Privacy Policy

Last updated: September 4, 2026

Synapse is operated by Hovo Apinyan, doing business as Synapse ("Synapse," "we," "us," or "our"). This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you use the Synapse mobile application, visit synapsebond.com, or communicate with us (collectively, the "Services").

Synapse helps you remember important details about people in your life, plan meaningful interactions, receive reminders, and obtain AI-generated relationship support. Because those features can involve personal information about you and people you add, please read this Policy carefully and enter only information you have the right to use.

1. At a Glance

  • We do not sell personal information.
  • We do not use advertising SDKs or advertising identifiers, and we do not track you across other companies' apps or websites for targeted advertising.
  • Synapse does not import your device address book and does not request access to Contacts, Camera, Bluetooth, or GPS/location services.
  • AI features are optional and are powered by OpenAI. When you choose an AI feature, relevant text and relationship context may be sent to OpenAI to generate a response. Contact and profile photos are not sent to OpenAI.
  • Some information is stored only on your device, and some is also stored in our AWS cloud systems. Relationship content cached on your device uses the app's ordinary local storage and is not separately end-to-end encrypted. Authentication tokens use your device's secure credential storage.
  • You can edit or delete people, export certain cloud-stored account data, and delete your account in the app. Deleting your Synapse account does not cancel an Apple App Store subscription.

2. Information We Collect

A. Account and authentication information

Depending on how you create or use an account, we may process:

  • your first and last name;
  • email address;
  • account and authentication identifiers;
  • password credentials, which are handled by Amazon Cognito and are not visible to us in readable form;
  • information provided through Sign in with Apple or Google Sign-In, such as a provider-specific identifier, name, and email address, subject to the choices offered by that provider; and
  • account preferences and settings.

If you use Sign in with Apple, Apple may provide a private relay email address instead of your personal email address.

B. Information you enter about people and relationships

Synapse is designed to let you create records about friends, family members, partners, colleagues, and other people. Depending on what you choose to enter or confirm, these records may include:

  • name, relationship type, and closeness;
  • birthday, location or city, occupation, phone number, or email address;
  • contact frequency, last-contact date, follow-up date, and notification settings;
  • interests, favorite topics, important events, how you met, goals, and relationship context;
  • free-text notes, conversation notes, interaction summaries, facts, memories, topics to avoid, and open or resolved threads;
  • information about what a person may be going through;
  • reminders and recurrence settings;
  • profile or contact photos you select; and
  • gift preferences, clues, budgets, exclusions, and saved gift ideas or links.

You enter this information manually or confirm a proposed addition. Synapse does not read, import, or upload your device's address book.

You are responsible for entering only information that you have a lawful right and appropriate permission to use. Please do not enter highly sensitive information about another person, including health, biometric, government-identification, financial-account, precise-location, religious, political, sexual-orientation, or similar information, unless you are legally permitted to do so and it is genuinely necessary for your personal use of the Services.

C. AI conversations and generated content

When you use an AI feature, we process the text you submit and the response generated for you. Depending on the feature and context, this may include:

  • your prompts and recent Synapse conversation;
  • names and relevant details from your people and relationship records;
  • notes, facts, context, open threads, and preferences;
  • onboarding preferences and limited feedback about responses you liked or disliked;
  • the current date or time context used to make a suggestion relevant;
  • gift clues, budgets, exclusions, product-search terms, and web-search findings; and
  • AI-generated summaries, suggestions, rewrites, gift ideas, or other outputs.

Before an account is created, the guest onboarding conversation may be sent to OpenAI, and the resulting draft connection may be kept on the device until you create an account, save it, clear it, or remove the app.

Synapse does not send contact photos or your locally selected user-avatar photo to OpenAI. AI chat history is generally kept on your device; information you choose to confirm—such as a new person, a fact, note, reminder, or memory—is saved to the relevant cloud record.

D. Subscription and purchase information

Subscriptions are purchased through Apple and managed for Synapse through RevenueCat. We may process:

  • a Synapse account identifier used as a RevenueCat App User ID;
  • product, entitlement, subscription-status, renewal, and trial information;
  • Apple receipt information and purchase history; and
  • limited technical information used to validate purchases and prevent fraud.

Apple processes the payment transaction. Synapse does not receive or store your full payment-card number or complete Apple billing details.

E. Notifications and device information

If you enable notifications, we may process:

  • an Expo or Apple push token;
  • platform, device name, app version, and time zone;
  • notification preferences, quiet hours, selected categories, and discreet-lock-screen setting;
  • notification delivery status and receipts; and
  • the content needed to deliver reminders or nudges you enable.

