# Privacy Policy

> Synapse · SYN-LEGAL-PRIVACY-2026-09 · Last updated: 19 September 2026 · https://synapsehubs.net/privacy

This Privacy Policy describes what personal data Synapse collects, why it is collected, the legal grounds relied on, who can see it, how long it is kept, how it is protected, and the choices and rights you have. It is written to match how the platform actually works — not a generic template — and it applies to every visitor and member of synapsehubs.net.

## The short version

- Your data is stored on the operator’s own server (PostgreSQL on a private VPS). It is not handed to a database vendor, an email vendor, or an advertising network.
- Email you receive from Synapse (verification codes, password resets) is sent by Synapse’s own mail server, signed with its own domain keys.
- Passwords are bcrypt-hashed. Direct messages and the text of message notifications are encrypted at rest. Private settings are never returned to other members.
- We do not sell personal data, show behavioral ads, or use your content to train third-party AI models.
- Payments (donations and purchases) are processed by Stripe. Card and bank details go to Stripe only — never to Synapse’s servers or database. Payment accounts sit behind two-factor authentication.
- You decide, category by category, whether AI systems may use your public content. Everything is off by default.
- You can export your data, change notification and privacy settings, and delete your account from Settings.

## 1. Overview & Who We Are

Synapse (“Synapse”, “we”, “us”) is a platform for publishing projects, solving problems together, joining groups, messaging, and networking with investor and company accounts. The service is operated by [operator legal name], [registered address] (the “Operator”), who is the data controller for personal data processed through the service.

This policy should be read together with the Terms of Service, the Content License Guide, and the product Documentation. If a specific feature shows you a more specific privacy notice at the moment you use it, that notice also applies.

## 2. Scope & Definitions

- **Personal data** — any information that identifies you or can reasonably be linked to you, such as your email address, handle, IP address, or the content you post under your account.
- **Processing** — anything done with personal data: collecting, storing, displaying, analysing, sharing, or deleting it.
- **Member** — a person with a Synapse account. **Visitor** — anyone browsing without an account.
- **Public content** — anything you publish so that other members or visitors can see it (projects, public profile fields, group posts in public groups, comments, Network posts).

This policy does not cover websites you reach through links posted by members; those sites have their own policies.

## 3. Information We Collect

### Account information

- **Email address** — required for email accounts and used to verify the inbox with a one-time code. Private by default; shown on your profile only if you switch that on.
- **Password** — stored only as a bcrypt hash. It is never logged or emailed. Google sign-in accounts have no Synapse password unless you set one.
- **Account type and identity fields** — Developer, Investor or Company; display name, @handle and a public profile ID.
- **Two-factor secret** — if you enable 2FA, the authenticator secret is stored in a dedicated table, separate from your profile.

### Profile information you choose to add

Bio, avatar, cover image, skills, social links, and — for Investor and Company accounts — firm or company details, focus areas, team members and verification references.

### Content you create

Projects and their files, problems, solutions, comments, group posts, direct messages, workspace revision history, Network posts, reports, appeals, feedback, and the metadata attached to them (timestamps, public content IDs, likes).

### Notifications

When something happens that concerns you — a comment, reply, mention, like, follow, message, group activity — we store a notification record containing who did it, a short excerpt, and a link to the place it happened.

### Usage and technical data

- **View events** — content ID, a first-party browser session key and a time stamp, used to count views without counting refreshes.
- **Sessions** — random session ID, creation time, device/browser string and IP address, so “log out” actually revokes access and you can review your active sessions.
- **Security events** — failed sign-ins, rate-limit hits and blocked requests (IP, time, reason), kept for a limited period.
- **Server logs** — request paths, status codes and errors kept briefly for reliability and abuse response.

### Trust and moderation records

Trust level, strikes, warnings, bans, soft-hide status, the text or screenshots involved in a decision, appeals you file, and safety reports you submit or that are filed about you.

### What we do not collect

We never receive or store payment card numbers, CVC codes or bank account numbers (Stripe does — see “Payments & Financial Data”). We also do not collect precise location, contacts, microphone or camera data, or advertising identifiers.

## 4. Where Data Comes From

- **You** — when you register, edit your profile, post, message, upload, report, or change settings.
- **Google** — if you choose “Continue with Google”, Google tells us your verified email address and name. We do not receive your Google password.
- **Other members** — content that mentions you, replies to you, follows you, messages you, or reports you.
- **Your browser and device** — technical data sent with every request (IP address, browser type, language).

