Privacy Policy

Last updated: 2026-09-17 · Scope: website synapse-app.at, native Synapse apps and the associated server services.

Note: The English version is provided for reader convenience only. Only the German version is legally binding.

Protecting your personal data is important to us. We process your data exclusively on the basis of the statutory provisions (GDPR, Austrian Data Protection Act, TKG 2021). In this declaration we inform you about the most important aspects of data processing within the scope of Synapse.

1. Controller

[First and last name / company name]
[Street and house number]
[Postal code] [City], Austria
Email: support@synapse-app.at

2. What data we process

a) Account data

At registration we collect: email address, username and a password hash. Optional: Google account ID when using "Sign in with Google".

b) Notebook content

If you use cloud sync, your notebooks, drawings and embedded media (images, PDFs, audio) are transmitted encrypted to our server and stored there. The content is accessible only to you.

c) Billing data

When concluding a paid subscription, the payment data is processed exclusively by the respective payment provider (see point 5): by Stripe Payments Europe, Ltd. for a purchase through this website, and by Google Play for an in-app purchase in the Android app.

We ourselves store only what is needed to assign the subscription: the plan code, the validity date, the status and, depending on the purchase route, the Stripe customer ID or the Google Play purchase identifier.

d) Technical data / server logs

On every access, IP address, user agent, timestamp and called URL are stored in the server log for a maximum of 14 days (legal basis: Art. 6(1)(f) GDPR — legitimate interest in IT security and abuse detection). After that the logs are automatically rotated and deleted.

e) AI usage data

When you use AI features (handwriting recognition, math solving, chat), the selected content (image excerpt, text) is transmitted to Google Gemini (see point 5) at the time of the request. We do not store the request itself, only the token count consumed, the model used and the timestamp — to settle your daily limit.

3. Purposes and legal bases

  • Performance of contract (Art. 6(1)(b) GDPR): account management, provision of the Synapse app, cloud sync.
  • Legitimate interest (Art. 6(1)(f) GDPR): IT security, abuse detection, server logs.
  • Legal obligation (Art. 6(1)(c) GDPR): retention obligations under UGB / BAO for invoices (7 years).
  • Consent (Art. 6(1)(a) GDPR): where we explicitly request your consent.

4. Retention period

  • Account data: until you delete the account. Invoice-related data is retained for 7 years under UGB/BAO and then deleted.
  • Notebook content: until you delete it. When you delete your account, all content (including cloud storage) is deleted immediately and irreversibly — there is no recovery window.
  • Server logs: automatically rotated after 14 days.
  • AI usage data: daily statistics retained for a maximum of 30 days.

5. Recipients

We share data with the following recipients. The role is stated with each entry: processors act solely on our instructions and under a contract pursuant to Art. 28 GDPR; independent controllers decide on the processing themselves and set this out in their own privacy policy.

  • IONOS SE (DE) — server hosting. Processor.
  • Cloudflare R2 (Cloudflare, Inc., US) — object storage for notebook snapshots. Processor.
  • Stripe Payments Europe, Ltd. (IE) — payment processing. Independent controller: Stripe determines the use of payment data itself, not least because of regulatory and anti-money-laundering obligations. Privacy: stripe.com/at/privacy.
  • Google Play — handling of in-app purchases in the Android app. Independent controller: the seller and payee is the Google entity named in the Google Play terms of service, which determines the use of the payment data itself. We receive only the purchase identifier and the subscription status. Privacy: policies.google.com/privacy.
  • Google Ireland Limited (Gemini API) — AI processing for handwriting, math, chat. Processor. Privacy: policies.google.com/privacy. Note: content is not used for model training under Google's terms.

6. Transfer to third countries

If data is transferred to third countries outside the EU/EEA (e.g. Google in the US), this is done on the basis of Standard Contractual Clauses of the EU Commission and/or within the framework of the EU-US Data Privacy Framework, which Google and Cloudflare have joined.

7. Cookies, analytics and similar technologies

This website uses no advertising or third-party tracking cookies. For operation we use functional browser storage (localStorage/sessionStorage, e.g. for your sign-in session and language preference) and a few strictly necessary cookies (e.g. cookie notice, theme selection).

Anonymous analytics: To improve the website we collect anonymous usage statistics with our own privacy-friendly system (no third party): the page visited, the referrer, language, a rough device category and click/funnel events (e.g. "plan clicked"). To recognize a device, a random, anonymous identifier is stored in localStorage. No IP addresses are stored and no data is shared with third parties. The legal basis is our legitimate interest in needs-based design (Art. 6(1)(f) GDPR).

8. Your rights

You have the right at any time to:

  • Information (Art. 15 GDPR) — which data do we have about you?
  • Rectification (Art. 16 GDPR) — have incorrect data corrected.
  • Erasure (Art. 17 GDPR) — "right to be forgotten". Can be exercised any time in the app under Account → Delete account.
  • Restriction of processing (Art. 18 GDPR).
  • Data portability (Art. 20 GDPR) — export of all your data as ZIP.
  • Objection (Art. 21 GDPR).
  • Complaint to the supervisory authority: Austrian Data Protection Authority (DSB), Barichgasse 40–42, 1030 Vienna.

To exercise your rights, an informal email to support@synapse-app.at is sufficient.

9. Data security

  • All connections are encrypted (HTTPS).
  • Passwords are stored exclusively as a cryptographic hash — never in plain text, neither in logs nor in the database.
  • Access tokens, too, are held server-side only as a hash.
  • The database is backed up daily and the backups are kept encrypted.
  • The server is protected by a firewall, automatic blocking after repeated failed sign-ins, and regular security updates.

10. Changes to this privacy policy

We reserve the right to adapt this privacy policy if features or legal situation change. Material changes will be communicated in the app and by email.


Note: This template provides a legally compliant starting point but does not replace individual legal advice.