Legal
Privacy Policy
How the Synsa website, its voice guide, Synsa news and Synsa accounts handle your information, in plain words.
The short version
- The voice guide on our site, called Synsa, is an AI. It isn’t a person, and it can get things wrong.
- We never save a recording of your voice. While your mic is on, your voice goes live to xAI, which turns it into text. xAI keeps it for up to 30 days to check for abuse (longer only if it’s flagged, or for legal or safety reasons).
- We save a written copy of each conversation, and of each tour you start, on Synsa’s own computer, with a few details such as your device type and country. After 180 days the transcript and those details are deleted automatically; only the date, length, device type and costs stay. We’ll delete yours sooner whenever you ask.
- A few companies help us: xAI, Cartesia and Cloudflare, and for some answers OpenRouter and Google. Some keep what they get for a while, and Cartesia may use the voice guide’s answers to improve its AI. See exactly who gets what.
- No ads, and we don’t track you across other sites. The only cookies are for signing in to a Synsa account, if you make one. Visitor statistics are switched off. We never sell your information.
- Synsa news keeps your email, when you signed up and where, until you unsubscribe. We use it only to send you Synsa news, about once a month, and we haven’t sent any yet. Unsubscribe any time.
- If you make an account, we keep your name if you give one, the email and name Google shares if you sign in with Google, how you sign in and your plan choices until you delete it, which you can do yourself at any time. There are no passwords, and the plans are a test: no money is taken.
- It’s your information. Ask us any time to see it, correct it or delete it. It’s free.
Contents 16 sections
Who we are
This policy covers the Synsa website (synsa.com), the AI voice guide that can talk with you on it, Synsa news (our email newsletter) and Synsa accounts made on the website. The Synsa Android app isn’t open yet; it will have its own privacy policy.
Synsa’s legal name, address and country will be added here before launch.
In this policy, “we”, “us” and “Synsa” mean the business that runs Synsa. The AI voice guide on our site is also called Synsa; here we call it “the voice guide”.
Under EU and UK data protection law, we are the “controller” of your information: we decide how it is used. We haven’t appointed a data protection officer, because the law doesn’t require one for a service like ours. Please write to us directly (see Contact us).
When you visit the site
Opening a page sends what every website receives: your IP address, your browser’s name, version and operating system (its “user agent”), the page you asked for and the time.
This preview address
Until synsa.com opens, the site is shown at a temporary preview address. Requests pass through Cloudflare’s network to a server we rent from Hetzner Online GmbH, a German hosting company, in its data center in Finland. So on this preview, Hetzner also holds your information for us.
That server writes one line for each request to its log: your IP address, the page asked for (including anything after a “?” in the address), the result and the time. Since September 28, 2026, each day’s lines are deleted automatically 30 days later. Lines from before that date went to the server’s system log, which removes old lines only when it gets large.
On this preview only, if our own copy of the Inter font fails to load, your browser fetches it from Google Fonts instead, and Google then sees your IP address.
Everything the pages show (fonts, pictures, icons and the voice guide’s recorded tour) comes from our own site, apart from Cloudflare’s bot check and, on this preview, the backup copy of the font described above. There are no ads, social media buttons, embedded videos or tracking pixels.
We don’t use visitor statistics (“analytics”). If we ever switch them on, we’ll update this page first.
While the voice guide is switched on, the home page also runs a bot check and looks up your rough location as soon as it opens, even if you never use the guide. That’s explained in The bot check and your location.
The voice guide: your voice and your words
The voice guide is an AI, not a person. It answers questions about Synsa and can show you around the page. Its answers are written by AI and its voice is made by AI, so it can get things wrong.
What starts a conversation
No conversation starts until you tap Talk to Synsa or, while the guide is on, Take the tour.
- “Talk to Synsa” turns your microphone on straight away. Your browser asks your permission first, unless you’ve already allowed our site to use it.
- “Take the tour” starts with the microphone off. You can turn it on by tapping the orb.
- You can type instead of speaking: say no when your browser asks about the microphone, or start with the tour, and type your question.
- There’s no mute button. To turn the microphone off, hang up. It also turns itself off after about 2 minutes with nobody speaking.
