Synaply

Privacy Policy

How Stanislav Tolmachov handles personal data in the Synaply alpha. Written to describe what the service actually does, not what a template says it might.

Edition: 2026-08-09 · In effect from: August 9, 2026

Draft — not ready to publishSome details of the operator are still placeholders. Fill them in before this page goes live.

1. Who is responsible

Stanislav Tolmachov, a private individual based in Norway, is the data controller for personal data processed through synaply.me. The alpha is operated personally, without a registered company; if a company takes over later, an updated edition of this policy will say so. Write to support@tolmachov.dev for anything in this document, including requests to exercise your rights.

No school, municipality or employer decides what Synaply collects or why. Everyone in the alpha — teachers included — takes part personally and voluntarily, and this policy is addressed to each of them directly.

2. What we collect

Account
Name, email address, interface language and time zone. The time zone is used to decide when your day starts, so daily limits and streaks match your evening, not UTC.
Learning data
Words you save, your own translations and notes, review history and scheduling state, sentences you write in practice and the AI feedback on them, and daily activity counters.
Technical data
Sessions (browser user agent, IP address, when they started and expire) and server logs. In logs the IP address is replaced by a keyed one-way pseudonym: we can tell that requests came from the same source, but the address itself is not stored there.
Usage events
Records of how the app is used: which screens are opened, when a lesson or a practice round starts and ends, whether an answer was submitted, and measurements of page loading speed and responsiveness. Each record holds an event name from a fixed list, the time it happened, a browser-tab session identifier, the device cookie and — when you are signed in — your account and language-pair identifiers. They never contain free text: an event carries only a small set of predefined keys with short predefined values, so the words you type, your translations and your answers are never part of them.
Class context
Which class you belong to, which assignments you were given, your progress on them and any feedback a teacher writes about your work.
Billing
Nothing. The alpha is free, no payment provider is connected, and we hold no card details, no invoices and no payment history.

We do not use advertising trackers, we do not profile you for marketing, and we do not sell data to anyone.

3. Why we process it, and on what legal basis

To run the service — contract, GDPR Art. 6(1)(b)
Keeping your account, storing your vocabulary, scheduling reviews, generating and checking exercises, and showing your teacher the progress on work they assigned.
To keep it safe — legitimate interest, Art. 6(1)(f)
Sessions, rate limits, lockout after repeated failed sign-ins and server logs. The interest is keeping accounts from being taken over and the service from being abused; we weigh it against your privacy by pseudonymising addresses in logs.
To keep it working — legitimate interest, Art. 6(1)(f)
Usage events and speed measurements, so we can see where the app is slow or where people get stuck and fix it. The interest is a service that works; we weigh it against your privacy by recording no free text at all, keeping the events for a limited time and never using them to decide anything about you individually.
To meet legal duties — Art. 6(1)(c)
Responding to obligations the law places on us, if and when they arise.

Your data is used exclusively to provide the service and for nothing else: no marketing, no profiling, no training of AI models, no sale or sharing beyond the processors listed below. Usage events are part of running the service, not an exception to this: they are counted in aggregate to find broken and slow places in the app, they never build a profile about you, and they never change what you are shown. We do not rely on consent as a legal basis, so withdrawing consent is not the way to stop the processing — closing your account is. Accepting these documents is a record that you were informed, not a consent that carries the processing.

4. Artificial intelligence

Word explanations, generated sentences, feedback on your translations and grammar reports are produced by a large language model operated by Anthropic PBC. What we send is the material the feature needs — the word or sentence in question and the language pair — and we do not send your name, email address or any other identifier with it. Under our agreement with Anthropic, this data is not used to train their models. Avoid putting personal details into the sentences you practise on; they are processed as text.

Model output is generated text. It can be wrong, and it is not language teaching by a qualified human. No decision with a legal or similarly significant effect on you is made automatically.

5. Who else sees the data

We use these processors to run the service: Hetzner Online GmbH (DE / FI), Anthropic PBC (US), {{MAIL_PROVIDER}} ({{MAIL_PROVIDER_REGION}}). They act on our instructions and may not use the data for their own purposes.

Hosting and storage are inside the EEA. Sending text to the AI provider means a transfer to the United States; it relies on the European Commission's standard contractual clauses, reinforced by the fact that what is transferred is learning text without identifiers. Ask us at the address above for a copy of the safeguards.

If you are in a class, your teacher sees your name, your progress on assignments and the error analyses produced for your work. They do not see your personal vocabulary or what you study outside the class material.

6. How long we keep it

The alpha comes first: as the Terms of Service explain, all alpha data — including everything listed below — may be deleted or reset at any time while the test runs, and when the alpha ends. Export your data from settings if you want to keep it. Within those limits, the ordinary retention periods are:

Account and learning data
For as long as the account exists, and then as described under your rights below.
Sessions
Until they expire or you sign out; at most 30 days from sign-in.
Read notifications
90 days.
Pending invitations
30 days, after which they expire and are closed.
Background job records
7 days after the job is published.
Usage events
13 months from the event, after which they are deleted in whole monthly batches. They are included in your data export, and they are erased with your account — including events recorded on your device before you created it.
Server logs
No longer than the alpha itself; they are cleared together with alpha data resets.

When you leave a class, you disappear from that class's reports entirely — the teacher no longer sees your name, your address or your numbers. Your own progress stays with you.

7. Your rights

You can exercise the first two yourself, in your account settings, without asking us and without waiting.

Access and portability
Download everything we hold about you as a single machine-readable file. It contains your data only — not your classmates' addresses or other students' answers.
Erasure
Request deletion of your account and everything in it. The request takes effect after 30 days and can be cancelled during that window; you get an email confirming it, because a request may have been filed from a session you left open. Class material you authored as a teacher may survive, stripped of your name and address.
Rectification
Correct your name, email address, language and time zone in settings at any time.
Restriction and objection
Write to support@tolmachov.dev. We answer within one month, as GDPR requires, and tell you if we need longer and why.

You can also complain to a data protection authority — in Norway that is Datatilsynet (https://www.datatilsynet.no) — or to the authority where you live. You do not have to contact us first, though it is usually faster.

8. Adults only

The alpha is open to adults only: creating an account requires confirming you are at least 18, and invitations may not be passed to minors. We do not knowingly process children's data in the alpha.

If you believe an account belongs to a person under 18, write to support@tolmachov.dev: we will look into it, close the account and delete its data.

9. Cookies

Synaply sets no advertising or analytics cookies, so there is no cookie banner to click away: under the Norwegian ekomloven, storage that is strictly necessary for a service you asked for needs no consent, and every cookie below is exactly that:

access_token, refresh_token
Keep you signed in. They are httpOnly, so page scripts cannot read them, and they never leave the server-to-server path to our API.
synaply_device_id
A random identifier used to apply rate limits per device, protecting the service from abuse, and to group usage events from the same browser before you sign in. It carries no name, address or other detail about you, and it is used for nothing beyond those two purposes.
synaply_tz
Your time zone, so your day starts at your midnight.
NEXT_LOCALE
Your interface language.
school_intent, synaply_verify_banner
Short-lived markers so the sign-up flow and the email reminder behave sensibly.

10. Security

Traffic runs over TLS. Passwords are stored as bcrypt hashes and never in readable form. Sessions can be revoked from your settings, and changing your password signs out every device. Access to production data is limited to the operator.

If a breach puts your rights at risk we will notify the supervisory authority within 72 hours and tell you directly when the law requires it.

11. Changes

When this policy changes we publish a new edition with a new effective date and ask you to read it the next time you sign in. Earlier editions you accepted stay on record — that is part of your data, and it is included in your export.