# SYNAPSE — complete public documents (plain text for AI assistants) Source of truth: https://synapsehubs.net · Updated automatically at every build. --- # Privacy Policy > Synapse · SYN-LEGAL-PRIVACY-2026-09 · Last updated: 19 September 2026 · https://synapsehubs.net/privacy This Privacy Policy describes what personal data Synapse collects, why it is collected, the legal grounds relied on, who can see it, how long it is kept, how it is protected, and the choices and rights you have. It is written to match how the platform actually works — not a generic template — and it applies to every visitor and member of synapsehubs.net. ## The short version - Your data is stored on the operator’s own server (PostgreSQL on a private VPS). It is not handed to a database vendor, an email vendor, or an advertising network. - Email you receive from Synapse (verification codes, password resets) is sent by Synapse’s own mail server, signed with its own domain keys. - Passwords are bcrypt-hashed. Direct messages and the text of message notifications are encrypted at rest. Private settings are never returned to other members. - We do not sell personal data, show behavioral ads, or use your content to train third-party AI models. - Payments (donations and purchases) are processed by Stripe. Card and bank details go to Stripe only — never to Synapse’s servers or database. Payment accounts sit behind two-factor authentication. - You decide, category by category, whether AI systems may use your public content. Everything is off by default. - You can export your data, change notification and privacy settings, and delete your account from Settings. ## 1. Overview & Who We Are Synapse (“Synapse”, “we”, “us”) is a platform for publishing projects, solving problems together, joining groups, messaging, and networking with investor and company accounts. The service is operated by [operator legal name], [registered address] (the “Operator”), who is the data controller for personal data processed through the service. This policy should be read together with the Terms of Service, the Content License Guide, and the product Documentation. If a specific feature shows you a more specific privacy notice at the moment you use it, that notice also applies. ## 2. Scope & Definitions - **Personal data** — any information that identifies you or can reasonably be linked to you, such as your email address, handle, IP address, or the content you post under your account. - **Processing** — anything done with personal data: collecting, storing, displaying, analysing, sharing, or deleting it. - **Member** — a person with a Synapse account. **Visitor** — anyone browsing without an account. - **Public content** — anything you publish so that other members or visitors can see it (projects, public profile fields, group posts in public groups, comments, Network posts). This policy does not cover websites you reach through links posted by members; those sites have their own policies. ## 3. Information We Collect ### Account information - **Email address** — required for email accounts and used to verify the inbox with a one-time code. Private by default; shown on your profile only if you switch that on. - **Password** — stored only as a bcrypt hash. It is never logged or emailed. Google sign-in accounts have no Synapse password unless you set one. - **Account type and identity fields** — Developer, Investor or Company; display name, @handle and a public profile ID. - **Two-factor secret** — if you enable 2FA, the authenticator secret is stored in a dedicated table, separate from your profile. ### Profile information you choose to add Bio, avatar, cover image, skills, social links, and — for Investor and Company accounts — firm or company details, focus areas, team members and verification references. ### Content you create Projects and their files, problems, solutions, comments, group posts, direct messages, workspace revision history, Network posts, reports, appeals, feedback, and the metadata attached to them (timestamps, public content IDs, likes). ### Notifications When something happens that concerns you — a comment, reply, mention, like, follow, message, group activity — we store a notification record containing who did it, a short excerpt, and a link to the place it happened. ### Usage and technical data - **View events** — content ID, a first-party browser session key and a time stamp, used to count views without counting refreshes. - **Sessions** — random session ID, creation time, device/browser string and IP address, so “log out” actually revokes access and you can review your active sessions. - **Security events** — failed sign-ins, rate-limit hits and blocked requests (IP, time, reason), kept for a limited period. - **Server logs** — request paths, status codes and errors kept briefly for reliability and abuse response. ### Trust and moderation records Trust level, strikes, warnings, bans, soft-hide status, the text or screenshots involved in a decision, appeals you file, and safety reports you submit or that are filed about you. ### What we do not collect We never receive or store payment card numbers, CVC codes or bank account numbers (Stripe does — see “Payments & Financial Data”). We also do not collect precise location, contacts, microphone or camera data, or advertising identifiers. ## 4. Where Data Comes From - **You** — when you register, edit your profile, post, message, upload, report, or change settings. - **Google** — if you choose “Continue with Google”, Google tells us your verified email address and name. We do not receive your Google password. - **Other members** — content that mentions you, replies to you, follows you, messages you, or reports you. - **Your browser and device** — technical data sent with every request (IP address, browser type, language). ## 5. How We Use Information - Create and secure your account: registration, email verification, sign-in, password reset, two-factor authentication and session management. - Show your public profile and content to others according to your privacy settings. - Deliver notifications and messages you should receive, and let you control which kinds you get. - Send transactional email you need (verification codes, password resets, deletion confirmations). We do not send marketing email. - Generate link preview cards so a pasted link appears with its title, description and image. - Moderate content and names, enforce our Terms, handle appeals and protect members from abuse, spam and fraud. - Rank and recommend content using engagement, recency, completeness and author trust. - Maintain, back up, monitor and improve the reliability and performance of the service. - Comply with legal obligations and respond to lawful requests. **We do not sell personal data, and we do not use your content or personal information to train third-party AI models.** ## 6. Legal Bases for Processing Where the GDPR, UK GDPR, Thailand’s Personal Data Protection Act B.E. 2562 (PDPA) or a similar law applies, we rely on: | Purpose | Legal basis | | --- | --- | | Account, sign-in, content hosting, messaging, notifications | Performance of a contract with you | | Security, abuse prevention, moderation, rate limiting, backups | Legitimate interests (a safe, reliable service) | | Public email, optional profile fields, notification preferences | Your consent, which you can withdraw in Settings | | Record keeping, responding to lawful requests | Legal obligation | ## 7. Notifications & Email ### In-app notifications Notifications are created by the server when the action happens, so the person concerned always receives them regardless of the page it happened on. They respect your Settings (comments, likes, follows, messages, groups, workspace) and your block list. The excerpt inside a message notification is encrypted at rest like the message itself. ### Email Synapse sends email from its own mail server. Each message is queued in our database, delivered directly to your email provider, and signed with our domain’s DKIM key. We keep a delivery log (recipient, subject, status, error text) for up to 60 days to diagnose delivery problems. Your email provider (for example Gmail) will of course process the message once it arrives — that is governed by their policy. We send only service email: verification codes, password reset links and account-deletion confirmations. Reset links expire after 30 minutes and work once; codes expire after 10 minutes. ## 8. Link Previews When a comment, message or post contains a link, the Synapse server may fetch that page to read its public title, description and preview image, and shows them as a card. Fetches are made by our server, not your browser, so the site you link to sees our server’s address rather than yours. Results are cached in our database for a few days. Links to Synapse’s own pages are previewed from our database instead. Private, internal and non-public addresses are never fetched. ## 9. Where Your Data Lives The database, uploaded files, encryption keys, mail signing keys and backups are stored on a dedicated virtual private server operated by the Operator. Synapse no longer relies on a third-party managed database or a third-party email delivery API. Cloudflare provides DNS, TLS termination, caching and DDoS protection in front of the site, which means it necessarily sees traffic to and from the site as it passes through. Encrypted-at-rest fields (direct messages, notification excerpts, payout notes and wallet-type fields) use AES-256-GCM. Automated database backups are written to the same server on a schedule and kept for 14 days. ## 10. Sharing & Recipients - **Other members and visitors** — see what you make public. Your email, settings, blocked list and private data are not returned by the API to anyone but you. - **Google** — only if you use Google sign-in, and only for authentication. - **Cloudflare** — network edge and security provider as described above. - **Stripe Payments** — processes card payments, holds saved cards and receiving-account (payout) details, and performs identity verification for receiving accounts. Stripe acts as an independent controller for its own regulatory duties; see its privacy policy. - **The other party to a payment** — the member you pay (or who pays you) sees your public profile name, the amount and the receipt number, never your card or bank details. - **Sites you link to** — receive a request from our server when a preview is generated. - **Operators and moderators** — may access moderation tools, reports, warnings and limited directory fields needed for safety work. They cannot read your password. - **Authorities and advisers** — where required by law or valid legal process, or to protect the rights, safety and property of members, the public or the Operator. - **Successors** — if the service is transferred to another operator, data may move with it under the same protections, and you will be told. We do not sell or rent personal data, and we do not share it with