SynaptiX
Document SHA-256: 16a981ca54d94af1820eb9afbc928cfb69cfcc383f5d4af81c2700b7aabb6573

SynaptiX Privacy Policy

Effective Date: June 30, 2026


Who we are

SynaptiX is a product operated by Paris Valentino Iason Kollias, a sole proprietor based in Ontario, Canada (referred to in this policy as "the Operator", "we", "us", or "our"). You can reach us at hi@synaptix.bio.

When you see the words "SynaptiX", "the App", or "the Software" in this policy, they refer to the SynaptiX desktop application and the licensing infrastructure that supports it.

What this policy covers

This policy explains what personal data we collect, how we use it, and the rights you have over it. It applies to:

SynaptiX v1 is not offered or sold in the 27 European Union member states, Iceland, Liechtenstein, Norway, or the United Kingdom. Switzerland is not part of that launch block. This policy does not promise GDPR or UK-GDPR service availability. Mandatory privacy rights that apply to an eligible purchaser are not waived by this policy.


The headline: what we do NOT do

SynaptiX is designed so that your raw genome stays on your computer. Interpreted findings may leave only for optional, profile-scoped cloud features you enable. We want to be unambiguous about that boundary before we describe the small amount of data we do collect:

If you exit the rest of this policy now and remember only one thing, remember this: your raw genome never leaves your device. Selected interpreted findings can leave only when you enable an optional cloud feature for that profile; the exact content is disclosed below by mode.

Anonymous diagnostics toggle and report exports

Two specific items deserve their own clear disclosure:

The "Anonymous diagnostics" toggle. The SynaptiX Settings screen includes an "Anonymous diagnostics" toggle, which is off by default. When you turn this toggle on, SynaptiX sends encrypted, de-identified usage and diagnostic events to our servers to help us improve the app. What is sent:

What is never included in the optional telemetry payload, even with the toggle on: your specific genetic results or genotype, your phenotype calls (e.g. we never learn whether you are a "poor metabolizer"), your name, date of birth, profile name, raw genome, rsID-level results, file paths, or your license key. The optional telemetry payload contains no IP-address field. Connection, CDN, hosting, and server infrastructure may process or log the source IP address as ordinary connection metadata; those operational logs are retained for 30 days.

How de-identification works: events carry a random client identifier that rotates every 14 days, so events cannot be stitched into a long-term profile of you. A payload guard runs on your device before any byte leaves, and again on our server, refusing to accept any field outside the documented schema. All optional telemetry, including raw events and any derived counts or frequency tables, is deleted after 90 days.

You can review exactly what would be sent via the "See what would be sent" panel in Settings, trigger an immediate send with "Send now", clear the local log at any time, or turn the toggle off entirely — turning it off stops all collection immediately. If we ever change what this toggle collects, we will update this policy first, and it will remain opt-in.

Report exports. A user-initiated Markdown, HTML, or print-to-PDF export contains the rendered report and basic display metadata: profile name, age, gender, generation date, and page count. Internal prompts, narrative input evidence, model reasoning, raw model output, diagnostics, model or source status, application build metadata, and local file paths are excluded. The export is saved only where you choose on your device; SynaptiX does not upload it. Anyone you later share the file with can read the report content and its profile metadata.


What we DO collect, and why

We collect specific data that is necessary to sell you a license and run the application. The server-side record categories described in this policy are: durable purchase and license records; pending transactional-email delivery records; checkout legal-acceptance, payment-event, and pending-revocation records; device-activation and portal-authentication data; public medication-card registry records; AI rate-limit metadata; optional telemetry when you enable it; and operational and security logs. Founders Edition purchases also carry founder-status fields. The sections below explain the main fields and purposes; this heading does not mean that the durable license row is the only server-side record.