If our voice server is offline, the tour plays recordings from our own site and no conversation is recorded.
Your voice
While your microphone is on, the sound is streamed live from your browser, through Cloudflare’s network, to our voice server, and from there to xAI, which turns it into text. We never save a recording of your voice: our server only ever holds the last couple of seconds in memory, so nothing is lost if the connection blips. We don’t use your voice to identify you, and we don’t make a “voiceprint”.
Your words
Whatever you say or type (a typed message can be up to 600 characters) is sent to an AI model that writes the voice guide’s answer:
- Grok, made by xAI, is always asked first.
- If Grok fails, or hasn’t started answering within about 2 seconds (sooner for a minute after Grok has been slow), the conversation is also sent to Gemini, made by Google, through a service called OpenRouter. Both then work on it, and you hear whichever answer starts first. So Google can receive your words even when the answer you hear is Grok’s.
The AI model receives the recent part of your conversation, the voice guide’s own instructions, whether you’re on a phone or a computer and, for xAI, a random conversation number. It doesn’t receive your IP address, browser details, location or time zone. The answers are then turned into speech by Cartesia, which receives only the text of the voice guide’s answers (they can repeat things you said) and never your own voice.
What we save
For every conversation, and every tour you start, our voice server saves on Synsa’s own computer:
- A written transcript: what you said or typed, what the voice guide said (only the part you actually heard) and the words of any tour recordings that played, each with the time.
- Details about the conversation:
- when it started and ended, and how it ended;
- phone or computer, and your browser’s user agent;
- your country and region (such as a US state);
- the address of the page you were on;
- how far you got in the tour;
- which AI model answered;
- counts we use to work out costs: how many messages, how many seconds of sound went to xAI, how many characters were spoken and how much of the AI was used.
This record starts as soon as the chat box connects, before you say or type anything, even if you only take the tour or hang up straight away. If your connection drops for a moment, the page tries for a few seconds to reconnect to the same conversation. If you reload the page or come back later, a new conversation starts.
We don’t save your voice, your time zone or your browser’s language, and we don’t save your IP address with the conversation. The page sends your time zone and language with the conversation; we hold them in memory during the call and drop them when it ends. Your IP address is used by the bot check, our abuse limits and the rough-location lookup (see The bot check and your location).
Please don’t share private things
Anything you say ends up in the written transcript, including names, email addresses or phone numbers you mention. Please don’t tell the voice guide about your health, your money, passwords or anything else sensitive. It doesn’t need them to answer. If you shared something like that by mistake, ask us and we’ll delete it.
The line under the chat box
In some places, and whenever we can’t tell where you are, a short line under the chat box says that the voice guide is an AI, which companies get what you say, and that a written copy is saved, with a link to this policy. Those places are the countries of the EU and the EEA, the UK, and the US states of California, Connecticut, Delaware, Florida, Illinois, Maine, Maryland, Massachusetts, Michigan, Montana, Nevada, New Hampshire, Pennsylvania and Washington. Everywhere else, this policy is your notice.
The line appears once the chat box has connected. That is also the moment your microphone starts sending sound, if you tapped “Talk to Synsa” and allowed the microphone. If you shrink the chat box while it’s connecting, the microphone still starts when it connects, and you’ll see the line when you open the box again. You can stop at any time by hanging up, and ask us to delete your conversation (see Your choices and rights).
Synsa news
Synsa news is our email newsletter. You can sign up at the bottom of our home page, or with the “Email me Synsa news” switch on your account page if you sign in with Google. We save your email address, when you signed up, where (the home page or your account page), the words you agreed to and whether the email is confirmed as yours. Nothing else: no IP address, browser details or location is saved with it.
Your sign-up is kept in our account store, on the same server as Synsa accounts, and nowhere else for now. To stop abuse, the website counts sign-ups from each internet address in the same scrambled way as sign-in tries, and deletes those counts within two hours (see Your Synsa account). The form gives the same answer whether or not an email was already on the list, so nobody can use it to find out who signed up; only when you’re signed in may it tell you that your own email is already there. Our website server’s log notes each sign-up and unsubscribe with a shortened email (like j***@gmail.com), never the whole address.
