Skip to main content

Synapse-AI Legal

<!-- Rendering-adapted copy of docs/legal/privacy-policy.md (rev 2, 2026-07-18). Tables are flattened to lists because the site renderer has no GFM support. If a data flow changes, update BOTH files and the Play Data Safety form (docs/legal/play-data-safety.md) together. -->

Privacy Policy

Effective date: 18 July 2026 Last updated: 23 July 2026

Synapse: Legal AI Assistant ("Synapse", "we", "us") is a professional legal-assistant application for advocates practising in India. This Privacy Policy explains what personal data we collect, how and where it is processed, who we share it with, and the rights available to you under India's Digital Personal Data Protection Act, 2023 (DPDPA).

This app is intended for use by advocates and legal professionals in India. It is not intended for individuals under 18.

1. Who we are and our role

Synapse: Legal AI Assistant is operated by:

  • Operator: Yousuf Ali Adnan Mohammed (individual developer, operating as "Synapse: Legal AI Assistant")
  • Address: 27-64, Gandhinagar IDPL Colony, Quthbullapur, Hyderabad 500054, Telangana, India
  • Contact email: support@synapse-ai.in
  • Grievance Officer: Yousuf Ali Adnan Mohammed, support@synapse-ai.in

Our role under the DPDPA. In respect of the personal data described in §2(a), §2(c) and §2(d) — your account, diagnostics and payment data — we act as the Data Fiduciary and determine the purpose and means of its processing. In respect of the content described in §2(b) — case material which may contain the personal data of your clients and of other individuals — you, the advocate, remain the Data Fiduciary, and we act solely as your Data Processor, processing that material only on your instructions and only to provide the service you have requested (see §8).

If you have questions or wish to exercise your rights, contact the Grievance Officer above. We aim to respond within the timelines required by the DPDPA.

2. The data we collect

We collect the following categories of personal data, in each case only to operate the service you have asked for:

a. Account & identity data

  • Email address
  • Name / display name
  • Phone number (mandatory at sign-up, verified by SMS one-time password)
  • Optional professional details you provide: bar-council enrolment, firm name

b. Content you create or upload (this is often the most sensitive data)

  • Audio recordings of consultations you record in the app
  • Transcripts generated from those recordings
  • Extracted case facts and the case files/matters you build
  • Documents and images you upload (e.g. FIRs, charge sheets, remand diaries, evidence images) and text extracted from them
  • Drafts, research notes, questions and chat messages you create using the Ask, Prep, Research and Drafting features

c. Diagnostics & technical data

  • Crash reports and error diagnostics
  • Device push-notification tokens (to deliver notifications)
  • Basic device and app-version information needed to operate and debug the app

d. Payment data

  • If you purchase a subscription, payment is processed by our payment providers (see §4). We do not store your full card details; we receive only transaction/subscription status.

We do not knowingly collect data from children, and we do not use your data for advertising or sell it to third parties.

3. How we use your data

  • To provide the core features you request: recording and transcribing consultations, extracting and organising case facts, research, drafting, and the Ask / Prep assistants.
  • To authenticate you and secure your account (including phone verification).
  • To send you service notifications.
  • To process subscriptions and enforce fair-use limits.
  • To diagnose crashes and improve reliability.
  • To comply with law and respond to lawful requests.

Our legal basis under the DPDPA is your consent (which you give when you create an account and use each feature) and, where applicable, the necessity of processing to provide a service you have requested.

4. AI processing and third-party processors (please read)

Synapse relies on specialist third-party service providers ("processors") to deliver its features. Some of these providers process data outside India, including in the United States and the European Union. We list them here in the interest of full transparency.

4.1 Where your data is stored

  • Supabase — our primary database, file storage and authentication. Hosted in India (South). Your account data, case files, transcripts, documents and audio are stored here.

4.2 Speech, vision and language AI

To provide AI features we send the relevant content (e.g. a transcript, a document, a set of case facts, or your question) to the following providers:

  • Anthropic (Claude) — fact extraction, drafting, research, Ask & Prep reasoning. Processing location: United States / global (no India region available).
  • OpenAI — limited secondary language/embedding processing. Processing location: United States.
  • Google (Gemini / Cloud Vision) — limited language processing and document OCR. Processing location: United States / global.
  • Speech-to-text (transcription) providers — transcribing your consultation recordings. Processing locations: United States and India.
  • A document-OCR provider — extracting text from uploaded documents. Processing location: India.
  • A text-embeddings provider — text embeddings for search/retrieval. Processing location: United States.

Important — AI is processed outside India. Except where a provider above is marked as located in India, the AI providers we use do not offer an India data region. When an AI feature runs, the relevant content is transmitted to and processed on their infrastructure outside India. All requests originate from our India-hosted servers, which act as the data-processing boundary, but the AI processing itself occurs abroad.

No model training on your content. None of the AI providers we use train or improve their models on your content. Where a provider's default settings would otherwise permit this, we have explicitly opted out: our reasoning and drafting provider does not train on inputs under its commercial terms; our transcription provider is configured with model-training turned off; and our text-embeddings provider is set to zero retention, meaning your content is deleted immediately after it is processed and is never retained or used to train any model.

