares, and unshared organizational memory—is erased in the initial deletion transaction. Account deletion removes MCP records through the account cascade, but it does not delete third-party copies or effects or cancel work already dispatched. A claimed invitation's one-way code hash may remain after its account and email identifiers have been removed solely to prevent reuse.

Already-accepted meter units are separated into an opaque cleanup ledger before Stripe subscription cancellation and customer deletion. If a remote step fails, deletion may return HTTP 202 pending and retain only the minimal retry state needed to finish safely. After cleanup, only a one-way hashed tombstone remains locally to prevent account resurrection and billing replay.

The initiating browser clears that account's chat history, retained official citation references, and individual memory. Browser-local copies on another device or browser must be removed there or by clearing that site's browser data. The non-account theme preference remains until you change it or clear site data. Stripe may retain legally required billing records, including invoice and tax records. Stripe meter aggregation is asynchronous, so an immediate final invoice is not guaranteed to include usage that was just submitted.

Subject to the conditions in the GDPR, you may ask for access, rectification, erasure, restriction, portability, or object to processing based on legitimate interests. You may withdraw consent at any time without affecting processing already carried out lawfully. Contact hello@synderesis.eu. We will respond without undue delay and normally within one month.

You also have the right to lodge a complaint with the data-protection authority in the EU/EEA country of your habitual residence, place of work, or the place of the alleged infringement.

7. Security

We use transport encryption, Argon2id password hashing, hashed API keys and session tokens, authenticated encryption for connected external credentials, HttpOnly cookies, CSRF protection, rate limiting, OAuth state and PKCE controls, webhook-signature verification, access controls, and data minimisation. No internet service is risk-free; please do not submit personal data that is unnecessary for your request.

8. Cookies

Under EU rules, non-essential cookies require your consent. When you first visit, a banner lets you choose Accept all or Necessary only. You can change that choice later with the button below.

Necessary (always on when you use the feature): authenticated browser session and CSRF protection cookies for account security (about seven days, or until you sign out); and the home-page free-demo cookie synderesis_demo, used only to count your three free preview questions if you use the demo.

Optional analytics (only if you accept): Google Analytics 4 (measurement ID G-BSHNJ7NBWG) for aggregate site usage, plus Synderesis's first-party anonymous semantic interaction counters described above. Google Analytics receives only the origin and path as the page location; query strings and fragments are excluded. Optional analytics are not activated until you choose Accept all. We do not use advertising cookies or sell personal data.

Your banner choice is stored in your browser (localStorage) so we do not show the banner on every page load. The optional Synderesis interaction queue is memory-only. Choosing Necessary only, changing preferences, entering Ghost mode, or clearing site data stops optional collection and clears that queue. Ghost mode also disables Google Analytics until after you leave Ghost mode, and only resumes it when your current choice is still Accept all.

9. Automated decision-making and children

Synderesis generates text using automated models, but the consumer account service does not make decisions producing legal or similarly significant effects about you. The service is not directed to children, and account holders must be at least 18 years old or have authority under applicable law.

10. Changes

We may update this notice when the service, processors, or legal requirements change. The effective date at the top identifies the current version. Material changes will be communicated through the service where appropriate.

Subscription billing and usage accounting

When subscription billing is enabled, Stripe processes hosted checkout, subscription, invoice, and tax information. Synderesis sends customer-wide accepted and advisory usage totals for billing; withheld outcomes are excluded, and browser and API-key activity are combined for the verified billing period.

Usage overages normalize Synderesis-funded provider costs to a true 50% provider-cost contribution margin. Planning, search, and answer work may remain billable when a later operation fails. Provider routes and internal cost details are never exposed in the account page.

Account deletion immediately blocks new usage and begins remote cancellation and customer deletion. The interface continues to show deletion as pending while cleanup is incomplete. Retry and terminal writeoff records retain only opaque operational identifiers and counts, never account content or credentials; the completed local tombstone is a one-way hash used for replay safety. Stripe may retain invoice and tax records for legally required retention periods.