Privacy Policy
Effective 22 April 2026 · Last updated 22 April 2026
This Privacy Policy explains how BaseThesis ("BaseThesis", "we", "us", "our") collects, uses, stores, shares, and protects your information when you use Synth (the "Service"), available at https://getsynth.io and through the Synth messaging channels we operate (including Telegram and, where enabled, WhatsApp and web chat). Synth is an AI operations assistant that connects to your productivity tools — such as Google Workspace and Microsoft 365 — and acts on your behalf, within the limits you authorise.
We have written this policy to be direct and specific. If anything is unclear, email us at engg@basethesis.com.
Who we are and how to contact us
The Service is operated by BaseThesis, registered in India. For any privacy matter — including data access, correction, export, or deletion requests — contact us at:
- Email: engg@basethesis.com
- General support: engg@basethesis.com
- Website: https://getsynth.io
Information we collect
2.1 Account information you provide
- Your email address and display name.
- A password (stored as a salted bcrypt hash; we never store or transmit your plaintext password).
- Messaging-channel identifiers if you link Synth to Telegram or WhatsApp (for example, your Telegram user ID), so that we can route messages to you.
- Payment identifiers when you subscribe to a paid plan. Payments are processed by third-party payment processors (for example, Razorpay). We do not store full card or bank details on our servers.
2.2 Google user data you authorise Synth to access
When you sign in with Google and grant consent, Synth accesses the Google user data listed below solely to provide the features you are using in the Synth user interface. The scopes we request, and why, are:
| Google OAuth scope | Why Synth needs it |
|---|---|
openid, userinfo.email, userinfo.profile | To create and sign you into your Synth account, and to display your name and email in the app. |
calendar | To read your schedule so that Synth can answer questions about your calendar, and to create, move, or cancel events when you ask it to. |
spreadsheets | To read and update the specific Google Sheets you reference in a request (for example, updating a pipeline tracker, reading a portfolio spreadsheet). |
drive.file (or, where enabled, drive) | To open files you select, and to upload documents Synth generates on your behalf (for example, saving a draft report to a folder you name). The broader drive scope is used only where listing or searching across your Drive is required to fulfil a request you made. |
gmail.send (and, where enabled, gmail.modify) | To send replies and new emails on your explicit instruction, and — where you enable inbox features — to read and organise messages so Synth can summarise threads, draft replies, and surface action items for you. |
2.3 Information generated through use
- Your conversations with Synth — the messages you send and the responses Synth produces.
- Derived memory — summaries, preferences, and facts Synth extracts from your conversations to personalise future replies. You can view, correct, or delete items in your memory on request.
- Operational telemetry — timestamps, request counts, error traces, model usage, approximate cost per session, and similar data used to operate the Service, detect abuse, and improve reliability.
- IP address and device/browser information collected automatically for security and rate-limiting.
How we use Google user data — our Limited Use commitment
Synth's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, we commit that Google user data obtained through Google APIs, and any data derived from it, is used only to provide or improve user-facing features that are prominent in the Synth interface. We do not:
- use or transfer Google user data for serving advertising, including retargeting, personalised, or interest-based advertising;
- sell Google user data, or transfer it to data brokers or information resellers;
- use Google user data to train, fine-tune, or improve generalised or third-party AI or machine-learning models; and
- allow humans to read your Google user data, except (a) with your affirmative consent for specific content, (b) for security purposes such as investigating abuse, (c) to comply with applicable law, or (d) where the data is aggregated and anonymised and used for internal operations in line with applicable law.
3.1 Specific user-facing features that use Google data
Within the limits above, we use Google user data to:
- Answer your questions about your calendar, email, and documents.
- Draft, send, and reply to emails on your instruction.
- Create, move, and cancel calendar events on your instruction.
- Read, summarise, and edit specific Drive files and Sheets you reference.
- Detect and surface action items, scheduling conflicts, and follow-ups you asked Synth to track.
- Personalise future responses using a memory layer that you control.
3.2 Use of AI models
Synth uses large language models provided by third-party AI providers (for example, Anthropic) to process your requests and generate responses. Google user data is sent to these providers only to fulfil the specific request you made, under contractual terms that prohibit the provider from using that data to train their models. We do not use your Google user data to train our own models or any third party's models.
How we share, transfer, or disclose data
We do not sell your data. We do not transfer or disclose your information to third parties for any purpose other than the ones described below.
