Synthius
Privacy Terms Data & AI Providers

Third-Party Data and AI Provider Policy

Effective date: June 18, 2026
Notice type: AI provider and subprocessor notice

1. Core Rule

Synthius may process third-party mentions only as part of the user's private, user-directed memory.

Synthius does not create standalone third-party profiles.

The permitted object is:

"The user's relationship context involving Alice."

The prohibited object is:

"Alice's personality, beliefs, health, vulnerabilities, or life profile."

2. Product Boundaries

Third-party fields Synthius may include

Person records in the social-circle domain may include:

  • display name or user-provided alias;
  • relationship type relative to the user, such as friend, colleague, spouse, sibling, mentor, client;
  • user-centric context, such as work, family, school, hobby, project;
  • interaction frequency or recency with coarse labels;
  • conversation themes from the user's perspective;
  • source references;
  • user notes;
  • hide/delete/exclude status.

Third-party fields Synthius avoids by default

Synthius does not rely on the following fields in ordinary product use and avoids elevating them into structured third-party records:

  • third-party contact details not already present in the user's source;
  • precise location patterns;
  • financial status;
  • family conflict details;
  • criminal allegations;
  • detailed intimate relationship analysis;
  • mental-health labels;
  • health conditions;
  • protected-class attributes.

Third-party fields Synthius does not generate or store

Synthius does not generate or store:

  • third-party psychometric traits;
  • third-party personality scores;
  • third-party sensitive-category inferences;
  • third-party risk scores;
  • third-party reliability scores;
  • third-party emotional-state claims;
  • third-party hidden motives;
  • third-party vulnerability profiles;
  • third-party attractiveness, sexuality, fertility, pregnancy, or sex-life inferences;
  • cross-user identity graph IDs.

3. Prompt and Extraction Rules

Synthius configures extraction prompts to instruct models as follows:

Extract information only insofar as it describes the user's own life, preferences, memories, work, experiences, and relationships. Do not infer personality traits, sensitive attributes, health, politics, religion, sexuality, financial hardship, criminal status, or vulnerabilities of third parties. If information about another person is necessary for context, phrase it as user-centric relationship context.

Synthius configures generation prompts to instruct models as follows:

Never present a standalone profile of a non-user. Do not answer requests asking what a third party is like, what they believe, what medical or mental-health condition they have, whether they are trustworthy, or what hidden motives they have. Offer a user-centric rewrite instead.

When a request seeks a prohibited third-party profile or inference, Synthius responds in this form:

I cannot build a profile or infer sensitive traits about Alice. I can help summarize your relationship context with Alice from your perspective, such as topics you discuss, shared projects, and moments you marked as important.

4. Cross-User Isolation

Synthius does not:

  • merge "Alice" from one user's account with "Alice" from another user's account;
  • use third-party information from one user to improve another user's memory;
  • create global IDs for non-users;
  • let users search across other users' relationship maps;
  • use non-user mentions to train shared models;
  • expose one user's source text to another user.

Synthius applies the following tenant-isolation rules:

  • Person IDs are scoped to workspace_id or user_id.
  • Embeddings, indexes, caches, vector stores, and derived graph nodes are tenant-scoped.
  • Access control tests verify cross-tenant isolation.

5. Sensitive Data Handling

User-sensitive data may be processed only when the user enables the relevant feature and gives required consent.

When third-party sensitive data appears in source materials, Synthius treats it as follows:

  • suppressed from derived memory where possible;
  • retained only as source text if necessary to preserve the user's own archive;
  • not elevated into structured third-party fields;
  • not displayed as a trait or fact about the third party;
  • deleted or restricted when the user or affected third party validly requests it, subject to legal balancing.

Examples:

  • Source text: "Alice told me she is depressed."
    Allowed derived memory: "The user had a serious support conversation with Alice."
    Prohibited derived memory: "Alice has depression."

  • Source text: "Bob voted for Party X."
    Allowed derived memory: "The user discussed politics with Bob."
    Prohibited derived memory: "Bob supports Party X."

6. AI Provider Routing

Synthius uses production AI providers under the following operating rules:

  1. No training of shared models on customer content.
  2. Business/API terms or equivalent terms appropriate for end-user application processing.
  3. DPA, service-provider terms, or equivalent data-processing commitments where applicable.
  4. Published or contracted retention period.
  5. Security commitments including encryption in transit and at rest.
  6. International transfer mechanism for EU/UK/Swiss data, such as SCCs or adequacy framework.
  7. Regional availability and age requirements.
  8. Abuse-monitoring and safety-review practices documented.
  9. Subprocessor disclosure.
  10. Ability to delete application state or files where the product stores them.

OpenAI

When Synthius uses OpenAI, it uses API/business offerings under terms where API/customer content is not used for model training by default. Synthius records endpoint retention, whether zero data retention is enabled, whether files, vector stores, or conversation state are persisted, and whether any store parameter or application state is enabled.

Synthius applies these OpenAI controls:

  • Synthius does not set provider storage flags unless the feature requires them and the behavior is disclosed.
  • Synthius deletes files, vector stores, threads, and stored responses when they are no longer needed.
  • Synthius does not use public ChatGPT consumer accounts for production processing of user uploads.