What we send
Only Synsa news: new AIs, new features and tips, about once a month. We haven’t sent any emails yet. Every email will have a link to unsubscribe. Before we send the first one, we’ll add the company that sends it to Who we share it with. We never sell your email, and we don’t share it with anyone for their own use.
If you sign up on our home page, the first email we send asks you to confirm it’s your address, and we send nothing else until you do. If you don’t confirm, we delete your email 30 days later. A sign-up on your account page needs no confirming, because Google has already confirmed that email is yours (the same goes for signing up on the home page with that email while you’re signed in).
Unsubscribing, and how long we keep it
We keep your email until you unsubscribe. You can do that at any time: with the link in any email (it opens our unsubscribe page, or your email app’s own Unsubscribe button does it in one tap), by turning off “Email me Synsa news” on your account page, or by contacting us. We stop at once: your email is marked as unsubscribed, so nothing more is sent to it, and it’s deleted automatically 30 days later. If you sign up again before then, it’s simply switched back on. Deleting your Synsa account, or removing Google from it, deletes its email’s sign-up at once.
Your Synsa account
You can make a Synsa account on our website and try the plans. There’s no password: you sign in with Google or with a passkey. The plans are in test mode: we never ask for a card, and no money is taken.
What we keep
- Your email address, if you sign in with Google: the one Google shares, and whether Google has confirmed it’s yours.
- Your name, if you give one or Google shares it.
- How you sign in. For Google: Google’s ID for your account, and the email and name it shared. For a passkey: its public key (the half that can only check a sign-in, never make one; the private half never leaves your device) and the kind of device that made it.
- Your plan: which plan you picked, when it started, renews or ends, and who shares it with you. Your account page shows this history.
- When you made the account and last used each way to sign in.
If you share a Duo or Family plan, the person who owns it sees your name and a shortened email (like j***@gmail.com), and you see their name.
We don’t save your IP address with your account. To stop abuse, the website counts sign-in tries for each internet address (for the newer, longer kind of address, per group of addresses). It saves these counts with a scrambled form of the address, never the address itself, and deletes them within two hours. Our website server’s log notes account events, such as a new account, a sign-in or a plan change, with the account’s random ID and a shortened email, never a whole email address. That log is the server’s system log, which removes old lines only when it gets large.
Cookies
When you sign in, we put one cookie in your browser that keeps you signed in. It holds a random code, and we keep only a scrambled copy of it. It runs out 30 days after your last visit, and signing out removes it. While you sign in with Google, a second cookie links the start and the end of that sign-in for up to 10 minutes. These cookies are needed for accounts to work, and we use them for nothing else.
Signing in with Google
If you choose Google, your browser goes to Google to sign in, under Google’s own privacy policy. Google tells us your account ID there, your email address and your name, and it learns that you signed in to Synsa.
How long we keep it
Until you delete your account. You can do that yourself on your account page, and your account is deleted at once: your name and email, your plan, every way you signed in, the plan history and your account email’s Synsa news sign-up. If you own a shared plan, the people on it move to Free.
Removing Google on your account page deletes Google’s ID for your account and the email it shared, at once, and that email’s Synsa news sign-up with them.
The bot check and your location
Cloudflare Turnstile
Our pages use Cloudflare Turnstile, a check that tells people and bots apart. While the voice guide is switched on, it runs as soon as the home page opens, even if you never use the guide. It usually works invisibly; now and then it may ask you to tick a box.
To do this, Cloudflare looks at signals from your browser: your IP address, technical details of your browser’s secure connection, your browser’s user agent and which site you’re on. We ask for a fresh check each time you start a voice conversation, and our server sends your IP address to Cloudflare along with it to confirm the result. Cloudflare uses these signals to spot bots and also, as its own decision, to improve Turnstile. It says it doesn’t use them to identify or profile you.
The check is automatic. If it decides you might be a bot, the voice guide doesn’t appear. If that happens to you by mistake, try again later or contact us.
