v1.1Effective September 17, 2026
Privacy Policy
Neivan Technology Holdings, LLC ("Neivan", "we", "us") runs Synapse, a platform organizations use to build, run and supervise AI agents that work in their connected business systems, together with our website at https://neivan.ai (together, the "Service"). This Privacy Policy explains what personal information we collect, how we use and disclose it, how long we keep it, and the choices and rights you have.
In short: we collect what we need to run the Service; we do not sell personal information or share it for advertising; we use no analytics or advertising cookies; and we process the content an organization puts into Synapse only to provide the Service to that organization.
Read this together with our Terms of Service, Data Processing Agreement, Cookie Policy, Subprocessor List and Data Deletion page.
1. The two roles we play
- We decide (controller or "business") for: your Synapse sign-in account, billing and payments, visitors to our website, support and sales conversations, and keeping the Service secure. This Policy governs that information directly.
- We act for a customer (processor or "service provider") for everything an organization puts into or connects to its Synapse workspace — its people's records, documents, messages and data from connected apps, agent instructions and results ("Customer Content"). The organization (the "Customer") decides how that information is used, and our Data Processing Agreement governs it. If your information is in a Customer's workspace — for example, because your employer uses Synapse — please send privacy requests to that organization first. If you contact us, we will pass your request on and help them respond.
2. What we collect
2.1 Information you give us
- Account information: name, work email, organization, role, password (stored only as a secure hash by our sign-in provider), and profile settings.
- Billing information: billing contact, plan and purchase history. Card payments are handled by Stripe; we never receive or store full card numbers.
- Communications: messages you send to support or sales, and privacy or deletion requests.
2.2 Customer Content (processed for the Customer)
Depending on what a Customer turns on and connects, this can include:
- prompts, chats, documents, knowledge sources and standard operating procedures;
- data read from connected apps — for example email, calendar, files, CRM, accounting or social-media accounts, including YouTube (see Section 6) — and actions agents take in them;
- people records the Customer maintains, which can include compensation (salary or hourly rate) used to estimate the value of automating work;
- personal knowledge a person chooses to build for their own assistant, such as writing samples, and audio or video recordings and transcripts used to capture someone's expertise;
- observation data when a Customer enables it and the person consents: activity information from connected apps (such as when a message was sent, its sender and recipients, and its subject line, but not message bodies or file contents) and, from the Synapse Recorder, window titles, on-screen control names and optional screenshots. See the Observation & Screen-Recording Disclosure.
2.3 Information collected automatically
- Technical data: IP address, browser and device type, and language.
- Usage and log data: pages and features used, agent-run records, timestamps, and error reports.
- Metered usage: the volume of AI requests, tokens used, and the model and feature used, for billing and limits.
- Cookies and browser storage: only what the Service needs to work and stay secure. See the Cookie Policy.
2.4 Information from others
- Connected apps a Customer or user authorizes, within the permissions granted.
- Sign-in providers, if your organization signs in through one.
- Service providers such as our payment processor.
3. How we use personal information
As a controller, we use personal information to: provide and operate the Service; create and secure accounts; process payments and prevent fraud; provide support and send service messages (security notices, billing notices, changes to our terms); detect, investigate and prevent abuse; find and fix errors and improve the Service; communicate with prospects who contact us; and comply with the law and defend legal claims.
We process Customer Content only to provide, secure and support the Service for that Customer, as described in the Data Processing Agreement. In Settings → Privacy & observation, you can also ask us not to use your data for product improvement.
4. AI processing
- How AI features work. When you run an agent, chat, or use another AI feature, the prompt and the content needed for that request — which may include Customer Content — are sent to an AI model provider. Neivan-managed AI features use Anthropic and OpenAI. If a Customer connects its own key for another provider, requests using that key go to that provider under the Customer's account.
- No training on your content. We do not use Customer Content to train, fine-tune or improve any AI model. Under the API terms of the providers we use, content sent through their APIs is not used to train their models.
- Review before relying on it. AI output can be wrong. We do not make decisions with legal or similarly significant effects about you based solely on automated processing. When a Customer's agents process personal information, the Customer is responsible for appropriate human oversight.
5. How we disclose personal information
We do not sell personal information and do not share it for cross-context behavioral advertising, and we have not done so.
We disclose personal information only:
- within the Customer's organization, according to its roles and permissions;
- to our subprocessors, who process it for us under contract — see the Subprocessor List;
- to connected apps, when a Customer or user directs an agent to act in them;
- for legal reasons, when required by law or legal process, to enforce our agreements, or to protect people's rights and safety. Where the law allows, we tell a Customer before disclosing its Customer Content in response to a legal demand;
- in a business transfer, such as a merger or sale of assets, subject to this Policy; or
- with your direction or consent.
6. YouTube API Services and Google user data
Synapse uses YouTube API Services. This section explains what happens when you or your organization connects a YouTube account. Use of YouTube is governed by the YouTube Terms of Service, and Google's own handling of your information is described in the Google Privacy Policy. Section 6.5 applies to information from every Google API the Service uses, not only YouTube.
6.1 What we access
When someone connects YouTube, Google asks them to grant Synapse two permissions: to manage their YouTube account and to upload videos to it. With them, and only when a person — or an agent their organization has set up — asks it to, the Service uses the YouTube Data API to read the connected account's information (such as the channel, its videos and playlists), to upload videos, and to change the account's content (such as a video's title or description). We never see or collect your Google password or anything else you enter on Google's sign-in screens.
6.2 What we store
- The access and refresh tokens Google issues for the connection, with the permissions granted and when the token expires. They are encrypted, kept in our credential vault, and only ever sent to Google.
- The connection's status, such as whether it is connected or needs reconnecting, and when it was last renewed.
