Scope and roles
This Privacy Policy explains how Synaptic handles personal information in its public website and hosted B2B service. In a hosted workspace, the customer organization controls the repositories, workspace content, and people it authorizes; Synaptic processes that material to provide the requested service. Synaptic also handles account, billing, security, and operational information needed to run the service.
Customer-operated self-hosted deployments process application data inside the customer's infrastructure. Synaptic receives deployment information only when the customer enables an optional heartbeat or uses a hosted support or licensing workflow.
Information the service handles
- Account and organization data: name, email, password verifier, membership, role, project grants, invitations, and organization settings.
- Repository connection data: provider and repository identity, clone URL, default branch, webhook events, immutable commit identifiers, and encrypted provider credentials.
- Customer content: temporary source checkouts, optional encrypted workspace overlays, derived code graphs, graph queries, and project metadata.
- Billing and licensing data: plan, seat and usage records, subscription and provider identifiers, license claims, and deployment registration. Raw payment card details are handled by the configured billing provider rather than the Synaptic application.
- Enterprise identity data: provider organization, directory user and group identifiers, name, email, status, and mapped role when enterprise identity is configured.
- Operational data: session and audit records, content-free request outcomes, timing, byte counts, health information, and salted hashes derived from network addresses.
How repository source is processed
The hosted web process does not execute repository code. A separate worker leases a credential for one active graph job, fetches one authorized immutable commit, clears the credential, and runs extraction inside a no-network Bubblewrap child. The job checkout and staging files are removed on success, failure, cancellation, or report-delivery loss.
The retained graph is a derived representation and can contain repository structure, identifiers, file paths, and other source-derived metadata. It remains customer data even though it is not the raw checkout. See the Security page for the exact extraction and artifact boundaries.
Cookies and browser storage
The current application uses functional cookies for authentication sessions, selected organization, sign-up plan, SSO request state, demo synchronization state, and short-lived one-time credential delivery. Authentication cookies are HttpOnly and SameSite; production session cookies are Secure.
The current codebase does not include an advertising network or third-party product analytics integration. If that changes, this notice and any required consent controls must be updated before non-essential tracking is enabled.
Why information is used
Information is used to authenticate users, enforce organization and project access, connect authorized source providers, generate and serve graphs, deliver MCP and API requests, administer plans and licenses, send transactional email, prevent abuse, troubleshoot failures, maintain audit evidence, and carry out export, retention, legal-hold, and deletion instructions.
Customer source and derived graphs are not used by the current application for advertising. They are processed to provide and secure the product and to follow the customer's configured workflows.
Providers and disclosure
Depending on deployment configuration, information can be exchanged with repository hosts, infrastructure and object-storage providers, Stripe for billing, Resend for transactional email, WorkOS for enterprise identity, and an operator-selected OpenTelemetry collector. Only the integrations enabled for a deployment receive data.
Synaptic can also disclose information when required by law, to protect users or the service from material harm, or as part of a business transaction subject to appropriate confidentiality and notice requirements. Current hosting regions and provider terms should be confirmed in the applicable order form or deployment documentation before regulated data is submitted.
Retention, exports, and deletion
Retention is controlled by organization policy and deployment configuration. Scheduled retention removes eligible historical graph snapshots, source events, and content-blind MCP request logs while preserving current snapshots and material covered by an active legal hold. Developer workspace graph artifacts expire separately; the default lifetime is 24 hours. Terminal workspace source deltas are purged rather than preserved as records.
Authorized organization owners can request a bounded export that omits credentials and secret material. Organization deletion uses a configurable cooling-off period—seven days by default—then cancels billing, attempts source-webhook cleanup, removes private artifacts, revokes credentials, and deletes tenant data. Active legal holds block destructive execution.
Access and privacy choices
Users can update account and organization information through the service, while organization administrators control membership, project grants, connected sources, enterprise identity, retention, exports, and deletion. Depending on applicable law, individuals may also request access, correction, deletion, restriction, objection, or a portable copy of personal information.
Because Synaptic is a B2B service, requests concerning customer-controlled workspace data may be routed to the relevant organization administrator. Submit privacy questions through enterprise@synaptic.dev and identify the organization connected to the request.
Security, changes, and contact
Synaptic uses scoped authorization, forced tenant row-level security, encrypted stored credentials, isolated extraction, private artifact grants, and content-blind logging. These safeguards reduce risk but cannot eliminate every risk. Operational detail and remaining deployment gates are published on the Security page.
We may update this policy as the product, providers, or legal requirements change. The date at the top identifies the current version. Privacy and data-processing questions can be sent to enterprise@synaptic.dev.