What we collect, why we collect it, who we share it with, and the rights you keep over it — written to be read, not to be survived.
This Privacy Policy explains how Cloudresty Limited, a company registered in England and Wales that operates the SynapCTX platform (“SynapCTX”, “we”, “us”), handles information when you use the SynapCTX platform at synapctx.com, the SynapCTX console, our APIs and MCP endpoint, and the sctx command-line tool (together, the “Service”). It applies to everyone who signs in to or is invited into a SynapCTX organization.
SynapCTX is an organizational context and memory platform for AI coding agents. It indexes the source code you connect into a knowledge graph, retrieves relevant context on demand, and stores durable organizational memory so that agents and developers share the same understanding of a codebase. The Service is operated by Cloudresty Limited, a company registered in England and Wales (company number 13644236; VAT number GB 392015217; registered office 39 The Metro Centre, Tolpits Lane, Watford, Hertfordshire WD18 9SB, United Kingdom), which is the data controller for the information described here. For any question about this policy or your data, contact us at privacy@synapctx.com.
We collect only what the Service needs to function. There are three categories.
When you create an account or are invited to one, we process your email address, display name, and organization membership. If you sign in with a third-party identity provider (Google or Microsoft), we receive the information described in section 3. Passwords, when you use email-and-password sign-in, are stored only as a salted hash — never in plain text.
When you connect a Git repository, we read its source code and metadata in order to index it: we generate vector embeddings, extract symbols and relationships, and build the knowledge graph and organizational memory that power retrieval. This content is processed and stored strictly to provide the Service to your organization. We do not use your source code to train foundation models, and we do not expose one organization’s content to another — every organization is an isolated tenant.
We record operational telemetry needed to run and bill the Service: which commands and API calls were made, token and context volumes (for usage limits and savings reporting), timestamps, and technical logs. We do not build advertising profiles and we do not sell any of this data.
If you choose “Sign in with Google”, SynapCTX requests only the following Google OAuth scopes:
| Scope | Data accessed | Why |
|---|---|---|
openid | Your Google account’s unique identifier (the OpenID subject) | To recognize you on return visits and link your session to your account |
email | Your email address and its verified status | To identify your account and match invitations addressed to you |
profile | Your basic profile: name and profile picture URL | To display who is signed in and personalize the console |
We request no access to Gmail, Google Drive, Contacts, Calendar, or any other Google service. We use Google user data only to authenticate you and provision or identify your SynapCTX account. We do not sell Google user data, we do not use it for advertising, and we do not share it with third parties except the infrastructure subprocessors listed in section 6 that operate the Service on our behalf.
SynapCTX’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. You can revoke SynapCTX’s access to your Google account at any time from your Google Account permissions page.
Where the GDPR or a comparable law applies, we process your information on the basis of: performance of a contract (to deliver the Service you signed up for), legitimate interests (to secure, operate, and improve the Service), consent (where you have given it, such as connecting a specific repository), and legal obligation (where the law requires it).
We do not sell your information. To run the Service we rely on a small, carefully selected set of infrastructure providers (“subprocessors”) who process data strictly on our behalf, each under a data-processing agreement. We disclose them by category below; the current list of named subprocessors is available to customers and prospective customers on request (see the note beneath the table).
| Category | Purpose | Region |
|---|---|---|
| Hosting & compute | Running the platform and storing your account, indexed code, and memory | European Union |
| ML inference (embeddings) | Generating vector embeddings of the code you connect | European Union |
| Transactional email | Sending verification, password-reset, and invitation email | United States (under SCCs) |
| Authentication providers | Sign-in, only when you choose Google or Microsoft SSO | United States |
We name our subprocessors by category rather than publicly listing every vendor. If you need the current list of named subprocessors and their data-processing terms — for your own vendor-assessment or DPA — email privacy@synapctx.com and we will provide it.
