SynaptiX Privacy Policy
Effective Date: June 30, 2026
Who we are
SynaptiX is a product operated by Paris Valentino Iason Kollias, a sole proprietor based in Ontario, Canada (referred to in this policy as "the Operator", "we", "us", or "our"). You can reach us at hi@synaptix.bio.
When you see the words "SynaptiX", "the App", or "the Software" in this policy, they refer to the SynaptiX desktop application and the licensing infrastructure that supports it.
What this policy covers
This policy explains what personal data we collect, how we use it, and the rights you have over it. It applies to:
- The SynaptiX desktop application you install on your computer
- The synaptix.bio website
- The licensing server that authorizes your installation
SynaptiX v1 is not offered or sold in the 27 European Union member states, Iceland, Liechtenstein, Norway, or the United Kingdom. Switzerland is not part of that launch block. This policy does not promise GDPR or UK-GDPR service availability. Mandatory privacy rights that apply to an eligible purchaser are not waived by this policy.
The headline: what we do NOT do
SynaptiX is designed so that your raw genome stays on your computer. Interpreted findings may leave only for optional, profile-scoped cloud features you enable. We want to be unambiguous about that boundary before we describe the small amount of data we do collect:
- Your raw genome never goes to SynaptiX servers. This means the file you open in SynaptiX and its rsIDs, chromosomal coordinates, raw nucleotide genotypes, and phased VCF calls. Parsing and analysis happen on your local machine. Optional cloud features may receive selected interpreted findings from that analysis—including APOE diplotypes, CYP star-alleles, and HLA types—only as disclosed below and only after that profile enables cloud AI.
- Optional, profile-scoped Deep Narration and Dr. Prime chat: accepting the legal terms or agreeing to local genome analysis does not silently turn on cloud AI. Each adult decides for their own profile. A profile for someone aged 13–17 starts with cloud AI off and requires separate agreement from both the parent/legal guardian and the minor before cloud processing begins; either may refuse or withdraw. When cloud AI is active for a profile, an interpreted, non-raw summary of that profile's findings transits through our zero-retention relay server, which forwards the request directly to Fireworks AI using our Fireworks account. Fireworks hosts and runs the open GLM 5.2 model weights on its own infrastructure; Z.ai developed the model, but Z.ai does not receive the request through this deployment. The scope depends on the mode (see "Deep Narration and Dr. Prime chat" below). It never includes the raw genome file, rsIDs, chromosomal coordinates, raw nucleotide genotypes, or phased VCF calls. Interpreted notation such as an APOE diplotype, CYP star-alleles, or HLA types may be included because those are the findings being explained. Request and response content is not stored by our relay; only rate-limit metadata (license ID, timestamp, token counts, and page identifier) is logged. Turning cloud AI off for one profile stops AI egress for that profile without changing another profile's choice.
- We do not run product analytics on you by default. Out of the box, the SynaptiX desktop application includes no optional product analytics and runs no trackers. It still contacts SynaptiX infrastructure when you activate a license and for update checks; automatic update checking can be disabled in Settings. It also makes network requests when you choose an online feature, such as cloud AI or Ancestry map tiles. The synaptix.bio marketing website uses limited third-party marketing measurement (Microsoft Clarity and X Ads/X Pixel) so we can understand site performance and ad conversions. If you submit the waitlist form, we may send X a server-side conversion event containing your email address hashed with SHA-256, the X click ID (
twclid) if X provided one, your IP address, your user-agent string, the page URL, and a conversion ID. This marketing measurement never includes your raw genome, interpreted findings, license key, AI prompts, or app usage. If you choose to turn on the optional "Anonymous diagnostics" toggle in the desktop app (off by default), the following applies — see "Anonymous diagnostics toggle" below for exactly what is and is not sent.
- We do not sell personal data or share genetic or health information with advertisers or data brokers. We do use X Ads for marketing-site attribution, as described above and in the third-party provider section below. We do not share your raw genome, genetic findings, health findings, license records, Deep Narration content, or desktop-app activity with advertising networks or data brokers. We also use service providers needed to operate payments, email delivery, hosting, and (optionally, at your election) Deep Narration and map tiles for the Ancestry tab. These providers are listed and described below.
- We do not sell your data. We have no business model that involves selling your information.
If you exit the rest of this policy now and remember only one thing, remember this: your raw genome never leaves your device. Selected interpreted findings can leave only when you enable an optional cloud feature for that profile; the exact content is disclosed below by mode.
Anonymous diagnostics toggle and report exports
Two specific items deserve their own clear disclosure:
The "Anonymous diagnostics" toggle. The SynaptiX Settings screen includes an "Anonymous diagnostics" toggle, which is off by default. When you turn this toggle on, SynaptiX sends encrypted, de-identified usage and diagnostic events to our servers to help us improve the app. What is sent:
- Usage events: which screens you view and which features you toggle on or off.