## 5. How We Use Information

- Create and secure your account: registration, email verification, sign-in, password reset, two-factor authentication and session management.
- Show your public profile and content to others according to your privacy settings.
- Deliver notifications and messages you should receive, and let you control which kinds you get.
- Send transactional email you need (verification codes, password resets, deletion confirmations). We do not send marketing email.
- Generate link preview cards so a pasted link appears with its title, description and image.
- Moderate content and names, enforce our Terms, handle appeals and protect members from abuse, spam and fraud.
- Rank and recommend content using engagement, recency, completeness and author trust.
- Maintain, back up, monitor and improve the reliability and performance of the service.
- Comply with legal obligations and respond to lawful requests.

**We do not sell personal data, and we do not use your content or personal information to train third-party AI models.**

## 6. Legal Bases for Processing

Where the GDPR, UK GDPR, Thailand’s Personal Data Protection Act B.E. 2562 (PDPA) or a similar law applies, we rely on:

| Purpose | Legal basis |
| --- | --- |
| Account, sign-in, content hosting, messaging, notifications | Performance of a contract with you |
| Security, abuse prevention, moderation, rate limiting, backups | Legitimate interests (a safe, reliable service) |
| Public email, optional profile fields, notification preferences | Your consent, which you can withdraw in Settings |
| Record keeping, responding to lawful requests | Legal obligation |

## 7. Notifications & Email

### In-app notifications

Notifications are created by the server when the action happens, so the person concerned always receives them regardless of the page it happened on. They respect your Settings (comments, likes, follows, messages, groups, workspace) and your block list. The excerpt inside a message notification is encrypted at rest like the message itself.

### Email

Synapse sends email from its own mail server. Each message is queued in our database, delivered directly to your email provider, and signed with our domain’s DKIM key. We keep a delivery log (recipient, subject, status, error text) for up to 60 days to diagnose delivery problems. Your email provider (for example Gmail) will of course process the message once it arrives — that is governed by their policy.

We send only service email: verification codes, password reset links and account-deletion confirmations. Reset links expire after 30 minutes and work once; codes expire after 10 minutes.

## 8. Link Previews

When a comment, message or post contains a link, the Synapse server may fetch that page to read its public title, description and preview image, and shows them as a card. Fetches are made by our server, not your browser, so the site you link to sees our server’s address rather than yours. Results are cached in our database for a few days. Links to Synapse’s own pages are previewed from our database instead. Private, internal and non-public addresses are never fetched.

## 9. Where Your Data Lives

The database, uploaded files, encryption keys, mail signing keys and backups are stored on a dedicated virtual private server operated by the Operator. Synapse no longer relies on a third-party managed database or a third-party email delivery API. Cloudflare provides DNS, TLS termination, caching and DDoS protection in front of the site, which means it necessarily sees traffic to and from the site as it passes through.

Encrypted-at-rest fields (direct messages, notification excerpts, payout notes and wallet-type fields) use AES-256-GCM. Automated database backups are written to the same server on a schedule and kept for 14 days.

## 10. Sharing & Recipients

- **Other members and visitors** — see what you make public. Your email, settings, blocked list and private data are not returned by the API to anyone but you.
- **Google** — only if you use Google sign-in, and only for authentication.
- **Cloudflare** — network edge and security provider as described above.
- **Stripe Payments** — processes card payments, holds saved cards and receiving-account (payout) details, and performs identity verification for receiving accounts. Stripe acts as an independent controller for its own regulatory duties; see its privacy policy.
- **The other party to a payment** — the member you pay (or who pays you) sees your public profile name, the amount and the receipt number, never your card or bank details.
- **Sites you link to** — receive a request from our server when a preview is generated.
- **Operators and moderators** — may access moderation tools, reports, warnings and limited directory fields needed for safety work. They cannot read your password.
- **Authorities and advisers** — where required by law or valid legal process, or to protect the rights, safety and property of members, the public or the Operator.
- **Successors** — if the service is transferred to another operator, data may move with it under the same protections, and you will be told.

We do not sell or rent personal data, and we do not share it with advertisers or data brokers.

## 11. International Transfers

Your data is stored on a server in [hosting country / region]. If you use Synapse from another country, your data is transferred to and processed in that location. Where the law requires a transfer mechanism (for example standard contractual clauses, or the safeguards in section 28 of the Thai PDPA) we rely on it. Traffic also passes through Cloudflare’s global network.

## 12. Security Measures

### Accounts and access

- bcrypt password hashing; revocable server-side sessions; optional TOTP two-factor authentication; login throttling and lockouts.
- HttpOnly session cookies with CSRF protection; strict CORS allow-list.
- Ownership checks on every update and delete; direct messages and notifications visible only to their participants.

