Third-Party Data and AI Provider Policy
Effective date: June 18, 2026
Notice type: AI provider and subprocessor notice
1. Core Rule
Synthius may process third-party mentions only as part of the user's private, user-directed memory.
Synthius does not create standalone third-party profiles.
The permitted object is:
"The user's relationship context involving Alice."
The prohibited object is:
"Alice's personality, beliefs, health, vulnerabilities, or life profile."
2. Product Boundaries
Third-party fields Synthius may include
Person records in the social-circle domain may include:
- display name or user-provided alias;
- relationship type relative to the user, such as friend, colleague, spouse, sibling, mentor, client;
- user-centric context, such as work, family, school, hobby, project;
- interaction frequency or recency with coarse labels;
- conversation themes from the user's perspective;
- source references;
- user notes;
- hide/delete/exclude status.
Third-party fields Synthius avoids by default
Synthius does not rely on the following fields in ordinary product use and avoids elevating them into structured third-party records:
- third-party contact details not already present in the user's source;
- precise location patterns;
- financial status;
- family conflict details;
- criminal allegations;
- detailed intimate relationship analysis;
- mental-health labels;
- health conditions;
- protected-class attributes.
Third-party fields Synthius does not generate or store
Synthius does not generate or store:
- third-party psychometric traits;
- third-party personality scores;
- third-party sensitive-category inferences;
- third-party risk scores;
- third-party reliability scores;
- third-party emotional-state claims;
- third-party hidden motives;
- third-party vulnerability profiles;
- third-party attractiveness, sexuality, fertility, pregnancy, or sex-life inferences;
- cross-user identity graph IDs.
3. Prompt and Extraction Rules
Synthius configures extraction prompts to instruct models as follows:
Extract information only insofar as it describes the user's own life, preferences, memories, work, experiences, and relationships. Do not infer personality traits, sensitive attributes, health, politics, religion, sexuality, financial hardship, criminal status, or vulnerabilities of third parties. If information about another person is necessary for context, phrase it as user-centric relationship context.
Synthius configures generation prompts to instruct models as follows:
Never present a standalone profile of a non-user. Do not answer requests asking what a third party is like, what they believe, what medical or mental-health condition they have, whether they are trustworthy, or what hidden motives they have. Offer a user-centric rewrite instead.
When a request seeks a prohibited third-party profile or inference, Synthius responds in this form:
I cannot build a profile or infer sensitive traits about Alice. I can help summarize your relationship context with Alice from your perspective, such as topics you discuss, shared projects, and moments you marked as important.
4. Cross-User Isolation
Synthius does not:
- merge "Alice" from one user's account with "Alice" from another user's account;
- use third-party information from one user to improve another user's memory;
- create global IDs for non-users;
- let users search across other users' relationship maps;
- use non-user mentions to train shared models;
- expose one user's source text to another user.
Synthius applies the following tenant-isolation rules:
- Person IDs are scoped to
workspace_idoruser_id. - Embeddings, indexes, caches, vector stores, and derived graph nodes are tenant-scoped.
- Access control tests verify cross-tenant isolation.
5. Sensitive Data Handling
User-sensitive data may be processed only when the user enables the relevant feature and gives required consent.
When third-party sensitive data appears in source materials, Synthius treats it as follows:
- suppressed from derived memory where possible;
- retained only as source text if necessary to preserve the user's own archive;
- not elevated into structured third-party fields;
- not displayed as a trait or fact about the third party;
- deleted or restricted when the user or affected third party validly requests it, subject to legal balancing.
Examples:
-
Source text: "Alice told me she is depressed."
Allowed derived memory: "The user had a serious support conversation with Alice."
Prohibited derived memory: "Alice has depression." -
Source text: "Bob voted for Party X."
Allowed derived memory: "The user discussed politics with Bob."
Prohibited derived memory: "Bob supports Party X."
6. AI Provider Routing
Synthius uses production AI providers under the following operating rules:
- No training of shared models on customer content.
- Business/API terms or equivalent terms appropriate for end-user application processing.
- DPA, service-provider terms, or equivalent data-processing commitments where applicable.
- Published or contracted retention period.
- Security commitments including encryption in transit and at rest.
- International transfer mechanism for EU/UK/Swiss data, such as SCCs or adequacy framework.
- Regional availability and age requirements.
- Abuse-monitoring and safety-review practices documented.
- Subprocessor disclosure.
- Ability to delete application state or files where the product stores them.
OpenAI
When Synthius uses OpenAI, it uses API/business offerings under terms where API/customer content is not used for model training by default. Synthius records endpoint retention, whether zero data retention is enabled, whether files, vector stores, or conversation state are persisted, and whether any store parameter or application state is enabled.
Synthius applies these OpenAI controls:
- Synthius does not set provider storage flags unless the feature requires them and the behavior is disclosed.
- Synthius deletes files, vector stores, threads, and stored responses when they are no longer needed.
- Synthius does not use public ChatGPT consumer accounts for production processing of user uploads.