advertisers or data brokers. ## 11. International Transfers Your data is stored on a server in [hosting country / region]. If you use Synapse from another country, your data is transferred to and processed in that location. Where the law requires a transfer mechanism (for example standard contractual clauses, or the safeguards in section 28 of the Thai PDPA) we rely on it. Traffic also passes through Cloudflare’s global network. ## 12. Security Measures ### Accounts and access - bcrypt password hashing; revocable server-side sessions; optional TOTP two-factor authentication; login throttling and lockouts. - HttpOnly session cookies with CSRF protection; strict CORS allow-list. - Ownership checks on every update and delete; direct messages and notifications visible only to their participants. ### Data protection - Sensitive fields encrypted at rest with AES-256-GCM; secrets never written to logs. - The database accepts connections only from the server itself (loopback), not the public internet. - Nightly encrypted-at-rest-disk backups with a 14-day rotation. ### Application hardening - Content-Security-Policy, HSTS, no-sniff, frame denial and a restrictive permissions policy. - Uploads restricted by type and size; risky file types served as inert text. - Link preview fetching is protected against server-side request forgery. - Rate limits on sign-in, writes, views, uploads and reports; automated abuse detection. No system is perfectly secure. Use a strong unique password and enable two-factor authentication. Product detail: Documentation → Security. ## 13. Payments & Financial Data ### What Stripe holds and what we keep Donations and purchases are paid with **Stripe**. Card numbers are typed into a secure form hosted by Stripe and go straight to Stripe; Synapse’s servers never receive, process or store card numbers, CVC codes or bank account numbers. For each paying account we keep only Stripe’s identifiers plus the card brand, last four digits, expiry month/year and card type (credit/debit), and the billing name and address you enter, so that we can show the card to you and match receipts. For each receiving account we keep only Stripe’s account identifier and its readiness status; identity documents and bank details are collected and held by Stripe. ### Transaction records For every payment we record the receipt number, date, amount, currency, the payer’s and recipient’s public profile names, the project, the card brand and last four digits, and the Stripe payment reference. These records, and the PDF receipts generated from them, are kept for as long as accounting, tax and anti-fraud rules reasonably require (normally up to seven years) even if an account is later deleted, after which they are deleted or anonymised. Receipt copies are stored on the Synapse server in a private folder. ### Protection of payment accounts - Opening payment settings requires a fresh two-factor code and locks again when you leave the page; every payment also needs an active authenticator session. - Up to seven paying accounts may be kept and up to five switched on at once; the same card cannot be added twice to one account. Up to five receiving accounts may be kept. - Payments can be refused or reversed by Stripe or the card issuer (for example for suspected fraud); we may pause payment features for accounts that show fraud signals. Funding links to other platforms (for example GitHub Sponsors or GoFundMe) leave Synapse; those platforms process that data under their own policies. Synapse still does not provide investment or securities services — the investor features are introductions only. See Terms → Payments, Donations & Sales. ## 14. AI & Data Access You control whether AI systems may use your public content. Settings → **AI & data** offers more than ten switches — allow everything, titles and posts, descriptions, source code only, code with documentation, images only, video only, audio only, 3D only, documents, hardware files, comments, public profile, tags and statistics — and **all of them are off by default**. Each switch records the time it was turned on (set by our server); turning it off deletes that record and resets it. Well-behaved AI crawlers identify themselves in their request headers. For those, our servers return only the categories you allowed, and refuse (with a “noai” signal) member content for which nothing is allowed. This is a technical control with a limit: it cannot stop a scraper that disguises itself, and once content is copied by others we cannot recall it. Public documents such as this Privacy Policy, the Terms, the license guide and the documentation are open to everyone, including AI systems, in complete plain-text and HTML editions (`/llms.txt`, `/llms-full.txt`, `/ai/*.md`). **Evidence.** Ten days after you switch a category on, you may ask Synapse for a written statement, with supporting files, confirming that only the permitted data was accessed. You describe the request, accept short request terms and may attach files. The request goes directly to the operator console; the answer reaches you by email and in-app notification and can be read and downloaded (PDF) on a dedicated page. We use your request text and files only to answer it, and keep them with the answer for as long as the record is useful for your account. ## 15. Automated Moderation Names, handles, titles and content are screened by automated rules for profanity, impersonation, hate, scams and unsafe material. A match can block a save, issue a time-limited warning, hide content, or — after an unresolved warning or repeated violations — suspend an account. These rules can be wrong. Every warning or suspension shows the reason and the evidence, and you may appeal; appeals are reviewed by a person. Trust levels influence how prominently content is ranked but do not carry legal effect. ## 16. Your Controls - Edit or delete your profile, projects, comments and posts. - Choose whether your email is public and whether you appear in the Network directory. - Turn each notification type on or off (comments, likes, follows, messages, groups, workspace). - Block members; report content or people. - Change your password, enable two-factor authentication, and review or revoke active sessions. - Export your data and delete your account. ## 17. Your Rights Depending on where you live you may have the right to: - **Access** a copy of the personal data we hold about you; - **Correct** inaccurate or incomplete data; - **Delete** your data, subject to the limits in “Account Deletion”; - **Restrict or object** to certain processing; - **Portability** — receive your data in a structured, machine-readable format; - **Withdraw consent** at any time, without affecting earlier lawful processing; - **Not be subject to solely automated decisions** with significant effect — you can always ask for human review of a moderation decision; - **Complain** to a data-protection authority (see “Regional Notices”). Most of these are self-service in Settings. For anything else, contact us (see below). We respond within 30 days and may need to verify your identity first. We do not charge for reasonable requests. ## 18. Retention Schedule | Data | Kept for | | --- | --- | | Account, profile, content | Until you delete it or your account | | Verification codes / reset links | 10 / 30 minutes, then purged | | Session records | While active; revoked records kept up to 12 months as a security log | | Security events and rate-limit records | Up to 90 days | | Payment receipts and transaction records | As required for accounting and tax purposes (normally up to 7 years), then deleted or anonymised | | AI-data settings and evidence requests | Settings until you delete your account; requests and answers as long as useful for your account | | Email delivery log | Sent: 30 days · failed: 60 days | | Link preview cache | Up to 14 days | | View-dedupe events | About 2 days | | Notifications | Until you clear them or delete your account | | Warnings, bans and appeal evidence | Kept while relevant to safety and appeal integrity, then reviewed | | Database backups | 14 days, then overwritten | ## 19. Account Deletion Deleting your account (Settings → Account → Danger Zone) permanently removes your credentials, two-factor secret, sessions and profile. Content that belongs to shared conversations — for example a comment inside someone else’s thread — may remain, attributed to a removed member, so that discussions stay coherent; you can delete individual items first if you prefer. Records needed for safety (for example a ban, or evidence in a report) may be retained for as long as they are needed for that purpose. Data in backups disappears when the backup rotation completes, up to 14 days later. ## 20. Cookies & Local Storage | Item | Purpose | Type | | --- | --- | --- | | Session cookie | Keeps you signed in | First-party, HttpOnly, strictly necessary | | CSRF cookie | Protects write requests from forgery | First-party, strictly necessary | | synapse_vid | Counts a view once per short window | First-party, HttpOnly | | Local / session storage | Signed-in flag, UI preferences, cached link previews, unsent drafts | On your device only | | Google sign-in | Only loaded on the sign-in pages if you use Google | Set by Google under its own policy | There are no advertising, analytics-profiling or cross-site tracking cookies. Because only strictly necessary and first-party functional storage is used, no cookie banner is required. ## 21. Public Content & Search Engines Public projects, profiles and posts can be seen by anyone and may be indexed by search engines and copied by others — we cannot recall content once it has been copied elsewhere. Pages shared to social networks show a preview built from the page’s public title, description and image. Do not post anything publicly that you want to keep private. ## 22. Data Breach Response If a breach affects personal data we will investigate and contain it, notify affected members without undue delay, and notify the relevant authority within the time the law requires (72 hours under the GDPR and the Thai PDPA where notification is required), describing what happened, what data was involved, the likely consequences and what we are doing about it. ## 23. Children’s Privacy Synapse is not directed at children under 13, and members must be at least 16 (or the age of digital consent where they live, if higher) unless a parent or guardian has agreed. If we learn we have collected data from a child below that age without valid consent, we will delete it. A parent who believes this has happened should contact us. ## 24. Regional Notices ### European Economic Area and United Kingdom You have the rights listed above and may lodge a complaint with your local supervisory authority. ### Thailand Under the PDPA you may request access, portability, objection, erasure, restriction and correction, and may complain to the Personal Data Protection Committee (PDPC) or its Office. ### California, United States