### Data protection

- Sensitive fields encrypted at rest with AES-256-GCM; secrets never written to logs.
- The database accepts connections only from the server itself (loopback), not the public internet.
- Nightly encrypted-at-rest-disk backups with a 14-day rotation.

### Application hardening

- Content-Security-Policy, HSTS, no-sniff, frame denial and a restrictive permissions policy.
- Uploads restricted by type and size; risky file types served as inert text.
- Link preview fetching is protected against server-side request forgery.
- Rate limits on sign-in, writes, views, uploads and reports; automated abuse detection.

No system is perfectly secure. Use a strong unique password and enable two-factor authentication. Product detail: Documentation → Security.

## 13. Payments & Financial Data

### What Stripe holds and what we keep

Donations and purchases are paid with **Stripe**. Card numbers are typed into a secure form hosted by Stripe and go straight to Stripe; Synapse’s servers never receive, process or store card numbers, CVC codes or bank account numbers. For each paying account we keep only Stripe’s identifiers plus the card brand, last four digits, expiry month/year and card type (credit/debit), and the billing name and address you enter, so that we can show the card to you and match receipts. For each receiving account we keep only Stripe’s account identifier and its readiness status; identity documents and bank details are collected and held by Stripe.

### Transaction records

For every payment we record the receipt number, date, amount, currency, the payer’s and recipient’s public profile names, the project, the card brand and last four digits, and the Stripe payment reference. These records, and the PDF receipts generated from them, are kept for as long as accounting, tax and anti-fraud rules reasonably require (normally up to seven years) even if an account is later deleted, after which they are deleted or anonymised. Receipt copies are stored on the Synapse server in a private folder.

### Protection of payment accounts

- Opening payment settings requires a fresh two-factor code and locks again when you leave the page; every payment also needs an active authenticator session.
- Up to seven paying accounts may be kept and up to five switched on at once; the same card cannot be added twice to one account. Up to five receiving accounts may be kept.
- Payments can be refused or reversed by Stripe or the card issuer (for example for suspected fraud); we may pause payment features for accounts that show fraud signals.

Funding links to other platforms (for example GitHub Sponsors or GoFundMe) leave Synapse; those platforms process that data under their own policies. Synapse still does not provide investment or securities services — the investor features are introductions only. See Terms → Payments, Donations & Sales.

## 14. AI & Data Access

You control whether AI systems may use your public content. Settings → **AI & data** offers more than ten switches — allow everything, titles and posts, descriptions, source code only, code with documentation, images only, video only, audio only, 3D only, documents, hardware files, comments, public profile, tags and statistics — and **all of them are off by default**. Each switch records the time it was turned on (set by our server); turning it off deletes that record and resets it.

Well-behaved AI crawlers identify themselves in their request headers. For those, our servers return only the categories you allowed, and refuse (with a “noai” signal) member content for which nothing is allowed. This is a technical control with a limit: it cannot stop a scraper that disguises itself, and once content is copied by others we cannot recall it. Public documents such as this Privacy Policy, the Terms, the license guide and the documentation are open to everyone, including AI systems, in complete plain-text and HTML editions (`/llms.txt`, `/llms-full.txt`, `/ai/*.md`).

**Evidence.** Ten days after you switch a category on, you may ask Synapse for a written statement, with supporting files, confirming that only the permitted data was accessed. You describe the request, accept short request terms and may attach files. The request goes directly to the operator console; the answer reaches you by email and in-app notification and can be read and downloaded (PDF) on a dedicated page. We use your request text and files only to answer it, and keep them with the answer for as long as the record is useful for your account.

## 15. Automated Moderation

Names, handles, titles and content are screened by automated rules for profanity, impersonation, hate, scams and unsafe material. A match can block a save, issue a time-limited warning, hide content, or — after an unresolved warning or repeated violations — suspend an account. These rules can be wrong. Every warning or suspension shows the reason and the evidence, and you may appeal; appeals are reviewed by a person. Trust levels influence how prominently content is ranked but do not carry legal effect.

## 16. Your Controls

- Edit or delete your profile, projects, comments and posts.
- Choose whether your email is public and whether you appear in the Network directory.
- Turn each notification type on or off (comments, likes, follows, messages, groups, workspace).
- Block members; report content or people.
- Change your password, enable two-factor authentication, and review or revoke active sessions.
- Export your data and delete your account.

