This policy explains what we do with personal information in the SynaiConnect platform and the Synai Community mobile app. It is written to be read, not just to be published, so it says plainly who decides what — because on a platform churches run for their own members, that distinction determines who can actually answer your request. Section 2 is the place to start.
1.Who we are
SynaiConnect is operated by Synai Core Technologies LLC, a limited liability company registered in the United States, at 8164 Ibis Cove Circle, Naples, FL 34119, United States. You can reach our privacy team at office@synaiconnect.com.
This policy covers the SynaiConnect administrative portal at synaiconnect.com, the Synai Community mobile app for iOS and Android, and the public pages and APIs that support them (together, the “Service”). We have not appointed a Data Protection Officer; privacy enquiries go to the address above.
2.Our role, and your organization’s role
This is the most important thing to understand about how your information is handled, because SynaiConnect is software that churches, ministries and communities (each an “Organization”) use to run themselves.
- For member information, your Organization decides. If you are a member of a church that uses SynaiConnect, that Organization is the controller of your information: it decides what to collect about you, who on its staff can see it, and how long to keep it. We act as its processor — we hold and process that information on its instructions and do not use it for our own purposes. The Organization’s own privacy practices apply alongside this policy, and requests about your member record are usually fastest through them.
- For our own customer relationship, we decide. When an administrator signs up, we are the controller of that account information, billing details, support correspondence, and the operational logs we keep to run and secure the Service.
Where this policy describes a choice as your Organization’s, that is not a deflection — it reflects who actually holds the decision, and therefore who can act on your request.
3.Information we collect
Information you or your Organization provide
- Account details — name, email address, and the credentials used to sign in.
- Member profile details — phone number, postal address, family relationships, and church milestones. On mobile, everything beyond name and email is optional.
- Organization records — the people directory, groups, events, attendance and check-in records, giving history, prayer requests, and messages that your Organization keeps in the Service.
- Content you post — messages, comments, prayer requests and replies, and photos you choose to upload.
Information collected automatically
- Operational logs — IP address, browser or device type, timestamps, and the actions taken in the Service. We use these to run it, investigate faults, and detect abuse.
- Crash and diagnostic reports — collected through Sentry when something breaks, so we can fix it. Not used for advertising or profiling.
- Push notification tokens — an anonymous device identifier, registered only if you allow notifications.
Information we receive from others
- Payment confirmations — when you give through the Service, Stripe processes the payment and tells us the amount, date, designation and status. Your full card number never reaches our systems.
- Delivery outcomes — our email and SMS providers report whether a message was delivered, bounced, or was marked as spam.
We do not buy personal information from data brokers.
Special-category data. Some information your Organization keeps about you is treated as sensitive under data protection law, and the Service is designed to hold it because churches need it:
- Health — allergies and special needs, primarily so children’s ministry volunteers can keep your child safe.
- Religious belief — baptism status and date, confirmation, first communion and profession-of-faith dates, and your membership of a faith community as such. Content you write in a prayer request or post may reveal belief too.
- Family and child-safeguarding details — who is and is not authorised to collect your child, including the reason where your Organization has recorded one.
Your Organization decides which of these fields it uses and on what basis; it is the controller of your member record, and we hold this information on its instructions. Ask your Organization’s administrator if you want a field corrected or left blank.
4.Why we use it, and our legal bases
Where the GDPR or UK GDPR applies, we must have a legal basis for each purpose. Ours are:
| Purpose | Legal basis |
|---|---|
| Providing the Service to your Organization and to you as its member | Performance of a contract (Art. 6(1)(b)); for member records, processing on the Organization’s instructions as its processor |
| Authenticating users, enforcing roles and permissions, keeping each Organization’s data separate | Legitimate interests — securing the Service (Art. 6(1)(f)) |
| Investigating faults, monitoring crashes, preventing abuse and fraud | Legitimate interests — keeping the Service working and safe |
| Account, security and Service notices; responding to support | Performance of a contract; legitimate interests |
| Processing donations and keeping transaction records | Performance of a contract, and legal obligation for tax and accounting records (Art. 6(1)(c)) |
| Push notifications, camera and photo access, one-time location lookup | Consent (Art. 6(1)(a)) — granted through your device permission prompt and withdrawable at any time |
| Complying with law and responding to lawful requests | Legal obligation |
Providing your name and email is necessary to hold an account — without them we cannot give you access. Everything else is optional, and declining it only limits the related feature.
We do not sell your personal information, we do not share it for cross-context behavioural advertising, and we do not use the content stored in the Service to train third-party advertising or foundation models.
5.Who we share it with
We disclose information in four situations, and no others:
- Within your Organization — according to the roles and permissions its administrators configure. An administrator can see more than a member can.
- To service providers who help us run the Service, listed below. Each is bound by contract to process information only on our instructions and to protect it.
- For legal and safety reasons — when we are legally required to, or where disclosure is necessary to protect the rights, safety or security of our users, the public, or the Service.
