Privacy Policy
Last updated: 2026-07-29
This policy applies to products and services operated by Synalux LLC, an Independent software vendor (ISV), at 18218 Fox Chase Cir, Olney, MD 20832, United States.
What we collect
- Account info: email, name, role, workspace.
- Health information (PHI) entered by your provider, when you are a patient.
- Communication preferences (email, SMS opt-in).
- Usage analytics: page views, button clicks, error reports — never tied to PHI.
- Audit logs: every access to OAuth tokens, every PHI read.
Prism AAC (Augmentative & Alternative Communication)
- Camera & Head Tracking: Prism AAC uses your device camera for head tracking and eye gaze input. Camera frames are processed on-device in real time and are never transmitted, stored, or sent to any server.
- Voice & Speech: Text-to-speech audio is generated on-device or via Azure TTS. Voice clone recordings are stored locally on your device only.
- AAC Phrases & Communication Data: Your phrase history, symbol selections, and communication patterns are stored locally on your device. Cloud sync (when enabled) encrypts data in transit and at rest.
- Switch Scanning & Accessibility Input: Input method data (switch presses, dwell times, gesture data) is processed on-device and never transmitted.
PrismCoach (Fitness Coaching)
- Apple HealthKit: PrismCoach reads heart rate, HRV (heart rate variability), resting heart rate, sleep analysis, and workout data from HealthKit to compute your Body Battery score and muscle recovery state. This data is processed on-device and is never sent to our servers.
- Biometric Data: Body Battery scores, muscle charge levels, and CNS readiness indicators are computed locally. No biometric data leaves your device.
- AI Coaching: On-device AI (Prism Coder 1.7B) processes your workout context locally. For Athlete tier users, anonymized workout context (no personally identifiable information) may be sent to our inference server for enhanced coaching.
Prism (Session Memory for Coding Agents)
Prism operates in local-only mode by default. In local-only mode your session content is written to a SQLite database on your own device and is not transmitted to Synalux or to any third party. We do not receive it, cannot read it, and do not process it — there is nothing for us to disclose, retain, or produce, because it never reaches us. Local-only mode requires no account, API key, or subscription, and it remains fully functional: search, recall, and inference all run on your device.
Transmission of session content to Synalux occurs only if you affirmatively enable cloud memory. That is an opt-in you make; it is off unless you turn it on, and turning it off returns Prism to local-only operation.
- What is stored locally: the session context you choose to save — summaries, decisions, open TODOs, changed file names, and keywords.
- Cloud memory (optional, opt-in): if you enable cloud storage for multi-device sync, that same session content is stored on Synalux servers under your account. It travels over TLS and is encrypted at rest at the database layer. It is not end-to-end encrypted and does not receive the application-layer AES-256-GCM treatment described below for PHI and OAuth tokens: searching your own memory requires the service to be able to read it. If that trade-off is unacceptable to you or your organisation, do not enable cloud memory — local-only mode gives you the full product without it.
- Skills and entitlements: Prism fetches its skill and agent definitions from synalux.ai. Paid tiers send an API key or session token so we can confirm your entitlement; the free tier fetches the public bootstrap package without authenticating. Neither request carries your session content, in either mode.
- Prompt routing stays on your device: your first message of a conversation is matched against skill trigger rules locally, for routing only. It is not transmitted for that purpose, in either mode.
- Local inference: when Prism runs a model on your device, prompts and responses are processed locally and are not sent to external servers.
On-Device AI Processing
- Prism Coder language models (1.7B–32B parameters) run entirely on your device.
- No prompts, responses, or conversation data are sent to external servers during on-device inference.
- Cloud fallback (when enabled) sends only the query text — never patient data, health data, or personal identifiers.
How we use it
- To deliver the service you signed up for.
- To send the communications you opted into (see SMS consent).
- To respond to support requests.
- For HIPAA-required treatment, payment, and healthcare operations purposes.
- To detect and prevent fraud or security incidents.
What we DO NOT do
- We do not sell, rent, or share your contact information with third-party marketers.