When you purchase a license

When you complete a purchase through the synaptix.bio checkout flow, we collect:

DataSourceWhy we collect it
Your email addressProvided by you at checkout (via Stripe)To send you your license key and to contact you about license-related issues
Payment information (credit/debit card details, billing address)Processed by Stripe, not stored by usStripe handles all payment data; we receive only transaction confirmation, not card numbers
Stripe transaction identifiers (checkout session ID, payment intent ID, customer ID)Generated by StripeRecords of which purchases produced which licenses, for receipt and refund reconciliation
The license tier you purchased (Individual or Family) and the price paidDetermined by your purchaseProvisions the correct entitlements on your license

The durable purchase and license record stores: cryptographic hashes and short suffixes of the license key and customer-portal activation token; the license tier, profile limit, feature and plan identifiers, and status; customer email; applicable Stripe checkout-session, payment-intent, customer, subscription, and price identifiers; purchase amounts and currency; email-delivery, creation, update, and activation timestamps; and, for a Founders Edition purchase, its founder number and date.

The durable record does not store a plaintext license key or activation token. Pending email delivery is a limited exception to the hash-only durable record: until the license email is delivered, the email outbox stores the customer email, tier, and recoverable copies of the working license key and customer-portal token protected with authenticated encryption, together with delivery-control timestamps and claim data. The outbox row is deleted after successful delivery, or if the license is refunded, revoked, or cancelled before delivery. The server must hold the separate encryption key while delivery is pending, so we do not claim that compromise of both the database and that server-side key could never expose a pending credential.

When you activate SynaptiX on a device

When you enter your license key in the desktop application to activate it, we collect:

DataWhy we collect it
A device identifier (a cryptographic hash derived from your device's hardware characteristics — see below)To enforce your activation limit (Individual: 3 devices; Family: 10 devices) and to let you manage your active devices through the customer portal
The application version installed on that deviceFor diagnostic purposes (knowing which versions are active in the field)
Timestamps for when the device first activated and when it was last seen by the serverTo show device activity in the customer portal and support manual device deactivation

How the device identifier works. The device identifier is a one-way cryptographic hash derived from your device's hardware characteristics — specifically the motherboard serial/UUID, the CPU identifier, and the primary network-adapter MAC address on Windows. These values are normalized (uppercased, whitespace-stripped), concatenated, and passed through SHA-256 to produce a stable 64-character hex string. We use this hardware-derived hash solely to enforce your activation limit, so that reinstalling the application on the same computer does not consume an additional activation slot. The hash is one-way — we cannot reverse it to recover your specific motherboard model, CPU serial, or MAC address. It identifies "this physical computer" to our licensing server; it does not reveal what that hardware is.

When you use optional Deep Narration and Dr. Prime chat

SynaptiX includes AI-enhanced features powered by the GLM 5.2 language model, developed by Z.ai and hosted directly by Fireworks AI. Fireworks runs the model weights on its own inference infrastructure; Z.ai does not receive the request through this deployment. These features write the reports SynaptiX generates in clearer, more personalized prose, and let you ask follow-up questions about your findings.

How it is turned on. Cloud AI has its own consent control for each profile. It is separate from legal acceptance and from permission to analyze the DNA locally. An adult profile owner can enable or disable it for themselves. For a profile aged 13–17, cloud AI is off by default and can turn on only after the parent/legal guardian and the minor each separately agree to the disclosed cloud processing. Either may withhold or withdraw that agreement. The disclosure is versioned: when the scope of what is sent materially changes, the affected profile must decide again before the changed flow takes effect. When a minor profile reaches 18, the prior two-party cloud consent expires and cloud egress remains blocked until the now-adult profile owner decides independently.

The scope of what is sent depends on the mode you are using. This is the honest, per-mode breakdown. The product is personalized — for example, full-reading narration is written to address you by name and reference your specific findings and medications, because that personalization is the value of the feature. The modes are:

Mode 1 — Default minimized narration (strict_minimized)

This is the most conservative narration mode. If you select it, the payload sent to the relay contains only:

What is never sent in this mode: your raw genome file, any rsID-level result, chromosomal coordinate, raw nucleotide genotype, phased VCF call, specific interpreted allele/star-allele/diplotype/HLA call, your name, your date of birth, exact age, specific medication names, specific family-history details, free-text intake answers, or exact height and weight.