4.3 Automated PII redaction — where it applies and where it does not

Applied for all users, always. Before content leaves our India servers for consultation and document fact extraction and for document translation, we apply automated redaction that replaces identifiers — Aadhaar numbers, phone numbers, PAN, bank-account numbers, IFSC, GSTIN, PIN codes, driving-licence and passport numbers, case numbers, email addresses and recognised party names — with placeholder tokens. The AI provider sees only the tokens; the real values are re-inserted only in the response shown to you.

Applied only if you enable Privacy Mode. The app offers an optional Privacy Mode (Settings). When it is ON, redaction becomes stricter (broader name matching), and the case fact sheet used for document drafting is also redacted before it is sent. When Privacy Mode is OFF (the default), drafting sends the case fact sheet without redaction. The drafting instructions you type are sent as written in either mode.

Not applied. The Ask assistant, the Prep / strategy chat, the Research agent, and draft-assist features (Improve, Insights, Evaluation, inline suggestions) send your case facts and your questions to the AI provider without this redaction, regardless of Privacy Mode, because they need the full context to work. The app also shows you an in-product notice to this effect. Please do not enter details into these features that you are not permitted to share with a US-based AI provider.

Limits. Redaction is automated and pattern-based. It covers the identifier types listed above, but it cannot guarantee that every identifying detail (for example a date, an address, or an unusual name) is caught.

4.4 Other processors

  • An SMS delivery provider — sending the SMS one-time password for phone verification. Location: United States (delivers SMS to your carrier).
  • A crash-reporting service — crash and error diagnostics. Location: European Union (Germany).
  • Apple (APNs, App Store) — iOS push notifications; in-app purchases. Location: global.
  • Google (FCM) — Android push notifications. Location: global.
  • Razorpay — payment processing. Location: India.
  • IndianKanoon, eCourts/CNR — public case-law and case-status lookups (we send your search query or a case number). Location: India.

We share data with these processors only to perform the functions above. They are contractually bound to process it on our instructions. We do not sell your data or share it for advertising.

We may also disclose data where required by law, court order, or to protect rights and safety.

5. Data retention

  • Your account data and case content are retained for as long as your account is active, and deleted when you delete your account or the specific item.
  • AI provider retention & training: our reasoning/drafting provider (Anthropic) may retain inputs for up to 30 days for abuse monitoring and does not use them to train its models. Our transcription provider has model-training opted out. Our text-embeddings provider is set to zero retention — your content is deleted immediately after it is processed. No AI provider we use trains its models on your content.
  • Crash diagnostics are retained per our diagnostics provider's standard period.
  • SMS verification codes are short-lived and expire quickly.

You can delete your account and all associated data at any time from within the app (Settings → account deletion) or by contacting the Grievance Officer. Deletion purges your data from our database and storage; we also instruct our processors to delete associated data where they retain any.

6. Security

We implement and maintain reasonable security practices and procedures consistent with applicable law — including the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules"), together with the security obligations of the Digital Personal Data Protection Act, 2023 — through appropriate technical and organisational measures designed to protect personal data against unauthorised access, disclosure, alteration and loss. These measures include:

  • All network communication uses encryption in transit (HTTPS/TLS).
  • Sensitive data on your device — the local database and audio recordings — is encrypted at rest using AES-256-GCM, with the key held in the device's secure hardware keystore (iOS Keychain / Android Keystore).
  • Data stored in Supabase is encrypted at rest by the provider.
  • Optional biometric (Face ID / fingerprint) app lock is available; we never receive your biometric data, only a yes/no unlock signal from your device.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

7. Your rights under the DPDPA

Subject to the Act, you have the right to:

  • Access a summary of the personal data we process about you.
  • Correct, complete or update your data.
  • Erase your data (subject to legal-retention obligations).
  • Withdraw consent at any time (this may limit features).
  • Nominate another individual to exercise your rights in the event of death or incapacity.
  • Grievance redressal — raise a complaint with our Grievance Officer, and escalate to the Data Protection Board of India if unresolved.

To exercise any right, contact support@synapse-ai.in.

8. Data of your clients

As an advocate, the case data you record may include personal data of your clients and other individuals. In respect of that data, you are the Data Fiduciary: you are responsible for having a lawful basis to process it and for honouring your professional and legal obligations to the individuals concerned. We act as your Data Processor and process that data only on your instructions, to provide the service (see §1, "Our role under the DPDPA").

9. International transfers

As described in §4, certain processing occurs outside India (United States, EU). By using AI, notification, and diagnostics features, you consent to your data being transferred to and processed in those locations by the processors listed. The Government of India may restrict transfers to certain countries; we will comply with any such notified restrictions.

10. Changes to this policy

We may update this policy as the app evolves or the law changes. Material changes will be notified in-app or by email. The "Last updated" date at the top reflects the current version.

11. Contact

Synapse: Legal AI Assistant Operator & Grievance Officer: Yousuf Ali Adnan Mohammed Email: support@synapse-ai.in Address: 27-64, Gandhinagar IDPL Colony, Quthbullapur, Hyderabad 500054, Telangana, India