Privacy Policy
What data Synapse collects, why, who can see it and how long it is kept.
Version 1.1 · Effective from 12 August 2026
In short
- We collect what the game needs to work: your account, packs, game results, reports.
- There is no analytics, no tracking and no advertising in Synapse at all.
- Your email is not visible to other players. Your password is stored only as a hash and shown to nobody.
- Private messages are seen by the people in the conversation. But they are stored on the server unencrypted — we have no end-to-end encryption, and we do not hide that.
- We do not ask for your date of birth. We keep no permanent history of your IP addresses in the database, but temporary server logs may hold an address for about 14 days.
- You can delete your account. Your data goes; played matches stay without any link to you — otherwise other players' statistics would break.
- Data is technically processed by: Hetzner (the server and database in Germany), Cloudflare R2 (files and encrypted backups) and Resend (service email).
- This is a summary. The full text is below.
This summary does not replace the full text and is provided for convenience only.
1. Who processes the data
Synapse is a private game project at synapse-game.com. The service currently has no separate legal entity, so we give no registration details, no address and no data protection officer: inventing them would be worse than honestly saying there are none.
When the legal status of the service is settled, this section will be updated and you will see a new version.
2. The core principle
We collect only what Synapse needs to work. We do not collect data “just in case it is useful later”.
There is no analytics, no behavioural tracking, no advertising profiles and no sale of data in Synapse. This is a decision, not an omission.
3. Account data
- email address — for sign-in, password recovery and confirming account deletion;
- login — for sign-in and as your public profile address;
- nickname — the public name other players see;
- password hash — the password itself is not stored and cannot be recovered;
- email verification status and registration date;
- your role in the service, if granted;
- avatar, if you uploaded one.
4. Age
We do not request or store your full date of birth. At registration you confirm that you are at least 13; we keep the fact of that confirmation with its date and rule version — not a birth date.
5. Document acceptance
We record which documents and which versions you accepted, and when. The version is set by the server.
Records of accepting earlier versions are not rewritten when a new revision appears: the acceptance remains a fact.
6. Password and tokens
Passwords are stored only as hashes (bcrypt). Neither the administration nor the service owner can see or recover them.
Links for email verification, password recovery and account deletion are stored only as hashes. The code itself exists only in the email: even a full copy of the database yields no working link.
Such links are single-use and time-limited: email verification 24 hours, password recovery 1 hour, deletion confirmation 24 hours.
7. Sessions
After sign-in your browser stores a cookie with an unpredictable token; only its hash is kept in the database.
In the Security section you can see your active sign-ins — their dates, not the tokens. You can end sessions on other devices or on all of them.
Changing or resetting your password ends every previous sign-in.
8. Games and statistics
We store match results: the room, questions played, scores, rating change and placement.
This forms your public statistics: rating, games played, wins, answer accuracy.
9. Packs and media
We store the packs you create: titles, descriptions, tags, questions, answers and uploaded images, video and audio.
Files live in separate storage, not in the database. Only a material identifier is exposed; the file path is never revealed.
Image metadata, including location tags, is stripped on upload.
A published pack version is immutable: running matches and game history depend on it.
10. Friends and presence
We store your friendships and requests. Online status lives only in server memory and is not written to the database.
11. Private messages — how it actually is
Private messages are available only between friends. The people in the conversation can see them.
There is NO way in the administration interface or API to open and read someone else's correspondence: no such function exists, and a test enforces this.
However, messages are stored on the server unencrypted. Synapse has no end-to-end encryption.
That means: technically, the data in the database is not encrypted. We do not claim that correspondence is inaccessible to the server, that it is “fully private”, or that it is “protected like an end-to-end encrypted messenger” — that would be untrue.
If server-inaccessible correspondence matters to you, take this into account and do not send through Synapse anything that should not end up there.
You can delete a conversation on your side at any time. The other person's copy remains: we cannot delete someone else's data at one side's request.
12. Reporting a message
If someone sent you something unacceptable, you may voluntarily attach that message's text to a report to the administration.
The administration sees exactly what you attached. No hidden access to correspondence is created for handling reports.
13. Reports and moderation
We store your messages to the administration and the correspondence about them. Someone else's report cannot be read even with an exact link.
Internal administration notes never reach the user interface.
Reports in the “Privacy and my data” category are visible only to the service owner: they contain the requester's personal data, and a moderator does not need them for their work.
14. Access to private packs during moderation
An authorised member of the administration may view pack content, including private packs, where needed to handle a report, ensure safety or enforce the rules.
This is a separate permission and does not grant access to private messages.
15. Sanctions and audit log
We store the history of restrictions: type, reason, duration and who lifted them. You see the reason and duration; a moderator's internal note you do not.
Administration actions are written to an immutable log. The log survives account deletion: the link to the account is cleared, but the record of what happened remains — otherwise history could be rewritten after the fact.
16. Technical data and IP
Your connection address is used at request time for rate limiting and abuse prevention.