Your rough location
To decide whether to show the line under the chat box, the page asks a small program we run on Cloudflare (a “Worker”) where you are. It works this out from your IP address with Cloudflare’s own lookup and answers with only your country and region, such as “US” and “CA”, never your city or exact location. Our Worker’s code saves nothing, but Cloudflare may keep a technical log of each request to it for up to 7 days, and that log can include the rough location Cloudflare worked out, such as the city. If the Worker doesn’t answer quickly, the line is shown anyway.
Your country and region are also saved with a voice conversation. Our voice server gets them from Cloudflare or from the page. We never ask your browser for your precise location.
Abuse limits
So that nobody can overload the voice guide, our server counts, per internet address (for the newer, longer kind of address, per group of addresses), how many conversations are open at once and how many were started in the last 10 minutes. These counts are kept in memory only, are never saved, and are wiped whenever the server restarts. If the bot check refuses someone, our server’s log notes their IP address (see How long we keep things).
Cookies and browser storage
- We use cookies only for Synsa accounts: one keeps you signed in, and one links the start and the end of a Google sign-in for up to 10 minutes (see Your Synsa account). Without signing in there are none. In our tests, Cloudflare’s bot check didn’t set any either.
- While you’re signed in, our pages note in your browser that you are (just that, never who you are), so the top bar shows your Account button straight away. Signing out removes the note.
- Cloudflare’s bot check keeps a small code in your browser, inside its own frame, named cf.turnstile.u. Cloudflare doesn’t publicly say what it contains or how long it lasts; in our tests it stayed the same between visits.
- Your browser may remember that you allowed our site to use the microphone. That’s your browser’s own setting, and you can change it in its site settings.
- The voice guide keeps nothing in your browser once you leave the page.
Apart from what is there for signing in, these are used only to keep the bot check working. You can remove all of them by clearing this site’s data in your browser.
Tracking, Do Not Track and Global Privacy Control
We don’t track you across other websites, and no advertising or analytics company collects information about you through our site. Cloudflare runs its bot check on many websites and sees the same kinds of signals on each, so it could recognize the same browser over time and across those sites; it says it uses these signals only to spot bots and improve the check, not to identify or profile anyone.
We don’t change anything when your browser sends a Do Not Track signal, because we have no tracking for it to switch off. If your browser sends a Global Privacy Control signal, we treat it as a request not to sell or share your information, which we never do anyway.
Where your information goes
Where Synsa’s own computer is (it keeps the conversation copies and our voice server’s logs) will be added here before launch.
The companies above are based in the United States, and they may handle your information in the US or in other countries where they or their suppliers work. If you’re in the EU, the EEA or the UK, this means your information leaves your region, and those countries’ laws may not protect it in the same way.
Each company says it protects European and UK information sent abroad in one of these ways:
- xAI: the EU’s standard contractual clauses (a contract, approved by the EU, that makes the company protect your information the way EU law does) and the UK’s addendum to them (the UK’s version), in its data processing addendum.
- Cartesia: the same contracts, in its data processing addendum.
- OpenRouter: the same contracts, in its data processing agreement.
- Google: it has signed up to the EU–US Data Privacy Framework (a scheme US companies join to promise EU-level protection), including its UK extension.
- Cloudflare: the Data Privacy Framework (with its UK extension), with the standard contractual clauses as a backup.
You can ask us for a copy of these safeguards (see Contact us).
How long we keep things
On Synsa’s computer
- Conversations: 180 days after a conversation started, its transcript is deleted automatically, together with your country and region, your browser’s user agent, the page address and any error messages saved with it. What stays is only what we need to count how the service is used and what it costs: when it started and ended and how it ended, phone or computer, how far the tour got, which AI model answered, and the counts and costs. None of that says who you are or what was said. The clean-up runs every few hours, so it can happen a few hours after the 180 days. Ask us and we’ll delete yours sooner.
- Synsa news sign-ups: until you unsubscribe; then it’s marked as unsubscribed at once and deleted automatically 30 days later. Deleting your account, or removing Google from it, deletes its email’s sign-up at once (see Synsa news).
- One exception: if a tour recording is stopped before you heard any of it, its line is removed from the transcript straight away.
