SynarchSign in →

Privacy Policy

Effective date: July 11, 2026 · Last updated: July 11, 2026

Synarch is a Certainty Enforcement OS that helps executives manage their time through classification and automation. This privacy policy explains how we collect, use, secure, and manage your personal information.

Data We Collect

Account Data: When you sign up, we collect your email address, name, and password (hashed). We store your preferences, OKRs, settings, and configuration.

Product-Usage Analytics: We collect product-usage analytics using a pseudonymous user ID to understand feature adoption and improve Synarch. Your email address and email content are never sent to analytics providers.

Google OAuth Data: When you connect your Google account, we request scoped access to:

  • Gmail (read and compose permissions): email content, headers, metadata, and message labels
  • Google Calendar: calendar events, titles, times, attendees, and descriptions
  • Google Tasks: task lists, task titles, descriptions, and due dates

GitHub Data: When you connect your GitHub account, we collect commit metadata including repository names, commit messages, and timestamps (via webhooks).

Communication Data: Twilio phone numbers when you opt into SMS or WhatsApp briefings. We do not store message content beyond processing.

Billing Data: Stripe customer ID and subscription status. Payment card data is handled directly by Stripe.

Automated Audit Data: We record all actions taken by Synarch (declined meetings, drafted emails, booked blocks, task assignments) for transparency and accountability.

Purpose of Processing

We process your data to:

  • Classify your activities (Direction, Multiplication, Execution, Recuperation) against your stated goals
  • Generate drafts in your voice and tone
  • Schedule deep work blocks and manage your calendar
  • Provide daily briefs and weekly receipts of your time allocation
  • Compute your Certainty Score and accountability metrics
  • Comply with billing and subscription management

Critical: Your email content, calendar events, and personal data are used ONLY for your own classification and execution. Your data is never used to train models for other users or sold to third parties. User content is never used to train Synarch models for other users.

Google API Services User Data Policy

Synarch's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Storage & Encryption

Database: All data is stored in Neon, a serverless PostgreSQL database. Data is encrypted at rest.

OAuth Tokens: Google and GitHub OAuth tokens (containing your `accessToken` and `refreshToken`) are encrypted at rest in the database and encrypted in transit via HTTPS.

Backups: Neon maintains encrypted backups of your data according to their standard retention policy.

In Transit: All communication between your device and Synarch is encrypted via HTTPS/TLS 1.3+.

Subprocessors

We use the following third-party services to provide Synarch:

  • Vercel: Hosting and deployment of the Synarch application
  • Neon: PostgreSQL database and data storage
  • Google Cloud: OAuth authentication and API integrations
  • Anthropic (Claude API): Classification, tone analysis, and email draft generation
  • Google Gemini: Sender profile enrichment and secondary fact-checking on important emails
  • Zep: Vector embeddings for memory and preference extraction
  • Twilio: SMS and WhatsApp message delivery for briefings
  • Stripe: Payment processing and subscription billing
  • Upstash: Redis cache for webhook debouncing (optional)

Each subprocessor is contractually bound to process data only as necessary to provide their service. Email content is never sent to Stripe or billing processors. Phone numbers are sent to Twilio only for message delivery.

Retention & Account Deletion

Retention: We retain your data for as long as your account is active. When you cancel your subscription, data is retained for 30 days to allow for account recovery, then permanently deleted.

Deletion Request: To request deletion of your account and all associated data, please email [HUMAN: support email address]. We will process your request within 30 days. Account deletion removes all account data, conduit activities, settings, and audit trails. This action cannot be undone.

Automatic Deletion: OAuth token data is automatically deleted when you disconnect a conduit (Google Calendar, Gmail, GitHub, etc.) from your account settings.

Your Rights & Control

One-Click Disconnect: You can disconnect your Google, GitHub, or other OAuth integrations at any time from your settings. When disconnected, Synarch immediately stops accessing new data and ceases autonomy operations.

Shadow Mode Default: When you first connect a conduit, Synarch runs in shadow mode—watching and suggesting, but never executing actions. You control when it earns each level of autonomy.

Access Your Data: You can export your activity log and audit trail from the `/budget/export` page.

Opt Out of Notifications: You can disable SMS/WhatsApp briefings and email notifications in settings.

Data Portability: For requests to export your data in a portable format beyond the built-in export, contact [HUMAN: support email address].

Reporting a Problem or Security Incident

If you believe Synarch has made a mistake—declined a meeting it shouldn't have, sent an email unexpectedly, or experienced any other trust breach—you can report it directly from the app via the "Report Problem" button. This immediately locks Synarch into a 28-day probation: all autonomy is suspended, and Synarch reverts to suggest-only mode until you re-opt in.

For security vulnerabilities or incidents, email [HUMAN: security contact email].

Privacy Questions or Requests

For questions about this privacy policy, data access requests, or deletion requests, contact [HUMAN: support email address].

Mailing Address:
Synarch, Inc.
[HUMAN: street address]
[HUMAN: city, state, ZIP]
[HUMAN: country]

This privacy policy is governed by the laws of [HUMAN: jurisdiction]. If you are in the EU/EEA, your rights under GDPR may provide additional protections.