SynthGapOpen the app

Privacy Policy

Effective date: October 2, 2026

This Privacy Policy explains what personal information SynthGap ("we," "us") collects when you use the SynthGap web application and related services (the "Service"), how we use and share it, and the choices and rights you have. We are the controller of the personal information described here. We are based in Cyprus, in the European Union. You can reach us at support@synthgap.com or Sehit Dumenci Street No 10, 99010 Nicosia, Cyprus.

The short version

1. Information we collect

Information you give us

Billing information

When you subscribe, you are sent to a page hosted by Stripe, which collects your payment method, billing name, billing email and other billing details and processes the payment. We never receive or store full card numbers. We send Stripe your email address (so receipts and payment notices reach you), an internal reference to your SynthGap account, and the plan you chose. If you change the email on your account, we update it at Stripe too. Stripe sends us back a customer ID, a subscription ID and your subscription status, which we store in your account record. In Stripe's dashboard we can also see your billing email and the brand and last four digits of your card, which we use for billing support. When you open Account, the Service asks Stripe for your recent receipts and invoices so it can show them to you, and Stripe may email receipts and payment notices to your billing email. Where sales tax or VAT applies, Stripe also uses the billing address and any tax ID you enter at checkout to calculate it. Stripe's use of your information is governed by its own privacy policy.

Information collected automatically

2. How we use your information

PurposeExamplesLegal basis (EEA/UK)
Provide the ServiceCreate and secure your account and let you sign in with your email; run discovery, screening, extraction and the other workflow stages; store your work; enforce plan limitsContract
Take payments and manage subscriptionsCheckout, subscription status, invoices, refundsContract; legal obligation (tax and accounting records)
Confirm your email and reset your passwordEmail you a link to confirm your address, or to choose a new passwordContract; legitimate interests (keeping accounts secure)
Keep the Service safeDetect abuse and misuse, for example by screening for invalid or disposable email addresses, requiring new free accounts to confirm their email, and stopping a deleted account's email address from opening a new account for 12 months; protect accounts and infrastructureLegitimate interests (keeping the Service secure and the free plan fair)
Support and service messagesAnswer your emails; contact you about your account, billing or security; tell you about changes to our Terms and PoliciesContract; legitimate interests
Reliability and troubleshootingDiagnose failed runs; monitor performance and cost; fix bugsLegitimate interests
Legal compliance and record-keepingKeep records of the Terms you accepted; respond to lawful requestsLegal obligation; legitimate interests (proving what you agreed to)

We do not use your personal information for advertising or to build advertising profiles, and we do not make automated decisions about you that have legal or similarly significant effects. (The AI in the Service drafts suggestions about research literature, which you review. See our AI Output & Research Disclaimer.)

3. AI processing of your content

To produce your results, the Service sends parts of your content to AI model and embedding providers listed on our Subprocessors page. Depending on the stage, that can include your topic text, protocol, search terms, article titles and abstracts, article full text (including text from files you upload), and your extraction and risk-of-bias inputs. We use these providers through their commercial APIs; their own terms and privacy policies govern how they handle data they process for us. We do not use your content to train AI models. Please don't enter information that identifies a patient or other individual.

4. How we share information

We do not sell personal information, and we do not share it for cross-context behavioral advertising. We have not done either in the past 12 months.

5. International transfers

We and our providers process information in the United States and other countries, which may have data-protection laws different from those where you live. Where the law requires it, we rely on safeguards such as the European Commission's Standard Contractual Clauses (with the UK Addendum where relevant) or a provider's certification under the EU-U.S. Data Privacy Framework.

6. How long we keep information

InformationRetention
Account record (email address, account ID or username, password hash, plan and usage counters, Stripe IDs, record of accepted Terms)Until you delete your account, which removes it immediately
Your content (runs, logs, uploaded files)Until you delete the run, or your account; either removes it from our active systems immediately. We do not currently delete content automatically
Billing records (held by Stripe and by us)Stripe keeps transaction records as long as tax, accounting and other laws require, typically up to seven years. Deleting your account also deletes your customer profile and saved payment methods at Stripe
Deleted usernamesReserved for 14 days after deletion, so an old sign-in can't be used on a new account with the same name, then removed
A fingerprint of a deleted account's email address (a keyed one-way hash, never the address itself)12 months after deletion, so the address can't be used to open a new account; then removed. It cannot be turned back into the address
Short-lived counters that cap how many emails we send and addresses we check (keyed by an internal account ID or a one-way hash of an address)Up to 2 days
Infrastructure logsFor a limited period set by our hosting provider
Emails to usAs long as needed to handle your request and keep a reasonable record

When you delete your account we immediately delete your account record, every run you started and all files you uploaded from our active systems, and we cancel any subscription. Copies may remain for a short period in routine backups kept by our hosting provider, and in anything others copied from a run while it was shared. Topic-based search indexes built from public PubMed records (which may be named after a topic) are shared infrastructure, are not linked to your account, and are not deleted with it. Stripe keeps transaction records as the law requires.

7. Your rights and choices

Everyone. You can delete your account yourself at any time: choose Account in the top bar, then Delete account. We immediately and permanently delete your account, all of your runs and uploaded files, and your customer profile at Stripe, and we cancel any subscription (Section 6 explains what we keep). The one thing we keep is a one-way fingerprint of the email address, for 12 months, so that it can't be used to open a new account straight away. You can also delete any single run yourself, from your history or the run's own page (this removes the run and its uploaded files immediately; if the run was shared it disappears for everyone). You don't need to contact us or give a reason. To get a copy of your personal information, to have it corrected, or if you can't sign in, email support@synthgap.com from the address on your account (or, on an older account without an email, with your username).

Verifying it's you. Before acting on a request sent by email, we may need to confirm that the account is yours, for example by checking that the request comes from the email address on the account, by giving you a phrase to enter into your account, or, for subscribers, by matching the billing email Stripe holds. We respond within the time the law requires (generally one month, or 45 days for California residents).

If you are in the EEA, the UK or Switzerland, you also have the right to restrict or object to processing based on our legitimate interests, to receive your data in a portable format, and to complain to your local data-protection authority.

If you are in California or another US state with a privacy law, you may have the right to know, access, correct and delete your personal information, to receive a portable copy, and not to be discriminated against for exercising your rights. You may also have the right to opt out of the sale or sharing of personal information and to limit the use of sensitive personal information; we do not sell or share personal information, and we use account credentials only to provide the Service. You can use an authorized agent to make a request on your behalf, and we may ask them to prove their authority. If we decline a request, you can appeal by replying to our response with the word "Appeal," and you may contact your state attorney general if you are unhappy with the outcome.

Categories of personal information we collected in the last 12 months (California):

CategoryExamplesSourceDisclosed to
IdentifiersEmail address; account ID or username; IP addressYou; your browserHosting provider; Stripe (email address, if you subscribe)
Commercial informationPlan, subscription status, Stripe customer and subscription IDsYou; StripeStripe; hosting provider
Internet or network activityUsage counters, run history and logsOur systemsHosting provider
Other information you provideResearch topics, protocols, uploaded documents and other contentYouHosting and AI providers
Sensitive personal informationAccount log-in credentials (stored as a password hash)YouHosting provider

Do Not Track and Global Privacy Control. We do not track you across websites. We treat Global Privacy Control signals as opt-out requests, although we do not sell or share personal information.

8. Security

We use measures including encrypted connections (HTTPS), one-way salted hashing of passwords, a signed, HttpOnly, Secure, SameSite=Strict session cookie, and access controls that limit private runs to their owner. No system is perfectly secure, so we cannot guarantee absolute security. If a breach affects your personal information we will notify you and regulators as the law requires, in the Service and, for subscribers, by email to the billing address on file.

9. Children

The Service is not directed to anyone under 18 and we do not knowingly collect information from them. If you believe a child has an account, contact us and we will delete it.

10. Cookies and similar technologies

We set one essential cookie to keep you signed in and use a little browser storage for convenience. We do not use analytics or advertising cookies. Details are in our Cookie Policy.

11. Information about authors in the literature

The Service processes publicly available bibliographic records, such as article titles, abstracts and author names, from PubMed and PubMed Central. That information is about published research, not about you. We use it only to provide the Service and do not build profiles of authors. If you are an author with a question or request about how your published information appears in the Service, contact us.

12. Changes to this policy

If we make material changes we will give notice in the Service and, where required, ask you to accept the updated Terms and Policies. The effective date above shows the current version.

13. Contact

SynthGap · Sehit Dumenci Street No 10, 99010 Nicosia, Cyprus · support@synthgap.com