We do not sell or share personal information for cross-context behavioral advertising, and we use sensitive information only to provide the service. California residents may request access, correction and deletion, and will not be discriminated against for doing so. ## 25. Changes to This Policy When we make a material change we update the date above and announce it in the product before it takes effect. Where the law requires your consent to a change, we will ask for it. Continuing to use Synapse after a change takes effect means you accept the updated policy where the law permits. ## 26. Contact & Complaints Privacy requests: signed-in members can use **Feedback**; anyone can write to [privacy contact email]. Safety concerns: use **Report** on the item or profile. Data protection officer / representative: [if appointed]. If we haven’t resolved your concern, you may complain to your data-protection authority. --- # Terms of Service > Synapse · SYN-LEGAL-TERMS-2026-09 · Last updated: 19 September 2026 · https://synapsehubs.net/terms These Terms of Service (“Terms”) are the agreement between you and the operator of Synapse (synapsehubs.net) covering the website, APIs, uploads, messaging, groups, notifications, and everything else offered through the service. Please read them carefully: by creating an account or using Synapse you agree to them. ## The short version - Synapse is a discovery and collaboration platform. Donations and purchases between members are processed by Stripe; Synapse is not a bank, broker, escrow agent or investment advisor and is not a party to what members agree between themselves. - You own what you upload. You give Synapse only the permission it needs to host and show it. The license you attach to a project decides what other members may do with it. - Be honest, lawful and respectful. Spam, impersonation, malware, harassment, infringement and scams are removed, and repeat or serious violations lead to suspension. - Automated safety checks exist, can be wrong, and every action can be appealed to a person. - Report copyright infringement using the process below; counter-notices are honoured. - The service is provided as-is; our liability is limited to the extent the law allows. ## 1. Acceptance of Terms These Terms form a binding agreement between you and [operator legal name] (the “Operator”). They apply together with the Privacy Policy, the Content License Guide, and any notice shown in the product that refers to them. If you do not agree, do not use the service. If you use Synapse for a company or other legal entity, you confirm that you have authority to bind it, and “you” includes that entity. ## 2. Definitions - **Service** — the Synapse website, APIs, apps and related features. - **Member Content** — anything a member submits: projects, files, problems, solutions, comments, posts, messages, profile data, reports and appeals. - **Public Content** — Member Content made visible to other members or visitors. - **Soft-hide** — making content inaccessible to the public while keeping it in storage, for example while its author is suspended. ## 3. Eligibility & Age - You must be at least 16 years old, or the age of digital consent where you live if higher, unless a parent or guardian has agreed to these Terms for you. - You must not be barred from using the Service under the laws that apply to you, and must not have been permanently suspended from Synapse before. - You must provide accurate registration information and keep it up to date. ## 4. The Service Synapse lets members publish projects, post problems and solutions, join groups, message each other, and use investor and company profiles to network. We may add, change, limit or remove features at any time. Some features (for example large uploads or the workspace editor) may be limited by size, rate, or account trust level to keep the service reliable for everyone. We work to keep the Service available but do not promise uninterrupted operation. Maintenance, upgrades, network problems and events beyond our control can cause downtime. ## 5. Accounts & Security - You are responsible for everything done through your account and for keeping your password and devices secure. Use a unique password and enable two-factor authentication. - Tell us promptly if you suspect unauthorized access. We may sign out all sessions and require a password reset. - One person, one account. You may not sell, rent or transfer an account, or create accounts to evade a suspension or a block. - We may verify your email address and may refuse or remove addresses that appear disposable, abusive or fraudulent. ## 6. Identity, Handles & Public IDs Display names, @handles and public IDs are how members recognise each other. You may not impersonate a person, company or brand, use a name intended to deceive, or use names that are hateful, sexual, or that promote violence. Handles are first-come, first-served and may be reclaimed if unused, misleading, or in breach of these Terms. Verified badges are granted only after review and can be removed if the underlying claims prove false. ## 7. Acceptable Use You agree not to: - Break the law or use the Service to plan or commit a crime. - Harass, threaten, stalk, dox or incite violence against anyone, or target people because of who they are. - Post spam, run engagement schemes, mass-message people, or use the Service to send unsolicited commercial communications. - Upload malware, exploit code aimed at users, phishing pages, or anything designed to damage or gain unauthorized access to systems or accounts. - Scrape, crawl, or copy the Service at a rate or in a way that burdens it, or bypass rate limits, access controls or moderation. - Manipulate likes, views, trust levels, rankings, reports or verification, including with bots or coordinated accounts. - Probe, scan or test the vulnerability of the Service except as allowed under “Security Research”. - Misrepresent your identity, affiliation, credentials, the state of a project, or funding you have or have not received. - Use the Service to solicit or offer investments, securities or payments in a way that breaks the law that applies to you. ## 8. Prohibited Content We remove, and may report to authorities, content that: - sexually exploits or endangers minors, or contains non-consensual intimate imagery; - contains credible threats, glorifies violence or terrorism, or promotes self-harm; - infringes intellectual property or trade-secret rights; - exposes private information (addresses, IDs, financial data, private messages) without consent; - is fraudulent, deceptive or a scam, including fake projects, fake investors, and fake verification; - is malicious software or links to it; - is illegal where you or the Operator are located. ## 9. Moderation, Trust & Soft-Hide To keep Synapse safe we use automated checks, member reports and human review. Depending on severity and history we may block a save, warn you with a deadline to fix something, reduce a piece of content’s visibility, remove it, or suspend an account temporarily or permanently. Members earn a trust level from age of account, contributions and clean history; trust affects ranking and some limits, and can go down after violations. While an account is suspended, its public content may be soft-hidden: it stays in storage but is not shown. If a group owner is suspended, that group is frozen until the suspension is lifted. Automated systems make mistakes — see “Suspension, Appeal & Termination” for how to challenge a decision. ## 10. Your Content & License to Us **You keep ownership** of everything you upload. To operate the Service you grant the Operator a worldwide, non-exclusive, royalty-free, sublicensable (only to service providers acting for us, such as hosting and network providers) license to host, store, back up, cache, reproduce, resize, transcode, display and distribute Member Content as needed to run and promote the Service — for instance to show a project to other members, to build link-preview cards, and to show a page preview when its link is shared elsewhere. This license lasts while the content is on the Service and for a reasonable time afterward in backups, and ends for anything you delete, except for copies others have lawfully made under the project’s license. You confirm that you have all rights required to upload the content and to grant the licenses in these Terms, that it does not infringe or violate anyone’s rights, and that any open-source components you include are used in line with their licenses. Your employer or client may own what you create at work — check before you post it. We do not use your content to train third-party AI models. Feedback and suggestions you send about the Service may be used by us without obligation to you. ## 11. Project Licenses Between Members When you publish a project you choose a license (for example MIT, Apache-2.0, GPL, Creative Commons, All Rights Reserved, or none). That license — not these Terms — governs what *other members and visitors* may do with your work, and is a separate legal relationship between you and them. Synapse shows the license and links to its text but is not a party to it and does not verify that you hold the rights you claim. Changing a license affects future recipients only; copies obtained under an earlier open license remain under that license. Read the Content License Guide before choosing one. ## 12. Groups & Collaboration Spaces - Group owners control settings, admit or remove members and may delete posts in their group. Owners are responsible for the conduct they allow and must follow these Terms. - An owner may **permanently delete the whole group**, which removes its posts and memberships; this cannot be undone from the product. - Private groups are visible only to members. Public groups appear in discovery subject to trust and soft-hide rules. - Workspaces and shared editing keep revision history so changes can be reviewed and reverted. Anything you contribute to someone else’s workspace is licensed as their project’s license provides. ## 13. Messages, Notifications & Email By using Synapse you agree to receive in-app notifications about activity that concerns you (comments, replies, mentions, likes, follows, messages, group and workspace activity) and service emails such as verification codes and password resets. You can turn most notification types off in Settings; security and account emails cannot be turned off while your account is active. Blocked members cannot notify you. We do not send marketing email. Direct messages are private between participants and encrypted at rest, but are not end-to-end encrypted: they can be reviewed if a report is filed, or where the law requires. ## 14. Links & Third-Party Content The Service shows links and previews of pages hosted by others. We do not control or endorse those pages, and previews may be out of date or inaccurate. You use third-party sites at your own risk and under their terms. Signing in with Google