Mode 2 — Full-reading narration (full_reading; the default when AI is on)

This is the default mode and the one that delivers personalized prose. The payload contains everything in Mode 1, plus:

What is still never sent: your raw genome file, any rsID-level result, chromosomal coordinate, raw nucleotide genotype, phased VCF call, your full date of birth, your exact age, specific family-history text, or your exact height and weight. Exact interpreted calls—including APOE diplotypes, CYP star-alleles, and HLA types—may be included in this mode. The deterministic "template baseline" the report would otherwise show is stripped before sending; the model receives the interpreted fields above, not your on-device draft prose.

Mode 3 — Dr. Prime chat (the in-app guide)

Dr. Prime is an optional in-app chat that helps you understand the active profile's own report — especially medication–gene relationships. Dr. Prime chat grounds on that profile's full interpreted report inventory, not only its medication card. This includes interpreted findings such as APOE diplotypes, polygenic risk scores, carrier states, haplogroups, and traits; the top salience-ranked findings are provided in context directly, with the remainder reachable through an on-device search. This uses the active profile's full-reading consent tier and the same on-device guard as narration. The hard floor (rsIDs, raw genotypes, coordinates, surname, full name, date of birth) is blocked in every mode. When cloud AI is enabled for that profile, Dr. Prime may send:

Before any message leaves your device, a separate on-device guard enforces a hard floor that applies in every mode: it blocks raw genetic identifiers that are pure pointers (rsIDs, raw nucleotide genotypes, phased VCF calls, chromosomal coordinates) and hard identifiers (surname, full name, full date of birth, exact age); if any would appear, the message is refused rather than sent. Interpreted calls such as diplotypes, star-alleles, and HLA types are not on the hard floor because they are the interpreted findings the chat exists to discuss. They flow only when the active profile has current cloud-AI consent and may be withheld under the stricter minimized tier. Dr. Prime uses the same zero-retention relay, Fireworks account, and rate limits described below. When cloud AI is off for the profile, no chat content or report context is sent to the relay.

Mode 4 — Ancestry prose (Ancestry tab only)

When you view the Ancestry tab with Deep Narration on, the relay payload for ancestry prose contains:

These are sent only when you are viewing the Ancestry tab with Deep Narration on; they describe interpreted ancestry structure, not your raw genotype, and they ride under the same Deep Narration consent. Supporting SNPs, raw rsID calls, and raw genotypes are never sent.

How our relay server handles the request — zero-retention

Our relay server's role is narrow and well-defined:

  1. Authenticate the request using your signed SynaptiX license entitlement.
  2. Check rate limits for your license (see "AI rate limits" below).
  3. Forward the request to Fireworks AI's API endpoint using our Fireworks API key.
  4. Return the model response to your device.
  5. Log usage metadata for rate-limit enforcement: license ID, timestamp, input/output token counts, and the body-system page identifier. The content of your request and the model response are not stored on our server.

We refer to this as a zero-retention pass-through: the content transits through our server but is not persisted there. Standard hosting infrastructure logs (described in "Website, licensing server, and security logs" below) may incidentally capture request metadata (IP address, timestamps) but not request bodies or response bodies.

What Fireworks AI receives, and under what account

Because we operate the relay using our own Fireworks API account, Fireworks AI sees the request content under our account, not yours. You do not have an account relationship with Fireworks; we do. Fireworks enables prompt caching by default. Prompt and generation data exist in volatile memory while a request is processed. Cached prompt data usually remains in volatile memory for at least several minutes and may remain for up to several hours, depending on the model, load, and deployment; responses are not cached. Fireworks states that it does not log or store prompt or generation data in persistent storage for open models and does not use prompts or API inputs to train or improve its models without explicit opt-in. We do not opt in. Fireworks logs service metadata such as token counts. The content does not persist on our relay. Fireworks' handling of the request during processing is governed by https://fireworks.ai/privacy-policy, https://docs.fireworks.ai/guides/security_compliance/data_handling, and https://docs.fireworks.ai/guides/prompt-caching.