- Service providers (sub-processors) who operate on our behalf under confidentiality and data-protection obligations: cloud infrastructure (for example, AWS or GCP), AI model providers (for example, Anthropic), payment processors (for example, Razorpay), transactional email and messaging providers, and error-monitoring tools. A current list is available on request at engg@basethesis.com.
- Legal and safety — where we have a good-faith belief that disclosure is required to comply with law, legal process, or a lawful government request, or to protect the rights, property, or safety of our users, BaseThesis, or the public.
- Business transfer — if BaseThesis is involved in a merger, acquisition, or sale of assets, we will obtain your explicit prior consent before any transfer of your Google user data.
How we store and protect your data
- Encryption in transit. All connections to Synth and to third-party APIs use TLS 1.2 or higher.
- Encryption at rest. Production databases and file storage are encrypted at rest.
- Container isolation. Each Synth user's agent runs in an isolated Linux container with its own filesystem. One user's agent cannot read another user's data.
- OAuth tokens are stored on our host systems, never placed inside per-user agent containers, and are encrypted at rest. Tokens are scoped to the minimum permissions needed.
- Access controls. Only a small number of BaseThesis personnel have production access, subject to multi-factor authentication and audit logging. Human access to user data is limited to the narrow circumstances described in Section 3 (Limited Use).
- Secure development. We follow reasonable industry practices for secure software development, dependency monitoring, and incident response.
No system is perfectly secure. If we become aware of a security incident that materially affects your personal data, we will notify you and, where required, regulators without undue delay.
Data retention and deletion
We retain personal information only for as long as is reasonably necessary to provide the Service and to comply with legal, accounting, and reporting obligations.
- Account data — retained for the life of your account.
- Google OAuth tokens — retained while your Google integration is connected. When you disconnect, we revoke and delete the refresh token within 7 days.
- Conversation history and derived memory — retained for the life of your account. You can delete specific items, clear memory, or request full deletion at any time.
- Operational logs and telemetry — retained for up to 90 days, after which they are deleted or fully anonymised.
- Backups — encrypted backups are retained for up to 30 days and then purged.
Right to deletion. You can delete your account and all associated data at any time by emailing engg@basethesis.com or via the in-product account settings. We will complete deletion of live data within 30 days of your request, and of backups within the backup retention window above, except where we are required by law to retain specific records (for example, tax invoices).
Revoking Google access. You can revoke Synth's access to your Google account at any time from https://myaccount.google.com/permissions. Revocation is immediate on the Google side; our servers will stop receiving new data on the next API call and will delete cached tokens within 7 days.
Your rights
Depending on where you live, you have the following rights in relation to your personal data:
- Access — obtain confirmation of, and a copy of, the personal data we hold about you.
- Correction — have inaccurate data corrected.
- Deletion — have your data deleted, subject to legal exceptions.
- Portability — receive your data in a structured, machine-readable format.
- Objection and restriction — object to, or restrict, certain processing.
- Withdrawal of consent — where processing is based on consent, withdraw it at any time.
- Complaint — lodge a complaint with your local data protection authority.
Indian users have additional rights under the Digital Personal Data Protection Act, 2023, including the right to grievance redressal and nomination. EEA/UK users have rights under the GDPR/UK GDPR. California users have rights under the CCPA/CPRA; we do not sell personal information.
To exercise any of these rights, email engg@basethesis.com. We will respond within 30 days.
International data transfers
BaseThesis operates from India. Depending on the infrastructure region you are served from, your personal data may be processed in India, the European Economic Area, the United States, or other countries where our service providers operate. Where required by law, we implement appropriate safeguards (for example, Standard Contractual Clauses) for international transfers of personal data.
Children
Synth is not directed to children under 13 (or the minimum age in your jurisdiction). We do not knowingly collect personal data from children. If you believe a child has provided us data, contact engg@basethesis.com and we will delete it.
Cookies and similar technologies
The Synth website and web chat use strictly necessary cookies to keep you signed in and to secure sessions. We may also use limited analytics cookies to understand aggregate product usage. We do not use advertising cookies. You can control cookies through your browser settings.
Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes — particularly to how we handle Google user data — we will notify you by email and, where required, prompt you to consent to the updated policy before the new practices take effect. The "Last updated" date at the top reflects the most recent revision.
Contact
For any privacy question or request, contact engg@basethesis.com. For general support, engg@basethesis.com.