is governed by Google’s terms and privacy policy for that step. ## 15. API & Automated Access Our APIs exist to power the Synapse apps. You may not use them for automated bulk collection, to build a competing dataset, or to circumvent limits. Search-engine and link-preview crawlers that respect `robots.txt` are welcome. We may throttle or block traffic that harms the Service. ## 16. Security Research If you find a vulnerability, please report it privately through Feedback or the contact address below before disclosing it, do not access data that is not yours, do not degrade the service, and give us reasonable time to fix it. Good-faith research that follows these rules will not be treated as a violation of these Terms. ## 17. Platform Intellectual Property The Synapse name, logos, interface design, documentation and platform software (as distinct from Member Content) belong to the Operator or its licensors. These Terms give you no right to use Synapse branding without written permission. Open-source components in the software stay under their own licenses. Member project licenses do not change the license of the platform. ## 18. Copyright Notices & Takedowns Synapse respects intellectual property and expects members to do the same. If you believe content on Synapse infringes your copyright (including under the U.S. Digital Millennium Copyright Act, the Thai Copyright Act B.E. 2537, and similar laws), send a notice using **Report → Copyright** or to [copyright agent email] that includes: - your name, address, email and telephone number, and an electronic or physical signature; - identification of the copyrighted work you claim is infringed; - the exact location of the material (URL or public ID) so we can find it; - a statement that you have a good-faith belief the use is not authorized by the owner, its agent or the law; - a statement that the notice is accurate and, under penalty of perjury where applicable, that you are the owner or authorized to act for the owner. On receiving a valid notice we will act expeditiously to remove or disable access to the material, tell the member who posted it, and record the notice. Knowingly false notices can create liability for damages and legal costs. ## 19. Counter-Notices & Repeat Infringers If your content was removed and you believe that was a mistake or that you have the right to use it, you may send a counter-notice containing: - your name, address, email, telephone number and signature; - identification of the removed material and where it appeared; - a statement, under penalty of perjury where applicable, that you believe in good faith that it was removed by mistake or misidentification; - your consent to the jurisdiction of the courts in your location, and to accept service of process from the person who sent the original notice. We will pass the counter-notice to the complainant. Unless the complainant tells us within 10 business days that they have started legal action, we may restore the material. Accounts that are repeatedly and verifiably found to infringe will be terminated. ## 20. Trademarks & Other IP Complaints about trademarks, trade dress, privacy of publicity or similar rights should identify the right, the contested use and your authority to complain, and can be sent through the same channels. Synapse hosts member content and does not pre-clear uploads for conflicts with third-party rights. ## 21. Payments, Donations & Sales **Payments are processed by Stripe.** Synapse never sees or stores card numbers or bank details, does not hold members’ money, and is not a bank, payment institution, broker, exchange or escrow agent. Investments and fundraising for equity are not offered through Synapse. ### How payments work - A member may add paying accounts (cards) and receiving accounts (Stripe Connect accounts). Opening payment settings requires two-factor authentication; every payment needs a valid authenticator session and an explicit confirmation of the amount and these terms. - A project owner may switch on *donations* and/or a fixed-price *sale* and choose which receiving account is paid. A payment goes directly from the payer’s card to the chosen receiving account through Stripe. Synapse currently charges no platform fee; if that ever changes, the fee will be shown before you pay. - Each successful payment produces a receipt with a unique number that both parties can download. Totals shown on a project are calculated by the server from confirmed payments only and cannot be edited by members. ### Your responsibilities - You are responsible for the accuracy of what you offer, for delivering what you sell, and for your own taxes, licences, consumer-law and reporting duties. Stripe may require identity and business verification before you can be paid. - You may only use a card or account you are authorised to use. Fraud, money laundering, prohibited goods and services, or attempts to bypass limits result in immediate suspension and reporting where the law requires. - Donations are voluntary gifts and confer no ownership, equity, profit share or right to future work unless the recipient separately agrees so in writing. Unless the recipient agrees or the law requires otherwise, donations are non-refundable. For sales, refunds are governed by the seller’s stated terms and applicable consumer law; disputes and chargebacks are handled through Stripe and the card issuer. ### External funding links Links to GitHub Sponsors, GoFundMe, Kickstarter, Indiegogo, Open Collective, Patreon, Ko-fi, Buy Me a Coffee and Liberapay take you to those sites. Synapse does not process, verify or guarantee anything paid there; their terms apply. ### No advice, no guarantee - Synapse does not provide financial, investment, tax or legal advice and does not vet, endorse or guarantee any project, claim, investor, company or outcome. Do your own diligence. - Nothing on Synapse is an offer or solicitation to buy or sell securities. A funding goal or “seeking investors” tag is informational. - Never send money to someone who pressures you to pay off-platform. Report suspected scams. ### Limits and availability Up to seven paying accounts (five switched on at once) and five receiving accounts may be kept per member; a single donation is limited to 5,000 in the chosen currency. We may pause or restrict payment features to prevent fraud, comply with law, or at Stripe’s request, and payments depend on Stripe’s availability. ## 22. AI & Data Use Members choose in Settings → AI & data whether AI systems may use their public content, category by category; every option is off by default and can be reset by switching it off. Operators of AI systems that access Synapse must identify themselves, respect these choices and the site’s robots rules, and must not use Synapse to build datasets from content whose author has not allowed it. Synapse does not sell member content to AI companies and does not use it to train third-party models. Members may request written evidence about access to their data ten days after switching a category on, using the process described in the Privacy Policy. Public documents (Privacy, Terms, licenses, documentation) may be read in full by anyone, including AI systems. ## 23. Suspension, Appeal & Termination - **By you** — you can stop using Synapse and delete your account at any time in Settings. - **By us** — we may warn, restrict, suspend or terminate accounts, and remove content, for breach of these Terms, legal requirements, risk to others, or extended inactivity. Where practical we tell you what happened and why. - **Appeals** — a suspended member can submit an appeal with an explanation and evidence. A person reviews it, and we may reverse the decision. - **Effect** — on termination your right to use the Service ends. Sections that by their nature should survive (content licenses already granted, disclaimers, liability limits, indemnity, disputes) survive. ## 24. Disclaimers THE SERVICE AND ALL MEMBER CONTENT ARE PROVIDED “AS IS” AND “AS AVAILABLE”, WITHOUT WARRANTIES OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, NON-INFRINGEMENT, ACCURACY, AND UNINTERRUPTED OR ERROR-FREE OPERATION. We do not guarantee that content is accurate, safe, lawful or fit for your purpose, that files are free of malware, or that any member is who they say they are. Download and run files at your own risk. Some jurisdictions do not allow certain disclaimers, so parts of this section may not apply to you. ## 25. Limitation of Liability TO THE FULLEST EXTENT PERMITTED BY LAW, THE OPERATOR AND ITS AFFILIATES, PERSONNEL AND SERVICE PROVIDERS WILL NOT BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY OR PUNITIVE DAMAGES, OR FOR LOSS OF PROFITS, REVENUE, DATA, GOODWILL OR OPPORTUNITY, ARISING FROM YOUR USE OF (OR INABILITY TO USE) THE SERVICE, MEMBER CONTENT, OR DEALINGS WITH OTHER MEMBERS. OUR TOTAL LIABILITY FOR ANY CLAIM RELATED TO THE SERVICE WILL NOT EXCEED THE GREATER OF THE AMOUNT YOU PAID US IN THE 12 MONTHS BEFORE THE CLAIM (WHICH IS ZERO FOR A FREE ACCOUNT) AND USD 100. Nothing here limits liability that cannot be limited by law, such as for fraud or for death or personal injury caused by negligence. ## 26. Indemnification You will defend and indemnify the Operator and its personnel against claims, damages, losses and reasonable legal fees arising from your Member Content, your breach of these Terms or the law, or your infringement of another person’s rights — except to the extent caused by the Operator’s own wrongdoing. ## 27. Dispute Resolution Before starting a formal claim, please contact us and give us 30 days to try to resolve it informally. Disputes that cannot be settled will be handled in the courts described under “Governing Law”. To the extent the law allows, claims must be brought individually, not as a class or representative action, and within two years of when the claim arose. Consumers keep any mandatory rights they have under the law of the country where they live. ## 28. Changes to These Terms We may update these Terms. For material changes we will update the date above and give notice in the product before they take effect (normally at least 14 days). If you keep using the Service after the effective date, you accept the new Terms; if you do not accept them, stop using the Service and delete your account. ## 29. Governing Law These Terms are governed by the laws of [Kingdom of Thailand / operator’s jurisdiction], without regard to conflict-of-law rules, and the courts of [operator’s city/country] have exclusive jurisdiction, subject to any mandatory consumer protections that apply where you live. ## 30. General Provisions - **Entire agreement** — these Terms, the Privacy Policy and referenced notices are the whole agreement about the Service. - **Severability** — if a provision is unenforceable, the rest stays in force. - **No waiver** — not enforcing a right is not giving it up. - **Assignment** — you may not assign these Terms; the Operator may, including to a successor operator of