Google Gemini
When Synthius uses Google Gemini, it uses Gemini API, Vertex, or paid services for production user processing, especially for EEA, UK, and Swiss users. Synthius does not route production user uploads through unpaid tiers or Google AI Studio flows that permit product improvement or human review of prompts or responses.
Synthius applies these Google Gemini controls:
- Synthius verifies active billing or an eligible enterprise account for paid or no-training terms.
- Synthius disables provider features that add unrelated data collection unless the feature requires them.
- Synthius documents any use of Grounding with Google Search or Maps because those features add extra data and display restrictions.
Other providers
Before Synthius enables any new provider, it completes a provider review covering:
- privacy policy;
- business/API terms;
- DPA or service-provider addendum;
- subprocessors;
- retention;
- training/product-improvement use;
- abuse monitoring;
- region and transfer;
- security certifications;
- deletion path;
- user-facing notice update.
7. Bring-Your-Own-Key Policy
When a user brings their own API key, Synthius:
- shows the AI provider section inside the persona creation gate, or the provider-change notice if the persona already exists;
- warns that the provider account's terms and settings control retention and training;
- does not store the key unencrypted;
- allows revocation;
- logs which provider and model processed each job;
- refuses provider endpoints known to train on user content by default;
- provides a safer Synthius-managed provider option.
8. Subprocessor Notice
Public subprocessor table fields:
| Provider | Purpose | Data categories | Location | Training on customer content | Retention | Transfer safeguard | Link |
|---|---|---|---|---|---|---|---|
| OpenAI | AI parsing, extraction, generation, and transcription when selected | prompts, excerpts, files needed for a requested feature, outputs, technical metadata | United States and other locations described by OpenAI | No under API/business terms by default | Endpoint- and account-specific; application state persists only when the selected feature requires it | DPA, SCCs, and DPF where applicable | OpenAI privacy |
| Google Gemini | AI parsing, extraction, generation, and transcription when selected | prompts, excerpts, files needed for a requested feature, outputs, technical metadata | United States and other locations described by Google | No for paid Gemini API services under applicable service terms | Service- and account-specific | Google data processing terms, SCCs, and DPF where applicable | Google Cloud privacy |
| Supabase | authentication, PostgreSQL database, encrypted object storage, and backups | account data, encrypted user content, metadata, security records | Project deployment region and provider support locations | N/A | Account life, user deletion workflows, and contracted backup cycles | DPA, SCCs, and DPF where applicable | Supabase privacy |
| Railway | backend API hosting and operational logs | request metadata, account identifiers, transient content processed by the backend, operational logs | Infrastructure regions used by Synthius and Railway support locations | N/A | Operational and contract-specific | DPA and SCCs where applicable | Railway privacy |
| Vercel | frontend, landing-site, and blog hosting; web analytics and performance metrics | IP address, device/browser data, page and performance events, request metadata | Global edge network and support locations | N/A | Product- and contract-specific | DPA, SCCs, and DPF where applicable | Vercel privacy |
| Stripe | balance top-ups and payment processing | billing contact details, transaction metadata, payment method data handled by Stripe | United States and other Stripe locations | N/A | Legal, fraud-prevention, and accounting periods | DPA, SCCs, and DPF where applicable | Stripe privacy |
| Composio | optional user-directed connections to third-party tools for agentic actions | connected-account identifiers, tool inputs and outputs, authorization metadata | Provider and connected-service locations | N/A | Until disconnected/deleted, plus provider security retention | DPA and SCCs where applicable | Composio privacy |
| Vapi | optional user-directed voice-agent functionality | voice/audio, transcripts, call and technical metadata | Provider infrastructure and support locations | N/A | Feature- and contract-specific | DPA and SCCs where applicable | Vapi privacy |
| Telegram | optional user-connected bot messaging | Telegram user/chat identifiers, messages sent to the bot, media and delivery metadata | Telegram infrastructure locations | N/A | Controlled by Telegram and Synthius chat deletion workflows | Provider terms and applicable transfer safeguards | Telegram privacy |
9. Provider Change Management
When Synthius changes provider, model, endpoint, region, retention setting, or training setting, it:
- updates the internal provider matrix;
- updates the public subprocessor notice if the change is material;
- tests the deletion path;
- updates consent and provider notices if the user-facing impact changes;
- notifies affected users if legally required or if the change is material;
- blocks the change for users who selected incompatible privacy settings.
10. Support Guidance
If a user asks "Can I use Synthius to analyze Alice?":
Synthius is for your own private memory. You can include Alice as part of your relationship context, such as how you know Alice or what you discuss with Alice, but you cannot use Synthius to build Alice's personality profile or infer sensitive information about Alice.
If a non-user asks "Do you have data about me?":
Synthius processes user-uploaded private materials. We do not create public profiles or cross-user profiles of non-users. If you believe information about you is present in a user's private account, submit a request through our privacy request page or email privacy@synthius.ai. We will verify and assess the request while protecting the rights of the Synthius user and other people.