This Disclosure explains how the Synapse platform ("Synapse") provided by Neivan Technology Holdings, LLC ("Neivan", "we", "us") observes work activity, exactly what is and is not collected, and how that activity is used. It is written for two audiences: the Customer (the organization that licenses Synapse and decides whether to turn observation on) and the Authorized Users (the Customer's admins and employees) who may be observed.
Read together with the Privacy Policy, the Data Processing Agreement (DPA), and the Employee Monitoring Notice (template) that the Customer is expected to deliver to its own staff.
Observation in Synapse is operated by the Customer, using tooling provided by Neivan.
Neivan does not operate a workforce-surveillance service. Synapse exists to discover repetitive work that can be automated — not to score, rank, or covertly watch individuals.
Synapse supports two distinct, separately controlled kinds of observation. A Customer may enable either, both, or neither, and consent is captured per employee, per source.
This reads activity information from tools the Customer has connected (for example, a mailbox, a calendar, or a document workspace). It records facts such as "a file was edited at a time" or "a message was sent to these recipients at a time" — the shape and timing of activity.
For email, this includes the sender, recipients, time and subject line of a message. It does not read message bodies, attachments, the contents of files, or the text of documents.
The mailbox connections Synapse uses for other features (such as letting an agent read email) technically permit reading message bodies. Observation deliberately requests only the fields listed above; that limit is enforced by Synapse, not by the email provider.
Cloud activity observation is opt-in and consent-gated per employee per connected source.
The Synapse Recorder is a native agent the Customer installs on a specific employee's machine. It is used to understand repetitive work that happens in desktop or legacy applications that have no usable API. It is consent-gated: the employee must grant consent, and that consent is mirrored by an in-app gate (referred to internally as can_capture / canObserve). If consent is not granted, the Recorder does not capture.
| Captured | Description |
|---|---|
| Active window / application title | The title of the app or window currently in focus (e.g. the name of the application and document tab). |
| Accessibility (a11y) control metadata | Metadata about the on-screen control a user interacted with (e.g. that a particular button or field was used), drawn from the operating system's accessibility layer. |
| Interaction events | That a control was invoked (a button or menu item pressed), that a tab or list row was selected, that a menu was opened, or that a window opened or closed — reported by the operating system's accessibility layer at the moment it happens. The Recorder records the name and type of the control (e.g. button "Save As"), not any content entered into it. |
| Screen frames — only at the optional "frames" fidelity | Screenshots / screen frames, captured only when the higher "frames" fidelity is explicitly enabled. Downscaled before transmission; not content-redacted — see "Redaction of screen frames" below. |
On-device scrubbing of text (on by default). Before any event leaves the machine, the Recorder masks patterns that look like personal or secret data — email addresses, long digit sequences (card / account / identification numbers), and credential-like strings (for example values following "password" or "api_key") — in the window title, the object label and the control name. This happens locally: the unmasked text is never transmitted. Pattern-based masking is a reasonable-effort measure, not a guarantee that every sensitive string is caught.
Redaction of screen frames — not implemented. ⚠️ On-device redaction of screen frames (optical character recognition plus blurring of text regions) is not implemented. A captured frame is downscaled to a small thumbnail before transmission, which materially reduces legibility, but it is not content-redacted and no configuration makes it so. The text-scrubbing described above applies to window titles, object labels and control names — not to pixels. Frame capture is governed by its own setting and is not enabled or disabled by the text-scrubbing control. Customers should treat a frame as an unredacted screenshot and should not enable "frames" fidelity in areas where sensitive data may appear on screen.
Observed and captured data is collected for one purpose: to discover repetitive, automatable work so that it can be turned into agents and workflows.
It is not used to:
Neivan will not repurpose observed data beyond what is needed to provide and improve the automation-discovery function described here and in the DPA.
The Customer remains responsible for ensuring that, in its jurisdiction and workforce context, consent is a valid and freely given basis — or for relying on another lawful basis where consent is not appropriate (see Section 8).
Synapse is designed so that an observed employee can see what is being captured about them, including the kind of observation enabled for them and the data it produces. Transparency is a core design property of the Recorder, not an add-on. The Customer should not configure Synapse to defeat this transparency.
Because the Customer controls the monitoring, the Customer must:
Neivan provides the controls to meet these obligations but cannot determine, for the Customer, what its local law requires.
To identify automatable steps, observed and captured data — including, at "frames" fidelity, screen frames — may be analyzed by a third-party large language model (LLM) via API — for Neivan-managed AI, Anthropic or OpenAI, as listed on the Subprocessor List. If the Customer uses its own AI provider key, that provider is used instead.
This analysis is performed to detect repetitive, automatable patterns. Observed data is not used to train the providers' models. The Customer's selection of provider and the applicable data-handling terms are governed by the DPA.