- In a business transfer — if the business is acquired or reorganised, information may transfer with it, subject to this policy.
| Recipient | What they do for us |
|---|---|
| Supabase | Database, authentication and file storage |
| Vercel | Application hosting and content delivery |
| Amazon Web Services | Media storage and processing, transactional email, background job queues, live video |
| Stripe | Payment and donation processing |
| Twilio | SMS and voice messaging |
| The Campaign Registry | SMS sender registration required by US mobile carriers |
| Vapi | Automated voice calling, including call recordings and transcripts |
| GetStream | In-app chat and activity feeds |
| OpenAI | Assistive drafting, translation, and message triage |
| Google (Gemini API) | Live caption translation and caption context |
| Soniox | Live speech-to-text and speech synthesis for captions |
| Speechmatics | Live speech-to-text for captions |
| ElevenLabs | Speech synthesis for translated captions |
| Google Firebase | Mobile push notification delivery only |
| Cookiebot (Usercentrics) | Cookie consent management and consent records |
| Sentry | Error monitoring and crash diagnostics |
6.International data transfers
We are based in the United States and the Service is hosted there, so information about members in the European Economic Area, the United Kingdom and Switzerland is transferred to the United States, and may be processed in other countries where our providers operate.
For those transfers we rely on the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable) in our agreements with the providers in section 5, or on another Article 46 safeguard where a provider offers one. You can request a copy of the relevant terms by writing to office@synaiconnect.com.
7.How long we keep it
We keep information for as long as your account and your Organization’s subscription are active, and afterwards only as long as we need it for the purposes in section 4. In practice:
- Your member account — until you or your Organization delete it. Deletion through the app or from our account deletion page is immediate; see section 9.
- Organization records — for the life of the subscription. Administrators can delete most records themselves at any time, and we delete an Organization’s data after its account is closed.
- Donation records — retained by your Organization and its payment processor for as long as tax and accounting law requires, even after you delete your account. Your name and contact details are removed from them when your account is deleted.
- Messages sent to you — the message body and your address are deleted after 90 days; the record that a message was sent and delivered is kept for 13 months.
- Two-way conversations with your Organization — 24 months from the last message. A conversation deleted by staff is removed permanently after 30 days.
- Automated phone calls — any recording is deleted after 30 days, the transcript after 12 months, and the call record after 24 months.
- Live service captions and transcripts — caption text after 90 days, a service transcript after 12 months.
- Text submitted to assistive features — 90 days.
- Change history and security logs — the detail of what changed, and any IP address, after 90 days; the record that a change happened, for 24 months.
- Children’s safeguarding incident reports — kept deliberately, for as long as your Organization needs them. This is the one place we keep records longer rather than shorter, because they may be needed years later.
These periods are enforced automatically by a scheduled job, not applied by hand. Where a record must survive for legal reasons but does not need to identify you, we remove the identifying parts and keep the rest.
Deleted data is removed from our active systems straight away and disappears from encrypted backups as those backups age out on their normal rotation.
8.Security
We use technical and organisational measures designed to protect your information, including encryption in transit, encryption at rest with our hosting providers, scoped access for staff, and audit logging of administrative actions.
The Service is multi-tenant, so tenant isolation is a security control we treat as fundamental: every record belonging to an Organization is tagged with that Organization and access is enforced both in the application layer and by row-level security in the database, so one Organization cannot read another’s data.
No system is perfectly secure, and we will not claim otherwise. If you believe you have found a vulnerability, please write to support@synaiconnect.com so we can investigate.
9.The Synai Community mobile app
The app asks for a small number of device permissions. Each one is requested in context, each is optional, and each can be revoked in your device settings.
- Notifications — if you allow them, we register a push token so your Organization can notify you about groups, events, prayer requests and mentions. Categories are configurable in the app’s notification settings.
- Camera and photo library — accessed only at the moment you choose to attach a photo to a post or your profile. We never read your library in the background.
- Location — requested once, during onboarding, purely to pre-fill your postal address so you do not have to type it. Your location is not tracked and is not stored as location data.
- Crash diagnostics — crash reports and basic device information, collected through Sentry to keep the app stable.
Deleting your account. You can permanently delete your account in the app under Account → Delete account, or from our account deletion page without needing the app — we email you a confirmation link, and nothing is deleted until you open it. What is deleted and what is legally retained is set out in full on that page.
Two limits worth stating plainly. When you delete your account we also delete your data from the services we use to run the Service — your uploaded photos, your chat identity, and your payment-processor customer record. Two processors provide no way for us to delete on your behalf: Vapi, which hosts recordings and transcripts of automated phone calls, and Google Firebase, which holds the push-notification token issued to your device. We delete our own copies of both, so no further message can be addressed to you — but we cannot reach theirs, and both then age out under those providers’ own retention. We would rather tell you that than claim an erasure we do not perform.