No permanent history of your addresses is kept in the main database: the application does not write them to PostgreSQL.
Requests do pass through a reverse proxy (Nginx), and its technical access and error logs may temporarily contain the connection address and request metadata — the page address, response code, browser type. This is needed to diagnose failures and to protect the server from abuse.
These logs are currently rotated daily and kept for about 14 days, after which they are deleted. This is technical storage separate from the database, and it is not a permanent history of your addresses.
Ordinary administrators are not shown addresses.
17. Cookies
We use three necessary cookies: one for account sign-in, one for a stable guest identity, and one that stores your own cookie choice. All three are inaccessible to page scripts.
There are no analytics or advertising cookies. Details are in the Cookie Policy.
18. Who sees your data
- other players — your nickname, login, avatar, rating, statistics, published packs and online status;
- people in your conversation — the messages you send them;
- the administration — reports, sanctions, the audit log, and pack content during review;
- the service owner — additionally your email address in the account management panel;
- nobody — your password, token hashes, or someone else's correspondence.
19. What other players do not see
- your email address;
- sign-in and session data;
- your reports to the administration;
- internal moderation notes and detailed sanction reasoning;
- the contents of your private packs;
- your private messages.
20. How long data is kept
- account and related data — while the account exists;
- unverified and unused account — 7 days, then deleted;
- verification and recovery links — until used or expired, then deleted;
- sessions — 8 hours or 30 days; ended on password change and recovery;
- private messages — until you delete them or delete your account;
- closed reports — 12 months after closure;
- expired temporary restrictions — 12 months;
- administration audit log — 24 months, then reviewed;
- match results — while the account exists; after deletion the link to you is severed.
21. Account deletion
You can delete your account in settings: it requires your current password and confirmation via a link sent by email.
Deleted: profile, email address, login, nickname, avatar, password, sessions, all confirmation links, acceptance records, friends, favourites, notifications, your messages and conversation membership, your pack ratings, your statistics and results, your reports and restrictions, your media files.
Your packs leave the catalogue, search, pack selection and new rooms, and the author link is removed.
22. What remains after deletion, and why
The played matches themselves and published pack versions remain — but with no link to you.
The reason is simple: OTHER players' rating, games played and wins are calculated from those same matches. Deleting them outright would silently corrupt other people's own statistics. So the match record stays and you are detached from it.
The administration audit log also remains — for the same reason it exists at all: so history cannot be rewritten. The link to your account in it is cleared.
A deleted account has no public profile or statistics and does not appear in search.
23. Backups
After deletion, data becomes inaccessible in normal service operation.
Database backups are encrypted before they leave the server and are kept away from it, in external object storage.
Backup copies may contain deleted data until the backup retention period expires. We do not promise that information disappears from every copy instantly: that would be untrue.
Off-site backups are currently kept for up to 60 days and are then deleted automatically. Until that period expires, deleted data may remain inside a backup; such copies are not used in normal service operation and are opened only to recover from a failure.
24. Who data is shared with
We do not sell data, do not share it for marketing purposes and do not use it for advertising.
That said, claiming “we share nothing with anyone” would be untrue: the service needs hosting, a database, file storage and an email delivery service, and these technically process data.
These are the technical infrastructure providers currently in use:
Hetzner (Hetzner Online GmbH) — the rented server in Germany that runs both the application itself and the PostgreSQL database. The database is not a separate external service: it is deployed on that same server.
Cloudflare (Cloudflare R2) — object storage for the files you upload, plus separate storage for encrypted database backups. The storage is closed to public access: files are served by the application itself after it checks permissions.
Resend — delivery of service email: email address verification, password recovery and account deletion confirmation.
Each of them is engaged as technical infrastructure the service cannot run without, and each processes only the data its part of the work requires: Resend — the address and the text of a message, Cloudflare — files and encrypted copies, Hetzner — the server all of this runs on.
Data may be disclosed where required by law applicable to the service.
25. Your rights
Synapse currently has no separate “download an archive of my data” button.
That does not mean you cannot obtain a copy of your data. If the law applicable to you grants rights of access, rectification, portability or erasure, you can contact us via “Contact the administration”, choosing the “Privacy and my data” category. Such reports are visible only to the service owner.
We do not disclose passwords, hashes or tokens in response to such requests: they cannot be disclosed even to the owner.
26. Security
Passwords are hashed, tokens are stored as hashes, cookies are inaccessible to scripts, production connections use HTTPS, and rate limiting and a content security policy are in place.
We do not claim the service cannot be breached: nobody can promise that.
27. Changes to this policy
This policy has a version and an effective date. When material changes are made, we publish a new revision and update its version and effective date.
Where the nature of a change or applicable requirements call for separate notice or acknowledgement, it will be provided in an appropriate manner.
28. Questions
Via “Contact the administration” → “Privacy and my data”. If you have lost access to your account, use the public contact form.
