Privacy Policy
Last updated: 2026-05-06
Overview
Synapki ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our knowledge management service.
Key principle: We process your wiki content but never store it. Your wiki pages are written directly to your own cloud storage (Google Drive, Dropbox, or OneDrive). We never copy, cache, or persist your wiki content on our servers.
Information We Collect
Information You Provide
- Account information: Email address, name, and password when you create an account
- Payment information: Credit card details and billing address, processed securely by Stripe — we never see or store your full card number
- Cloud storage credentials: OAuth tokens that allow us to write wiki pages to your Google Drive, Dropbox, or OneDrive
- Communications: Information you provide when contacting us for support
Information Collected Automatically
- Usage data: Number of clips, AI queries, and feature usage for tier enforcement
- Device information: Browser type, operating system, device identifiers for security and compatibility
- Log data: IP addresses, access timestamps, and error logs for security monitoring
- Cookies: See our Cookie Policy for details on cookie usage
Information We Do NOT Collect or Store
- Wiki page content (stored in your own cloud storage only)
- Clipped web page content (processed in memory, never persisted)
- LLM conversation history or prompts
- Search queries or research topics
- Full credit card numbers (handled entirely by Stripe)
How We Use Your Information
- Service delivery: Process web clips and generate wiki pages using AI
- Cloud storage access: Write wiki pages to your Google Drive, Dropbox, or OneDrive using your OAuth tokens
- Account management: Create, maintain, and secure your account
- Billing: Process subscription payments and enforce tier limits via Stripe
- Usage tracking: Monitor clip counts and query limits per your subscription tier
- Security: Detect and prevent fraud, abuse, and unauthorized access
- Communications: Send service notifications, billing receipts, and policy updates
- Improvement: Analyze aggregated, anonymized usage patterns to improve the service
How We Share Your Information
We do not sell or rent your personal information. We share data only with the following service providers:
Payment Processing
Stripe, Inc. — All payment processing is handled by Stripe, a PCI DSS Level 1 certified provider. Stripe collects and processes your payment information independently. We receive only confirmation of payment and a customer ID. See Stripe's Privacy Policy for details.
Cloud Storage Providers
Google, Dropbox, Microsoft — Your wiki content is written directly to your chosen cloud storage provider. These providers' privacy policies govern how they handle your data.
LLM Providers
OpenRouter (and underlying providers: OpenAI, Anthropic, etc.) — Clipped content is sent to LLM providers for AI processing. This content is processed in real-time and is not stored by us. See OpenRouter's Privacy Policy for details.
Infrastructure
Supabase — Hosts our database containing account metadata (email, subscription tier, usage counts, encrypted OAuth tokens). See Supabase's Privacy Policy for details.
Legal Requirements
We may disclose your information if required by law, regulation, legal process, or governmental request.
Data Security
We implement industry-standard security measures to protect your information:
- Encryption at rest: OAuth tokens and sensitive data are encrypted in our database
- Encryption in transit: All communications use HTTPS/TLS
- Access controls: Strict internal access controls limit who can view user data
- Regular audits: We regularly review our security practices and infrastructure
- Zero wiki storage: Since we don't store your wiki content, there is no content data to breach on our servers
Data Retention
We retain your account data for as long as your account is active. Upon account deletion:
- Your profile and all metadata are deleted from our database
- All extension tokens are invalidated
- All OAuth connections are revoked
- Backup data is purged within 30 days
Your wiki content in your cloud storage is unaffected by account deletion.
Your Rights
Depending on your location, you may have the following rights:
- Access: Request a copy of your personal data we hold
- Correction: Request correction of inaccurate data
- Deletion: Request deletion of your account and associated data
- Export: Download your account metadata as JSON
- Restriction: Request that we limit how we process your data
- Objection: Object to our processing of your data for certain purposes
- Portability: Request transfer of your data to another service
- Revoke consent: Revoke our access to your cloud storage at any time
To exercise any of these rights, contact us at privacy@synapki.com. We will respond within 30 days.
International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. We ensure appropriate safeguards are in place, including standard contractual clauses, to protect your data in accordance with this Privacy Policy.
Children's Privacy
Our Service is not directed to individuals under 18. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child without parental consent, we will take steps to delete it.
Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email at least 30 days before they take effect. The "Last updated" date at the top of this page indicates when this policy was last revised.
Contact
For privacy questions, data requests, or concerns, contact us at privacy@synapki.com