SynapseRx Psych Privacy Policy

Effective and last updated: August 8, 2026

This policy explains how SynapseRx Psych handles information when you use the website, beta preview, account and subscription features, browser-based clinical workflow tools, Discussion Board, mobile app, or support channels (collectively, the “Service”).

Do not enter protected health information or direct patient identifiers. SynapseRx Psych is not an electronic health record, is not intended to receive or store PHI, and should be used only with de-identified or sample information. Unless separately agreed in writing, SynapseRx Psych does not offer a business associate agreement or represent that browser Saved Work is an approved clinical record system.

Information we handle

Account and access informationEmail address, user/account identifiers, authentication status, entitlement or plan, named-account policy acknowledgements, and related account metadata when an account, subscription, or gated feature is used.
Billing informationStripe or an app-store provider processes payment details. SynapseRx may receive customer, subscription, transaction, plan, renewal, payment-status, and limited billing metadata needed to provide or manage access. SynapseRx does not intentionally store full payment-card numbers in the app.
Beta access informationThe invite-only preview processes the tester email and credentials submitted for access and places a secure, HTTP-only beta-session cookie in the browser. Access records may include an invite identifier and expiration.
Usage and technical informationPage and feature routes, approximate location, browser/device information, session statistics, pseudonymous analytics identifiers, request information, diagnostics, and security logs may be processed by analytics, hosting, authentication, or security providers.
Account security signalsWhen account features are used, SynapseRx and its authentication providers may process sign-in, sign-out, session, device, IP-derived location, user-agent, failed-access, verification, MFA, password-reset, session-revocation, and suspicious-activity signals to protect accounts, enforce named-user access, and investigate possible shared-login or credential-compromise risk.
Discussion Board contentIf the Discussion Board is enabled, posts, replies, reports, moderation status, basic account identifiers, and timestamps may be stored server-side so the forum can work across users and devices. Do not post PHI, patient identifiers, copied chart text, screenshots, documents, or patient-specific clinical details.
Support and feedbackIf you email support or send feedback, the message and the contact information supplied by you are processed to answer the request and improve the Service. Do not include PHI or patient identifiers.
User-created browser dataCare plans, HPI/workspace data, generated notes, screening results, encounter facts, favorites, saved medications, preferences, lists, exports, and similar clinical workspace content are designed to remain in that browser unless you choose to copy, print, download, export, restore, or otherwise transmit them.

How information is used

Local Saved Work and clinical workflow data

Saved Work, care plans, favorites, saved medications, HPI/workspace data, generated notes, screening results, exports, and many preferences are stored in browser storage on the device and browser profile being used. They are not automatically synchronized to a SynapseRx account, are not stored in the Discussion Board database, and are not backed up by SynapseRx. Local information can disappear when site data or browser history is cleared, private browsing ends, storage is evicted, or the user changes browsers, profiles, or devices.

Encrypted Saved Work backup files are created only when the user requests an export. The user controls the file and passphrase. SynapseRx cannot recover a forgotten passphrase. Copy, print, download, email, or operating-system share actions are user-directed and may send information to another app, device, printer, or service selected by the user.

Analytics and cookies

The web app uses Google Analytics to measure visits and feature routes. The current implementation may send page/route metadata, feature and surface labels, access-tier labels, browser/device information, approximate geography, session statistics, and pseudonymous client/session identifiers. Google Analytics commonly uses first-party cookies such as _ga and _ga_*.

Custom SynapseRx analytics events are designed not to send encounter free text, patient note contents, initials, Saved Work, screening answers, or other clinical-input contents. Do not place identifying information in routes, feedback, or app fields. Browser settings, cookie controls, content blockers, and the Google Analytics opt-out browser add-on may limit analytics.

Service providers and disclosures

SynapseRx may use service providers to operate the Service, including Netlify for hosting and server functions, Clerk for authentication and account management, Supabase or similar database services for Discussion Board data only, Stripe and app-store providers for payments and subscriptions, Google Analytics for usage measurement, and email or device providers selected by a user for support, exports, or sharing. These providers process information under their own terms and privacy notices and may process it in the United States or other countries.

Information may also be disclosed when reasonably necessary to comply with law or legal process; protect rights, safety, and security; investigate fraud or abuse; complete a merger, financing, acquisition, reorganization, or asset transfer; or with the user’s direction or consent. SynapseRx does not sell patient information and does not intentionally collect patient-identifiable information.

Retention and security

Browser-local data remains until the user deletes it or the browser removes it. Account, subscription, beta-access, Discussion Board, analytics, support, and technical records are retained as reasonably needed for the purposes described above, contractual requirements, security, moderation, dispute resolution, and legal obligations; provider-controlled retention may also apply. No security method is perfect, and SynapseRx cannot guarantee absolute security.

Your choices and privacy requests

Children

The Service is intended for healthcare professionals, adult students, educators, and supervised trainees and is not directed to children under 13. Contact SynapseRx if you believe a child provided personal information.

Policy changes

This policy may be updated as features, providers, or legal requirements change. The effective date above identifies the current version. Material changes may also be communicated in the app or through account contact information when appropriate.

Contact

For privacy questions or requests, contact support@synapserx.app. Do not include PHI or patient-identifying information.