// legal

Privacy policy

What this website collects, which company sees it, and how to get rid of it. This describes the site we actually built, tool by tool.

Last updated
Applies to
synapsereality.io
Controller
Synapse Research Ltd

01 Who we are

Synapse Research Ltd runs this website and decides what happens to the data described below. Under the GDPR that makes us the controller.

We have not appointed a Data Protection Officer. We have no representative in the EU or in the UK either. Send every privacy request to the address above.

02 The short version

03 What we collect

Forms, audits and unsubscribes

Our server writes one row to a table called visitor_event when you send a form, run the audit tool or unsubscribe. Reading a page does not write a row.

The row records the path, the time, the site you came from and your browser's user agent string. It also keeps your browser language, device type and any campaign tags in the link. Cloudflare adds the country, region, city and network of the connection. An ad blocker does not stop it, which is why we rely on it instead of on a tag.

It never stores your IP address. To tell one visit from the next, it uses a code made from your connection and browser. That code changes every day and cannot be turned back into an address. If you accept analytics, it sets a cookie called sy_vid instead. It holds a random ID for 13 months, so your later actions join up with earlier ones. Declining, or withdrawing consent later, deletes it.

Anything you type into a form

The contact form, the lead forms and the instant audit tool post what you typed to our own API on this domain. That is your name, your email address, your message, and the URL you asked us to look at if you used the audit tool. We use it to answer you and to run the work you asked about. Your email address reaches two places, our database and Resend, which delivers the mail.

The forms also carry a hidden field that only a bot fills in, and we limit how often one address can send. Both exist to stop spam, and neither is used to profile you.

Email we send you

Automated mail comes from hello@synapsereality.io. Resend sends it from its EU region, in Ireland. Replies reach Ben.

None of this is a cookie. The pixel and the links live in the email, so the cookie banner does not change them. Blocking remote images in your mail app stops the open record.

Analytics, if you accept them

The three third-party tools below measure which pages lead to an enquiry. In the EU, the EEA, the UK and Switzerland they are off until you say yes. Refusing them costs you nothing on this site.

04 Who processes it

This is the whole chain. If a company is not in this table, it does not touch data from this website.

Processors used by synapsereality.io
WhoWhat it does hereWhat it seesBrowser storageRuns in the EU, EEA, UK and Switzerland
CloudflareCDN, DNS, firewall and the tunnel the site is served through. Every request passes it.IP address, requested URL, user agent, TLS and request metadata.May set __cf_bm and cf_clearance for bot management and challenges. Strictly necessary.Yes. It is the network the site runs on.
Cloudflare ZarazLoads and runs the Google Analytics tag from our own domain at Cloudflare's edge instead of from googletagmanager.com.The same page data GA4 would see, before passing it to Google.The GA4 client identifier, written through Zaraz.Only after you accept.
Google Analytics 4Traffic and audience measurement.Page URL, referrer, device and browser, coarse location, a client identifier.Yes. Non-essential, so it waits for consent.Only after you accept.
Microsoft ClaritySession replay and heatmaps, so we can see where a page confuses people.Pointer movement, scrolling, clicks and page structure. Clarity masks text input by default.Yes. Non-essential, so it waits for consent.Only after you accept.
PostHogProduct analytics, hosted in PostHog's EU cloud. Events go to /ingest/ on this domain first, and our server forwards them.Pages viewed, funnel events such as starting a form, and a device identifier once you consent.None until you accept. If you refuse, PostHog counts you with a rotating hash and stores nothing in your browser.Only after you accept.
Cloudflare Web AnalyticsCookieless page counts and Core Web Vitals.Page URL, referrer, coarse device data, loading timings.None. It sets no cookie and builds no cross-site identifier.Yes. It sets no cookie and stores nothing in your browser.
ResendSends our automated mail from hello@synapsereality.io, from its EU region in Ireland. Reports delivery, opens and link clicks.Your email address, your name, the content of that message, and when you open it or click a link in it.None. Open and click tracking lives in the email itself and sets no cookie.Yes, for mail we send you. Nothing loads in your browser.
Synapse, on our own serverThe visitor_event log, the form database, the sy_vid cookie, and the API behind them.Everything in section 03.None.Yes.

Each of these companies is used under its own data processing terms, which allow it to act on our instructions and forbid it from using what it sees for its own purposes.

05 What EU, EEA, UK and Swiss visitors get

If Cloudflare reports your connection as coming from the EU, the EEA, the UK or Switzerland, you see a consent banner. Until you accept, no Google Analytics, no Clarity and no PostHog loads. You get the page, our own server-side log, and Cloudflare Web Analytics, which counts the visit without a cookie or any identifier.

How that decision is made: the page asks Cloudflare's /cdn-cgi/trace endpoint which country its edge saw, and only then decides whether anything else may load. If that request fails, times out or answers something unexpected, we treat you as a visitor who has to be asked. The check looks at the connection, so a VPN exit in Frankfurt reads as European, and a European on a US exit does not.

07 Where it goes

We are based in Israel, which the European Commission has recognised as providing an adequate level of protection, so data reaching us needs no extra transfer mechanism.

Google, Microsoft, PostHog, Cloudflare and Resend are US companies with global infrastructure. Transfers to them rely on the mechanism set out in each one's data processing agreement, which is the EU standard contractual clauses, the EU to US Data Privacy Framework, or both.

Two of them keep our data in Europe. PostHog holds it in its EU cloud in Frankfurt, and it discards your IP address before anything is stored. Resend sends our mail from its EU region in Ireland.

08 How long we keep it

One record has no end date. We keep an unsubscribe for as long as the address is suppressed, because deleting it would let the mail start again.

09 Your rights

If the GDPR or the UK GDPR applies to you, you can ask us to show you what we hold, correct it, delete it, limit what we do with it, hand it over in a portable file, or stop processing that rests on legitimate interests. You can withdraw consent for analytics whenever you like, which stops collection from that moment but does not undo what came before.

Email ben@synapsereality.io. Ben answers inside one month, which is the statutory limit, and we do not charge for it.

You can also complain to a supervisory authority: the one in the EU country you live in, or the Information Commissioner's Office in the UK. If you are in Israel, the Protection of Privacy Law gives you a right to see and correct data held about you, and the Privacy Protection Authority takes complaints.

10 Children

This site sells services to businesses. It is not aimed at children, we do not knowingly collect anything from them, and Microsoft's own terms forbid running Clarity on a site that targets under-18s. If you think a child has sent us something, tell us and we will delete it.

11 Changes to this page

The date at the top is real. If we add a processor or change what we collect, that date moves and we say what changed. Adding a tool quietly would make this page a lie, which defeats the point of writing it.

Asking us something about this

Privacy requests go to ben@synapsereality.io. Anything else about the site goes through the contact page. A security problem has its own route: report it here.