We may also disclose information if required by law, to enforce our Terms of Service, or to protect the rights, safety, and security of SynapCTX, our users, or the public. If the Service is involved in a merger or acquisition, we will notify you before your information becomes subject to a different privacy policy.
The SynapCTX platform — your account, indexed code, knowledge graph, and organizational memory — is hosted on infrastructure located in Germany, within the European Union. Some subprocessors (see section 6) operate in the United States; where data reaches them, the transfer is governed by appropriate safeguards such as the EU Standard Contractual Clauses.
We keep your information for as long as your account or organization is active. Indexed repository content is retained while the repository is connected; disconnecting it removes it from active indexes. If you delete your account or an organization, we delete or irreversibly anonymize the associated data within a reasonable period, except where we must retain limited records to meet legal, accounting, or security obligations.
We protect information with encryption in transit (TLS), tenant isolation enforced at the database level, hashed credentials, scoped internal service authentication, and least-privilege access controls. No system is perfectly secure, but we design SynapCTX so that a failure defaults to denying access rather than exposing data.
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to withdraw consent. You can exercise most of these directly from your account, or by contacting privacy@synapctx.com. We will respond within the time required by applicable law. You also have the right to lodge a complaint with your local data-protection authority.
We use no analytics, advertising or third-party tracking cookies of any kind. Every cookie below is set by SynapCTX itself. We do not sell or share cookie data, and nothing here builds a profile of you.
Cookies marked strictly necessary are required to deliver the service you asked for and are set without consent, as the law permits. The two marked preference are set only if you agree; if you choose “Essential only”, the product works exactly the same, we simply stop remembering your theme between visits.
| Cookie | Purpose | Category | Retention |
|---|---|---|---|
sctx_session | Keeps you signed in to the console. Contains only an opaque identifier; it is not readable by scripts. | Strictly necessary | 24 hours, extended while you are active |
synapctx_org | Remembers which organisation you are viewing. | Strictly necessary | Session |
synapctx_project | Remembers the project you have selected. | Strictly necessary | Session |
sctx_invite | Carries an invitation through sign-up. | Strictly necessary | Minutes; cleared on completion |
sctx_intended_plan | Remembers the plan you picked before creating an account. | Strictly necessary | Minutes; cleared on completion |
synapctx_consent | Records this cookie choice, so we do not ask again on every page or every subdomain. | Strictly necessary | 180 days |
synapctx_theme | Remembers whether you chose light, dark or system appearance. | Preference | 12 months |
synapctx_account | Lets synapctx.com show “Open console” instead of “Sign in” when you are already signed in, and show your profile picture. Contains a flag, your display name and a random identifier for the picture — no session identifier, no token, and it grants no access. | Preference | Matches your session |
If you sign in with Google, your Google profile picture is shown in the console and on this website. We fetch it once, at sign-in, and serve our own copy from console.synapctx.com. We do not link to Google’s servers, so loading a SynapCTX page never tells Google that you visited it — which is also why the claim above, that we use no third-party requests, stays true.
The copy is held in memory (Redis) for up to seven days, is deleted when you sign out, and is reachable only through a random, unguessable address. We never store the picture in our database, and we do not use it for anything other than showing it to you. Signing in with a password sets no picture at all — your initial is shown instead.
Your cookie choice is recorded for synapctx.com and its subdomains — including console.synapctx.com and auth.synapctx.com — because they are one service operated by one company. Deciding once on any of them applies to all of them, and the banner says so before you choose.
You can withdraw or change your choice at any time, and it is as easy as giving it: reopen your cookie choices. You can also delete SynapCTX cookies in your browser settings at any point; the strictly necessary ones will be set again on your next visit because the service cannot function without them.
SynapCTX is a professional tool not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us information, contact us and we will delete it.
We may update this policy as the Service evolves. When we make a material change, we will update the “Last updated” date above and, where appropriate, notify you by email or in the console. Continuing to use the Service after a change takes effect means you accept the revised policy.
Questions, requests, or concerns about your privacy? Email privacy@synapctx.com or hello@synapctx.com.