Beta software. The Platform is a proof of concept provided for evaluation. This policy describes it as it actually behaves.
1Who we are, and what this policy covers
SynesisLabs Pty Ltd (ACN 700 856 088), an Australian company trading as SynesisLabs.ai (“we”, “us”), is responsible for the personal information described here. This policy covers the P_success Q&A Platform at poc.synesislabs.ai.
We handle personal information in accordance with the Australian Privacy Principles in the Privacy Act 1988 (Cth).
The Platform is a beta proof of concept. It is not a hardened production system, and this policy describes it as it actually behaves rather than as we would like it to behave.
2What personal information we collect and hold
- Account information: your email address, and the sign-in and session records held by our authentication provider. We do not hold your password; our authentication provider does.
- Your choices: a record of what you accepted or confirmed you had seen, with the version, the date and the text shown to you, and of each answer you give to the switch described in section 5. It is kept whichever way the switch is set, and clearing project history does not remove it.
- What you submit: your project name and description, your Define Project conversation, your parameter settings, and the scenarios and benchmarks you generate.
- Document text: text extracted from documents you add, and outputs the model writes from it. See section 5, which distinguishes the two.
- Operational records, such as request times, status codes, token counts, your account identifier, and usage and diagnostic data about how the Platform handled your request.
We do not ask for and do not want payment details, government identifiers, health information, or other sensitive information.
3How we collect and hold it
Documents you add to a project. The file is sent to our servers over an encrypted connection, written to a working store, and read by one isolated process that extracts its text. That process cannot send the file anywhere. We read the document only to extract that text, and neither the file nor its text is used to train any model.
How long we keep it. We keep a document and its text only as long as we need them. The extracted text is deleted when your browser collects it. The file is deleted when the reading finishes. Text your browser never collects, and any file whose reading does not finish, are deleted within one hour of upload. We keep a record of each reading: its file type, size, duration and outcome. That record holds no filename and nothing from inside the document, and ages out with our other operational records.
Dictation. The microphone in Define Project uses your browser’s speech recognition. We receive only the resulting text, which becomes part of your project description. Section 6 says where your browser sends the audio.
What is sent to us. When you select RUN, the following is sent to our servers over an encrypted connection: your question and project description, the text extracted from your documents, your parameter settings, and your Define Project conversation. Our servers apply our scoring model and pass the request to Anthropic, using an Anthropic account we hold. You do not provide, and we do not ask for, an AI provider key.
Web search. One step in a run gathers external evidence using Anthropic’s web-search tool. Search queries derived from your project description are sent to Anthropic and, through it, to Anthropic’s search provider. Do not include in a project description anything you would not enter into a public search engine.
We hold this material in a database on servers in Australia that we manage.
4Why we collect, hold, use and disclose it
- To provide the Platform to you and produce the outputs you asked for.
- To calibrate and improve the Platform, subject to your choice in section 5.
- To keep the Platform secure, diagnose faults, and understand load.
- To meet legal obligations.
We do not use your material to train any AI model. We do not sell it. We do not disclose it to anyone other than the providers in section 6 and as required by law.
5What we retain, and your choice
Extracted document text is not retained. It is held only until your browser collects it, and no longer than one hour after upload. In either privacy setting, it is not written to the activity log and is not kept in our records afterwards.
Outputs derived from it are retained. Research notes, parameter rationales, scenarios, benchmarks and summaries routinely quote figures, dates and plans from your documents, and where a statement is drawn from a specific file that file’s name is recorded alongside it. These are retained subject to your choice below.
Your choice. The “Help improve our platform” switch appears in the notice shown when you enter the Platform, and again under Privacy in your account menu. With the switch off, we stop retaining your project content: the research notes, rationales, scenarios, benchmarks and summaries, the outputs that can quote your documents, are no longer retained.
Some information is retained whichever way the switch is set, and clearing project history in your profile's privacy tab does not remove it, including:
- Your project’s name and the question you asked.
- The Define Project conversation, in full, because it is the record of how the question was arrived at.
- Usage and diagnostic data, such as which parameters were scored, how many scenarios, benchmarks, documents and searches were involved, and how our AI model handled your request. This does not include your documents, or the research notes, scenarios, benchmarks and summaries the model writes.
