Legal

Privacy Policy

Last Updated:

Synheart ("we," "our," "us") builds technologies that help people understand their emotional, cognitive, and physiological state using biosignals, behavioral patterns, and AI-powered interpretation. This Privacy Policy explains how we collect, use, store, and protect personal information across the Synheart ecosystem, including Synheart Wear, Synheart Core SDK, Syni, Syni Life, Synheart Dashboard, and all related services ("Services").

By using Synheart products, you agree to this Privacy Policy.

1. Information We Collect

We collect three categories of data:

1.1 Biosignal Data (Physiological Data)

When you use Synheart Wear, participate in Syni Life sessions, or enable integrations with supported wearables (e.g., WHOOP, Garmin), we may collect:

Heart rate (HR)

Heart rate variability (HRV)

Respiratory rate

Sleep stages & duration

Movement & accelerometer data

Skin temp (if supported by device)

Stress markers

Focus-related metrics

Important:

Raw biosignals stay on-device unless you explicitly consent to cloud processing.

1.2 Behavioral Signals (Device Interaction Data)

If you enable the Synheart Behavioral SDK, we may collect:

Keystroke cadence (timing, not content)

Scroll velocity and interaction patterns

App interaction bursts and idle gaps

Focus patterns and task switching frequency

Motion and device orientation

We never collect message content, keystroke content, or personal text. Only timing-based signals.

1.3 App, Account & System Data

Name, email, phone (if provided)

Device information (OS, version, model)

IP address (for security)

Crash logs and analytics

Subscription or billing info (if applicable)

2. How We Use Your Data

We use data to deliver and improve Synheart features:

2.1 To Generate Cognitive & Emotional Insights

Focus estimation

Emotion & stress modeling

Flow state detection

HRV-based cognitive readiness

2.2 To Operate Our Platform

Account creation & authentication

Cloud synchronization (if consented)

Developer integrations

Wearable device linking

2.3 To Improve Our Models (Only With Consent)

Model training and enhancement

Anonymous benchmarking

Quality improvement

2.4 To Communicate With You

Product updates

Support requests

Security notifications

We do not sell personal data.

We do not use data for advertising.

3. Where Data Is Processed

Depending on the Service:

On-device: Core behavioral signals, some biosignal processing, HSI fusion.

Cloud (with consent): Synheart Cloud, Syni, model inference.

Regions: AWS (US/EU/Canada regions depending on your country).

4. Raw Data Policy

Raw data never leaves the device unless you opt in.

Raw data includes:

High-resolution HRV windows

PPG/accelerometer streams

Behavioral sequences

Keyboard timing samples

If you grant permission:

Data is encrypted before leaving your device.

Only necessary segments are transmitted for the selected feature.

You can disable cloud upload at any time.

5. Sharing Your Data

We may share data only in these cases:

5.1 With Your Consent

For example:

Linking your wearable

Connecting third-party apps

Using Syni with cloud inference

5.2 With Service Providers

To operate Synheart Cloud:

AWS (hosting)

Analytics & crash reporting tools

All are bound by contractual privacy requirements.

5.3 For Legal Compliance

If required by law, with proper documentation.

We never share biosignal or behavioral data with advertisers, data brokers, or unrelated third parties.

6. Data Retention

We retain data only as long as necessary:

Account data: while account is active

Biosignals: configurable in app

Behavioral data: typically 30–90 days (for rolling window models)

Logs & telemetry: 30 days

Backups: encrypted, limited access

You can request complete deletion at any time (see Section 9).

7. Your Rights

Depending on your region (GDPR, CCPA, PIPEDA), you have the right to:

Access your data

Correct your data

Delete your data

Export your data (portable export)

Withdraw consent

Restrict processing

Object to profiling

Submit a complaint

We will respond within the legally required time frame.

8. Security Measures

We use strong security methods including:

End-to-end encryption for sensitive data

On-device processing wherever possible

Strict access controls

Secure key management

Encrypted backups

Regular penetration testing

Despite best efforts, no system is 100% secure.

9. Your Choices & Controls

You can control:

Whether raw data leaves your device

Whether behavioral signals are collected

Whether cloud inference is used

Whether wearable data syncs

Whether analytics are enabled

You may also delete your account at any time, which removes all personal data from our systems.

10. Children's Privacy

Synheart is not intended for children under 16.

We do not knowingly collect data from children.

11. Changes to This Policy

We may update this Privacy Policy to reflect improvements, legal changes, or new features.

If changes are significant, we will notify users.

Contact Us

If you have any questions about this Privacy Policy or wish to exercise your rights, please contact us:

Email: legal@synheart.ai