Privacy & GDPR Notice
This notice explains how Synderesis processes personal data when you use synderesis.eu, create an account, manage API keys, or call the Synderesis service. This legal notice explains the service’s data handling in plain language.
1. Data we process
Chrome extension
The Synderesis AI Chrome extension reads page text, titles, URLs, headings, and selections to provide the browser assistance you request. Page context is on by default; the side-panel banner identifies the page included when you send. Use Exclude, Tools → Page context, or Extension settings to turn it off. Explicit page actions, selections, and files or tabs you add still supply their selected content. Prompts, relevant conversation context, and included source text are sent over HTTPS to Synderesis and its model providers to answer your request. PDF and DOCX text is extracted locally before it is sent. Optional video transcript requests may contact YouTube using your browser's existing site session.
The extension stores its account credential in Chrome local extension storage, not Chrome sync. Non-secret preferences and account metadata, including customer ID, email, plan, and key prefix, may be synchronized by Chrome according to your browser settings. Conversation history is account-scoped local extension storage, separate from website history, with a maximum of 20 conversations. Raw page and attachment context is not retained as history metadata; selected text in your prompt and material quoted in an answer can remain in saved messages. Private mode skips saving that chat and suppresses optional analytics, but requests still use the online service and its processors.
Delete chats through extension history or remove the extension to clear its local data. Disconnect removes the extension's credential and account metadata; it does not revoke the server key or erase saved chats. Website logout does not disconnect an already linked extension. Revoke its key in the account dashboard to stop further use. Provider retention and the account-deletion process described in this policy also apply. We use extension data to provide and improve its stated browser-assistance purpose, not to sell browsing data, target advertisements, determine creditworthiness, or make lending decisions.
2. Purposes and legal bases
- Provide your account, waitlist, access invitation and subscription, API access, responses, usage information, and support: performance of a contract or steps you ask us to take before entering one (GDPR Article 6(1)(b)).
- Protect accounts, prevent abuse, meter service use, diagnose failures, and establish or defend legal claims: our legitimate interests in operating a secure and reliable service (Article 6(1)(f)).
- Measure optional aggregate site and product interactions: your consent (Article 6(1)(a)), which you can withdraw through Cookie preferences for the website or Extension settings for the Chrome extension. No optional interaction event is sent before the applicable consent, while website Ghost mode is active, or while extension Private mode is active.
- Process special-category information you voluntarily place in prompts or stored conversations: your explicit consent (Article 9(2)(a)). You may withdraw consent for future processing by stopping submission of that information and deleting stored conversations or your account.
- Meet tax, accounting, regulatory, or lawful authority requirements: compliance with a legal obligation where applicable (Article 6(1)(c)).
Providing an email address and password is necessary to create an account. Prompt content is necessary only when you ask the service to produce a response. You are not required to include sensitive personal data in a prompt.
3. Recipients and processors
We disclose data only as needed to operate the service. Current categories of recipients include cloud hosting and repository infrastructure (including Hugging Face), upstream model and inference providers selected for the Synderesis backend, and professional advisers or authorities where legally required. Prompt content may be sent to the configured model providers to generate a response.
If you are issued a complimentary access invitation, the operational email provider or mailbox used by Synderesis processes your account email address and the invitation message, including its private email-bound code, so the invitation can be delivered. Do not forward that message or code.
Public queries, raw source records, excerpts, and URLs remain turn-scoped and are excluded from browser history, retries, shares, and downloads. Assistant text may reproduce facts or supplied material and is retained like ordinary answers. Official citations remain distinct from public-web citations; these limits do not promise that assistant output cannot reproduce submitted or fetched material.
Public websites receive page-fetch requests and ordinary connection metadata. Before tool approval, connection setup and refresh send MCP initialization/client metadata and discovery requests, with server-side authentication where required. For an approved MCP call, remote tool servers receive only its approved arguments plus server-side authentication. Authorization providers handle sign-in. Those external recipients have their own policies. OAuth pending authorization and PKCE data and approval arguments are encrypted and expire after five minutes. Expired ciphertext is cleared during subsequent bounded cleanup. Physical deletion occurs when that cleanup runs. Status, digest, and replay metadata persists with the account. Results are not stored in the database; sealed receipts are kept only in browser memory and expire after five minutes. Expiry makes a receipt unusable; it does not itself erase browser memory.