- Our server’s log files start a new file every day (or sooner, if one gets large), and each file is deleted automatically 30 days after its last line was written. They note how the service is running:
- when a conversation starts: a short conversation code, device type, country and AI model;
- the mic going on and off, tour steps and how a call ended;
- the IP address (or group of addresses) of anyone the bot check refused;
- words picked up while the voice guide was talking that it ignored, because they sounded like “okay” or “yeah”, or like its own voice echoing back. Now and then that can be a whole sentence you said.
- Your Synsa account: until you delete it; then it’s deleted at once (see Your Synsa account). Unfinished sign-ins in our account store are deleted soon after they run out.
- Kept in memory only, never saved: the one-time pass that opens a conversation (60 seconds), the details of a call while it lasts, and the abuse counts (until the server restarts).
At the companies that help us
These are their own rules, as their published terms describe them:
- xAI may keep what it receives, including the sound of your voice, for up to 30 days to check for abuse, then deletes it automatically. It can keep it longer if it’s flagged for breaking xAI’s rules, for safety or security reasons, or if the law requires it. xAI’s terms say it doesn’t use it to train its AI without the customer’s permission. It may make anonymous statistics about how its service is used, which can’t identify anyone or show what you said.
- Cartesia publishes no fixed time limit: it may keep the text it receives and the audio it makes for as long as it needs them. Its terms also allow it to use them to train its AI unless its customer opts out.
- OpenRouter says it doesn’t store the text of requests or answers unless its customer turns on logging (it’s off by default), and that it doesn’t train AI on them. It keeps usage details such as size and timing, and it sorts a small sample of requests into topics without linking them to anyone.
- Google’s terms say it doesn’t use this text to improve its products, because it arrives through Google’s paid service. OpenRouter can use one of two Google services: one keeps the text for up to 55 days to check for abuse (see Google’s usage policies); the other, according to OpenRouter, keeps nothing. If something is flagged as possible abuse, Google may have it reviewed and may use it to train its abuse-detection systems, but not its other AI.
- Cloudflare doesn’t publish a fixed time limit. It keeps request information such as IP addresses as its services and security need, uses bot-check signals to improve Turnstile, and may keep a log of requests to our Worker for up to 7 days.
Our legal reasons for using your information
EU and UK law asks us to name a legal reason for each use of your information. Most of ours are “legitimate interests”: we need the information for a reasonable purpose of ours that doesn’t unfairly affect you, and you can object (see below). Here they are:
| What we do | Information | Legal reason |
|---|---|---|
| Show you the website and keep it working and secure | IP address, browser details | Legitimate interests: running a safe, working website |
| Tell people and bots apart, and stop abuse | IP address, bot-check signals, abuse counts | Legitimate interests: protecting the service and its visitors from bots, fraud and overload |
| Decide whether to show the line under the chat box | Country and region | Legitimate interests: following the rules of the place you’re in |
| Talk with you once you start a conversation: turn your voice into text, write answers, speak them | Your voice, your words | Legitimate interests: answering the questions you ask the voice guide |
| Keep a record and a written copy of each conversation or tour you start, to improve the guide, fix problems and answer questions about it | Transcript and conversation details | Legitimate interests: making the voice guide work well and dealing with problems and questions |
| Let Cartesia use the voice guide’s answers to improve its AI, as its terms allow | The text of the voice guide’s answers | Legitimate interests: using a standard voice service on its normal terms |
| Understand what the guide costs to run | Usage counts, AI model used | Legitimate interests: running the service within budget |
| Give you your Synsa account, sign you in and run your test plan | Email, name, sign-in details, plan choices, the sign-in cookie | Contract: the account you asked us for |
| Send you Synsa news | Your email and when and where you signed up | Consent: you sign up |
| Deal with legal claims and legal duties | Whatever is needed | Legal obligation, or legitimate interests in defending our rights |
For Synsa news we rely on your consent. You can withdraw it at any time: use the unsubscribe link in any email we send, turn off “Email me Synsa news” on your account page, or ask us. Withdrawing doesn’t make what we did before unlawful.