- What agents did with it: a record of each action an agent took (what it did, whether it succeeded, and any error), and the agent's results, working state, conversation and task history, which can include YouTube data the agent read, such as a video's title.
We do not keep a separate copy of your channel or video library.
6.3 How we use and share it
- We use YouTube data only to provide the YouTube features a person asked for, inside the organization's workspace, where it is shown according to the organization's roles and permissions.
- We send YouTube data to our AI model providers only as needed to complete the request (see Section 4), and to YouTube when an agent acts in the connected account.
- We do not sell YouTube data, use it for advertising, use it to train AI models, or disclose it except as described in Section 5.
6.4 Keeping it current, revoking access, and deleting it
- Refreshed or deleted every 30 days. We keep stored YouTube data only as long as needed for the purpose it was granted for, and we refresh or delete it at least every 30 days.
- Disconnect in Synapse. Choosing Disconnect on the YouTube connection asks Google to revoke our access and deletes the stored tokens.
- Revoke in Google. In addition to our own ways of deleting stored data, you can revoke Synapse's access to your data at any time from the Google security settings page at https://security.google.com/settings/security/permissions. When access is revoked, we delete the stored tokens and other stored YouTube data within 30 days.
- Ask us to delete it. Email [email protected] or follow our Data Deletion page, and we delete stored data related to you that we obtained through YouTube API Services as soon as possible and within 7 days.
6.5 Google API Services User Data Policy (Limited Use)
Neivan's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. This covers every Google API the Service uses — for example Gmail, Google Calendar, Google Drive, Google Sheets, Google Docs and YouTube. In particular, we:
- use Google user data only to provide or improve the user-facing features a person can see in Synapse;
- transfer it to others only as needed to provide or improve those features, for security, to comply with the law, or as part of a merger, acquisition or sale of assets with the user's prior consent;
- never use it to serve advertising, never sell it, and never use it to decide on credit or lending;
- never use it to develop, improve or train generalized AI or machine-learning models; and
- do not let any person read it unless the user has given affirmative agreement for specific data, it is needed for security purposes such as investigating abuse, it is required by law, or it has been aggregated and anonymized for internal operations.
6.6 Questions and complaints
Questions or complaints about how we handle YouTube or other Google user data go to [email protected], or by post to the address in Section 14.
7. Where we process information
Neivan is based in the United States, and our systems and subprocessors process information in the United States. The Service is currently offered to organizations in the United States. We do not yet offer EU or UK data residency, and we will update this Policy before offering the Service to customers in the European Economic Area, the United Kingdom or Switzerland.
8. How long we keep information
| Information | How long |
|---|
| Account information and Customer Content | While the account is active, except YouTube data (next row). A user who deletes their own account is removed immediately (see Data Deletion) |
| YouTube tokens and other stored YouTube data | Refreshed or deleted at least every 30 days; tokens deleted on Disconnect; deleted within 30 days after access is revoked in Google, and within 7 days of a deletion request (see Section 6.4) |
| Customer Content after an organization's account ends | Until the Customer asks us to delete it (we then delete it within 30 days), and in any case we may delete it any time after 90 days following the end of the account |
| Writing samples in a person's personal knowledge | Deleted after the retention period that person sets (365 days unless they change it) |
| Recorder screenshots | 90 days |
| Delivered desktop activity events | 180 days |
| Detailed usage metering | 13 months |
| Items in an organization's recycle bin | 30 days |
| Audit log entries | For the life of the organization's account |
| Billing and payment records | As long as tax and accounting laws require (generally up to 7 years) |
| Privacy and deletion requests | As long as needed to show we handled them |
9. Security
We protect information with encryption in transit and at rest, additional encryption of stored credentials, database-level separation of each organization's data, role-based permissions, and an audit log. No system is perfectly secure. Our Security Overview describes what is in place and what is still planned. If a breach affects your personal information, we will notify you and the authorities as the law requires.
10. Your privacy rights
Depending on where you live, you may have the right to:
- know and access the personal information we hold about you and get a portable copy;
- correct inaccurate information;
- delete your personal information;
- opt out of the sale or sharing of personal information, targeted advertising, and certain profiling (we do none of these);
- limit the use of sensitive personal information (we use it only as needed to provide the Service, such as sign-in credentials); and
- not be discriminated against for using these rights.
How to use them:
We verify requests before acting on them — usually by confirming control of the email address on the account — and respond within the time the law allows (within 45 days under most US state laws). You may use an authorized agent where the law permits. We do not charge for requests unless they are clearly unfounded or excessive.
Appeals. If we decline your request, you can appeal by emailing [email protected] with the subject "Privacy Appeal". If we deny your appeal, you may contact your state Attorney General.
California. In the past 12 months we collected these categories of personal information: identifiers; customer records; commercial information; internet or other electronic network activity; approximate location derived from IP address; professional or employment information; and audio or visual information (recordings or screenshots, where a Customer enabled those features). We use and disclose them for the business purposes in Sections 3 and 5. We do not sell or share personal information, including of consumers under 16, and we do not disclose personal information to third parties for their own direct marketing.
11. Children
The Service is for businesses and is not directed to children under 16. We do not knowingly collect personal information from children under 16. If you believe a child has given us personal information, contact [email protected] and we will delete it.
12. Do Not Track and Global Privacy Control
We do not track people across other websites, so we behave the same whether or not your browser sends a Do Not Track or Global Privacy Control signal. Where the law requires it, we treat a Global Privacy Control signal as a valid request to opt out of sale and sharing.
13. Changes to this Policy
We will post any change here with a new effective date. For a material change, we will also notify account owners by email or in the Service before it takes effect.
14. Contact