- Diagnostics: where errors occur (an error class and a sanitized, truncated message; never your raw data), report-build outcomes (timing and counts), and AI-narration relay outcomes (success/failure, timing, error class).
- Report outcome metadata: the number of findings by category, which report sections ran, narration length, and the gene and drug names that appear in your report (e.g. that "CYP2D6" or "HLA-B" was part of a report). This helps us find coverage gaps in our pharmacogenomics data.
What is never included in the optional telemetry payload, even with the toggle on: your specific genetic results or genotype, your phenotype calls (e.g. we never learn whether you are a "poor metabolizer"), your name, date of birth, profile name, raw genome, rsID-level results, file paths, or your license key. The optional telemetry payload contains no IP-address field. Connection, CDN, hosting, and server infrastructure may process or log the source IP address as ordinary connection metadata; those operational logs are retained for 30 days.
How de-identification works: events carry a random client identifier that rotates every 14 days, so events cannot be stitched into a long-term profile of you. A payload guard runs on your device before any byte leaves, and again on our server, refusing to accept any field outside the documented schema. All optional telemetry, including raw events and any derived counts or frequency tables, is deleted after 90 days.
You can review exactly what would be sent via the "See what would be sent" panel in Settings, trigger an immediate send with "Send now", clear the local log at any time, or turn the toggle off entirely — turning it off stops all collection immediately. If we ever change what this toggle collects, we will update this policy first, and it will remain opt-in.
Report exports. A user-initiated Markdown, HTML, or print-to-PDF export contains the rendered report and basic display metadata: profile name, age, gender, generation date, and page count. Internal prompts, narrative input evidence, model reasoning, raw model output, diagnostics, model or source status, application build metadata, and local file paths are excluded. The export is saved only where you choose on your device; SynaptiX does not upload it. Anyone you later share the file with can read the report content and its profile metadata.
What we DO collect, and why
We collect specific data that is necessary to sell you a license and run the application. The server-side record categories described in this policy are: durable purchase and license records; pending transactional-email delivery records; checkout legal-acceptance, payment-event, and pending-revocation records; device-activation and portal-authentication data; public medication-card registry records; AI rate-limit metadata; optional telemetry when you enable it; and operational and security logs. Founders Edition purchases also carry founder-status fields. The sections below explain the main fields and purposes; this heading does not mean that the durable license row is the only server-side record.
When you purchase a license
When you complete a purchase through the synaptix.bio checkout flow, we collect:
| Data | Source | Why we collect it |
|---|---|---|
| Your email address | Provided by you at checkout (via Stripe) | To send you your license key and to contact you about license-related issues |
| Payment information (credit/debit card details, billing address) | Processed by Stripe, not stored by us | Stripe handles all payment data; we receive only transaction confirmation, not card numbers |
| Stripe transaction identifiers (checkout session ID, payment intent ID, customer ID) | Generated by Stripe | Records of which purchases produced which licenses, for receipt and refund reconciliation |
| The license tier you purchased (Individual or Family) and the price paid | Determined by your purchase | Provisions the correct entitlements on your license |
The durable purchase and license record stores: cryptographic hashes and short suffixes of the license key and customer-portal activation token; the license tier, profile limit, feature and plan identifiers, and status; customer email; applicable Stripe checkout-session, payment-intent, customer, subscription, and price identifiers; purchase amounts and currency; email-delivery, creation, update, and activation timestamps; and, for a Founders Edition purchase, its founder number and date.
The durable record does not store a plaintext license key or activation token. Pending email delivery is a limited exception to the hash-only durable record: until the license email is delivered, the email outbox stores the customer email, tier, and recoverable copies of the working license key and customer-portal token protected with authenticated encryption, together with delivery-control timestamps and claim data. The outbox row is deleted after successful delivery, or if the license is refunded, revoked, or cancelled before delivery. The server must hold the separate encryption key while delivery is pending, so we do not claim that compromise of both the database and that server-side key could never expose a pending credential.
When you activate SynaptiX on a device
When you enter your license key in the desktop application to activate it, we collect:
| Data | Why we collect it |
|---|---|
| A device identifier (a cryptographic hash derived from your device's hardware characteristics — see below) | To enforce your activation limit (Individual: 3 devices; Family: 10 devices) and to let you manage your active devices through the customer portal |
| The application version installed on that device | For diagnostic purposes (knowing which versions are active in the field) |
| Timestamps for when the device first activated and when it was last seen by the server | To show device activity in the customer portal and support manual device deactivation |
How the device identifier works. The device identifier is a one-way cryptographic hash derived from your device's hardware characteristics — specifically the motherboard serial/UUID, the CPU identifier, and the primary network-adapter MAC address on Windows. These values are normalized (uppercased, whitespace-stripped), concatenated, and passed through SHA-256 to produce a stable 64-character hex string. We use this hardware-derived hash solely to enforce your activation limit, so that reinstalling the application on the same computer does not consume an additional activation slot. The hash is one-way — we cannot reverse it to recover your specific motherboard model, CPU serial, or MAC address. It identifies "this physical computer" to our licensing server; it does not reveal what that hardware is.