the Service. - **Force majeure** — neither side is liable for failure caused by events beyond reasonable control. - **Language** — if this document is translated, the English version prevails where the law permits. ## 31. Contact Questions about these Terms: use **Feedback** when signed in, or write to [legal contact email]. Copyright notices: [copyright agent email]. Safety issues: use **Report** on the item or profile. --- # Content License Guide > Synapse · SYN-LEGAL-LICENSES-2026-09 · Last updated: 19 September 2026 · https://synapsehubs.net/licenses Every public project, problem and post on Synapse should say what other people may do with it. This guide explains the license types offered and contains the full text of each. ## 1. How licensing works on Synapse - Publishing does not give Synapse ownership of your work. It only hosts it under the terms you attach. - Viewing on the site is allowed. Download, fork, commercial use and modification follow the license text, not the card summary. - Custom and proprietary licenses are only as strong as the terms you write. Empty custom terms mean no license is granted. - These drafts are starting points, not legal advice. If the work is valuable, consult a lawyer in your country. ## 2. License families ### Keep the work closed All Rights Reserved and Proprietary. Viewers can read it on Synapse. Copying, reuse, or commercial use needs your written permission unless you write extra terms. New posts start here. ### No license attached No license is an explicit choice that you are not offering a grant. People may view the post. They do not get permission to copy or reuse the work unless the law already allows it or you grant rights later. It is not the same label as All Rights Reserved, but reuse is still not granted. ### Permissive open licenses MIT, Apache 2.0, and BSD 2-Clause. Others may use, change, and ship the work, including commercially, if they keep the copyright notice and any extra conditions (Apache also grants patents and asks you to mark changes). ### Copyleft and share-alike GNU GPL v3 and CC BY-SA 4.0. Others may build on the work, but what they distribute must stay under the same family of terms. ### Creative Commons for media and writing CC BY, CC BY-SA, CC BY-NC, and CC0. These fit images, docs, and datasets better than software. CC BY-NC forbids commercial reuse. CC0 waives copyright as far as the law allows. ## 3. At a glance | Type | Copy & use | Commercial use | Credit required | Share-alike | | --- | --- | --- | --- | --- | | All Rights Reserved / none | Only with permission | Only with permission | n/a | n/a | | MIT, BSD-2-Clause | Yes | Yes | Keep notice | No | | Apache-2.0 | Yes, with patent grant | Yes | Keep notice, state changes | No | | GNU GPL v3 | Yes | Yes | Keep notice | Yes | | CC BY 4.0 | Yes | Yes | Yes | No | | CC BY-SA 4.0 | Yes | Yes | Yes | Yes | | CC BY-NC 4.0 | Yes | No | Yes | No | | CC0 | Yes | Yes | No | No | ## 4. Choosing well - Software you want people to adopt: MIT or Apache-2.0 (choose Apache-2.0 if patents matter). - Software that must stay open: GNU GPL v3. - Art, writing, datasets and 3D models: a Creative Commons license (avoid CC licenses for software). - A business you plan to sell: keep All Rights Reserved and grant permission case by case. - Code you did not write entirely: you can only license what you own; keep third-party code under its own license. - Employer or client work: check your contract, they may own it. - Open licenses are hard to take back: recipients keep their rights if you later change the license. ## 5. All Rights Reserved (UNLICENSED) You keep every right. Others may view the work on Synapse but may not copy, modify, distribute, or use it — including commercially — without your explicit written permission. ### What this allows - You keep full copyright and all related rights. - Viewing on Synapse is allowed; reuse is not. - Any copy, modification, or commercial use needs your written permission. ### Full license text ``` ALL RIGHTS RESERVED Copyright (c) [year] [copyright holder]. All rights in this work are reserved by the copyright holder. Except for viewing this work on the platform where it was published, no person may copy, reproduce, distribute, publicly display, modify, adapt, translate, create derivative works from, sublicense, or commercially exploit this work, in whole or in part, in any medium, without the prior written permission of the copyright holder. This notice does not grant any implied license. Any permission granted in writing is limited to the scope stated in that writing and may be revoked if those terms are breached. THE WORK IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED. THE COPYRIGHT HOLDER SHALL NOT BE LIABLE FOR ANY CLAIM, DAMAGES, OR OTHER LIABILITY ARISING FROM THE WORK. ``` ## 6. No license (NOASSERTION) You are not attaching a license. People may view the post on Synapse. They do not get permission to copy, modify, ship, or use the work unless the law already allows it (for example fair use) or you later grant rights in writing. ### What this allows - No license is granted by this post. - Viewing on Synapse is allowed. - Reuse, copies, and commercial use are not permitted unless you grant them separately. - You can switch to All Rights Reserved or an open license later. ### Full license text ``` NO LICENSE Copyright (c) [year] [copyright holder]. The author has not offered a license for this work. Publication on this platform lets others view the work there. It does not grant a copyright license to copy, modify, distribute, publicly perform, sublicense, or commercially exploit the work. If you want to use this work beyond viewing it on the platform, contact the author and obtain permission in writing. Until a license is attached, treat the work as unlicensed. This notice is not legal advice and does not waive any rights the author may have. THE WORK IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND. ``` ## 7. MIT License (MIT) A short permissive license. Anyone may use, copy, modify, merge, publish, and sell the work, including commercially, if they keep the copyright notice and license text. Provided as-is, with no warranty. ### What this allows - Commercial use, modification, distribution, and private use are allowed. - The copyright notice and this license must be kept in copies. - No warranty or liability is accepted by the author. ### Full license text ``` MIT License Copyright (c) [year] [copyright holder] Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions: The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software. THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. ``` ## 8. GNU GPL v3 (GPL-3.0-only) Strong copyleft. Anyone may run, study, share, and change the work, including commercially, but distributed modifications must also be licensed under GPL v3 and the corresponding source must be offered. Official text: https://www.gnu.org/licenses/gpl-3.0.html ### What this allows - You may run, study, share, and change the work. - Distributed derivatives must be licensed under GPL v3. - Corresponding source must be offered with binaries. - No additional restrictions may be imposed. ### Full license text ``` GNU GENERAL PUBLIC LICENSE Version 3, 29 June 2007 Copyright (c) [year] [copyright holder] This program is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation, version 3. This program is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details. You should have received a copy of the GNU General Public License along with this program. If not, see . Summary of the freedoms and conditions (the official legal code is the GNU GPL v3 published by the Free Software Foundation): 0. Definitions. "The Program" is this work. "Covered work" means the Program or a work based on it. "Corresponding Source" is the source needed to generate, install, and run the object code and to modify the work. 1. Basic permissions. You may run the unmodified Program. You may make, run, and propagate covered works that you do not convey, without conditions, as long as your license remains in force. 2. Conveying verbatim copies. You may convey verbatim copies of the Program's source, in any medium, provided you conspicuously publish an appropriate copyright notice, keep intact license and warranty notices, and give all recipients a copy of this License along with the Program. 3. Conveying modified versions. You may convey a work based on the Program under section 2, provided the work carries prominent notices that you modified it and the date, that it is released under this License, and the entire work is licensed as a whole under this License to anyone who comes into possession of a copy. 4. Conveying non-source forms. You may convey a covered work in object code form if you also convey the machine-readable Corresponding Source under the terms of this License, in one of the ways required by GPL v3 section 6 (accompany the source, offer it in writing for at least three years, or use a network server). 5. Additional terms and patents. You may not impose further restrictions. Each contributor grants a non-exclusive, worldwide, royalty-free patent license for essential patent claims to make, use, sell, offer for sale, import, and otherwise run, modify, and propagate the contents of its contributor version. 6. Termination. Any attempt to copy, modify, sublicense, or convey other than as expressly provided voids your rights. Licenses of downstream recipients are not terminated if they remain in compliance. THE PROGRAM IS PROVIDED "AS IS". THE ENTIRE RISK AS TO THE QUALITY AND PERFORMANCE OF THE PROGRAM IS WITH YOU. The binding legal text is the GNU General Public License, version 3, published by the Free Software Foundation at https://www.gnu.org/licenses/gpl-3.0.html. ``` ## 9. Apache License 2.0 (Apache-2.0) Permissive like MIT, plus an express patent license from contributors, a requirement to state significant changes, and NOTICE-file preservation. Official text: https://www.apache.org/licenses/LICENSE-2.0 ### What this allows - Commercial use, modification, and distribution are allowed. - Contributors grant a patent license for their contributions. - Keep the license, state significant changes, and preserve NOTICE. - No trademark rights are granted. ### Full license text ``` Apache License Version 2.0, January 2004 http://www.apache.org/licenses/ Copyright [year] [copyright holder] Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0 Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License. Operative terms (the official legal code is Apache License 2.0): 1. Grant of Copyright License. Each Contributor grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare Derivative Works of, publicly display, publicly perform, sublicense, and distribute the Work and such Derivative Works in Source or Object form. 2. Grant of Patent License. Each Contributor grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable (except as stated) patent license to make, have made, use, offer to sell, sell, import, and otherwise transfer the Work, where such license applies only to patent claims licensable by such Contributor that are necessarily infringed by their Contribution(s) alone or by combination of their Contribution(s) with the Work. If you institute patent litigation, the patent licenses granted to you under this License terminate as of the date such litigation is filed. 3. Redistribution. You may reproduce and distribute copies of the Work or Derivative Works in any medium, with or without modifications, provided you give any other recipients a copy of this License; cause modified files to carry prominent notices stating that you changed the files; retain all copyright, patent, trademark, and attribution notices from the Source form; and, if the Work includes a NOTICE file, include a readable copy of the attribution notices within Derivative Works as required by the License. 4. Submission of Contributions. Unless you explicitly state otherwise, any Contribution intentionally submitted for inclusion in the Work is under the terms of this License. 5. Trademarks. This License does not grant permission to use the trade names, trademarks, service marks, or product names of the Licensor, except as required for reasonable and customary use in describing the origin of the Work. 6. Disclaimer and Limitation. THE WORK IS PROVIDED "AS IS", WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND. IN NO EVENT SHALL ANY CONTRIBUTOR BE LIABLE FOR ANY DAMAGES OF ANY CHARACTER ARISING AS A RESULT OF THIS LICENSE OR OUT OF THE USE OR INABILITY TO USE THE WORK. The binding legal text is the Apache License, Version 2.0, at https://www.apache.org/licenses/LICENSE-2.0. ``` ## 10. BSD 2-Clause (BSD-2-Clause) A short permissive license. Anyone may use, copy, modify, and distribute the work, including commercially, if they keep the copyright notice and this license text. ### What this allows - Commercial use, modification, and distribution are allowed. - Keep the copyright notice and license text. - No warranty or liability is accepted. ### Full license text ``` BSD 2-Clause License Copyright (c) [year] [copyright holder] Redistribution and use in source and binary forms, with or without modification, are permitted provided that the following conditions are met: 1. Redistributions of source code must retain the above copyright notice, this list of conditions and the following disclaimer. 2. Redistributions in binary form must reproduce the above copyright notice, this list of conditions and the following disclaimer in the documentation and/or other materials provided with the distribution. THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. ``` ## 11. CC BY 4.0 (CC-BY-4.0) Anyone may share and adapt the work for any purpose, including commercially, if they give appropriate credit, provide a link to the license, and indicate if changes were made. Official deed: https://creativecommons.org/licenses/by/4.0/ ### What this allows - Sharing and adaptation are allowed, including commercially. - Credit the author and link to CC BY 4.0. - Indicate if changes were made. No extra legal terms that restrict the license. ### Full license text ``` Creative Commons Attribution 4.0 International Copyright (c) [year] [copyright holder] This work is licensed under the Creative Commons Attribution 4.0 International License. You are free to: Share — copy and redistribute the material in any medium or format. Adapt — remix, transform, and build upon the material for any purpose, even commercially. The licensor cannot revoke these freedoms as long as you follow the license terms. Under the following terms: Attribution — You must give appropriate credit, provide a link to the license, and indicate if changes were made. You may do so in any reasonable manner, but not in any way that suggests the licensor endorses you or your use. No additional restrictions — You may not apply legal terms or technological measures that legally restrict others from doing anything the license permits. No warranties are given. The license may not give you all permissions necessary for your intended use (for example, publicity, privacy, or moral rights may still apply). The binding legal code is CC BY 4.0: https://creativecommons.org/licenses/by/4.0/legalcode ``` ## 12. CC BY-SA 4.0 (CC-BY-SA-4.0) Same as CC BY, plus share-alike: adaptations must be licensed under CC BY-SA 4.0 (or a compatible license). Official deed: https://creativecommons.org/licenses/by-sa/4.0/ ### What this allows - Sharing and adaptation are allowed, including commercially. - Credit the author and link to CC BY-SA 4.0. - Adaptations must use the same license (share-alike). ### Full license text ``` Creative Commons Attribution-ShareAlike 4.0 International Copyright (c) [year] [copyright holder] This work is licensed under the Creative Commons Attribution-ShareAlike 4.0 International License. You are free to share and adapt the material for any purpose, even commercially, under these terms: Attribution — Give appropriate credit, provide a link to the license, and indicate if changes were made. ShareAlike — If you remix, transform, or build upon the material, you must distribute your contributions under the same license as the original. No additional restrictions — You may not apply legal terms or technological measures that legally restrict others from doing anything the license permits. No warranties are given. The binding legal code is CC BY-SA 4.0: https://creativecommons.org/licenses/by-sa/4.0/legalcode ``` ## 13. CC BY-NC 4.0 (CC-BY-NC-4.0) Anyone may share and adapt the work with attribution, but only for non-commercial purposes. Commercial use needs a separate permission. Official deed: https://creativecommons.org/licenses/by-nc/4.0/ ### What this allows - Sharing and adaptation are allowed for non-commercial purposes. - Credit the author and link to CC BY-NC 4.0. - Commercial use requires a separate written permission. ### Full license text ``` Creative Commons Attribution-NonCommercial 4.0 International Copyright (c) [year] [copyright holder] This work is licensed under the Creative Commons Attribution-NonCommercial 4.0 International License. You are free to share and adapt the material under these terms: Attribution — Give appropriate credit, provide a link to the license, and indicate if changes were made. NonCommercial — You may not use the material for commercial purposes. No additional restrictions — You may not apply legal terms or technological measures that legally restrict others from doing anything the license permits. No warranties are given. The binding legal code is CC BY-NC 4.0: https://creativecommons.org/licenses/by-nc/4.0/legalcode ``` ## 14. CC0 1.0 (Public Domain) (CC0-1.0) You waive copyright and related rights to the fullest extent allowed by law. Anyone may use the work for any purpose, including commercially, with no attribution required. Official statement: https://creativecommons.org/publicdomain/zero/1.0/ ### What this allows - All copyright and related rights are waived to the extent allowed. - Anyone may use the work for any purpose, including commercially. - Attribution is appreciated but not required. ### Full license text ``` CC0 1.0 Universal [copyright holder], [year] The person who associated a work with this deed has dedicated the work to the public domain by waiving all of his or her rights to the work worldwide under copyright law, including all related and neighboring rights, to the extent allowed by law. You can copy, modify, distribute and perform the work, even for commercial purposes, all without asking permission. In no way are any of the following rights affected by CC0: — Patent or trademark rights held by the person who associated them with this work. — Rights other persons may have in the work or in how the work is used, such as publicity or privacy rights. Unless expressly stated otherwise, the person who associated a work with this deed makes no warranties about the work, and disclaims liability for all uses of the work, to the fullest extent permitted by applicable law. The binding legal code is CC0 1.0: https://creativecommons.org/publicdomain/zero/1.0/legalcode ``` ## 15. Proprietary (LicenseRef-Proprietary) You keep ownership and grant only the rights you write below. Use this for paid or negotiated licenses. The draft is a starting point — edit it so it matches what buyers may actually do. ### What this allows - The author keeps ownership of the work. - Only the rights written in the project terms are granted. - All other rights remain reserved. ### Full license text ``` PROPRIETARY LICENSE Copyright (c) [year] [copyright holder]. All rights reserved. This work is proprietary. Title and all intellectual-property rights remain with the copyright holder. Subject to payment of any applicable fees and to the project terms attached to this work, the copyright holder grants the licensee a limited, non-exclusive, non-transferable, non-sublicensable license to use the work solely as described in those project terms. Except as expressly granted in writing: (a) no copy, modification, distribution, public performance, or derivative work is permitted; (b) no license is granted under any patent, trademark, or other right by implication or estoppel; (c) confidential information in the work must not be disclosed. This license terminates automatically if the licensee breaches it. Upon termination the licensee must stop using the work and destroy copies in its possession, except as required by law. THE WORK IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT. IN NO EVENT SHALL THE COPYRIGHT HOLDER BE LIABLE FOR ANY CLAIM, DAMAGES, OR OTHER LIABILITY ARISING FROM THE WORK. ``` ## 16. Custom License (LicenseRef-Custom) Use this when no standard license fits. Start from the draft, then rewrite the grant, restrictions, and disclaimer so they say exactly what you allow. ### What this allows - Only the terms you write below apply. - Until you publish terms, treat the work as all rights reserved. - Say clearly what is allowed, what is forbidden, and who is liable. ### Full license text ``` CUSTOM LICENSE Copyright (c) [year] [copyright holder]. The project terms attached to this work are the license. If those terms are empty, no license is granted and all rights remain reserved. Where the project terms are silent, the following default rules apply: — no right is granted by implication; — copyright and related rights stay with the author; — THE WORK IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND. ``` --- # Synapse Platform Documentation > Synapse · SYN-DOCS · Last updated: 19 September 2026 · https://synapsehubs.net/docs Complete reference for accounts, publishing, supported file formats, security, sandbox behaviour and usage guidelines. ## Getting started First visit → useful account Synapse is a members site for publishing projects, posting problems, joining groups, browsing Network posts (investor / company), and messaging other people. This instance does **not process payments** — there is no donate, checkout, or express-interest flow. Create an account Gmail + password (confirm a 6-digit email code) or Continue with Google. Finish onboarding Pick Developer, Investor, or Company. Set a public display name. You get a unique @handle and an 8-character profile ID. Use the header Create / Archive / Problems / Groups / Network / Messages. Turn on 2FA in Settings → Security. Start publishing from Create. Discover work on Archive. Need the rules that bind the site? See Terms and Privacy. ## Accounts & identity What others see vs what stays private Public profile Display name, optional avatar & banner, bio, skills, @handle, and profile ID. URLs look like `/u/yourhandle` and `/id/ABCD2345`. Email stays private unless you turn on “show email” in Settings. Unsafe display names are blocked on save; mild hits open a 1-day warning, severe hits can suspend immediately. Groups show a public ID like `G-XXXXXXXX`. Account types **Developer** — publish projects and problems. **Investor / Company** — org profile, optional Network directory listing, verification request flow (review is operator-side). Payments stay locked. Sign-in methods Email accounts use a password (stored only as a bcrypt hash). Google accounts never share your Google password with Synapse. Either kind can enable an authenticator app (TOTP) in Settings. You can list and revoke sessions from other devices. Team / org helpers Investor and company profiles can invite team members on the org card. Team roles are for collaboration on that profile — they do not bypass ownership of projects you personally created. ## Projects & publishing Creator Studio — what visitors actually get Create is a multi-step wizard: basics → media & files → documentation → license & links → review. On media and later steps you get a **live preview** of the public page (hero / sandbox and docs) before you publish. How files are attached **ZIP** → stored as attachment URLs. **Folder upload** → a browsable `file_tree` (junk folders like `node_modules` / `.venv` are skipped). Loose files are fine for covers, videos, and one-off downloads. Default max is **300 MB per file**, **1.2GB for video**, and **300 MB for a 3D model** (one per upload) — unless the operator changed these. Format chips on Create are discovery tags (40+). See Files & previews for upload vs Synapse render vs download-only. What visitors see A display plan picks the hero (video, cover, gallery, interactive 3D, audio, or Synapse sandbox). You can override that in the wizard. Overview renders Markdown docs. Files tab shows README (if present), the source tree, and downloads when you allow them. HTML / JS are listed as source by default — a standalone `.html` file can also be opened with a "Run (sandboxed)" toggle, which plays it inside an isolated sandbox with no access to Synapse's cookies, session, or API. Installers (.exe/.msi/.apk) and archives stay download-only — they can never run inside Synapse at all, only after you download and install them yourself. License & comments You keep ownership. The license you pick is what others may do with that work — choose carefully (license index). Comments can be turned off per project. When on, threads appear under Discussion with types like feedback, question, and bug report. Draft vs published Save draft or publish from the last step. Edit later with `/create?edit=…` from your project page when you are the owner. Synapse does **not process payments**. A listed price or “looking for investors” tag is discovery only. ## Write-ups & Markdown What “Copy Markdown link” is for — and what actually renders Every public project has an About write-up. You type it in Create (or optionally override with a chosen .md file). That text is Markdown: headings, lists, tables, images from your files, `#tags`, and diagrams. Raw HTML and JavaScript in a write-up are **not executed**. Copy Markdown link (the ⋮ menu) On a post such as CodeMind-architecture-AI, the kebab copies a snippet like `[CodeMind-architecture-AI](…/project/…)`. **What it is for:** paste that into another project’s write-up, a README, a group post, or a comment. Synapse turns the title into a clickable chip (labeled Project) that opens that post in the app — not a raw website address. **What it is not:** it is not a download, not a license grant, not an embed of the other project’s files, and not a secret admin URL. Copy page link vs Markdown link **Copy page link** — a normal URL for chat, email, or another website. **Copy Markdown link** — the title plus URL in Markdown form, for write-ups and comments on Synapse (and any other Markdown editor that understands `[text](url)`). What you can write Headings with ##. Lists and tables. Images that point at files you uploaded. `#LLM`-style tags that link to Archive search. Diagrams: a fenced block starting with mermaid (flowcharts, sequence, class, and similar). Synapse draws them in the sandbox theme. Same-site links to projects, problems, groups, and profiles stay inside the app. Off-site http(s) links open in a new tab and are checked so javascript: URLs never become buttons. Where it shows up Overview on the public post, README in Files when you pick one, comments and replies, Network posts, group posts, and problem write-ups. Comments: paste the Markdown snippet and it becomes a Project chip with the title you copied — so a name like CodeMind-architecture-AI is the label, not a hostname. ## Problems, groups, Network & investors The rest of the product, as it ships today Problems & workspace Post a problem with files, then open the in-browser workspace to edit text, preview media, and keep revision history of saves. Formal solutions live under Solutions; Discussion is for questions and hints. Collaborator saves can ping the owner (Settings → Workspace edits). Groups Create or join a group, post in the feed, reply in threads. Each group gets a short public ID (G-XXXXXXXX). Owners manage members and settings. Joining someone else’s group can notify the owner. Unsafe group names are blocked on save. Network posts Investor / company posts (jobs, RFPs, etc.) use a full-page editor with scheduling when allowed. Public detail pages render Markdown. Verification is a request + operator review — not a paid badge store. Direct messages One-to-one chat. Conversations refresh by short polling (and push when the connection allows). You can edit or delete your own messages. Blocking stops new DMs both ways. Message alerts respect Settings → Messages. Follows Follow other members. Follower / following lists live on each profile. A new follow can notify the person you followed, unless they turned Follows off in Settings. Investors page Pipeline of posts marked as seeking capital, plus signals you sent or received. Charts are activity snapshots. Payment buttons stay locked; reported “raised” figures are not escrowed money. Notifications The bell lists follows, likes, comments, messages, group joins/mentions, and workspace edits. Filter on the full inbox. You can turn each category off in Settings. You are never notified about your own actions. Money features (locked) Donation and express-interest buttons are disabled platform-wide. Figures on a project are not live balances. Any real money talk is off-site and your responsibility under the law that applies to you. ## Views, likes, comments & alerts How counts, discussion, and the bell behave Views (YouTube-like, not forever-once) Opening a project or problem page records a view. The same browser can count again after a short cooldown (about **20 seconds**) so refreshes do not spam the counter, but returning later still increments. Viewers are identified with a small **session cookie** (`synapse_vid`), not by “logged-in user may only ever count once.” Different browsers / devices count separately. Counts on cards and detail pages stay in sync across the site via a lightweight live feed (and short polls when push is unavailable). Likes Likes require sign-in. Toggling like updates the count for everyone watching that item. There is no separate analytics product or third-party tracker. Comments On projects (when enabled) and problems, comments support types, replies, likes, edit/delete of your own posts, and optional pasted images. Paste a Markdown link copied from another post — it becomes a titled Project chip, not a hostname. #tags link to Archive search. New comments show up for others within a few seconds (poll backup if live push cannot connect). Notifications (bell) Follows, likes, comments, messages, group joins/mentions, and workspace saves. The dropdown is a short preview; /notifications is the full inbox with filters. Each category has a switch in Settings. System notices (warnings, suspensions) still arrive. Duplicate pings from the same action are folded so the bell stays light. What views are not Not ad impressions, not a paid ranking product, not sold to advertisers. Operators may use aggregates for moderation and capacity — not for selling your browsing history. Automatic safety (names & content) Profile names, handles, group names, project/problem titles, Network post titles, org firm/company names, comments, group posts, and messages are checked on every save. Mild / general hits: warn first (1–2 day fix window), then escalate if still unsafe. Severe hits (hate, threats, sexual, scam, child-safety): **immediate suspension**with durations based on severity (including permanent). A background scan also scrubs legacy bad labels. ## Files & previews 57+ Create tags · three different meanings of “supported” “Supported” on Synapse is not one switch. Create’s format chips are **discovery tags**(57 options today) — they describe what is in the project. Separately, the upload API accepts almost any project file (default **300 MB** for most files, **1.2GB** for video, and **300 MB** for a 3D model — one model per upload). Preview is a third story: only some extensions go through **Synapse’s own renderers**; the rest still upload and download. 1 · Upload / store Bytes land on disk or object storage. Only a tiny set of browser page types is blocked (.xhtml, .shtml, .swf, .hta). HTML/JS/SVG still upload for IDE use but are served as text so they cannot run as pages. 2 · Synapse render Our gallery, video/audio players, PDF embed, Three.js 3D (GLB/GLTF/OBJ/FBX/STL), and the custom sandbox (RTL maps, SPICE, Markdown, highlighted code). 