If you connect GitHub for Spark or Pro, GitHub receives the installation, OAuth, identity, repository-list, and exact file requests required for the feature. Only repositories granted to the read-only Synderesis GitHub App are available.
Synderesis's browser-local and application-database retention limits do not by themselves determine an independent provider's operational, security, abuse-monitoring, backup, or legally required retention. Provider processing and retention are governed by the applicable processor arrangements, service terms, and policies. Contact us if you want current provider and transfer details before submitting sensitive content.
Where another organisation provides Synderesis to its staff, customers, or members, that organisation may be a separate controller or processor for its use of the API. Its own privacy notice may also apply.
4. International transfers
Some processors may operate outside the European Economic Area. Where personal data is transferred to a country without an EU adequacy decision, we use an applicable safeguard such as the European Commission's Standard Contractual Clauses and assess supplementary measures as required. You may request information about the safeguard through the privacy contact.
5. Retention
- Account profile, consent record, API-key metadata, usage events, and stored conversations remain until you delete the account or the data is no longer necessary.
- Waitlist and invitation lifecycle records remain with the account until account deletion or until they are no longer needed to operate the invitation programme. On account deletion, those records are erased. If a code was claimed, its one-way hash may remain without the account identifier or email hash solely to prevent the same code from being reused.
- Browser-local chat history is limited to the 20 most recently updated completed conversations. Each chat keeps the newest complete pairs within 100 messages and 100,000 text characters. Serialized chat records also have a 2,500,000-character limit; when necessary, the browser removes the oldest unpinned chats first while keeping the active chat where possible. A legacy v1 history record is removed only after it has been migrated successfully to v2. Bounded official citation references are retained and deleted with the local chat; raw public-source, uploaded-document, and GitHub request context is not stored there. Assistant output may contain material derived from that context and is retained like other completed assistant text. You can delete individual chats, use Ghost mode, or clear the site's browser data.
- The browser theme preference remains until you change it or clear the site's browser data.
- Browser-local individual memories remain until you edit or clear them, delete the account from that browser, or clear the site's browser data. Turning memory off retains the entries but stops using or learning them.
- Shared conversation snapshots become unavailable when revoked and expire automatically after 30 days. Expired and revoked snapshots are deleted from the active application database.
- Browser sessions expire after seven days and can be ended earlier by signing out.
- Older encrypted model-key records may remain from the retired bring-your-own-key feature. Current native BYOK routes are unavailable, and these keys are not used for AI calls. Disabling the feature or reaching a credential's expiry does not establish that its stored ciphertext has been erased. Account deletion removes these records.
- A GitHub connection remains encrypted until you disconnect it, GitHub revokes or disables it, or you delete the account. Repository selections live only in the current tab, and fetched repository content is request-scoped.
- Revoked key hashes remain with the account so status and metering records can be understood; they are erased with account deletion.
- The Synderesis browser-chat service does not add public queries, raw source records, excerpts, or URLs to browser history, retries, shares, downloads, or a server conversation-history database. Assistant text may reproduce that material and is retained like ordinary answers. Usage accounting may include planning, search, answers, and failures. Operational question/answer improvement records are collected only when that separate server-side feature is expressly enabled and are normally limited to 30 days.
- MCP credentials remain account-bound and encrypted until replacement, removal, or account deletion. Pending OAuth authorization, PKCE material, and approval arguments expire after five minutes; later bounded cleanup clears expired ciphertext rather than guaranteeing physical deletion at the expiry instant. Connection status, digests, and replay metadata remain with the account. Tool results are not stored in the database. Sealed receipts are memory-only and expire after five minutes; expiry ends their validity. Browser-memory cleanup follows the application lifecycle.
- First-party optional product-interaction counters are hourly aggregates and are deleted after 30 days. Withdrawing the applicable website or extension analytics consent stops future collection and clears its in-memory queue; neither client has a persistent telemetry queue.