When you use optional Deep Narration and Dr. Prime chat
SynaptiX includes AI-enhanced features powered by the GLM 5.2 language model, developed by Z.ai and hosted directly by Fireworks AI. Fireworks runs the model weights on its own inference infrastructure; Z.ai does not receive the request through this deployment. These features write the reports SynaptiX generates in clearer, more personalized prose, and let you ask follow-up questions about your findings.
How it is turned on. Cloud AI has its own consent control for each profile. It is separate from legal acceptance and from permission to analyze the DNA locally. An adult profile owner can enable or disable it for themselves. For a profile aged 13–17, cloud AI is off by default and can turn on only after the parent/legal guardian and the minor each separately agree to the disclosed cloud processing. Either may withhold or withdraw that agreement. The disclosure is versioned: when the scope of what is sent materially changes, the affected profile must decide again before the changed flow takes effect. When a minor profile reaches 18, the prior two-party cloud consent expires and cloud egress remains blocked until the now-adult profile owner decides independently.
The scope of what is sent depends on the mode you are using. This is the honest, per-mode breakdown. The product is personalized — for example, full-reading narration is written to address you by name and reference your specific findings and medications, because that personalization is the value of the feature. The modes are:
Mode 1 — Default minimized narration (strict_minimized)
This is the most conservative narration mode. If you select it, the payload sent to the relay contains only:
- Per-finding insights: for each finding on the page, an opaque finding identifier (a one-way token, not your real result ID), the gene name (e.g., "CYP2C19", "APOE" — a gene name only, validated against a fixed catalog), and an interpreted risk or phenotype tier drawn from a fixed vocabulary (e.g., "poor metabolizer", "higher risk", "carrier").
- A bucketed profile summary: a decade age band (e.g., "50s", never your exact age), your gender selection (Male/Female), a broad continental ancestry bucket (e.g., "European", "East Asian" — never a specific sub-population), and coarse lifestyle bands for body type, BMI (a WHO category computed on-device from height and weight, which themselves stay on-device), smoking status, exercise level, and sleep. It also includes a small set of yes/no flags indicating only that a risk-amplifying factor applied (e.g., that a family-history amplifier fired) — without the underlying family-history text.
- The current page identifier (e.g., "brain", "heart", "summary") so the model knows which page's narrative it is refining.
What is never sent in this mode: your raw genome file, any rsID-level result, chromosomal coordinate, raw nucleotide genotype, phased VCF call, specific interpreted allele/star-allele/diplotype/HLA call, your name, your date of birth, exact age, specific medication names, specific family-history details, free-text intake answers, or exact height and weight.
Mode 2 — Full-reading narration (full_reading; the default when AI is on)
This is the default mode and the one that delivers personalized prose. The payload contains everything in Mode 1, plus:
- Your first name. Full-reading narration is written to address you personally (for example, "Paris, your empathy profile runs higher than average") — the personalization is the point of the mode. Your name is sent so the model can write prose that speaks to you.
- Broader interpreted findings. A wider set of interpreted gene/finding/phenotype context than the minimized mode, so the narrative can connect findings across body systems.
- Medication context. Your current medication names and relevant pharmacogenomic findings, so the narrative can discuss how your genetics relate to medications you actually take.
What is still never sent: your raw genome file, any rsID-level result, chromosomal coordinate, raw nucleotide genotype, phased VCF call, your full date of birth, your exact age, specific family-history text, or your exact height and weight. Exact interpreted calls—including APOE diplotypes, CYP star-alleles, and HLA types—may be included in this mode. The deterministic "template baseline" the report would otherwise show is stripped before sending; the model receives the interpreted fields above, not your on-device draft prose.