Synapse is designed to use discreet lock-screen wording and not place detailed relationship notes in remote push notifications. You control notification previews and permissions through Synapse and your device settings. Delivery is not guaranteed.

F. Photos and device permissions

Synapse requests Photo Library access only when you choose a photo. We receive only the image you select. A contact photo may be uploaded to our AWS storage. Your personal account-avatar selection is stored locally on your device.

Synapse may request permission to send push notifications. It does not request Contacts, Camera, Bluetooth, or device-location permission. You can revoke permissions in your device settings, although the related feature may stop working.

G. Technical, security, and diagnostic information

When you use the Services, we and our infrastructure providers may automatically process information such as:

  • IP address, date and time, request and account identifiers;
  • action requested, response status, duration, and error details;
  • device type, operating system, app version, and language or locale;
  • authentication, fraud-prevention, rate-limit, and security events; and
  • crash or diagnostic information made available through Apple, the operating system, or development tools.

Our routine server logs are not designed to record full relationship notes or full AI prompts. However, error or debugging records can sometimes contain identifiers or information included in a request. We use logs to operate, secure, troubleshoot, and improve the Services.

H. Website information, cookies, and communications

Our website is hosted by Squarespace. When you visit it, Squarespace and we may process:

  • IP address;
  • browser, network, and device information;
  • referring pages and pages you view;
  • clicks, internal links, scrolling, searches, and timestamps; and
  • cookies and similar technologies needed to serve, secure, and measure the website.

Required Squarespace cookies may be used to operate the site. Where a cookie banner or applicable law requires a choice, analytics or performance cookies are used according to that choice. You can also control cookies through your browser, although blocking required cookies may affect the site.

If you use a website form or email us, we collect the information you submit, such as your name, email address, message, and any information you choose to include, so we can respond and maintain appropriate support records.

Links to Instagram, the App Store, retailers, and other third-party sites take you outside Synapse. Those services receive information according to their own privacy practices when you visit or interact with them.

3. Where Information Comes From

We collect information:

  • directly from you when you type, upload, select, confirm, or communicate it;
  • from Apple or Google when you choose their sign-in service;
  • from Apple and RevenueCat in connection with subscriptions;
  • automatically from your device, browser, and use of the Services;
  • from OpenAI when it returns AI-generated content or web-search findings; and
  • from another Synapse user if that user enters information about you.

If another user enters information about you, we generally do not have a direct relationship with you and may not know that the record concerns you. You may contact us as described in Section 13 if you believe Synapse holds personal information about you.

4. How We Use Information

We use personal information to:

  • create, authenticate, and manage accounts;
  • store, synchronize, and display people and relationship records;
  • provide AI conversations, summaries, suggestions, rewrites, gift research, and planning support;
  • generate and deliver reminders, notifications, and user-requested schedules;
  • process subscription status, restore purchases, apply entitlements, and prevent purchase fraud;
  • provide location-name suggestions based on text you enter;
  • provide, personalize, maintain, and troubleshoot the Services;
  • respond to support, privacy, and legal requests;
  • protect accounts, investigate misuse, enforce our Terms, and maintain security;
  • comply with legal obligations and valid legal process;
  • protect the rights, safety, and integrity of users, other people, Synapse, and the public; and
  • evaluate diagnostics and feedback and develop the Services.

Synapse does not send marketing or promotional email newsletters and does not send SMS marketing.

5. AI Features and Live Gift Research

Synapse clearly presents its AI-powered features as AI, not as a human advisor. AI output may be inaccurate, incomplete, outdated, or inappropriate. It is intended as optional relationship-support and organizational assistance—not professional, medical, mental-health, legal, financial, or emergency advice.

When you ask Synapse to use an AI feature, the relevant information described in Section 2(C) is sent to OpenAI through our server. We configure our requests with store: false, so the relevant endpoint does not keep the response as ordinary application state. OpenAI states that API data is not used to train its models by default unless the customer opts in. OpenAI may nevertheless use temporary prompt caching and retain prompts, responses, and related metadata in abuse-monitoring logs for up to 30 days by default, and longer where required by law or reasonably necessary to protect its services or others from harm. Different retention may apply if our OpenAI account is approved for and configured with additional data controls.

Gift suggestions may use OpenAI's live web-search capability. Search terms can be derived from the gift clues, relationship context, budget, and exclusions you provide. Product titles, images, prices, availability, retailer names, and links may come from third-party webpages and can change without notice. Synapse does not send your selected photos to OpenAI for gift research.

6. Location-Name Suggestions

If you type a city or place into a person's details, the text you type is sent to the public OpenStreetMap Nominatim service to return matching place names. We do not access or send your device's GPS location. OpenStreetMap may receive the search text, IP address, app identification, timestamp, and technical request information under its own privacy practices. Do not type a home address or confidential information into this field.