- Security and infrastructure logs are normally retained for no more than 30 days, except where a longer period is necessary to investigate an incident or comply with law. Independent provider retention follows the applicable processor arrangements, terms, and policies; it is not controlled by these Synderesis application-retention periods. Processor-controlled backup copies, if any, are removed or overwritten under the relevant processor retention schedule.
6. Account deletion and your rights
The account dashboard includes a self-service Delete account action. Password confirmation immediately fences access and revokes sessions, API keys, encrypted provider credentials, the encrypted GitHub connection, OAuth flows, and device grants. Logout invalidates pending MCP authorization, but revocation cannot undo already dispatched remote effects. An unknown outcome is not automatically retried, and there is no exactly-once guarantee. Stop ends rendering. Remote effects, compute and usage may continue. Application PII—including the active account profile, waitlist entry, invitation lifecycle record, usage audit details, conversation and prompt-improvement content, private shares, and unshared organizational memory—is erased in the initial deletion transaction. Account deletion removes MCP records through the account cascade, but it does not delete third-party copies or effects or cancel work already dispatched. A claimed invitation's one-way code hash may remain after its account and email identifiers have been removed solely to prevent reuse.
Already-accepted meter units are separated into an opaque cleanup ledger before Stripe subscription cancellation and customer deletion. If a remote step fails, deletion may return HTTP 202 pending and retain only the minimal retry state needed to finish safely. After cleanup, only a one-way hashed tombstone remains locally to prevent account resurrection and billing replay.
The initiating browser clears that account's chat history, retained official citation references, and individual memory. Browser-local copies on another device or browser must be removed there or by clearing that site's browser data. The non-account theme preference remains until you change it or clear site data. Stripe may retain legally required billing records, including invoice and tax records. Stripe meter aggregation is asynchronous, so an immediate final invoice is not guaranteed to include usage that was just submitted.
Subject to the conditions in the GDPR, you may ask for access, rectification, erasure, restriction, portability, or object to processing based on legitimate interests. You may withdraw consent at any time without affecting processing already carried out lawfully. Contact hello@synderesis.eu. We will respond without undue delay and normally within one month.
You also have the right to lodge a complaint with the data-protection authority in the EU/EEA country of your habitual residence, place of work, or the place of the alleged infringement.
7. Security
We use transport encryption, Argon2id password hashing, hashed API keys and session tokens, authenticated encryption for connected external credentials, HttpOnly cookies, CSRF protection, rate limiting, OAuth state and PKCE controls, webhook-signature verification, access controls, and data minimisation. No internet service is risk-free; please do not submit personal data that is unnecessary for your request.
8. Cookies
Under EU rules, non-essential cookies require your consent. When you first visit, a banner lets you choose Accept all or Necessary only. You can change that choice later with the button below.
Necessary (always on when you use the feature): authenticated browser session and CSRF protection cookies for account security (about seven days, or until you sign out); and the home-page free-demo cookie synderesis_demo, used only to count your three free preview questions if you use the demo.
Optional analytics (only if you accept): Google Analytics 4 (measurement ID G-BSHNJ7NBWG) for aggregate site usage, plus Synderesis's first-party anonymous semantic interaction counters described above. Google Analytics receives only the origin and path as the page location; query strings and fragments are excluded. Optional analytics are not activated until you choose Accept all. We do not use advertising cookies or sell personal data.
Your banner choice is stored in your browser (localStorage) so we do not show the banner on every page load. The optional Synderesis interaction queue is memory-only. Choosing Necessary only, changing preferences, entering Ghost mode, or clearing site data stops optional collection and clears that queue. Ghost mode also disables Google Analytics until after you leave Ghost mode, and only resumes it when your current choice is still Accept all.
9. Automated decision-making and children
Synderesis generates text using automated models, but the consumer account service does not make decisions producing legal or similarly significant effects about you. The service is not directed to children, and account holders must be at least 18 years old or have authority under applicable law.
10. Changes
We may update this notice when the service, processors, or legal requirements change. The effective date at the top identifies the current version. Material changes will be communicated through the service where appropriate.