Future Deep Personalization design

Deep Personalization is a dormant design associated with the future SynaptiX+ add-on. SynaptiX+ is default-off and is not currently sold; Deep Personalization is not currently available. The old add-on name "Dr. Prime+" is permanently deprecated.

If this feature is launched later, it must have its own profile-scoped consent step. Standard narration consent cannot enable it. The intended payload may include:

What is never sent, even in Deep Personalization: your raw genome file, rsIDs, chromosomal coordinates, raw nucleotide genotype calls, phased VCF calls, or HGVS strings. Exact APOE diplotypes, CYP star-alleles or diplotypes, and HLA types are interpreted findings rather than raw-genome pointers and may be included only after the separate Deep Personalization consent described above. A fail-closed on-device guard runs before egress.

Because supplement-protocol output can be perceived as medical or therapeutic advice, a future launch must keep its consent distinct from standard narration consent and apply the EULA's no-medical-advice boundary in full. This paragraph describes design intent; it does not activate or offer the feature.

QR viewer and MedicamentiX card sharing

On your MedicamentiX medication-safety card, you can generate a QR code that encodes your medication and vaccine pharmacogenomic findings (including, where you have entered them, your name, gender, age, generation date, and emergency-contact name and phone number). This lets you share a scannable card with a clinician, pharmacist, or emergency responder.

How the QR works — bearer artifact with an online lifecycle check:

Medication and vaccine input (processed locally)

When you enter medication or vaccine names into SynaptiX (for example, telling the app what you currently take, or asking Dr. Prime about a specific drug), that free-text input is processed locally on your device for brand-name and synonym resolution (mapping "Tylenol" to "acetaminophen", or a vaccine brand to its generic antigen, using on-device dictionaries). This resolution happens entirely on your machine; the raw free-text inputs are not sent to SynaptiX servers as part of resolution.

Where medication names may leave the device: when cloud AI is active for a profile, full-reading narration or Dr. Prime chat may include that profile's medication names in the interpreted payload sent to the relay, as described above. When cloud AI is off for the profile, its medication names never leave the device through an AI request.

Family and profiles (stored locally)

With the Family tier, SynaptiX lets you manage up to four total genome profiles on one device, including the purchaser's profile. The following data is stored locally on your device for each family profile:

To draw the roster while profiles are locked, SynaptiX keeps a small local index containing the member's display name, gender, approximate five-year age band, relationship, and report-status counts. Exact age or date of birth, the DNA-file path, medications, conditions, family history, consent records, and other intake answers are kept separately in an encrypted private-intake envelope. Family analysis, narration, medication-card, monograph, and aggregation artifacts are also stored in profile- and artifact-bound encrypted envelopes. Corrupt or unauthenticated protected data is reported as an error; it is not treated as an empty profile.

Family profiles, cross-profile summaries, and aggregated analysis are stored locally on your device and are not sent to SynaptiX servers. Each adult controls their own profile consent. A profile for a person aged 13–17 requires both consent from a parent or legal guardian with authority and separate assent from the minor. Anyone under 13 is blocked. When a minor reaches 18, existing reports remain readable, but new analysis and cloud AI stay blocked until that person reviews the current terms and decides independently.

When you contact us by email

If you email us (e.g., at hi@synaptix.bio for support), we receive your email address and the contents of your message. We use this only to respond to you. We retain support correspondence for as long as needed to resolve the issue and for a reasonable period thereafter for our records.

