SynsisAI

Privacy Policy

Last updated: July 4, 2026

1. Who we are

Synsis ("Synsis", "we", "us") operates the application at synsis.app, which helps you detect paid subscriptions from your billing emails and manage calendar scheduling. This policy explains what data we collect, how we use it, and — in particular — with whom we share, transfer, or disclose Google user data. For any privacy question or request, contact us at [email protected].

2. Data we collect

We collect account details you provide (name, email, password hash), your billing/plan status, product usage metadata, and — only if you connect Google — the Google user data described in the next section. If you do not connect Google, we never access any Google user data.

3. Google user data we access

When you connect Google, we request only the following OAuth scopes, which are the exact scopes shown on the Google consent screen:

  • Read-only Gmail access
    .../auth/gmail.readonly
    Detect paid subscriptions and billing charges. Our servers request only message metadata (sender, subject, date, labels, and the short preview snippet) — we never download email bodies or attachments.
  • Read-only Google Calendar access
    .../auth/calendar.readonly
    Read your primary-calendar availability (free/busy) and time zone so the assistant can answer agenda and availability questions.
  • Manage Google Calendar events
    .../auth/calendar.events
    Create and cancel meetings (including Google Meet links) on your primary calendar when you ask the assistant to schedule or cancel a call.
  • Your primary Google email address
    .../auth/userinfo.email
    Identify the Google account you connected and link it to your Synsis account.
  • Your basic Google profile
    .../auth/userinfo.profile
    Show your name and profile picture inside the app.

4. How we use Google user data

We use Google user data solely to provide and improve the user-facing features you request — subscription detection, spending summaries, calendar availability, and meeting scheduling. Synsis's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

5. With whom we share, transfer, or disclose Google user data

We do not sell your data. We share Google user data only with the service providers (sub-processors) listed below, strictly to operate the features you use, and only the minimum data each provider needs. Each is bound by contractual data-protection terms.

  • Cloudflare, Inc.United States
    Purpose: Application hosting, compute, database (D1), vector search (Vectorize), on-service AI embeddings (Workers AI), and background job queues.
    Google data received: Your Google account email, OAuth access/refresh tokens, and the subscription records and embeddings we derive from your Gmail billing emails (sender domain, subject, short snippet, and amount).
  • OpenAI, L.L.C.United States
    Purpose: Classifying whether billing emails represent real paid subscriptions and interpreting the scheduling questions you type into the assistant.
    Google data received: A limited set of email-derived fields (sender domain, subject line, a short preview snippet, and detected amount) and the text of questions you ask. Processed through OpenAI's API; per OpenAI's API data policy it is not used to train their models.
  • Resend (Resend, Inc.)United States
    Purpose: Sending transactional email such as sync-complete notifications and password-reset codes.
    Google data received: Your Google account email address (as the recipient) and summary figures such as the number of emails scanned, count of detected subscriptions, and estimated monthly spend.
  • Stripe, Inc.United States
    Purpose: Processing payments and subscriptions for paid plans.
    Google data received: Your account email and payment details only. Stripe does not receive your Gmail or Google Calendar content.

We may also disclose data if required by law or valid legal process, to protect the safety, rights, or security of our users and service, or as part of a merger, acquisition, or asset sale (in which case the recipient must continue to honor this policy). Any such transfer of Google user data will remain consistent with the Google API Services User Data Policy.

6. What we do not do

  • We do not sell Google user data or share it with data brokers.
  • We do not use Google user data for advertising or to build advertising profiles.
  • We do not use Google user data to develop, improve, or train generalized or non-personalized AI/ML models.
  • We do not allow humans to read your Google user data, except: with your explicit consent (e.g. support you request); when necessary for security purposes such as investigating abuse; to comply with applicable law; or on aggregated, anonymized data for internal operations, as permitted by the Limited Use requirements.

7. Storage, location, and retention

Google user data is stored on Cloudflare infrastructure in the United States. We retain it only as long as needed to provide the service or as required by law. OAuth tokens are stored to keep your connection active and are deleted when you disconnect (see below).

8. Your controls: revoke and delete

You can disconnect Google at any time from Dashboard → Connections. Disconnecting immediately deletes the stored Google credentials (access and refresh tokens) and the connected Google account email from our systems and stops all further access. You can also revoke access directly at myaccount.google.com/permissions. To delete your account and all remaining data derived from your emails, email [email protected] and we will complete deletion promptly.

9. Security

We apply industry-standard safeguards including encryption in transit, scoped access, and least-privilege practices to protect your account and connected data.

10. Newsletter and communications

Newsletter emails are opt-in. If selected during sign-up, we may send product updates and release notes. You can unsubscribe from newsletter communications at any time.

11. Changes and contact

We may update this policy and will revise the date above when we do. Questions or data requests: [email protected].

Back to sign up