## 17. Your Rights

Depending on where you live you may have the right to:

- **Access** a copy of the personal data we hold about you;
- **Correct** inaccurate or incomplete data;
- **Delete** your data, subject to the limits in “Account Deletion”;
- **Restrict or object** to certain processing;
- **Portability** — receive your data in a structured, machine-readable format;
- **Withdraw consent** at any time, without affecting earlier lawful processing;
- **Not be subject to solely automated decisions** with significant effect — you can always ask for human review of a moderation decision;
- **Complain** to a data-protection authority (see “Regional Notices”).

Most of these are self-service in Settings. For anything else, contact us (see below). We respond within 30 days and may need to verify your identity first. We do not charge for reasonable requests.

## 18. Retention Schedule

| Data | Kept for |
| --- | --- |
| Account, profile, content | Until you delete it or your account |
| Verification codes / reset links | 10 / 30 minutes, then purged |
| Session records | While active; revoked records kept up to 12 months as a security log |
| Security events and rate-limit records | Up to 90 days |
| Payment receipts and transaction records | As required for accounting and tax purposes (normally up to 7 years), then deleted or anonymised |
| AI-data settings and evidence requests | Settings until you delete your account; requests and answers as long as useful for your account |
| Email delivery log | Sent: 30 days · failed: 60 days |
| Link preview cache | Up to 14 days |
| View-dedupe events | About 2 days |
| Notifications | Until you clear them or delete your account |
| Warnings, bans and appeal evidence | Kept while relevant to safety and appeal integrity, then reviewed |
| Database backups | 14 days, then overwritten |

## 19. Account Deletion

Deleting your account (Settings → Account → Danger Zone) permanently removes your credentials, two-factor secret, sessions and profile. Content that belongs to shared conversations — for example a comment inside someone else’s thread — may remain, attributed to a removed member, so that discussions stay coherent; you can delete individual items first if you prefer. Records needed for safety (for example a ban, or evidence in a report) may be retained for as long as they are needed for that purpose. Data in backups disappears when the backup rotation completes, up to 14 days later.

## 20. Cookies & Local Storage

| Item | Purpose | Type |
| --- | --- | --- |
| Session cookie | Keeps you signed in | First-party, HttpOnly, strictly necessary |
| CSRF cookie | Protects write requests from forgery | First-party, strictly necessary |
| synapse_vid | Counts a view once per short window | First-party, HttpOnly |
| Local / session storage | Signed-in flag, UI preferences, cached link previews, unsent drafts | On your device only |
| Google sign-in | Only loaded on the sign-in pages if you use Google | Set by Google under its own policy |

There are no advertising, analytics-profiling or cross-site tracking cookies. Because only strictly necessary and first-party functional storage is used, no cookie banner is required.

## 21. Public Content & Search Engines

Public projects, profiles and posts can be seen by anyone and may be indexed by search engines and copied by others — we cannot recall content once it has been copied elsewhere. Pages shared to social networks show a preview built from the page’s public title, description and image. Do not post anything publicly that you want to keep private.

## 22. Data Breach Response

If a breach affects personal data we will investigate and contain it, notify affected members without undue delay, and notify the relevant authority within the time the law requires (72 hours under the GDPR and the Thai PDPA where notification is required), describing what happened, what data was involved, the likely consequences and what we are doing about it.

## 23. Children’s Privacy

Synapse is not directed at children under 13, and members must be at least 16 (or the age of digital consent where they live, if higher) unless a parent or guardian has agreed. If we learn we have collected data from a child below that age without valid consent, we will delete it. A parent who believes this has happened should contact us.

## 24. Regional Notices

### European Economic Area and United Kingdom

You have the rights listed above and may lodge a complaint with your local supervisory authority.

### Thailand

Under the PDPA you may request access, portability, objection, erasure, restriction and correction, and may complain to the Personal Data Protection Committee (PDPC) or its Office.

### California, United States

We do not sell or share personal information for cross-context behavioral advertising, and we use sensitive information only to provide the service. California residents may request access, correction and deletion, and will not be discriminated against for doing so.

## 25. Changes to This Policy

When we make a material change we update the date above and announce it in the product before it takes effect. Where the law requires your consent to a change, we will ask for it. Continuing to use Synapse after a change takes effect means you accept the updated policy where the law permits.

## 26. Contact & Complaints

Privacy requests: signed-in members can use **Feedback**; anyone can write to [privacy contact email]. Safety concerns: use **Report** on the item or profile. Data protection officer / representative: [if appointed]. If we haven’t resolved your concern, you may complain to your data-protection authority.