Website, licensing server, and security logs

When you visit synaptix.bio, use the customer device-management portal, download the application, or activate a license, our hosting and licensing infrastructure may automatically process technical logs containing:

DataWhy it's collectedRetention
Your IP addressTo deliver the requested content, prevent abuse, rate-limit, and secure the licensing system30 days
Your user agent string (your browser or application version)Diagnostic purposes (knowing which clients are connecting) and security (detecting unusual patterns)Same as IP address
The URL path you requested and HTTP methodOperational logging and security monitoringSame as above
Request timestampOperational and audit loggingSame as above
Error / status codes and security eventsTo troubleshoot service issues and detect abuse30 days

We use these logs only to operate the Services, prevent abuse, troubleshoot issues, and secure the licensing infrastructure. We do not use these logs for advertising, behavioral analytics, or building user profiles, and we do not share them with third parties except where required to operate the underlying hosting service (e.g., the hosting provider itself processes them as part of delivering the service) or where required by law.

This logging is an unavoidable feature of operating any web service. We have configured our infrastructure to retain the minimum necessary and to expire logs on the schedules above.


Third parties we use, and what they receive

To operate SynaptiX, we rely on external service providers across the following functions: payment processing, optional Deep Narration, email delivery, web/application hosting, content-delivery / security proxy, and map tiles for the Ancestry tab. Here is exactly what each category receives.

Stripe (payment processing)

When you purchase a SynaptiX license, your payment is processed by Stripe, Inc., a Delaware-based corporation that is a global standard for online payments. Stripe receives the data necessary to process your transaction: your card or payment-method details, billing address, and customer email.

Stripe's handling of your payment data is governed by Stripe's Privacy Policy, which you can read at https://stripe.com/privacy.

We never see your full card number or other sensitive payment-method details. We receive only transaction confirmations from Stripe (the checkout session ID, payment intent ID, customer ID, and transaction amounts).

Fireworks AI and GLM 5.2 (optional Deep Narration and Dr. Prime backend)

Only a profile with current, profile-scoped cloud-AI consent sends the interpreted payload described in "When you use optional Deep Narration and Dr. Prime chat" above through our relay server. The relay then forwards that request to Fireworks AI using our Fireworks API account. Fireworks hosts GLM 5.2 directly; Z.ai developed the model weights, but Z.ai does not receive the request through this deployment. Local legal acceptance and local genome analysis do not turn this on by themselves.

Fireworks AI receives the interpreted fields described in the per-mode breakdown above — gene names, interpreted risk tiers, a bucketed profile, the current page identifier; in full-reading mode your first name, broader interpreted findings (including interpreted genetic calls such as diplotypes, star-alleles, and HLA types), and medication context; in Dr. Prime chat (which honors that same default tier) your typed question, the medication names you ask about, the relevant interpreted genetic calls, and your first name; and in Ancestry prose your haplogroup IDs and ancestry-projection coordinates. It does not receive your raw genome file, rsID-level results, raw nucleotide genotypes, phased VCF calls or chromosomal coordinates, your surname or full name, your full date of birth, your exact age, or your specific family-history details. The transaction occurs under our Fireworks account, not yours; you do not need to maintain a Fireworks account. Fireworks' policies at https://fireworks.ai/privacy-policy and https://docs.fireworks.ai/guides/security_compliance/data_handling govern how Fireworks handles request content during processing.

If cloud AI is off for a profile, that profile sends no data to Fireworks AI or to our relay server's AI endpoint. One profile's choice does not enable cloud AI for another profile.

Our email delivery provider — Proton Mail

When we send you your SynaptiX license key or other transactional emails, we send them via Proton Mail's SMTP service (operated by Proton AG, a Swiss company). Proton Mail receives your email address and the contents of the message so it can deliver it to your inbox. Proton operates under Swiss jurisdiction and its handling of email content and metadata is governed by Swiss data-protection law and Proton's own privacy practices.

Proton Mail's privacy policy is at https://proton.me/legal/privacy.

Because we send directly via Proton Mail's SMTP, we do not use a separate bulk-email delivery service such as SendGrid or Mailgun. Proton Mail, the Internet infrastructure that carries the message, and your receiving email provider may process message content and delivery metadata in transit.