3 · Download-only Installers, archives, CAD packages, Blender, Unity packages, spreadsheets, and many other tags — listed in the tree / downloads, opened with your tools. How Synapse’s preview pipeline works Opens with Synapse’s own viewers (gallery, video, audio, PDF, interactive 3D). Processed by Synapse’s post sandbox — hardware maps, circuits, docs, highlighted code. Also previewed (beyond Create tags) AVIF / HEIC / BMP / ICO — Image gallery when decodable. MKV / M4V / AVI — Video if the browser can play the codec. M4A — Audio controls. YouTube URL — Embedded via youtube-nocookie. Sandbox extras (folder / IDE files) V / SV / VHDL / VHD — RTL → Synapse hardware module map + source. CIR / SPICE / SP / SCH — Circuit netlist → Synapse circuit summary + source. PY / RS / GO / JAVA / C / C++ / … — Syntax-highlighted code pane (many languages). YAML / XML / TOML / TSV — Data / config text preview. MDX / RST / ADOC — Document-style text / markdown family. Labels: Renders in Synapse · Synapse sandbox · Source / text preview · Upload & download. Interactive 3D today = GLB, GLTF, OBJ, FBX, STL. Other 3D tags still upload. ## Speed, cache & storage Why pages should feel light — without listing servers One origin, hashed assets The public site and API share one host. JavaScript/CSS filenames include a content hash and are cached for a long time. HTML is not cached, so a deploy shows up on the next visit. Compression API and page responses are compressed when the browser asks. Live stats streams are left uncompressed so they are not delayed. Uploads Files land on this instance’s disk, or object storage if the operator configured it. Unique filenames can be cached hard. There is no public “list the whole bucket” page. Synapse does not recompress 3D or re-encode video for you. Size & junk filters Default 300 MB per file (1.2GB for video, 300 MB for a 3D model). Folder uploads skip dependency / virtualenv junk. Oversized or unreadable uploads are rejected. Live counts without hammering Views, likes, and comments use a short-lived connection when it works, and slower polling when the tab is visible. Hidden tabs do not keep polling. The home marketing block does not fade in from invisible, so the page does not bounce twice. Images in the tab Images you already loaded can be reused in the same visit. That is a local convenience cache, not a tracker. No money pipeline Uploading does not start payouts, invoices, or escrow. What we do not publish here Operator machine addresses, internal hostnames, and database locations stay off this page. Public traffic uses HTTPS at the edge of this instance. ## Reports, warnings & appeals How members escalate problems — and how suspensions work Three public channels (footer + header where shown): **safety reports** (harassment, hate, scams, impersonation, threats, sexual content), **site feedback** (bugs and ideas), and **appeals** (challenge a suspension with your side of the story). Safety and feedback require a normal signed-in session. Appeals also work after a suspended account verifies email/password or Google once — that unlocks a short **appeal-only** session (not full site access). - Header flag or footer Report - Header Feedback or footer Feedback — bugs / ideas only - Footer Appeal (next to Docs) — suspensions and mistaken bans - Report on a profile — fills @handle and profile ID for you Up to four screenshots. Empty spam is rejected. Filing is rate-limited. Bad public names/content are **blocked on save** — you do not wait for someone else to file a report. Mild cases warn first (1-day fix window); severe cases suspend immediately. Ban durations used by operators and automation: **1 / 3 / 7 / 14 / 30 days or permanent**. Evidence is stored on the ban record so appeals are reviewed against facts, not as a black box. A suspended account cannot use the rest of the site until the ban ends or an operator lifts it. Posts, comments, and related public content from a suspended account are **soft-hidden** (kept in the database, removed from feeds/search/chat) — not deleted. Direct messages with that account are blocked while the ban is active. Discovery uses a **5-level trust ranking** (Restricted → Caution → Standard → Established → Trusted). Clean, established accounts rank higher in search and feeds. Warnings step trust down; bans force Restricted. Trust recovers slowly after clean time (about a week) once warnings expire and the ban is lifted. ## Security — full picture Server, browser, uploads, and what you still control Written to match the live stack (Express + Helmet + Postgres, Vite/React front end). Legal wording lives in the Privacy Policy. Accounts & sessions Passwords & Google Email passwords are stored only as bcrypt hashes — Synapse cannot show them back. Google sign-in never receives your Google password. Your session lives in an HttpOnly cookie the browser sends automatically — no page script, extension, or injected code can read it, and it's cleared on logout. Two-factor (TOTP) Optional authenticator codes. Secrets sit in a dedicated table, separate from the public profile. Enable under Settings → Security — once on, changing your @handle also requires a fresh code. Revocable sessions Each sign-in creates a server session ID. Logout or “revoke device” invalidates that session on the API immediately — closing one tab is not enough if you leave another device signed in. Rate limits Login, signup, password reset, reports, uploads, and owner-console unlock slow down after repeated hits. This is abuse control, not a hidden reputation score. Server (API & storage) Private fields stay private Email (unless you publish it), payout notes, notification prefs, and similar fields are returned only to the owner. Other members receive the public profile shape only. Ownership on every write You cannot grant yourself admin from DevTools. Project/problem edits check ownership. Likes and views only move through dedicated actions — not by patching a JSON counter. Upload hardening Almost any project file can be uploaded. Only a few browser-executable page types are blocked. HTML/JS/SVG still upload for the IDE but are served as text/plain + nosniff so they cannot run as pages. Default size cap 300 MB per file (the operator can lower it). How files are served Files are served through Synapse routes, not as a public bucket listing. HTML/JS/SVG/CSS are sent as plain text with nosniff so a direct link never runs as a page on Synapse's own origin — the only way to run an .html file at all is the opt-in sandbox described below. URL & media sanitization On create/update, media and link fields are filtered to http(s) or trusted upload paths. javascript: and similar schemes are rejected before they are stored. View cookie A first-party HttpOnly cookie applies the short view cooldown per browser. It is not an advertising ID and is not sold. No payment processor Donate, checkout, and investor-interest writes are rejected. Raised totals cannot be forged from the browser. Off-site deals are between members. Browser origins Cross-site browser calls to the API are limited to this instance’s allowed front ends. Unknown sites cannot ride your session from another origin. Browser & front end HTTPS & security headers Public instances sit behind HTTPS. The API sends Helmet headers, a Content Security Policy, and a permissions policy that does not ask for camera, microphone, location, or in-browser payments. Content Security Policy CSP defaults to same-origin scripts, blocks object embeds, and forbids framing the app in other sites. Dangerous schemes such as javascript: in media are blocked in the browser even if bad data slipped through. Markdown & comments User Markdown is rendered without running raw HTML as a site. Link destinations are checked so javascript: URLs do not become clickable actions. Same-site project links show the copied title, not a server hostname. Web sources: source by default, sandboxed if you ask HTML / JS / CSS / SVG open as highlighted source (or plain text) by default — nothing runs automatically just from opening a project. A standalone .html file adds a "Run (sandboxed)" toggle that plays it inside an isolated frame with its own scripting-only permissions: no cookies, no session, no calling Synapse's API, no reaching the rest of the page. It never runs as a live app on Synapse's own origin. 3D & media viewers The Three.js viewer and media players load only http(s)/upload URLs the app already accepted. They are not a general “run arbitrary plugins” surface. What you should still do Unique password, turn on 2FA, never paste secrets into public files, and report impersonation early. No stack is perfect — see Privacy for breach language. Threat model in one line ## How the site talks to itself Same-origin /api — not a public developer platform There is **no public API key product**, no partner webhook catalog, and no “build third-party apps” program. The React app calls `/api` on the same host with your session. Live-feeling updates (views, likes, comments, feeds) use a mix of short polling and optional push channels. If a live connection cannot be established, the site falls back to polling and a stats stream so counts and comments still move. Editing data in DevTools cannot invent permissions. The server checks ownership, session validity, bans, and rate limits on every write. ## Usage guidelines Practical rules that keep the archive useful Content you upload Only publish work you own or have rights to share under the license you pick. Credit originals on derivatives. Stolen, illegal, or abusive material can be removed and accounts suspended. File size & honesty Stay within the per-file cap. Do not upload malware, credential dumps, or scrapers. The site stores what you send — it is not a free CDN for unrelated bulk hosting. Money claims Synapse does not process payments. There are no donate or checkout buttons. The browser cannot forge raised totals or donation notifications. Off-site deals are your legal responsibility. Groups Owners can delete the whole group (posts and members cascade). Banned owners’ groups stay in storage but are locked — no enter, join, or chat. Identity One person, one account. No email addresses in display names. Impersonation gets suspended. Licensing & IP You keep ownership. The license on each project is the rule others follow. Use Report for copyright/IP complaints with work description, location, and contact details. How to report Safety: header flag / footer Report / profile Report. Feedback: header or footer Feedback. Appeals: footer Appeal (works after suspended accounts verify credentials once). Signed-in or appeal-session only. Do not publish other people’s private contact details. ## Legal Pointers — not a substitute for the full pages Full text elsewhere Terms of Service and Privacy Policy are the binding documents. This docs page explains the product; those pages govern the relationship. Accounts You are responsible for login security, 2FA, and activity from your account. Your files You keep ownership. Synapse hosts and shows what you publish so members can discover it under your license. Copyright complaints need work description, URL/ID, and contact info. No payments here Synapse is not a processor, broker, or advisor. Donation / interest UI is locked; the API rejects interest records and forged money notifications until a real ledger is turned on. Suspension & soft-hide Rule-breaking can mean a warning first, then timed bans or permanent. Soft-hide removes banned authors’ content from discovery without deleting storage. Appeal-only tokens cannot unlock the rest of the site.