Last updated: March 24, 2026
Synaps ("we", "us", "our") is a sound frequency wellness application. We respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and share your information when you use the Synaps mobile application.
When you create a Synaps account, we collect:
We never store your password directly; authentication is handled securely through Supabase Auth with encrypted tokens.
During setup, you may optionally provide:
This data is stored locally on your device only and is used to personalize your experience. It is not transmitted to our servers.
When you use Synaps, we collect:
This data is synced to your account for cross-device access and to generate your weekly listening reports.
With your permission, we access your approximate location to retrieve local weather conditions from the Open-Meteo API. This enables weather-based sound adaptation. Your coordinates are sent directly to Open-Meteo and are not stored on our servers.
We may access your device's accelerometer to detect motion state (stationary, walking, running) for adaptive sound features. This data is processed entirely on-device and is never transmitted externally.
For crash reporting and stability improvements, we collect:
| Data | Purpose | Legal Basis (GDPR) |
|---|---|---|
| Email, name | Account creation, authentication, password recovery | Contract performance (Art. 6(1)(b)) |
| Listening sessions | Usage statistics, weekly reports, cross-device sync | Contract performance (Art. 6(1)(b)) |
| Mood ratings | Personal progress tracking | Consent (Art. 6(1)(a)) |
| Location | Weather-based sound adaptation | Consent (Art. 6(1)(a)) |
| Motion data | Activity-based sound adaptation | Legitimate interest (Art. 6(1)(f)) |
| Crash logs | App stability and bug fixes | Legitimate interest (Art. 6(1)(f)) |
| Subscription data | Access management, payment verification | Contract performance (Art. 6(1)(b)) |
We use the following third-party services:
Authentication, database, and file storage. Your account data and listening sessions are stored on Supabase's servers with row-level security.
Subscription and purchase management. RevenueCat processes your anonymous user ID and purchase receipts from Apple/Google to verify your subscription status.
Error and crash reporting. Sentry receives crash logs, device information, and your user ID to help us diagnose and fix issues. No personal content or listening data is sent to Sentry.
Weather data API. When you enable location-based sound adaptation, your coordinates are sent to Open-Meteo to retrieve weather conditions. Open-Meteo is an open-source, free API that does not require authentication and does not track users.
If you sign in with Apple or Google, your authentication token is processed through their respective services. We receive only your email and name (if provided).
We use Expo's over-the-air update service to deliver app improvements. This service checks your app version and runtime version but does not collect personal data.
Local storage: Preferences, onboarding data, favorites, and custom presets are stored on your device using encrypted local storage (AsyncStorage) and secure keychain/keystore (for authentication tokens).
Cloud storage: Account information and listening sessions are stored on Supabase servers with row-level security policies, ensuring you can only access your own data.
Encryption: All data in transit is encrypted using HTTPS/TLS. Authentication tokens are stored in your device's secure keychain (iOS) or keystore (Android).
We retain your data for as long as your account is active. Listening sessions older than 90 days are automatically pruned from local storage.
Account deletion: You can delete your account at any time from Profile → Delete Account. This will:
Account deletion is irreversible and typically completes within 30 days.
Depending on your jurisdiction, you may have the following rights:
You have the right to know what personal information we collect, request deletion, and opt-out of any sale of personal information. We do not sell personal data.
You may exercise your rights by contacting us. You also have the right to lodge a complaint with your local supervisory authority.
To exercise any of these rights, contact us at moguzbulbul@gmail.com.
Synaps is not intended for children under the age of 13 (or under 16 in the EU/EEA). We do not knowingly collect personal data from children. If we learn that we have collected data from a child without parental consent, we will promptly delete it. If you believe a child has provided us with personal data, please contact us immediately.
With your permission, Synaps may send local push notifications including daily listening reminders, sleep session reminders, focus break suggestions, and weekly listening reports. These notifications are generated entirely on your device and are not sent from external servers. You can manage or disable notifications in your device settings or within the app at Settings → Notifications.
Your data may be processed in countries other than your own. Our service providers (Supabase, RevenueCat, Sentry) may store data in the United States or other jurisdictions. Where applicable, these transfers are protected by Standard Contractual Clauses or other legally recognized transfer mechanisms.
We may update this Privacy Policy from time to time. We will notify you of significant changes by posting a notice in the app or by other appropriate means. Your continued use of Synaps after changes are posted constitutes acceptance of the updated policy.
If you have any questions about this Privacy Policy or our data practices:
Email: moguzbulbul@gmail.com
Developer: Muhammet Oğuz Bülbül