Mode 3 — Dr. Prime chat (the in-app guide)
Dr. Prime is an optional in-app chat that helps you understand the active profile's own report — especially medication–gene relationships. Dr. Prime chat grounds on that profile's full interpreted report inventory, not only its medication card. This includes interpreted findings such as APOE diplotypes, polygenic risk scores, carrier states, haplogroups, and traits; the top salience-ranked findings are provided in context directly, with the remainder reachable through an on-device search. This uses the active profile's full-reading consent tier and the same on-device guard as narration. The hard floor (rsIDs, raw genotypes, coordinates, surname, full name, date of birth) is blocked in every mode. When cloud AI is enabled for that profile, Dr. Prime may send:
- Gene names relevant to your findings
- Interpreted genetic calls — your diplotypes (e.g., APOE E4/E4), star-allele codes (e.g., CYP2D6\4), and specific HLA types (e.g., HLA-B\57:01) — so you can discuss what your result means
- The medication names you ask about (and, where relevant, the medications you are currently taking)
- Severities and pharmacogenomic guideline levels (e.g., CPIC tiers, evidence-source badges such as
CGfor clinical-guideline sources andPRfor published-research sources) - Your typed question to Dr. Prime
- Your first name, so the assistant can address you naturally and disambiguate members of a shared household
- Relevant de-identified findings drawn from your interpreted report
Before any message leaves your device, a separate on-device guard enforces a hard floor that applies in every mode: it blocks raw genetic identifiers that are pure pointers (rsIDs, raw nucleotide genotypes, phased VCF calls, chromosomal coordinates) and hard identifiers (surname, full name, full date of birth, exact age); if any would appear, the message is refused rather than sent. Interpreted calls such as diplotypes, star-alleles, and HLA types are not on the hard floor because they are the interpreted findings the chat exists to discuss. They flow only when the active profile has current cloud-AI consent and may be withheld under the stricter minimized tier. Dr. Prime uses the same zero-retention relay, Fireworks account, and rate limits described below. When cloud AI is off for the profile, no chat content or report context is sent to the relay.
Mode 4 — Ancestry prose (Ancestry tab only)
When you view the Ancestry tab with Deep Narration on, the relay payload for ancestry prose contains:
- Your haplogroup IDs (e.g., "R-M269", "H1a", "K1a" — interpreted ancestry calls that describe broad maternal and paternal lineage groupings, including deeper subclades where your chip coverage supports them)
- Broad ancestry-projection coordinates (numerical points that summarize where your DNA sits in continental ancestry space, derived from many positions across your chip)
These are sent only when you are viewing the Ancestry tab with Deep Narration on; they describe interpreted ancestry structure, not your raw genotype, and they ride under the same Deep Narration consent. Supporting SNPs, raw rsID calls, and raw genotypes are never sent.
How our relay server handles the request — zero-retention
Our relay server's role is narrow and well-defined:
- Authenticate the request using your signed SynaptiX license entitlement.
- Check rate limits for your license (see "AI rate limits" below).
- Forward the request to Fireworks AI's API endpoint using our Fireworks API key.
- Return the model response to your device.
- Log usage metadata for rate-limit enforcement: license ID, timestamp, input/output token counts, and the body-system page identifier. The content of your request and the model response are not stored on our server.
We refer to this as a zero-retention pass-through: the content transits through our server but is not persisted there. Standard hosting infrastructure logs (described in "Website, licensing server, and security logs" below) may incidentally capture request metadata (IP address, timestamps) but not request bodies or response bodies.
What Fireworks AI receives, and under what account
Because we operate the relay using our own Fireworks API account, Fireworks AI sees the request content under our account, not yours. You do not have an account relationship with Fireworks; we do. Fireworks enables prompt caching by default. Prompt and generation data exist in volatile memory while a request is processed. Cached prompt data usually remains in volatile memory for at least several minutes and may remain for up to several hours, depending on the model, load, and deployment; responses are not cached. Fireworks states that it does not log or store prompt or generation data in persistent storage for open models and does not use prompts or API inputs to train or improve its models without explicit opt-in. We do not opt in. Fireworks logs service metadata such as token counts. The content does not persist on our relay. Fireworks' handling of the request during processing is governed by https://fireworks.ai/privacy-policy, https://docs.fireworks.ai/guides/security_compliance/data_handling, and https://docs.fireworks.ai/guides/prompt-caching.
Future Deep Personalization design
Deep Personalization is a dormant design associated with the future SynaptiX+ add-on. SynaptiX+ is default-off and is not currently sold; Deep Personalization is not currently available. The old add-on name "Dr. Prime+" is permanently deprecated.
If this feature is launched later, it must have its own profile-scoped consent step. Standard narration consent cannot enable it. The intended payload may include:
- Your name
- An age band (decade, never your exact age or date of birth)
- Your gender (Male/Female)
- Your current medication names
- The full set of interpreted findings (gene · interpretation · severity · guideline tier), including exact interpreted APOE diplotypes, CYP star-alleles or diplotypes, and HLA types when present
- Your stated goals / the question you asked
What is never sent, even in Deep Personalization: your raw genome file, rsIDs, chromosomal coordinates, raw nucleotide genotype calls, phased VCF calls, or HGVS strings. Exact APOE diplotypes, CYP star-alleles or diplotypes, and HLA types are interpreted findings rather than raw-genome pointers and may be included only after the separate Deep Personalization consent described above. A fail-closed on-device guard runs before egress.