- The record of your choices described in section 2.
Clear project history, on the same Privacy page, applies the same rule retrospectively to what we already hold. You can change the switch at any time; it applies to material you submit after the change. Both controls are locked while a run is in progress, so a single run is never retained under two different rules.
If what the switch covers changes. If we change what the switch lets us use retained material for, we ask you again. The change applies only to material you submit after you agree to it; what we already hold stays under the answer you gave when it was collected.
Retention period. During the beta, retained material has no automatic expiry. It is removed on request, when you use Clear project history, or when we no longer need it. Operational records are retained whichever way the switch is set, for security, billing and diagnostics.
The record of your choices in section 2 outlives your account, as our record of what you agreed to. We remove it if you ask us by email, unless we need it to meet a legal obligation.
You can also contact us at hello@synesislabs.ai to opt out, to ask what we hold, or to request deletion.
6Who we disclose to, and where they are
We use the following providers to run the Platform. Using the Platform involves disclosing your material outside Australia.
| Provider | Purpose | Location |
|---|---|---|
| Anthropic PBC | Model inference and web search | United States |
| Clerk Inc. | Account identity, sign-in and session management | United States |
Our own servers and database are in Australia, and we manage them.
We remain accountable under Australian Privacy Principle 8 for how these providers handle personal information you give us, and we take reasonable steps to ensure they handle it consistently with the Australian Privacy Principles.
When you use the microphone in Define Project, your browser sends your voice to its own speech service: Google for Chrome, Microsoft for Edge, Apple for Safari. We receive only the text those services return, and their privacy policies govern the audio.
Anthropic’s published terms state that customer content submitted through its API is not used to train its models and is deleted within 30 days. Content its automated safety systems flag can be kept for up to two years, and content may also be kept where the law requires it. Those are Anthropic’s terms, not ours; we do not control Anthropic and cannot guarantee its practices or that its terms will not change. See Anthropic’s commercial terms, privacy policy and retention policy.
7Cookies and browser storage
The Platform sets no advertising or analytics cookies and uses no third-party trackers. It stores:
| What | Purpose |
|---|---|
| Cookies set by our authentication provider on this domain | Keep you signed in |
| A session identifier in your browser’s session storage | Groups your requests together in our operational records |
| A count of sign-in retries in your browser’s session storage, on the administrator page only | Stops that page retrying a stale session without end |
| Preferences in your browser’s local storage: your light or dark theme, and how you last ran a project | Remembers how you like the interface |
All of these are necessary for the Platform to work or to remember your own settings. Session storage is cleared when you close the tab. You can clear local storage through your browser at any time; the Platform will fall back to defaults.
8Automated processing
The Platform produces a P_success score for an initiative you describe, using a formula applied to parameters an AI model estimates from your description, your documents and web search results.
This is a statement about the initiative you described, not a decision about you. We do not use it to make decisions about any individual’s rights, entitlements or access to a service. Outputs are estimates and should be verified independently, as the Terms of Use set out.
What the program reads is your project description, your uploaded documents and web search results. Those may include names, roles and other information about identifiable people, depending on what you put in them; your account details are not sent to the model. Where its output bears on a decision, the decision is yours, about the project you described. Do not upload documents about identifiable people whose employment, contracts or access to a service turn on the decision you are scoring: the Platform is not built for projects of that kind.
9Security
Data in transit is encrypted. Access to retained material within our organisation is limited to authorised personnel. Credentials and API keys are redacted from our operational records.
The Platform is a beta proof of concept and has not been through a formal security certification or penetration test. We tell you this because it should inform what you choose to put into it.
10Access, correction and deletion
You may ask us to give you access to the personal information we hold about you, to correct it, or to delete it. Contact hello@synesislabs.ai. We will respond within 30 days. We will tell you if we cannot give you access or make a correction, and why.
11Complaints
If you believe we have mishandled your personal information, contact hello@synesislabs.ai with the details. We will acknowledge your complaint within 5 business days and respond substantively within 30 days.
If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner: oaic.gov.au, 1300 363 992, GPO Box 5288 Sydney NSW 2001.
12Changes to this policy
We may update this policy. The Last updated date at the top shows when it last changed. A change takes effect when we publish it, and reaches you as section 11 of our Terms of Use describes.