01 / Public Website
A small public Website.
Synodic does not intentionally add advertising cookies, behavioural advertising, or advertising analytics to its public pages. Netlify may process ordinary request, device, network, and security information needed to deliver, protect, and operate the Website. External links open services operated by others under their own privacy practices.
02 / Account and authentication
Information needed to run an Account.
Supabase processes the email address used for sign-in, authentication and session information, and security records needed to establish and protect an Account. Synodic stores the matching Synodic profile and the minimum Account state needed to provide Account features. If an authentication security feature is used, related factor, challenge, and assurance metadata may also be processed.
Passwords, access tokens, refresh tokens, one-time authentication codes, and authentication-factor secrets are not public profile information. Do not send those values to Synodic support.
03 / Membership and billing
Stripe handles payment collection.
Synodic uses Stripe-hosted Checkout, invoices, and the Stripe Customer Portal for subscription payment processing. Stripe collects and processes payment-method information under its own privacy practices. Synodic does not place raw card numbers or card verification values into Synodic Website forms or store them in the Synodic database.
Synodic processes the identifiers and status metadata needed to connect an Account to its Stripe customer, subscription, Checkout, invoice, payment, charge, or refund records. This can include membership tier, currency, amount, billing country, billing period, lifecycle status, and verified provider-event state. These records are used to provide access, prevent duplicate processing, reconcile billing, handle refunds and cancellations, answer support requests, and meet applicable record-keeping obligations.
04 / Entitlements and Account linking
Access is server-authoritative.
Synodic processes membership and product-entitlement status, tier, capabilities, effective periods, and related identifiers so participating products can determine eligible access. Signed entitlement data may be issued to an eligible product installation and contains access fields and verification material, not reading content.
When an authenticated Account creates an Active Reader link code, Synodic processes short-lived challenge state. Active Reader then sends the single-use code and a random installation identifier to the entitlement service. Synodic stores one-way hashes and access-state records rather than the plaintext code or reusable installation credential. The Active Reader privacy policy explains that product flow and its local data in detail.
05 / Support and security
Records needed to help and protect the service.
If you contact Synodic, the information you choose to provide and the resulting support correspondence may be processed to answer the request. Synodic may also retain bounded audit, rate-limit, webhook, fraud-prevention, and security-event records needed to investigate errors, enforce access boundaries, and protect Accounts and services.
Current implementations do not define one universal deletion period for every Account, commerce, linking, support, or security record. Records may need to remain while an Account, membership, entitlement, dispute, security event, or legal obligation remains relevant.
06 / Service providers
Who processes information.
Supabase
Hosts Synodic Account authentication, database records, and server functions. Read Supabase's privacy policy.
Stripe
Processes Checkout, billing, invoices, payment methods, and the Customer Portal. Read Stripe's privacy policy.
Netlify
Hosts and protects the Synodic Website and Account interface. Read Netlify's privacy statement.
07 / Choices and contact
Control and questions.
- Sign out to remove the current browser's active Account session state.
- Use the Stripe Customer Portal for supported billing controls.
- Disconnect an Active Reader installation through the product's supported flow.
- Contact support about Account, membership, entitlement, linking, or support records.
Email legal@synodichub.com for privacy questions, security@synodichub.com for security reports, or support@synodichub.com for Account support. Synodic may need to authenticate the relevant Account before disclosing or changing protected records.
Policy updates will be published at this URL with a revised effective date.