Because supplement-protocol output can be perceived as medical or therapeutic advice, a future launch must keep its consent distinct from standard narration consent and apply the EULA's no-medical-advice boundary in full. This paragraph describes design intent; it does not activate or offer the feature.
QR viewer and MedicamentiX card sharing
On your MedicamentiX medication-safety card, you can generate a QR code that encodes your medication and vaccine pharmacogenomic findings (including, where you have entered them, your name, gender, age, generation date, and emergency-contact name and phone number). This lets you share a scannable card with a clinician, pharmacist, or emergency responder.
How the QR works — bearer artifact with an online lifecycle check:
- The health data is embedded in the URL fragment (the
#portion of a link such ashttps://synaptix.bio/v/#<payload>). The fragment is parsed on the viewer's device and is not sent to or stored on SynaptiX servers. No SynaptiX server receives the card contents. - Each newly generated card uses a new one-card public signing key. To certify that key, the desktop app sends the licensing service the public key, a device-key proof, and an optional random ID of the card being replaced. It does not send the profile ID, name, medications, findings, emergency contact, QR fragment, or other card contents.
- The card registry stores a random 128-bit card ID, the associated license and device IDs, the one-card public key, lifecycle status, replacement links, and issue/update/withdrawal timestamps. These records are retained with the license record so status checks remain meaningful; withdrawing a card changes its status rather than erasing the lifecycle record. If the license record is deleted, its card-registry rows are deleted with it.
- After rendering the signed snapshot, an online viewer sends only the random card ID to the SynaptiX status endpoint. The response contains lifecycle status and timestamps, not health data. The request also carries ordinary connection metadata such as IP address, user agent, and time through our API and Cloudflare, as described under website, licensing-server, and security logs.
- The viewer may show Current, Newer card exists, or Withdrawn. If it cannot connect, it says status is unavailable and keeps the signed snapshot visible. A status change cannot erase a printed card, screenshot, saved link, or copy already held by another person.
- Anyone who has the QR code or the link can view the encoded findings. There is no reader login or authentication. Online lifecycle status is context, not access control.
- You control whether to generate, print, or share the QR. SynaptiX does not transmit the card contents on your behalf.
- SynaptiX is not responsible for the security of physical cards or shared links after you generate them. Treat a printed MedicamentiX card with the same care you would treat any document containing your health information.
Medication and vaccine input (processed locally)
When you enter medication or vaccine names into SynaptiX (for example, telling the app what you currently take, or asking Dr. Prime about a specific drug), that free-text input is processed locally on your device for brand-name and synonym resolution (mapping "Tylenol" to "acetaminophen", or a vaccine brand to its generic antigen, using on-device dictionaries). This resolution happens entirely on your machine; the raw free-text inputs are not sent to SynaptiX servers as part of resolution.
Where medication names may leave the device: when cloud AI is active for a profile, full-reading narration or Dr. Prime chat may include that profile's medication names in the interpreted payload sent to the relay, as described above. When cloud AI is off for the profile, its medication names never leave the device through an AI request.
Family and profiles (stored locally)
With the Family tier, SynaptiX lets you manage up to four total genome profiles on one device, including the purchaser's profile. The following data is stored locally on your device for each family profile:
- Member name (the label you assign to the profile)
- Gender
- Age or date of birth
- Relationship type to you (e.g., spouse, parent)
- DNA source (which raw-DNA file / chip the profile was built from)
- Analysis results (the interpreted report for that profile)
- PIN hashes and sealed cryptographic keys where Family Mode PIN protection is enabled — the PIN itself is never stored; only an Argon2id hash of it and the sealed private key material are.
- Consent records showing whether the profile owner consented for themselves or, for ages 13–17, when a parent/legal guardian consented and the minor separately assented. These records remain local in the encrypted private-intake envelope.
To draw the roster while profiles are locked, SynaptiX keeps a small local index containing the member's display name, gender, approximate five-year age band, relationship, and report-status counts. Exact age or date of birth, the DNA-file path, medications, conditions, family history, consent records, and other intake answers are kept separately in an encrypted private-intake envelope. Family analysis, narration, medication-card, monograph, and aggregation artifacts are also stored in profile- and artifact-bound encrypted envelopes. Corrupt or unauthenticated protected data is reported as an error; it is not treated as an empty profile.
Family profiles, cross-profile summaries, and aggregated analysis are stored locally on your device and are not sent to SynaptiX servers. Each adult controls their own profile consent. A profile for a person aged 13–17 requires both consent from a parent or legal guardian with authority and separate assent from the minor. Anyone under 13 is blocked. When a minor reaches 18, existing reports remain readable, but new analysis and cloud AI stay blocked until that person reviews the current terms and decides independently.
