Syno

Effective 2026-09-18

A little space to think

Your privacy in Syno

A clear account of the information involved when you join Syno, sign in, and use your personal companion.

Who is responsible

Syno is operated by SYNO LABS LLP. This notice covers the Syno web and iOS product, including its invitation and waitlist experience. Contact us about privacy or support at dey.debaditya@gmail.com. Other services have their own privacy notices.

When you sign in

If you choose Google or Apple, Syno receives an identifier for your provider account, the email information supplied by that provider, and available profile information such as your name. Apple may supply a private relay email address instead of your usual email. Syno accepts that address.

Syno uses this information to verify your sign-in, identify an existing connected account, and apply the invitation or waitlist rules. Google sign-in requests basic identity information only. It does not connect your Gmail, Drive, Calendar, or other Workspace content. Connecting those services is a separate choice.

Syno does not receive your Google or Apple password. If you connect a provider to an existing Syno password account, you must prove access to that Syno account. Email similarity alone does not connect accounts.

Invitations and the waitlist

An invitation is required to create a new Syno account. Without an available invitation, Syno records your email in its waitlist. A name may be absent. If you use email signup, the email is the address you supply; if you use a provider, it is the verified address supplied by that provider.

The waitlist records your request so the Syno team can contact you manually when a slot opens. Joining the waitlist does not create a Syno account or give access to the product. It does not guarantee a place or an admission date. Invitation and conversion records help prevent duplicate redemption and preserve your admission history.

When you use your companion

Depending on the features you use, Syno processes your conversations, attachments, saved memory, preferences, task results, and information from services or devices you choose to connect. Some tasks can involve external model providers or connected services. Information relevant to those tasks may be sent to those providers to carry out your request.

Syno uses hosted infrastructure as well as your device. Its current cloud servers and object storage are provided by Vultr in Bangalore, India. Private beta services also use operator-managed equipment. Tailscale provides private network connectivity, and Cloudflare provides DNS. These network arrangements do not mean that information stays only on your device or cannot be accessed by authorized operators.

Sessions and security

Syno uses necessary browser storage, cookies and device storage to keep you signed in and recover interrupted sign-in attempts. Sign-in requests also involve technical information such as source IP addresses, timestamps and status records to limit abuse and investigate failures.

Sign-in proof and temporary authorization material are protected separately from ordinary application content. Session credentials are returned through the application’s secure connection. Authorization responses and these notice pages do not include third-party analytics. This statement does not assert that every other product surface has been audited for analytics.

The iOS app can send a limited set of reliability events to Syno, such as whether setup used a confirmed server or cached result and whether a document failed to render. These event payloads contain fixed event and outcome labels, not conversation text, documents or arbitrary diagnostic text. The request still uses your authenticated connection. Other service records can contain account and task context needed for operation and troubleshooting.

Who receives information

Google and Apple process your use of their own sign-in services under their own terms. Vultr hosts Syno services and backup storage. Tailscale and Cloudflare support network connectivity and DNS. Apple also provides iOS distribution and, where enabled, push delivery. Authorized Syno operators can access records for support, security and service operation.

Syno uses external AI providers for relevant tasks. The current system assistant configuration uses OpenAI. Depending on your configured features and credentials, tasks may use other supported providers, including Anthropic, Google or Sarvam, or services that you connect. Relevant prompts, conversation context, files, audio or tool results may be transmitted to the provider used for the task. Signing in with Google alone does not grant access to Google Workspace content.

Providers may process information outside your country. Their retention and data-use terms depend on the service and account involved. Syno does not represent that every provider offers identical retention or training arrangements. Where law requires consent or a particular safeguard before a transfer or use, that requirement applies in addition to this notice.

Commercial analytics, audience insights and outreach

SYNO LABS LLP does not sell personal data. Subject to applicable law, the permissions under which information was obtained and the restrictions described below, we may process eligible first-party usage information to produce aggregated or effectively anonymised statistics, inferred interests and audience-level profiles. We may use those non-identifying outputs for product and service improvement, market research, business intelligence, development of business platforms, audience segmentation, selection and measurement of advertising, and planning of relevant commercial outreach. We may provide non-identifying statistical insights to business customers.

For these purposes, effectively anonymised information means information that cannot reasonably identify, single out or be linked back to a person, taking account of the means reasonably available to us or a recipient. Merely removing a name, hashing an email, substituting an identifier or calling information a derived profile does not make it anonymous. We will not attempt to re-identify anonymous outputs or permit recipients to do so.