- We do not use PHI for advertising or training general-purpose AI models.
- We do not access your data without a logged reason.
Security
- OAuth tokens encrypted at rest with AES-256-GCM and per-row AAD binding (Pattern C isolation).
- PHI encrypted at rest with AES-256-GCM.
- Every PHI / token decryption logged to a tamper-evident hash chain.
- A HIPAA Business Associate Agreement is available to covered-entity providers on request.
Your rights
You can request your data, request deletion, or revoke any consent (including SMS opt-in via STOP). Email support@synalux.ai — we respond within 30 days.
Google API Services — User Data Policy Disclosure
Synalux Health's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Data Accessed
When you connect a Google account, Synalux may request the following scopes depending on which features you enable:
- Gmail (
gmail.modify) — search and read your inbox threads, send email you compose, and perform user-initiated read, archive, and Trash actions from within the Synalux Mail interface. - Google Calendar (
calendar.calendarlist.readonly and calendar.events) — list your subscribed calendars and read, create, update, or delete events you choose from within the Synalux Calendar interface. Synalux cannot create or delete calendars, change calendar properties, or manage sharing permissions. - Google Contacts (
contacts.readonly) — read your contact list to auto-complete recipient fields. - Google Drive (
drive) — browse and search your Drive files, open Google documents inside Synalux Drive, and save document edits back to Google Drive when you explicitly choose Save. - OpenID / profile — your Google account name, email address, and profile photo for sign-in and display purposes.
We request only the scopes needed for the features you actively use. Unused scopes are not requested.
Data Usage
- Google user data is used only to operate the specific feature you connected (Mail, Calendar, Contacts, Drive).
- Gmail data is displayed in the Synalux Mail interface and used to send messages you compose or apply read, archive, and Trash actions you select. It is never read by analytics pipelines or used for AI training.
- Calendar data is displayed in the Synalux Calendar interface and used to create or update events you explicitly request.
- Contact data is used solely to populate auto-complete fields within your session.
- Drive data is used solely to list, search, display, and edit files you explicitly open. Google Drive file content is not copied into Synalux file storage; document edits are sent directly back to Google when you select Save.
- Google data is never used for advertising, profiling, or training machine-learning models.
Data Sharing
- We do not share Google user data with any third party except as required to operate the service you requested (e.g., Supabase database hosting for token storage).
- Sub-processors with access to Google tokens are bound by Data Processing Agreements and may not use the data for any independent purpose.
- We do not transfer, sell, or broker Google user data.
Data Storage & Protection
- Google OAuth access and refresh tokens are encrypted at rest using AES-256-GCM with a per-row Authentication Associated Data (AAD) binding — pattern C isolation as defined in our security architecture.
- Tokens are never written to logs, error reports, or analytics events.
- Every token decryption is logged to a tamper-evident audit chain (HMAC-chained rows) so unauthorized access is detectable.
- Token storage is scoped to Supabase, deployed in AWS us-east-1, encrypted at the storage layer in addition to our application-layer encryption.
Data Retention & Deletion
- Google tokens are deleted immediately when you disconnect the integration from your settings page.
- Cached message previews (if any) are purged within 24 hours of disconnection.
- On full account deletion, all Google tokens and any associated cached data are permanently deleted within 7 days.
- To request immediate deletion, email support@synalux.ai.
Financial Data & Bank Connections
- Connection Providers: Bank and card accounts are linked through Plaid and Stripe Financial Connections. Both are used read-only, to retrieve the account information described below; neither is used to move money.
- Bank Account Verification: When you connect a bank account, we receive account verification data (account holder name, balance, and — where you grant that permission — account and routing numbers) to enable payroll direct deposit setup and transaction reconciliation.
- Transaction Data: Bank and card transaction history is retrieved for accounting reconciliation purposes only. Transaction data is stored in our database encrypted at rest, hosted in the United States (AWS us-east-1). We do not store financial data outside the United States.