When you contact us by email
If you email us (e.g., at hi@synaptix.bio for support), we receive your email address and the contents of your message. We use this only to respond to you. We retain support correspondence for as long as needed to resolve the issue and for a reasonable period thereafter for our records.
Website, licensing server, and security logs
When you visit synaptix.bio, use the customer device-management portal, download the application, or activate a license, our hosting and licensing infrastructure may automatically process technical logs containing:
| Data | Why it's collected | Retention |
|---|---|---|
| Your IP address | To deliver the requested content, prevent abuse, rate-limit, and secure the licensing system | 30 days |
| Your user agent string (your browser or application version) | Diagnostic purposes (knowing which clients are connecting) and security (detecting unusual patterns) | Same as IP address |
| The URL path you requested and HTTP method | Operational logging and security monitoring | Same as above |
| Request timestamp | Operational and audit logging | Same as above |
| Error / status codes and security events | To troubleshoot service issues and detect abuse | 30 days |
We use these logs only to operate the Services, prevent abuse, troubleshoot issues, and secure the licensing infrastructure. We do not use these logs for advertising, behavioral analytics, or building user profiles, and we do not share them with third parties except where required to operate the underlying hosting service (e.g., the hosting provider itself processes them as part of delivering the service) or where required by law.
This logging is an unavoidable feature of operating any web service. We have configured our infrastructure to retain the minimum necessary and to expire logs on the schedules above.
Third parties we use, and what they receive
To operate SynaptiX, we rely on external service providers across the following functions: payment processing, optional Deep Narration, email delivery, web/application hosting, content-delivery / security proxy, and map tiles for the Ancestry tab. Here is exactly what each category receives.
Stripe (payment processing)
When you purchase a SynaptiX license, your payment is processed by Stripe, Inc., a Delaware-based corporation that is a global standard for online payments. Stripe receives the data necessary to process your transaction: your card or payment-method details, billing address, and customer email.
Stripe's handling of your payment data is governed by Stripe's Privacy Policy, which you can read at https://stripe.com/privacy.
We never see your full card number or other sensitive payment-method details. We receive only transaction confirmations from Stripe (the checkout session ID, payment intent ID, customer ID, and transaction amounts).
Fireworks AI and GLM 5.2 (optional Deep Narration and Dr. Prime backend)
Only a profile with current, profile-scoped cloud-AI consent sends the interpreted payload described in "When you use optional Deep Narration and Dr. Prime chat" above through our relay server. The relay then forwards that request to Fireworks AI using our Fireworks API account. Fireworks hosts GLM 5.2 directly; Z.ai developed the model weights, but Z.ai does not receive the request through this deployment. Local legal acceptance and local genome analysis do not turn this on by themselves.
Fireworks AI receives the interpreted fields described in the per-mode breakdown above — gene names, interpreted risk tiers, a bucketed profile, the current page identifier; in full-reading mode your first name, broader interpreted findings (including interpreted genetic calls such as diplotypes, star-alleles, and HLA types), and medication context; in Dr. Prime chat (which honors that same default tier) your typed question, the medication names you ask about, the relevant interpreted genetic calls, and your first name; and in Ancestry prose your haplogroup IDs and ancestry-projection coordinates. It does not receive your raw genome file, rsID-level results, raw nucleotide genotypes, phased VCF calls or chromosomal coordinates, your surname or full name, your full date of birth, your exact age, or your specific family-history details. The transaction occurs under our Fireworks account, not yours; you do not need to maintain a Fireworks account. Fireworks' policies at https://fireworks.ai/privacy-policy and https://docs.fireworks.ai/guides/security_compliance/data_handling govern how Fireworks handles request content during processing.
If cloud AI is off for a profile, that profile sends no data to Fireworks AI or to our relay server's AI endpoint. One profile's choice does not enable cloud AI for another profile.
Our email delivery provider — Proton Mail
When we send you your SynaptiX license key or other transactional emails, we send them via Proton Mail's SMTP service (operated by Proton AG, a Swiss company). Proton Mail receives your email address and the contents of the message so it can deliver it to your inbox. Proton operates under Swiss jurisdiction and its handling of email content and metadata is governed by Swiss data-protection law and Proton's own privacy practices.
Proton Mail's privacy policy is at https://proton.me/legal/privacy.
Because we send directly via Proton Mail's SMTP, we do not use a separate bulk-email delivery service such as SendGrid or Mailgun. Proton Mail, the Internet infrastructure that carries the message, and your receiving email provider may process message content and delivery metadata in transit.