Private conversations, uploaded files, connected-service content, credentials and sensitive personal information are not made available to business customers or used as a source for advertising audiences under this clause. Information received through Google Workspace APIs or MCP integrations, and information derived from it, is excluded from advertising, audience commercialisation and unrelated outreach. Our use of Google Workspace information is subject to the Google API Services User Data Policy and its Limited Use requirements; this commercial-use clause does not override those restrictions.

Advertising profiles and targeted outreach are not enabled by this sign-in release. If we introduce a feature that uses information still relating to an identifiable person for these purposes, we will provide a specific notice and the consent or choice required by law before activating that use. We will not treat provider sign-in, joining the waitlist or acceptance of these terms as blanket consent to unrelated marketing. Marketing communications will offer a way to opt out. Profiling for advertising will not be directed at people known to be under 18.

How long information remains

Account details, connected identity references, admission history, waitlist entries and product content are retained for service operation, recovery and security. The current beta does not apply a single automatic deletion period to all of these records. Signing out or removing authorization in a provider’s settings does not delete your Syno data.

The identity service removes temporary encrypted authorization material from eligible expired flows after a further 24 hours, through periodic cleanup. Flows still processing or holding an active recovery lease are excluded until safe to clean. This does not delete the account, the waitlist ledger or completed admission records.

Memory-review settings can preserve a full audit history or apply selected cleanup to review content. The presence of a retention-days setting is not a promise that all saved memory is erased after that many days. Approved saved memory and historical task/workspace records have separate lifecycles.

Database backups use a separate retention configuration. Historical file and workspace backup versions currently have no general automatic expiry schedule. Deleting an active record therefore does not necessarily erase every older backup immediately. A deletion request must also address retained copies as explained below; the existence of a backup is not a blanket reason to refuse erasure.

Your choices and requests

You can choose whether to use a connected provider, cancel a sign-in attempt, and sign out of Syno. You can manage Google or Apple authorization in that provider’s account settings. Revoking Apple authorization disables that connected method and its refresh sessions after Syno receives the relevant notification; an already issued short-lived session can remain usable until it expires.

Contact dey.debaditya@gmail.com for access, correction, waitlist removal, deletion or other privacy requests. Requests are handled manually by the Syno team. We may request proportionate information to verify your identity and locate the records concerned; do not send passwords or authentication tokens. This release has no in-app account-deletion or provider-disconnection control. Your applicable statutory rights are unaffected.

Account deletion and the 30-day period

Upon receipt of an account-deletion request, we will take reasonable steps to verify the requester and locate personal data associated with the account. Subject to any lawful retention requirement or exception, we will close the account and delete, or irreversibly anonymise where legally appropriate, associated personal data within our possession or control within 30 days after receipt of the request, or sooner where applicable law requires. The scope includes information reasonably retrievable through our ordinary systems and derived records that remain identifiable; it is not limited to the information originally supplied by you.

Where a particular extension or refusal is permitted by applicable law, we will explain the reason, relevant retained categories and the expected next steps within the original response period. We will not reset that period merely by requesting verification or rely on a general statement that deletion is technically inconvenient.

We may retain only information reasonably necessary for a specific legal obligation, an applicable exception, the establishment or defence of legal claims, or a minimal record needed to honour a request, where law permits. Such information is restricted to that purpose. Residual backup copies must be put beyond ordinary use and, where required, removed or made inaccessible under an applicable retention or erasure process. If a retained backup is restored, applicable deletion restrictions must be reapplied before the information is returned to ordinary use. We will explain any retained copies and the applicable basis rather than claiming all historical copies have disappeared.

To the extent permitted by law, deletion does not require us to re-identify genuinely anonymous statistical outputs solely to associate them with a requester, reconstruct personal data that no longer exists, or reverse processing lawfully completed before the request. This exception does not cover pseudonymous or derived information that still relates to an identifiable person, and does not exclude any non-waivable duty concerning processors, recipients or retained copies.

Age and availability

The minimum age is 13, subject to any higher age or other eligibility requirement under the law where you live. There are no product-specific country exclusions; applicable law, provider availability, invitation capacity and the private beta’s network requirements still apply.

This beta does not provide an age-verification or parental-consent process. Where parental authorization is required, access must await an appropriate authorization process; these words do not themselves collect that consent. The invitation process must respect those restrictions. Future advertising and outreach features require separate eligibility and data-use controls.

Contact and changes

Contact SYNO LABS LLP at dey.debaditya@gmail.com. Do not send passwords, invitation codes, provider codes or authentication tokens with a support request.

The effective date and revision appear on this page. Material changes to how Syno handles information will be announced through the product or your contact email.