Hosting and licensing-server infrastructure — 1984 Hosting (Iceland)

The synaptix.bio website, the customer device-management portal, and the licensing server are hosted on 1984 Hosting (1984.is), a hosting provider based in Reykjavik, Iceland, operating under Icelandic jurisdiction on infrastructure powered by 100% renewable energy. The hosting provider processes:

1984 Hosting retains access logs for a short window for security and abuse-prevention purposes, governed by their own terms and Icelandic law. 1984 Hosting's privacy/GDPR practices are described at https://1984.hosting/GDPR/.

Content-delivery / security proxy — Cloudflare

Cloudflare sits in the request path in front of synaptix.bio and our licensing infrastructure. For proxied HTTPS requests, Cloudflare terminates the connection from your browser or application and establishes a separate encrypted connection to our origin. It therefore processes connection and request metadata (including IP address, request path, method, and timestamps) and can process request headers and bodies while routing and securing the request. This includes the body of an optional cloud-AI relay request when that endpoint is proxied. The raw genome file is not placed in that request, but the request can contain the interpreted findings and profile context disclosed in the cloud-AI section above. Whether Cloudflare inspects or retains particular content depends on the Cloudflare services and configuration in use; this policy does not describe that processing as metadata-only.

Cloudflare's privacy policy is at https://www.cloudflare.com/privacypolicy/.

Microsoft Clarity and X Ads / X Pixel (marketing website measurement)

The public synaptix.bio marketing website uses Microsoft Clarity to understand aggregate page behavior, rendering issues, and site usability. Clarity may receive page URLs, browser and device metadata, interaction events, IP-derived location, and similar website-analytics information according to Microsoft's privacy practices. Clarity does not receive your raw genome, interpreted findings, license key, AI prompts, or desktop-app activity.

The marketing website also uses X Ads / X Pixel for advertising measurement and conversion attribution. The browser pixel can receive standard pixel-request metadata such as page URL, browser/device information, IP address, and any X click ID (twclid) associated with the visit. When you submit the waitlist form, our server may also send X a Conversion API event containing: your email address hashed with SHA-256, twclid if present, your IP address, your user-agent string, the event source URL, the conversion timestamp, and a conversion ID used for attribution/deduplication. We use this only to measure whether marketing campaigns are producing waitlist signups. We do not send X your raw genome, genetic or health findings, license key, Deep Narration content, or desktop-app activity.

Microsoft's privacy statement is at https://privacy.microsoft.com/privacystatement. X's privacy policy is at https://x.com/privacy.

CARTO / OpenStreetMap (Ancestry tab map tiles)

The Ancestry tab displays an interactive map using map tiles served by CARTO and OpenStreetMap. When you view the map, your device requests tile images directly from CARTO's tile servers. As a result, CARTO may receive your IP address and standard request metadata (timestamp, user-agent, the tile coordinates requested). No SynaptiX data and no genetic information is sent to CARTO or OpenStreetMap — only the tile-image requests needed to draw the map. The haplogroup and ancestry data shown on the map is rendered locally in your browser from data already on your device.

CARTO's privacy policy is at https://carto.com/privacy/, and OpenStreetMap's is at https://wiki.osmfoundation.org/wiki/Privacy_Policy.


Where we store data, and how we protect it

Your local data (everything related to your DNA and analyses, including family profiles and their PIN-protected material) lives on your computer, under your operating system's user-data permissions. We have no access to it, and we cannot recover it for you if you lose it. Family protected artifacts use context-bound authenticated encryption: a member PIN can open that member's material, while the sealed Family key lets the PAH master PIN recover Family material. The PINs themselves are never stored. On Windows, non-Family private intake uses a random local vault secret protected for the current Windows user with DPAPI. Individual derived report artifacts that are not Family-PIN protected remain local under the operating system user's app-data permissions; they are not represented as PIN-encrypted.