7. How We Disclose Information

We disclose personal information only as described below.

Service providers

  • Amazon Web Services (AWS): cloud hosting, API processing, authentication through Amazon Cognito, database storage, file storage, operational logging, and related infrastructure.
  • OpenAI: AI inference and live web-search features when you choose AI functionality.
  • Apple: app distribution, Sign in with Apple, in-app purchases, subscription billing, and push-notification delivery.
  • Google: Google Sign-In when you choose that option.
  • RevenueCat: subscription status, receipt validation, purchase history, entitlements, and related subscription analytics.
  • Expo: push-token services, notification delivery to Apple, and delivery receipts.
  • OpenStreetMap Foundation / Nominatim: matching city and location names from text you type.
  • Squarespace: website hosting, security, cookies, site analytics, and webform processing if you submit a form.

These providers may process information under contracts with us and/or their own terms and privacy policies, depending on their role.

Legal, safety, and business reasons

We may also disclose information:

  • when required by law, subpoena, court order, or other valid legal process;
  • to investigate fraud, abuse, security incidents, or violations of our Terms;
  • to protect rights, property, safety, and the integrity of the Services;
  • in connection with a merger, financing, acquisition, bankruptcy, reorganization, or sale of all or part of the business, subject to applicable law; or
  • at your direction or with your authorization.

We do not sell personal information. We do not share personal information for cross-context behavioral advertising or use it for targeted advertising.

8. Legal Bases for EEA, UK, and Swiss Users

Where applicable law requires a legal basis, we rely on:

  • Contract: to create your account and provide the features you request;
  • Legitimate interests: to secure, operate, troubleshoot, and improve the Services, prevent misuse, and understand website performance, balanced against your rights;
  • Consent: for optional permissions, nonessential cookies where required, and processing for which consent is the appropriate basis; and
  • Legal obligations and vital interests: to comply with law or protect a person's safety.

You are not generally required by law to provide personal information to us. Information marked as required is necessary to create an account or provide the requested feature; if you do not provide it, that feature may not work.

Synapse does not use solely automated processing to make legal or similarly significant decisions about you.

9. Data Retention

We retain information for the shortest period reasonably necessary for the purposes described in this Policy, using the following criteria:

  • Account and cloud relationship data: generally retained while your account or the relevant person record remains active, until you delete it, subject to legal, security, dispute, and backup needs.
  • Contact photos: generally retained until replaced, the person is deleted, or the account is deleted. Deletion from storage is best effort and copies may remain temporarily in backups or provider systems.
  • AI chat and local app data: the main AI thread, local reminders, onboarding answers, preferences, and some response feedback are stored on your device until you clear them, sign out where the item is included in the sign-out cleanup, delete your account, or remove app data. The in-app export covers certain cloud-stored account data and may not include every device-only item.
  • Notification history: a limited recent history may be kept on the device and automatically pruned.
  • Purchase records: retained as needed to manage entitlements, accounting, fraud prevention, legal obligations, and disputes. Apple and RevenueCat apply their own retention rules.
  • Security, diagnostic, and support records: retained according to their nature and our operational, security, legal, and dispute-resolution needs.
  • OpenAI processing: subject to the retention described in Section 5 and OpenAI's applicable policies and account settings.
  • Website information: retained according to our settings and Squarespace's applicable practices.

We may retain information longer when required by law, needed to establish or defend legal claims, required for security or abuse prevention, or maintained in a backup that is isolated from ordinary use. When information is no longer needed, we delete, deidentify, or securely isolate it as appropriate.

10. Your Choices and Privacy Rights

Depending on where you live, you may have the right to:

  • know whether we process your personal information and access it;
  • correct inaccurate personal information;
  • delete personal information;
  • receive a portable copy of certain information;
  • object to or restrict certain processing;
  • withdraw consent where processing is based on consent;
  • opt out of a legally defined sale, targeted advertising, or certain profiling (Synapse does not currently engage in these activities); and
  • appeal our refusal of a privacy request, where applicable.

You can edit or delete individual people and certain information in the app. Account → Export My Data provides a JSON export of certain cloud-stored people, memory, bubble, and notification-preference data. It does not necessarily include device-only chat history, local reminders, onboarding answers, local feedback, provider logs, or data controlled directly by third parties.

You can delete your Synapse account in the app. This starts deletion of cloud relationship records, account memory, notification records, bubble records, contact photos, RevenueCat subscriber information on a best-effort basis, the Cognito identity, and local app caches. Some records may remain temporarily in backups, security logs, or provider systems, or where retention is legally required. If the deletion process is interrupted, contact us so we can investigate.