Hosting and licensing-server infrastructure — 1984 Hosting (Iceland)
The synaptix.bio website, the customer device-management portal, and the licensing server are hosted on 1984 Hosting (1984.is), a hosting provider based in Reykjavik, Iceland, operating under Icelandic jurisdiction on infrastructure powered by 100% renewable energy. The hosting provider processes:
- Your IP address and user-agent string (as part of delivering HTTP responses to your browser or the SynaptiX desktop application)
- Request paths, timestamps, and HTTP status codes (standard web-server access logs maintained by the hosting provider for operational and security purposes)
- Application-layer data we explicitly send to it (your license records and AI-usage rate-limit metadata, as described above)
1984 Hosting retains access logs for a short window for security and abuse-prevention purposes, governed by their own terms and Icelandic law. 1984 Hosting's privacy/GDPR practices are described at https://1984.hosting/GDPR/.
Content-delivery / security proxy — Cloudflare
Cloudflare sits in the request path in front of synaptix.bio and our licensing infrastructure. For proxied HTTPS requests, Cloudflare terminates the connection from your browser or application and establishes a separate encrypted connection to our origin. It therefore processes connection and request metadata (including IP address, request path, method, and timestamps) and can process request headers and bodies while routing and securing the request. This includes the body of an optional cloud-AI relay request when that endpoint is proxied. The raw genome file is not placed in that request, but the request can contain the interpreted findings and profile context disclosed in the cloud-AI section above. Whether Cloudflare inspects or retains particular content depends on the Cloudflare services and configuration in use; this policy does not describe that processing as metadata-only.
Cloudflare's privacy policy is at https://www.cloudflare.com/privacypolicy/.
Microsoft Clarity and X Ads / X Pixel (marketing website measurement)
The public synaptix.bio marketing website uses Microsoft Clarity to understand aggregate page behavior, rendering issues, and site usability. Clarity may receive page URLs, browser and device metadata, interaction events, IP-derived location, and similar website-analytics information according to Microsoft's privacy practices. Clarity does not receive your raw genome, interpreted findings, license key, AI prompts, or desktop-app activity.
The marketing website also uses X Ads / X Pixel for advertising measurement and conversion attribution. The browser pixel can receive standard pixel-request metadata such as page URL, browser/device information, IP address, and any X click ID (twclid) associated with the visit. When you submit the waitlist form, our server may also send X a Conversion API event containing: your email address hashed with SHA-256, twclid if present, your IP address, your user-agent string, the event source URL, the conversion timestamp, and a conversion ID used for attribution/deduplication. We use this only to measure whether marketing campaigns are producing waitlist signups. We do not send X your raw genome, genetic or health findings, license key, Deep Narration content, or desktop-app activity.
Microsoft's privacy statement is at https://privacy.microsoft.com/privacystatement. X's privacy policy is at https://x.com/privacy.
CARTO / OpenStreetMap (Ancestry tab map tiles)
The Ancestry tab displays an interactive map using map tiles served by CARTO and OpenStreetMap. When you view the map, your device requests tile images directly from CARTO's tile servers. As a result, CARTO may receive your IP address and standard request metadata (timestamp, user-agent, the tile coordinates requested). No SynaptiX data and no genetic information is sent to CARTO or OpenStreetMap — only the tile-image requests needed to draw the map. The haplogroup and ancestry data shown on the map is rendered locally in your browser from data already on your device.
CARTO's privacy policy is at https://carto.com/privacy/, and OpenStreetMap's is at https://wiki.osmfoundation.org/wiki/Privacy_Policy.
Where we store data, and how we protect it
Your local data (everything related to your DNA and analyses, including family profiles and their PIN-protected material) lives on your computer, under your operating system's user-data permissions. We have no access to it, and we cannot recover it for you if you lose it. Family protected artifacts use context-bound authenticated encryption: a member PIN can open that member's material, while the sealed Family key lets the PAH master PIN recover Family material. The PINs themselves are never stored. On Windows, non-Family private intake uses a random local vault secret protected for the current Windows user with DPAPI. Individual derived report artifacts that are not Family-PIN protected remain local under the operating system user's app-data permissions; they are not represented as PIN-encrypted.
Our server-side databases contain the licensing, checkout, device-portal, public-card, AI-usage, and optional-telemetry records described above and are stored on a server we operate. The durable license record uses cryptographic hashes for license keys and activation tokens. The pending email outbox is the disclosed exception: it contains recoverable credentials protected with authenticated encryption until its row is deleted after delivery or an earlier refund, revocation, or cancellation.
We use HTTPS encryption for all communication between the SynaptiX desktop application and our licensing server.
If the Personal Information Protection and Electronic Documents Act (PIPEDA) applies, we will report a breach to the Office of the Privacy Commissioner of Canada and notify affected individuals as soon as feasible when the breach creates a real risk of significant harm. SynaptiX v1 does not offer a GDPR or UK-GDPR service in the blocked launch countries and makes no EU- or UK-specific breach-notification promise in this policy. If another mandatory law applies to a particular incident, that law controls.
