Sinaps
Sign in

Privacy Notice

What Sinaps collects about you, why, who else can see it, and how to get it back or get it deleted.

In effect from 1 September 2026

1. Who is responsible

Sinaps decides what personal data is collected and why, and is the data controller for it. Sinaps is operated from Chișinău, Republic of Moldova. A Moldovan company is being registered; these documents will be updated with its registered name and address once it is. Until those details are published, write to privacy@sinaps.md to reach whoever is responsible for your data.

For anything in this notice, including any request about your data, write to privacy@sinaps.md.

2. What we collect

Account: your email address, and — if you sign in with Google — the account identifier and display name Google gives us. We never receive your Google password.

Profile: your chosen display name, public-name preference, interface language and study preferences. Earlier academic profile values may remain in existing account records; the general-study interface does not require them.

Study activity: which questions you answered and whether each was right or wrong, your attempts and their scores, and which lessons you have marked as read. This is what produces your mastery percentages, accuracy, and streak.

Study resources: your uploaded files and notes, quizzes, lessons, personal Subjects, resource pins, visibility settings and saved AI conversations. A duplicate-file notice can refer to your own files or already-public files, but does not disclose someone else's identical private upload.

Devices and sessions: a record of the devices you sign in from, used to keep you signed in and, after the beta, to enforce account sharing limits.

Technical data: hosting logs may include IP addresses and browser details. Error reports sent to PostHog contain error types, code locations, application area and release, with error messages removed and no account identifier. They do not contain your files, answers or AI conversations.

Optional usage analytics: only with your consent, we send an opaque account identifier, general screen names and action outcomes such as starting or finishing a quiz. We do not send your name, email, scores, answers, filenames, uploaded content, AI prompts or full page URLs. We do not record sessions or automatically capture clicks.

We do not collect health data about you, and you should not send us any.

3. Why we use it, and on what basis

To provide the service you asked for — your account, your library, your progress. This is necessary to perform our agreement with you.

To keep the service secure and working, including preventing account sharing and bulk extraction and diagnosing technical faults. This is our legitimate interest in running a viable service, balanced against your interests. Redacted technical error reporting is separate from optional usage analytics.

To understand which features are useful, through optional usage analytics based on your consent. You can decline or withdraw consent in Account without losing access to study features. Withdrawal stops future usage events; it does not automatically erase events already sent.

To send you service email — confirming your address, resetting your password. Marketing email, if we ever send any, will be by consent and separately unsubscribable.

To meet legal obligations, including tax and accounting records once the service is paid.

4. Who else handles it

We use a small number of processors, each bound to use the data only for what we ask:

Supabase — database, authentication, and file storage. Vercel — application hosting. Google — only if you choose to sign in with Google. Resend — sending service email. PostHog Cloud EU — optional product analytics and redacted technical error reporting. A payment provider acting as merchant of record will handle payment data once the service is paid; we never see your card details.

We do not sell your data, and we do not share it with advertisers.

5. Where it is stored, and for how long

Your data is stored in the European Union. Some processors are established outside it; where that is the case, transfers rely on the safeguards those providers offer, such as standard contractual clauses.

We keep your account data while your account exists. When you close it, your profile, study activity, and uploaded files are deleted within 30 days, except where we must keep a record for tax or accounting purposes.

Server and error logs are kept for a short period — normally no more than 90 days.

6. Your rights

You can ask us for a copy of your data, ask us to correct it, ask us to delete it, ask us to restrict how we use it, object to uses based on our legitimate interests, and ask for your data in a portable form.

Write to privacy@sinaps.md and we will answer within 30 days. You can also complain to the National Centre for Personal Data Protection of the Republic of Moldova, or to the data protection authority where you live.

7. Cookies and local storage

Sinaps sets a cookie to keep you signed in, and stores your language, theme, and accent choices in your browser so the app looks the same next time. These are necessary for the service to work as you have set it up.

We store your analytics choice separately for each account in this browser. PostHog does not store an analytics cookie or persistent device identifier in your browser. Declining analytics does not disable essential technical error reporting.

We do not use advertising cookies and we do not track you across other websites. Study-session state may be kept in your browser to help resume work. You must sign in to open public study resources.

8. Changes

If we change this notice in a way that affects you, we will tell you by email or in the app before the change takes effect.