Privacy policy
Last updated 13 September 2026
synapseHQ (“we”, “us”) is a study app. This policy says what we collect, why, who else sees it, and how you get rid of it. It is written to be read, not skimmed past.
Who is responsible
The service is operated by synapseHQ. Questions about this policy go to ngong7053@gmail.com.
What we collect
Account
- Your email address (from GitHub sign-in or from sign-up), and a password hash if you set a password. We never store the password itself.
- A public handle you choose, an optional one-line bio, and an optional avatar. If you sign in with GitHub we receive the name and picture GitHub provides; the name is never shown publicly.
- An optional contact email, if you add one, and whether you want product updates (nothing sends yet).
What you make
- Your sets, cards, categories, notes, postmortems and folders, including any images or files you attach. Attachments are stored on Vercel Blob and served only through an authenticated route that checks you may see them.
- Sets are private by default. You can make one link-shareable or public; a public set is listed under your handle.
How you study
- Every answer you give in a study mode (Review, Test) — what you wrote, whether it was right, per-idea outcomes, and derived confidence and mastery numbers. This is the learner memory the app is built around.
- Session records: when you studied, which set, how long. Games record nothing.
- If you join a study group, members of that group can see your progress on the group’s sets — and only those sets. The join screen states this and requires your acknowledgement. Leaving a group ends it immediately; nothing is copied.
AI credentials
- The app grades written answers and generates questions using AI providers you configure with your own API keys. Keys are encrypted at rest (AES-256-GCM) and used only to make requests on your behalf.
- When an AI feature runs, the card text, your answer, and a compact, ID-free summary of your recent performance are sent to the provider you chose (for example Google, Anthropic, OpenAI, OpenRouter, or a custom endpoint). That provider’s privacy terms apply to that request. We keep a log of each call’s provider, model, token counts and outcome — never the key.
Technical
- One essential cookie keeps you signed in. We set no advertising or third-party tracking cookies.
- If you allow it in the cookie banner, we count visits with Vercel Analytics, which is cookieless and does not identify you. You can change that choice at any time from the footer.
- Standard server logs (IP address, user agent, timestamps) are kept by our hosting provider, Vercel, for security and operations.
Why we use it
- To run the service: sign you in, show you your sets, grade your answers, build your plan.
- To keep it safe: rate limits, abuse and spam prevention, moderation of published sets.
- To improve it: aggregate, non-identifying usage counts (only if you allowed analytics).
We do not sell personal data and we do not show advertising.
Who else sees it
- Vercel — hosting, file storage (Blob), and optional analytics.
- Neon or Supabase — the Postgres database.
- Resend — transactional email (verification and password reset).
- GitHub — if you sign in with GitHub.
- The AI providers you configure — as described above, using your keys.
- Other users — only what you publish (public sets under your handle, your profile page) and what you share by joining a study group.
How long we keep it
For as long as your account exists. Forgetting a card or a set from your Danger Zone deletes the underlying evidence, not just the estimate. Deleting your account deletes your sets, study history, credentials, and group memberships; published sets that others have copied remain as their copies, credited to your handle at the time of the copy.
Your choices and rights
- Edit your handle, bio, contact email and password on the Account page.
- Change a set’s visibility from its Share menu at any time.
- Leave any study group at any time.
- Turn analytics off from the footer’s cookie choices.
- Ask us for a copy of your data, or for its deletion, at ngong7053@gmail.com. If you are in the UK or EU you also have the rights to rectification, restriction, portability and to complain to your supervisory authority.
Children
The service is not directed at children under 13, and we do not knowingly collect their data. If you believe a child has an account, contact us and we will delete it.
Changes
If this policy changes materially we will update the date above and, for signed-in users, say so in the app. The current version is always at /privacy.
See also the terms of use and the cookie notice.