Deleting your Synapse account does not cancel an Apple App Store subscription. Cancel the subscription separately through your Apple account settings.

To exercise a right not available in the app, or to appeal a decision, email synapse.stayclose@gmail.com. State that your request concerns privacy, identify the right you wish to exercise, and provide enough information for us to locate and verify the relevant record. We may request additional information to verify your identity and protect other users. Authorized agents may submit requests where permitted by law. We will not discriminate against you for exercising a privacy right.

EEA, UK, and Swiss users may also lodge a complaint with their local data-protection authority.

Browser privacy signals

Because Synapse does not sell personal information or use it for cross-context behavioral advertising, browser opt-out signals such as Global Privacy Control do not change those practices. Our website does not currently respond to legacy "Do Not Track" signals because there is no uniform technical standard. Where applicable law requires recognition of a browser-based preference signal, we will process it as required.

11. Washington Consumer Health Data Notice

This section is intended to serve as Synapse's Consumer Health Data Privacy Notice under Washington's My Health My Data Act. Synapse is not a medical, health-care, counseling, or wellness service and does not ask you to provide consumer health data. However, free-text notes or AI conversations could include information that Washington law defines broadly as consumer health data, including information about physical or mental health, treatment, medication, reproductive or sexual health, or information inferred from what a person submits.

Categories and sources

Any consumer health data we process comes directly from information a user voluntarily types or confirms, or from an AI output generated from that information. Synapse does not connect to medical-record, pharmacy, health-device, biometric, or precise-GPS sources, and it does not create biometric identification templates from selected photos.

Purposes

We process this information only as necessary to provide the specific Synapse features the user requests, maintain security, comply with law, and honor privacy rights. We do not use consumer health data for advertising, data brokerage, or unrelated profiling.

Disclosures

Depending on the feature used, this information may be processed by AWS for hosting and by OpenAI for an AI response. It may also be disclosed for legal or safety reasons described in Section 7. We do not sell consumer health data. We do not share it with third parties for their independent advertising or commercial purposes.

Your Washington rights

Subject to applicable law, you may ask us to confirm whether we collect, share, or sell consumer health data about you; access that data and a list of relevant third parties; withdraw consent for future collection or sharing; delete the data; or appeal a refusal. Submit a request or appeal to synapse.stayclose@gmail.com. You do not need to create a new account to make a request. We will authenticate and respond within the time required by law, generally within 45 days, with one permitted 45-day extension when reasonably necessary and explained to you. Deletion from archived or backup systems may take up to six months where Washington law permits.

Do not enter consumer health data about another person unless you have that person's valid permission and a lawful basis to do so. Acceptance of Synapse's general Terms is not consent on behalf of another person.

12. Security and On-Device Storage

We use administrative, technical, and organizational measures designed to protect personal information, including encrypted network connections, authenticated API requests, user-scoped cloud records, provider-managed encryption for cloud storage, operating-system secure storage for authentication tokens, access controls, and rate limits.

Synapse also caches relationship content and settings in the app's ordinary local storage to support responsiveness and offline use. That local relationship cache is not separately end-to-end encrypted by Synapse and may be included in device backups depending on your operating-system settings. Protect your device with a strong passcode, limit notification previews, and avoid entering information that you would not want stored on that device.

No security measure is perfect. We cannot guarantee that information will never be accessed, disclosed, altered, lost, or destroyed.

13. Children's Privacy

The Services are intended for a general audience age 13 and older and are not directed to children under 13. We do not knowingly collect personal information from a child under 13. If we learn that we have done so, we will take reasonable steps to delete it. If you are under the age of legal majority where you live, you may use the Services only with permission from a parent or legal guardian.

Parents or guardians who believe a child under 13 has provided information may contact synapse.stayclose@gmail.com.

14. International Data Transfers

Synapse is operated from the United States. Our primary AWS infrastructure is configured in the United States, and our providers may process information in the United States and other countries. Those countries may have different data-protection laws from your home country.

Where required, we rely on legally recognized transfer mechanisms and provider contractual protections. You may contact us for more information about safeguards relevant to your information.

15. Changes to This Policy

We may update this Policy to reflect changes to the Services, our practices, providers, or law. We will update the "Last updated" date and provide additional notice when required. If a change materially expands how we collect, use, or disclose information, we will provide notice before the new practice takes effect and obtain consent where required.

16. Contact Us

For privacy questions, requests, or complaints, contact:

Hovo Apinyan, doing business as Synapse
429 9th Ave
Kirkland, WA 98033
United States
Email: synapse.stayclose@gmail.com