- ACH Transfers: Payroll direct deposit and retirement-plan contributions are initiated through Mercury, our business banking provider. Transfer amounts, dates, and recipient details are logged for audit and tax reporting purposes.
- No Selling: Financial data is never sold, rented, or shared with third-party marketers or data brokers.
- Provider Compliance: Our use of Plaid data complies with the Plaid End User Privacy Policy. Our use of Stripe Financial Connections data complies with the Stripe Privacy Policy.
Data Retention and Disposal Policy
Synalux retains data only as long as necessary for the purposes described in this policy and as required by applicable law.
- Account Data: Retained for the duration of your active account. Deleted within 30 days of account closure upon written request.
- Financial Data (Plaid / Stripe Financial Connections): Bank account credentials and connection identifiers are deleted immediately when you disconnect the integration. Transaction history is retained for 7 years for tax and audit compliance, then permanently deleted.
- Payroll Records: Retained for 7 years as required by IRS regulations (26 CFR 31.6001-1) and state labor laws.
- Audit Logs: Security and access audit logs are retained for 3 years, then archived or deleted.
- Communication Data (Email/SMS): Retained for the duration of your active account. Purged within 30 days of opt-out or account deletion.
- Health Information (PHI): Retained per HIPAA minimum necessary standards and provider agreements. Minimum 6 years per HIPAA (45 CFR 164.530(j)).
- On-Device Data: Data processed on-device (camera frames, AI inference, HealthKit data) is never transmitted to our servers and is managed by your device OS.
Disposal Methods
- Electronic records are permanently deleted using cryptographic erasure (key destruction) or database-level hard delete.
- Backup copies are purged within 90 days of primary deletion.
- Deletion requests can be submitted to support@synalux.ai and are fulfilled within 30 days.
Policy Review
This data retention policy is reviewed annually or when significant changes occur to applicable regulations, business operations, or data processing activities.
SMS & Text Messaging
Synalux sends transactional text messages only after a user makes an affirmative choice through separate optional written web checkboxes that are unchecked by default:
- POS toll-free program: Order confirmations, Secure payment links and payment receipts, Pickup and delivery notifications, Customer-care responses. Typical frequency is 1–3 messages per order, up to 15 messages per month.
- Separate healthcare program: Appointment reminders, Telehealth session links, Billing notifications. Typical frequency is 2–8 messages per month. This program is not included in the POS toll-free verification submission.
- Authentication: Two-factor or login codes use a separate flow and are not bundled with either transactional messaging checkbox.
Opt-In
Each messaging program has its own optional checkbox. Consent is not required to create an account or receive services, is not bundled with acceptance of the Terms or Privacy Policy, and is not inferred from placing an order or scheduling an appointment. The dedicated POS web form is available at https://pos.synalux.ai/sms-consent. Healthcare consent is collected separately in the patient registration flow. No marketing messages are sent.
Opt-Out
Reply STOP to any message to immediately unsubscribe. Reply START to re-subscribe. You may also email support@synalux.ai to opt out.
Message Frequency & Rates
POS messaging typically totals 1–3 messages per order, up to 15 messages per month; healthcare messaging typically totals 2–8 messages per month. Actual frequency varies with orders, appointments, and customer-care requests. Message and data rates may apply. Synalux does not charge end recipients for these messages.
Data Handling
Mobile opt-in data and consent are never sold, rented, or shared with third parties for marketing or promotional purposes. Mobile opt-in data may be shared only with messaging providers, aggregators, and carrier partners as necessary to deliver the messages a user requested. Phone numbers are used for the selected transactional program and customer care.
All the above categories exclude text messaging originator opt-in data and consent; this information won't be shared with any third parties.
Sub-processors
Synalux uses third-party providers only as needed (hosting, email/SMS delivery, payment processing). Each is bound by a Data Processing Agreement. Current list available on request.
Changes
Material changes to this policy are emailed to all account holders 30 days before they take effect.
Contact
support@synalux.ai or write to: Synalux LLC, Privacy Officer, 18218 Fox Chase Cir, Olney, MD 20832, United States.