Our server-side databases contain the licensing, checkout, device-portal, public-card, AI-usage, and optional-telemetry records described above and are stored on a server we operate. The durable license record uses cryptographic hashes for license keys and activation tokens. The pending email outbox is the disclosed exception: it contains recoverable credentials protected with authenticated encryption until its row is deleted after delivery or an earlier refund, revocation, or cancellation.

We use HTTPS encryption for all communication between the SynaptiX desktop application and our licensing server.

If the Personal Information Protection and Electronic Documents Act (PIPEDA) applies, we will report a breach to the Office of the Privacy Commissioner of Canada and notify affected individuals as soon as feasible when the breach creates a real risk of significant harm. SynaptiX v1 does not offer a GDPR or UK-GDPR service in the blocked launch countries and makes no EU- or UK-specific breach-notification promise in this policy. If another mandatory law applies to a particular incident, that law controls.


How long we retain your data

CategoryRetention period
License records (email, transaction IDs, license status)For the lifetime of your license, plus 7 years for tax and accounting record-keeping
Device activation records (keyed by hardware-derived device identifier)For the lifetime of the device's activation, plus 6 months after the activation is revoked or deactivated
AI-narration usage metadata (license ID, timestamp, token counts, page ID)Rolling 24-hour window for rate-limit enforcement; not retained beyond that
Operational logs (server access, CDN, and licensing)30 days
Optional anonymized telemetry90 days
Email correspondence with support2 years from the date of the most recent message
Marketing or newsletter signups (if applicable)Until you unsubscribe, plus 30 days

We do not retain data longer than necessary for the purposes described in this policy.


Your rights

Depending on where you live, you may have legal rights over your personal data. Where these rights apply, we will honor them. The most common rights are:

To exercise any of these rights, email us at hi@synaptix.bio. We may ask you to verify your identity before honoring a request, to make sure we are not sending your data to someone else.


International data transfers

The Operator is based in Ontario, Canada. Our license server is hosted by 1984 Hosting in Reykjavik, Iceland, under Icelandic jurisdiction. Our transactional email is delivered via Proton Mail (Proton AG, Switzerland), under Swiss jurisdiction. If you are located outside Canada, Iceland, or Switzerland, your data may be transferred to and processed in one or more of those countries.

The v1 launch restriction remains the same: no offering or sale in the EU27, Iceland, Liechtenstein, Norway, or the United Kingdom. Switzerland remains eligible. This policy makes no GDPR, UK-GDPR, Standard Contractual Clauses, or EU/UK adequacy promise for the v1 service.

Some providers operate US/global infrastructure: Stripe is US-based for payment processing; Cloudflare operates a global edge network; Microsoft Clarity and X Ads operate global marketing-measurement infrastructure; CARTO operates US/global map-tile infrastructure. Personal data handled by those services may therefore be processed in the United States or other jurisdictions where the relevant provider operates. This policy does not claim that every such transfer is covered by Standard Contractual Clauses or the EU-US Data Privacy Framework unless that safeguard has been verified for the specific provider, recipient, account, and transfer. Optional AI request content is processed on Fireworks AI's infrastructure in the United States under our account. Z.ai does not receive the request through this deployment. Review Fireworks' privacy practices at https://fireworks.ai/privacy-policy and https://docs.fireworks.ai/guides/security_compliance/data_handling.


Minors

You must be at least 18 years old, or the age of majority in your jurisdiction if higher, to purchase a SynaptiX license. Profile eligibility is different:

The purchaser or Family administrator cannot consent to cloud AI for another adult profile. A Family master PIN provides local administration and recovery access; it is not consent on another person's behalf.


Changes to this policy

We may update this policy from time to time. When we do, we will revise the "Effective Date" at the top. For material changes, we will additionally notify customers via email.

The current version is always available at https://synaptix.bio/legal/privacy-policy.


Contact us

Questions about this policy, requests under the rights described above, or general privacy concerns:

Email: hi@synaptix.bio Operator: Paris Valentino Iason Kollias Location: Ontario, Canada


This policy was drafted in plain English to be readable. If anything is unclear, email us and we will explain it.