Privacy Policy

Last updated: July 27, 2026

This policy explains what personal data Synapse AI (synapseai.work) collects, how it is used and what your rights are, in compliance with Brazil's LGPD and, where applicable, the GDPR.

1. Controller and contact

Synapse AI is the data controller. For any personal-data request, write to contato@synapseai.work.

2. Data we collect

Account: name, e-mail and identifier provided by Google at sign-in (or e-mail/password if you sign up directly).

Study content: notes, files, images, audio and transcripts you upload, plus the content generated from them (summaries, flashcards, mock exams, assessments).

Voice Coach: the microphone is activated only by your action. The temporary recording is sent to the transcription provider, deleted from the device immediately after processing and is not stored by Synapse AI. The transcript is shown for review and enters the conversation only when you choose to send it.

Usage data: learning events (sessions, reviews, validations, scores), browser-detected timezone and IP-inferred country (to display times and metrics correctly).

Payment: handled entirely by Dodo Payments (Merchant of Record). We never store card data — we only receive the subscription status.

3. How we use data

To operate the service: organise your knowledge base, run the AI features you trigger, compute progress, reviews and usage limits.

To improve the product: aggregated usage metrics (e.g. how many users activate a feature). We do not sell personal data and we show no advertising.

4. AI and subprocessors

To power AI features, excerpts of your content are sent to the configured model providers: OpenAI (platform default; includes embeddings, transcription and audio), Anthropic and Google (optional). Under their API policies, these providers process the content to generate the response and do not use it to train models.

Other subprocessors: Supabase (database, authentication, storage), Vercel (hosting and infrastructure) and Dodo Payments (payments). Some operate servers outside Brazil; international transfers rely on adequate contractual safeguards.

5. Legal bases (LGPD/GDPR)

Contract performance: operating the platform you signed up for. Legitimate interest: aggregated usage metrics and security. Consent: where applicable (e.g. optional communications). Legal obligation: payment/tax records, kept by the Merchant of Record.

6. Retention

Your data is kept for as long as your account exists. When you delete your account (Settings → Account), all data — notes, files, embeddings, study history and conversations — is permanently removed in cascade. Operational backups expire on the infrastructure's normal cycle.

7. Your rights

At any time you can: export your data (Settings → Account → Export data, as JSON); correct data by editing it in the platform; delete your account and all data; and request information about processing via the contact e-mail. LGPD/GDPR requests are honoured within the legal deadline.

8. Cookies

We use essential cookies only: the authentication session (Supabase) and the language preference. No advertising or cross-site tracking cookies.

9. Security

Data travels over HTTPS and is isolated per user in the database (Row Level Security). API keys you add are encrypted (AES-256-GCM) and never returned to the browser. No system is 100% secure, but relevant incidents will be communicated as required by law.

10. Changes

We may update this policy; material changes will be announced in the platform or by e-mail. The date at the top indicates the current version.