How long we retain your data
| Category | Retention period |
|---|---|
| License records (email, transaction IDs, license status) | For the lifetime of your license, plus 7 years for tax and accounting record-keeping |
| Device activation records (keyed by hardware-derived device identifier) | For the lifetime of the device's activation, plus 6 months after the activation is revoked or deactivated |
| AI-narration usage metadata (license ID, timestamp, token counts, page ID) | Rolling 24-hour window for rate-limit enforcement; not retained beyond that |
| Operational logs (server access, CDN, and licensing) | 30 days |
| Optional anonymized telemetry | 90 days |
| Email correspondence with support | 2 years from the date of the most recent message |
| Marketing or newsletter signups (if applicable) | Until you unsubscribe, plus 30 days |
We do not retain data longer than necessary for the purposes described in this policy.
Your rights
Depending on where you live, you may have legal rights over your personal data. Where these rights apply, we will honor them. The most common rights are:
- The right to know what personal data we hold about you and how we use it. This entire policy is our standing answer; if you want a specific export of your individual record, email us at hi@synaptix.bio.
- The right to access the personal data we have about you. We will provide a copy on request, generally within 30 days.
- The right to correct inaccurate or incomplete personal data we hold about you.
- The right to delete your personal data. Note that we may retain certain records (e.g., transaction records for tax purposes) where the law requires us to.
- The right to portability — receiving your personal data in a structured, commonly used format.
- The right to object to certain processing of your data, where the law gives you that right.
- The right to withdraw consent for any processing that depends on your consent (such as AI-enhanced narration, Dr. Prime chat, and ancestry prose). Deep Personalization is a future design and is not currently active.
- The right to lodge a complaint with a data-protection authority where applicable law grants that right. In Canada, that is the Office of the Privacy Commissioner of Canada (https://www.priv.gc.ca).
To exercise any of these rights, email us at hi@synaptix.bio. We may ask you to verify your identity before honoring a request, to make sure we are not sending your data to someone else.
International data transfers
The Operator is based in Ontario, Canada. Our license server is hosted by 1984 Hosting in Reykjavik, Iceland, under Icelandic jurisdiction. Our transactional email is delivered via Proton Mail (Proton AG, Switzerland), under Swiss jurisdiction. If you are located outside Canada, Iceland, or Switzerland, your data may be transferred to and processed in one or more of those countries.
The v1 launch restriction remains the same: no offering or sale in the EU27, Iceland, Liechtenstein, Norway, or the United Kingdom. Switzerland remains eligible. This policy makes no GDPR, UK-GDPR, Standard Contractual Clauses, or EU/UK adequacy promise for the v1 service.
Some providers operate US/global infrastructure: Stripe is US-based for payment processing; Cloudflare operates a global edge network; Microsoft Clarity and X Ads operate global marketing-measurement infrastructure; CARTO operates US/global map-tile infrastructure. Personal data handled by those services may therefore be processed in the United States or other jurisdictions where the relevant provider operates. This policy does not claim that every such transfer is covered by Standard Contractual Clauses or the EU-US Data Privacy Framework unless that safeguard has been verified for the specific provider, recipient, account, and transfer. Optional AI request content is processed on Fireworks AI's infrastructure in the United States under our account. Z.ai does not receive the request through this deployment. Review Fireworks' privacy practices at https://fireworks.ai/privacy-policy and https://docs.fireworks.ai/guides/security_compliance/data_handling.
Minors
You must be at least 18 years old, or the age of majority in your jurisdiction if higher, to purchase a SynaptiX license. Profile eligibility is different:
- Under 13: SynaptiX blocks profile creation and DNA analysis.
- Ages 13–17: local analysis requires consent from a parent or legal guardian with authority and separate assent from the minor. The profile's exact date of birth and local consent timestamps are stored in its encrypted private-intake record so the App can enforce the age boundary.
- Cloud AI for ages 13–17: off by default and enabled only when the guardian and minor separately agree to the disclosed cloud processing. Either may refuse or withdraw.
- At 18: the earlier guardian consent and minor assent stop authorizing new analysis and cloud AI. Existing local reports remain readable. The now-adult profile owner must review the current terms and decide independently before those operations resume.
The purchaser or Family administrator cannot consent to cloud AI for another adult profile. A Family master PIN provides local administration and recovery access; it is not consent on another person's behalf.
Changes to this policy
We may update this policy from time to time. When we do, we will revise the "Effective Date" at the top. For material changes, we will additionally notify customers via email.
The current version is always available at https://synaptix.bio/legal/privacy-policy.
Contact us
Questions about this policy, requests under the rights described above, or general privacy concerns:
Email: hi@synaptix.bio Operator: Paris Valentino Iason Kollias Location: Ontario, Canada
This policy was drafted in plain English to be readable. If anything is unclear, email us and we will explain it.