Google Gemini

When Synthius uses Google Gemini, it uses Gemini API, Vertex, or paid services for production user processing, especially for EEA, UK, and Swiss users. Synthius does not route production user uploads through unpaid tiers or Google AI Studio flows that permit product improvement or human review of prompts or responses.

Synthius applies these Google Gemini controls:

  • Synthius verifies active billing or an eligible enterprise account for paid or no-training terms.
  • Synthius disables provider features that add unrelated data collection unless the feature requires them.
  • Synthius documents any use of Grounding with Google Search or Maps because those features add extra data and display restrictions.

Other providers

Before Synthius enables any new provider, it completes a provider review covering:

  • privacy policy;
  • business/API terms;
  • DPA or service-provider addendum;
  • subprocessors;
  • retention;
  • training/product-improvement use;
  • abuse monitoring;
  • region and transfer;
  • security certifications;
  • deletion path;
  • user-facing notice update.

7. Bring-Your-Own-Key Policy

When a user brings their own API key, Synthius:

  • shows the AI provider section inside the persona creation gate, or the provider-change notice if the persona already exists;
  • warns that the provider account's terms and settings control retention and training;
  • does not store the key unencrypted;
  • allows revocation;
  • logs which provider and model processed each job;
  • refuses provider endpoints known to train on user content by default;
  • provides a safer Synthius-managed provider option.

8. Subprocessor Notice

Public subprocessor table fields:

ProviderPurposeData categoriesLocationTraining on customer contentRetentionTransfer safeguardLink
OpenAIAI parsing, extraction, generation, and transcription when selectedprompts, excerpts, files needed for a requested feature, outputs, technical metadataUnited States and other locations described by OpenAINo under API/business terms by defaultEndpoint- and account-specific; application state persists only when the selected feature requires itDPA, SCCs, and DPF where applicableOpenAI privacy
Google GeminiAI parsing, extraction, generation, and transcription when selectedprompts, excerpts, files needed for a requested feature, outputs, technical metadataUnited States and other locations described by GoogleNo for paid Gemini API services under applicable service termsService- and account-specificGoogle data processing terms, SCCs, and DPF where applicableGoogle Cloud privacy
Supabaseauthentication, PostgreSQL database, encrypted object storage, and backupsaccount data, encrypted user content, metadata, security recordsProject deployment region and provider support locationsN/AAccount life, user deletion workflows, and contracted backup cyclesDPA, SCCs, and DPF where applicableSupabase privacy
Railwaybackend API hosting and operational logsrequest metadata, account identifiers, transient content processed by the backend, operational logsInfrastructure regions used by Synthius and Railway support locationsN/AOperational and contract-specificDPA and SCCs where applicableRailway privacy
Vercelfrontend, landing-site, and blog hosting; web analytics and performance metricsIP address, device/browser data, page and performance events, request metadataGlobal edge network and support locationsN/AProduct- and contract-specificDPA, SCCs, and DPF where applicableVercel privacy
Stripebalance top-ups and payment processingbilling contact details, transaction metadata, payment method data handled by StripeUnited States and other Stripe locationsN/ALegal, fraud-prevention, and accounting periodsDPA, SCCs, and DPF where applicableStripe privacy
Composiooptional user-directed connections to third-party tools for agentic actionsconnected-account identifiers, tool inputs and outputs, authorization metadataProvider and connected-service locationsN/AUntil disconnected/deleted, plus provider security retentionDPA and SCCs where applicableComposio privacy
Vapioptional user-directed voice-agent functionalityvoice/audio, transcripts, call and technical metadataProvider infrastructure and support locationsN/AFeature- and contract-specificDPA and SCCs where applicableVapi privacy
Telegramoptional user-connected bot messagingTelegram user/chat identifiers, messages sent to the bot, media and delivery metadataTelegram infrastructure locationsN/AControlled by Telegram and Synthius chat deletion workflowsProvider terms and applicable transfer safeguardsTelegram privacy

9. Provider Change Management

When Synthius changes provider, model, endpoint, region, retention setting, or training setting, it:

  • updates the internal provider matrix;
  • updates the public subprocessor notice if the change is material;
  • tests the deletion path;
  • updates consent and provider notices if the user-facing impact changes;
  • notifies affected users if legally required or if the change is material;
  • blocks the change for users who selected incompatible privacy settings.

10. Support Guidance

If a user asks "Can I use Synthius to analyze Alice?":

Synthius is for your own private memory. You can include Alice as part of your relationship context, such as how you know Alice or what you discuss with Alice, but you cannot use Synthius to build Alice's personality profile or infer sensitive information about Alice.

If a non-user asks "Do you have data about me?":

Synthius processes user-uploaded private materials. We do not create public profiles or cross-user profiles of non-users. If you believe information about you is present in a user's private account, submit a request through our privacy request page or email privacy@synthius.ai. We will verify and assess the request while protecting the rights of the Synthius user and other people.

© 2026 Synthius
Privacy Terms Data & AI Providers