10.Text messages (SMS)
Organizations use SynaiConnect to text their own members — service and service-time updates, event announcements, prayer requests, and volunteer coordination. Your Organization is the sender and decides what goes out; we provide the tooling, and Twilio carries the message to your carrier. This section is set out separately because a text message is the one part of the Service that reaches you whether or not you open an app.
What we hold for text messaging
- Your mobile number — as you gave it, or as your Organization holds it in its member directory.
- Your consent to receive text messages — the fact that you agreed and which of the methods below captured it, recorded against your member record by your Organization.
- Message content — what was sent to you, and any reply you send back.
- Delivery status — whether the carrier delivered, queued, rejected or failed the message, and whether the number has opted out.
How you opt in
There are three ways, and every one of them is recorded against your member record with the method and the moment:
- You tick the box yourself. When you follow your Organization’s invitation link to create a password, that screen offers a text-message consent checkbox. It is separate from accepting these policies, it starts unticked, and it is not required — your account is created either way.
- You text START to your Organization’s number. This also works if you had replied STOP before and want messages again.
- Your Organization confirms it already has your consent. If it collected your agreement through its own channels — a membership form, in person, or its own website — and then added or imported you here, an administrator confirms that at the point of adding you. That is their responsibility as the sender under section 11 of our Terms and Conditions.
Consent is recorded per member and per Organization — agreeing to hear from one church does not enrol you with another, and an Organization may only text people who have agreed to hear from it. All three methods, including what the consent checkbox actually looks like, are documented publicly on our text message consent page.
These are recurring messages, and the frequency varies with what your Organization has on: some weeks bring a single service reminder, others several event or volunteer messages. Message and data rates may apply. We do not charge you for receiving them; your own mobile plan governs what they cost you.
How to stop, and how to get help
Reply STOP to any message to opt out. Opt-outs are handled by our messaging provider at the network level, so they take effect for that number straight away and do not depend on anyone at your Organization acting on them. Reply HELP to any message for help information. You can also ask your Organization to remove your number from its directory, or write to office@synaiconnect.com. Opting out of text messages does not delete your account or stop email and in-app notifications — those are separate, and section 9 covers deleting the account itself.
We do not share your mobile number
Mobile phone numbers and SMS consent data are not shared, sold, rented or otherwise provided to third parties or affiliates for marketing or promotional purposes. There is no exception to that and no setting that changes it.
The only third parties that ever receive your mobile number are the providers who have to have it in order to deliver a message you agreed to receive: our messaging provider, Twilio, listed in section 5, and the mobile carrier that hands the message to your phone. Twilio acts on our instructions and is contractually bound to use the number only to carry that message, not for its own or anyone else’s marketing. Nothing about your text messaging is passed to advertisers, data brokers, lead generators or any other Organization on the platform.
12.Your rights, and how to use them
Depending on where you live, you have some or all of these rights:
- Access — get a copy of the personal information we hold about you.
- Correction — have inaccurate information fixed. Most profile fields you can edit yourself in the app.
- Deletion — have your information erased, subject to records we must keep by law.
- Portability — receive your information in a machine-readable format.
- Restriction and objection — ask us to pause processing, or object to processing we base on legitimate interests.
- Withdrawing consent — turn off notifications, camera access or location at any time in your device settings, without affecting anything already done.
If you are in California, you additionally have the right to know what we collect and disclose, to delete it, to correct it, and not to be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined by the CCPA/CPRA, so there is no opt-out to exercise.
To make a request, contact your Organization’s administrator if it concerns your member record — they hold the decision — or write to office@synaiconnect.com. We will verify your request against your account email and respond within the period the applicable law allows, normally one month. Exercising these rights is free.
If you are in the EEA, the UK or Switzerland and you are not satisfied with how we have handled your request, you have the right to lodge a complaint with your local data protection supervisory authority. You may also seek a remedy through the courts.
13.Automated decision-making
We do not make decisions about you by automated means alone that would have a legal or similarly significant effect, and we do not profile you for advertising. The Service includes assistive features that draft or translate text on request, but a person always decides what to send.
14.Children and age limits
The administrative portal is for adults: you must be at least 18 to hold a staff or administrator account. The Synai Community app is for members aged 16 and over. We do not knowingly collect information directly from children below those ages, and if we learn that we have, we will delete it.
Organizations do use the Service to keep records about children — a kids check-in register, for example, or a family profile listing someone’s children. In those cases the child is not a user of the app; the Organization is the controller of that record and is responsible for obtaining whatever parental consent and notice its own law requires. We process it on the Organization’s instructions.
If you believe a child has created an account, write to office@synaiconnect.com and we will remove it.
15.Changes to this policy
We may update this policy as the Service changes or the law does. The date at the top always reflects the current version. If a change materially affects your rights, we will give notice in the Service or by email before it takes effect, rather than changing this page quietly.
16.How to contact us
Privacy questions and requests: office@synaiconnect.com. General support: support@synaiconnect.com.
Synai Core Technologies LLC
8164 Ibis Cove Circle, Naples, FL 34119, United States
See also our Terms and Conditions.