Your right to object
Where we rely on legitimate interests, you have the right to object at any time, for reasons that come from your own situation. Tell us, and we’ll stop unless we have strong, legitimate reasons that outweigh your interests, or we need the information for legal claims. For the voice guide, you can also simply hang up or not use it, and ask us to delete a conversation.
If we ever want to use your information for something new, for example to train an AI of our own, we’ll update this policy first and ask for your consent where the law requires it.
Your choices and rights
Everyone, wherever you live
You can ask us to:
- tell you what information we have about you, and give you a copy;
- correct it;
- delete it;
- stop using it, or stop sending you Synsa news.
If you have a Synsa account, you can see and change most of it, and delete it, yourself on your account page.
It’s free, and we won’t treat you any differently for asking. You can also type instead of speaking (say no to the microphone), hang up at any time, or not use the voice guide at all: the rest of the site works without it.
How to ask
Contact us. Voice conversations aren’t linked to accounts, so we need your help to find yours: tell us roughly when you talked to the voice guide (the date and time, and your time zone), whether you used a phone or a computer, and something you said. For Synsa news, tell us the email you signed up with. We may ask a question to make sure the information is yours before we share or delete it, and we use what you send only to handle your request.
We’ll answer within one month. If a request is complicated, we may take up to two more months, and we’ll tell you if so. If we say no, we’ll explain why, and you can ask us to think again. Someone you authorize can ask for you; we may ask them to show that you did.
Do you have to give us this information?
No. No law or contract requires it. The voice guide needs your voice or your typing, Synsa news needs your email, and an account needs one way to sign in. While the voice guide is switched on, the bot check and the rough-location lookup run when the home page opens, even if you never use the guide. If you’d rather not talk or sign up, simply don’t use those parts.
Decisions made by computer
We don’t make decisions about you by computer alone that have legal or similarly important effects on you. The only automatic decisions are the bot check and our abuse limits, which can stop the voice guide, or a Synsa news sign-up, from working for you, and a check that hides the voice guide from browsers that say they’re being run by automation software. See The bot check and your location.
In the United States
Some state privacy laws, such as California’s, apply only to larger businesses. We give everyone the rights above anyway. We don’t sell or share personal information for targeted advertising, and we don’t use sensitive personal information to learn about you or profile you.
In the EU, the EEA and the UK
You also have the right to limit how we use your information, to get it in a format a computer can read (“portability”), to object (see Our legal reasons) and to withdraw your consent.
You can complain to a data protection authority, in the country where you live or work or where you think the problem happened. EU and EEA authorities are listed by the European Data Protection Board. In the UK, it’s the Information Commissioner’s Office. You can also complain to us first: we’ll confirm we have your complaint within 30 days, look into it, and tell you what we found and did.
Children
Our website and the voice guide aren’t meant for children. Please don’t use the voice guide, sign up for Synsa news or make an account if you’re under 16. If we learn that we have information from someone under 16, we’ll delete it. Parents and guardians can contact us.
Keeping it safe
- Everything between your browser, our site and our voice server travels encrypted, through Cloudflare.
- Conversation copies are kept on a computer Synsa runs itself. Only Synsa can sign in to it, sitting at it or remotely over a private, encrypted connection.
- Accounts have no passwords to steal. Our account store keeps the sign-in cookie’s code only in a scrambled form, and passkeys only as public keys.
- No system is perfectly secure. If a breach puts your information at risk, we’ll tell you and the authorities as the law requires.
Changes to this policy
When this policy changes, we’ll update this page and the “Last updated” date at the top. For important changes, we’ll also put a notice on our home page. Earlier versions are listed here:
- Synsa news, our email newsletter, replaces the waitlist: a new section, Synsa news, says what a sign-up keeps and how to unsubscribe, and the bot check no longer runs for sign-ups.
- Synsa accounts and test plans: a new section, Your Synsa account, signing in with Google, the sign-in cookies, and how to contact us (our inbox is at Gmail).
- The “Install the Synsa App” bar is gone, and with it the note your browser kept when you closed it.
- First version.
Contact us
For questions about this policy, to see, correct or delete your information, to stop Synsa news, or to make a complaint: