Privacy Policy
Effective date: October 2, 2026
This Privacy Policy explains what personal information SynthGap ("we," "us") collects when you use the SynthGap web application and related services (the "Service"), how we use and share it, and the choices and rights you have. We are the controller of the personal information described here. We are based in Cyprus, in the European Union. You can reach us at support@synthgap.com or Sehit Dumenci Street No 10, 99010 Nicosia, Cyprus.
The short version
- You sign up with your email address and a password. We use your email to identify your account and to contact you about it, not for advertising, and other users never see it.
- We check new email addresses with ZeroBounce (to reject invalid or disposable ones) and send our account emails, such as the link to confirm your address or reset your password, through Resend.
- Stripe handles payments. We never see or store your card number.
- Your research content is private by default. If you share a run, other signed-in users can see it.
- To produce results we send your content to AI and infrastructure providers (listed on our Subprocessors page). We do not sell personal information and we do not use your content to train AI models.
- We set one essential cookie to keep you signed in. No analytics or advertising cookies.
- You can delete your account and all your data yourself, any time, from the Account menu in the app. To ask for a copy of your data or a correction, email support@synthgap.com.
1. Information we collect
Information you give us
- Account information. Your email address and password. (Accounts created before we asked for an email may use a username instead, and can add an email under Account.) The password is stored only as a salted, one-way hash, so we cannot read it. Each new account also gets an automatically generated ID. We use it internally, and it is what other users see if you share a run. Your email address is never shown to other users. When you sign up or change your email, we also check the address with a third-party service (ZeroBounce), which tells us whether it can receive mail and is not a disposable address. We keep only the category it returns (for example "valid"), and we record whether you have confirmed the address and when.
- Your content. The research topics and clinical areas you enter; protocols and PICO questions; search strategies; screening decisions; extracted data; risk-of-bias judgments; synthesis settings and overrides; PRISMA entries; manuscript text and notes; and files you upload (PDF or text, up to 20 MB each; we keep both the original file and the text extracted from it). It also includes the results the Service generates from these inputs.
- Messages to us. If you email us, we keep your message and our reply.
Billing information
When you subscribe, you are sent to a page hosted by Stripe, which collects your payment method, billing name, billing email and other billing details and processes the payment. We never receive or store full card numbers. We send Stripe your email address (so receipts and payment notices reach you), an internal reference to your SynthGap account, and the plan you chose. If you change the email on your account, we update it at Stripe too. Stripe sends us back a customer ID, a subscription ID and your subscription status, which we store in your account record. In Stripe's dashboard we can also see your billing email and the brand and last four digits of your card, which we use for billing support. When you open Account, the Service asks Stripe for your recent receipts and invoices so it can show them to you, and Stripe may email receipts and payment notices to your billing email. Where sales tax or VAT applies, Stripe also uses the billing address and any tax ID you enter at checkout to calculate it. Stripe's use of your information is governed by its own privacy policy.
Information collected automatically
- Account and usage records. When you created your account, your plan, how many discovery runs you have used in the current period and when the period began, which version of our Terms you accepted and when, each time you confirmed the renewal terms of a plan before checkout (which plan, when, and which version), and whether your last payment failed.
- Run records and logs. For each discovery run, a log of what the AI agent did (searches issued, papers examined, its output), timestamps, and model-usage statistics.
- Technical data. Your IP address, browser type and request details are processed by our hosting infrastructure when you use the Service and may appear in infrastructure logs kept by our hosting provider for security and troubleshooting.
- Cookies and local storage. See our Cookie Policy.
2. How we use your information
| Purpose | Examples | Legal basis (EEA/UK) |
|---|---|---|
| Provide the Service | Create and secure your account and let you sign in with your email; run discovery, screening, extraction and the other workflow stages; store your work; enforce plan limits | Contract |
| Take payments and manage subscriptions | Checkout, subscription status, invoices, refunds | Contract; legal obligation (tax and accounting records) |
| Confirm your email and reset your password | Email you a link to confirm your address, or to choose a new password | Contract; legitimate interests (keeping accounts secure) |
| Keep the Service safe | Detect abuse and misuse, for example by screening for invalid or disposable email addresses, requiring new free accounts to confirm their email, and stopping a deleted account's email address from opening a new account for 12 months; protect accounts and infrastructure | Legitimate interests (keeping the Service secure and the free plan fair) |
| Support and service messages | Answer your emails; contact you about your account, billing or security; tell you about changes to our Terms and Policies | Contract; legitimate interests |
| Reliability and troubleshooting | Diagnose failed runs; monitor performance and cost; fix bugs | Legitimate interests |
| Legal compliance and record-keeping | Keep records of the Terms you accepted; respond to lawful requests | Legal obligation; legitimate interests (proving what you agreed to) |
We do not use your personal information for advertising or to build advertising profiles, and we do not make automated decisions about you that have legal or similarly significant effects. (The AI in the Service drafts suggestions about research literature, which you review. See our AI Output & Research Disclaimer.)
3. AI processing of your content
To produce your results, the Service sends parts of your content to AI model and embedding providers listed on our Subprocessors page. Depending on the stage, that can include your topic text, protocol, search terms, article titles and abstracts, article full text (including text from files you upload), and your extraction and risk-of-bias inputs. We use these providers through their commercial APIs; their own terms and privacy policies govern how they handle data they process for us. We do not use your content to train AI models. Please don't enter information that identifies a patient or other individual.
4. How we share information
- Service providers. We share information with the providers on our Subprocessors page so they can host the Service, process payments and run the AI features. They may use it only to provide those services to us, except where their own policies say otherwise (for example, Stripe's use of payment data for fraud prevention and legal compliance).
- Other users, if you share a run. A shared run, with your account name as its owner (an automatically generated ID, or the username on an older account; never your email address) and everything stored in it, is visible to every signed-in user (see Section 7 of our Terms). Private runs are not visible to other users. The one exception is operational: while a discovery is running, a user who tries to start a discovery at the same moment is told which topic is running and under which account name.
- Legal and safety. We may disclose information if we believe it is required by law or legal process, or necessary to protect the rights, safety or security of users, the public or the Service.
- Business transfers. If we are involved in a merger, acquisition or sale of assets, information may be transferred as part of it. We would give notice in the Service before it became subject to a different privacy policy.
- With your direction. We share information when you ask us to.
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We have not done either in the past 12 months.
5. International transfers
We and our providers process information in the United States and other countries, which may have data-protection laws different from those where you live. Where the law requires it, we rely on safeguards such as the European Commission's Standard Contractual Clauses (with the UK Addendum where relevant) or a provider's certification under the EU-U.S. Data Privacy Framework.
6. How long we keep information
| Information | Retention |
|---|---|
| Account record (email address, account ID or username, password hash, plan and usage counters, Stripe IDs, record of accepted Terms) | Until you delete your account, which removes it immediately |
| Your content (runs, logs, uploaded files) | Until you delete the run, or your account; either removes it from our active systems immediately. We do not currently delete content automatically |
| Billing records (held by Stripe and by us) | Stripe keeps transaction records as long as tax, accounting and other laws require, typically up to seven years. Deleting your account also deletes your customer profile and saved payment methods at Stripe |
| Deleted usernames | Reserved for 14 days after deletion, so an old sign-in can't be used on a new account with the same name, then removed |
| A fingerprint of a deleted account's email address (a keyed one-way hash, never the address itself) | 12 months after deletion, so the address can't be used to open a new account; then removed. It cannot be turned back into the address |
| Short-lived counters that cap how many emails we send and addresses we check (keyed by an internal account ID or a one-way hash of an address) | Up to 2 days |
| Infrastructure logs | For a limited period set by our hosting provider |
| Emails to us | As long as needed to handle your request and keep a reasonable record |
When you delete your account we immediately delete your account record, every run you started and all files you uploaded from our active systems, and we cancel any subscription. Copies may remain for a short period in routine backups kept by our hosting provider, and in anything others copied from a run while it was shared. Topic-based search indexes built from public PubMed records (which may be named after a topic) are shared infrastructure, are not linked to your account, and are not deleted with it. Stripe keeps transaction records as the law requires.
7. Your rights and choices
Everyone. You can delete your account yourself at any time: choose Account in the top bar, then Delete account. We immediately and permanently delete your account, all of your runs and uploaded files, and your customer profile at Stripe, and we cancel any subscription (Section 6 explains what we keep). The one thing we keep is a one-way fingerprint of the email address, for 12 months, so that it can't be used to open a new account straight away. You can also delete any single run yourself, from your history or the run's own page (this removes the run and its uploaded files immediately; if the run was shared it disappears for everyone). You don't need to contact us or give a reason. To get a copy of your personal information, to have it corrected, or if you can't sign in, email support@synthgap.com from the address on your account (or, on an older account without an email, with your username).
Verifying it's you. Before acting on a request sent by email, we may need to confirm that the account is yours, for example by checking that the request comes from the email address on the account, by giving you a phrase to enter into your account, or, for subscribers, by matching the billing email Stripe holds. We respond within the time the law requires (generally one month, or 45 days for California residents).
If you are in the EEA, the UK or Switzerland, you also have the right to restrict or object to processing based on our legitimate interests, to receive your data in a portable format, and to complain to your local data-protection authority.
If you are in California or another US state with a privacy law, you may have the right to know, access, correct and delete your personal information, to receive a portable copy, and not to be discriminated against for exercising your rights. You may also have the right to opt out of the sale or sharing of personal information and to limit the use of sensitive personal information; we do not sell or share personal information, and we use account credentials only to provide the Service. You can use an authorized agent to make a request on your behalf, and we may ask them to prove their authority. If we decline a request, you can appeal by replying to our response with the word "Appeal," and you may contact your state attorney general if you are unhappy with the outcome.
Categories of personal information we collected in the last 12 months (California):
| Category | Examples | Source | Disclosed to |
|---|---|---|---|
| Identifiers | Email address; account ID or username; IP address | You; your browser | Hosting provider; Stripe (email address, if you subscribe) |
| Commercial information | Plan, subscription status, Stripe customer and subscription IDs | You; Stripe | Stripe; hosting provider |
| Internet or network activity | Usage counters, run history and logs | Our systems | Hosting provider |
| Other information you provide | Research topics, protocols, uploaded documents and other content | You | Hosting and AI providers |
| Sensitive personal information | Account log-in credentials (stored as a password hash) | You | Hosting provider |
Do Not Track and Global Privacy Control. We do not track you across websites. We treat Global Privacy Control signals as opt-out requests, although we do not sell or share personal information.
8. Security
We use measures including encrypted connections (HTTPS), one-way salted hashing of passwords, a signed, HttpOnly, Secure, SameSite=Strict session cookie, and access controls that limit private runs to their owner. No system is perfectly secure, so we cannot guarantee absolute security. If a breach affects your personal information we will notify you and regulators as the law requires, in the Service and, for subscribers, by email to the billing address on file.
9. Children
The Service is not directed to anyone under 18 and we do not knowingly collect information from them. If you believe a child has an account, contact us and we will delete it.
10. Cookies and similar technologies
We set one essential cookie to keep you signed in and use a little browser storage for convenience. We do not use analytics or advertising cookies. Details are in our Cookie Policy.
11. Information about authors in the literature
The Service processes publicly available bibliographic records, such as article titles, abstracts and author names, from PubMed and PubMed Central. That information is about published research, not about you. We use it only to provide the Service and do not build profiles of authors. If you are an author with a question or request about how your published information appears in the Service, contact us.
12. Changes to this policy
If we make material changes we will give notice in the Service and, where required, ask you to accept the updated Terms and Policies. The effective date above shows the current version.
13. Contact
SynthGap · Sehit Dumenci Street No 10, 99010 Nicosia, Cyprus · support@synthgap.com