Privacy Policy

Version 1 · Effective June 1, 2026 · Last updated June 1, 2026

Effective date: June 1, 2026 · Last updated: July 2, 2026

This Privacy Policy explains how Synafe LLC (“we,” “us,” or “our”) collects, uses, shares, and protects personal information when you use My Activity Genie (the “Service”). It is part of and incorporated into our Terms of Service. By using the Service, you agree to this Policy.

1. Information We Collect

  • Account and profile information. When you sign in (via Google or Microsoft) or register, we receive your name, email address, and profile image, and we store account details such as your role and settings.
  • Content you create. Calendars, events, documents, newsletters, images, templates, and other materials you create or upload, including the People/Staff directory and vendor/professional contacts you maintain — which may include names, email addresses, phone numbers, roles, and addresses of third parties. You control what you enter; see “Third-Party Data” below.
  • Payment information. If you purchase a paid plan, our payment processor collects your payment details. We do not store full payment card numbers; we receive limited billing and subscription information.
  • AI prompts and usage. When you use AI features, the prompts and relevant content you provide, plus usage metadata (such as token counts), are processed to generate output.
  • Usage, device, and log data. We collect technical information such as IP address, browser/device type, pages and actions, timestamps, and error logs to operate and secure the Service.
  • Cookies and local storage. We use cookies and local storage for essential functions such as authentication sessions and saving preferences (for example, your light/dark theme). We do not use third-party advertising trackers. On your first visit, we show a brief notice describing this use, which you can dismiss.
  • Communications. Records of your support requests, feedback, and emails we send (such as invitations and notifications).

We do not intend to collect Protected Health Information (PHI) or sensitive/special-category data, and the Terms prohibit you from submitting it. Do not enter such data into the Service.

2. How We Use Information

  • provide, operate, maintain, and secure the Service and your account;
  • generate AI-assisted output you request;
  • process payments and manage subscriptions;
  • send service-related communications (invitations, approvals, notices, retention warnings);
  • provide support and respond to requests;
  • monitor, prevent, and address fraud, abuse (including duplicate free accounts), security, and technical issues;
  • improve and develop the Service; and
  • comply with legal obligations and enforce our terms.

Where required, our legal bases include performance of our contract with you, your consent, our legitimate interests in operating and securing the Service, and compliance with law.

3. AI Processing

To provide AI features, we send your prompts and relevant content to our AI provider (currently OpenAI) for processing. That provider processes the data to return output to you and under its own terms. We do not use your content to train our own models. Review AI output before relying on it, and do not submit PHI or restricted data.

4. How We Share Information; Sub-Processors

We do not sell or share your personal information (as those terms are defined under the California and other U.S. state privacy laws), and we do not use it for cross-context behavioral or targeted advertising. We share it only as needed to operate the Service:

  • Identity providers — Google and Microsoft (Azure AD) for sign-in, and (if you connect them) for calendar/contact import.
  • AI — OpenAI, to process AI prompts and content.
  • Storage — Cloudflare R2 (object storage) for images and exported files.
  • Payments — Stripe, to process subscriptions and payments.
  • Email — our email provider (e.g., Resend or an SMTP provider) to send transactional email.
  • Hosting and infrastructure — our cloud hosting (e.g., Oracle Cloud) and Cloudflare (delivery/security); optionally Upstash (rate-limiting).
  • Legal and safety — to comply with law, enforce our terms, or protect rights, safety, and security.
  • Business transfers — in connection with a merger, acquisition, or sale of assets, subject to this Policy.

Each provider processes data on our behalf under appropriate agreements, or as an independent controller per its own policy. We do not currently use third-party advertising or analytics trackers.

5. Third-Party (Staff, Resident, and Vendor) Data

When you enter personal information about other people (such as staff, residents, families, or vendors), you are the controller of that information and we act as a processor on your behalf, processing it according to your instructions through your use of the Service. You are responsible for having the legal right and any necessary consents to provide it, for limiting it to what is necessary, and for not entering PHI or sensitive data. Requests from such individuals about their data should be directed to you; we will reasonably assist you in responding. Business customers acting as controllers may request our Data Processing Addendum (available at /legal/dpa) to govern our processing of such data on their behalf.

6. Data Retention

We retain account information for as long as your account is active. Content is subject to plan-based retention: on some plans (including the free tier) calendars, documents, and images are automatically deleted after a set period of inactivity (for example, 30 days without edits on the free tier — editing an item restarts its retention period), while other plans may retain content until deleted. We send a reminder before scheduled deletion (currently about 15 days in advance). We also periodically purge operational logs and AI-usage records. When you delete content or your account, we delete or de-identify the associated data within a commercially reasonable period, except for residual backup copies and data we must keep to comply with law, resolve disputes, or enforce agreements.

7. Security

We use technical and organizational measures designed to protect personal information, including encryption in transit, access controls, and encryption of stored integration credentials. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a data breach affects your personal information, we will notify you and other affected parties and provide information about the incident as required by applicable law.

8. Your Rights and Choices

Depending on your location, you may have rights to access, correct, delete, or export your personal information, to object to or restrict certain processing, and to withdraw consent. You can update much of your information in the Service, or exercise your rights through our contact form at /legal/contact. We will respond as required by applicable law (such as the GDPR or U.S. state privacy laws). We will not discriminate against you for exercising these rights. For data about third parties you entered, contact the relevant organization (the controller).

California residents. If you are a California resident, you have the right to know the categories and specific pieces of personal information we collect, the purposes for which we use and disclose it, and the categories of recipients; to request deletion or correction; and not to be discriminated against for exercising your rights. Because we do not sell or share personal information or use it for cross-context behavioral advertising, no “Do Not Sell or Share My Personal Information” choice is required. Exercise your rights through our contact form at /legal/contact; we will verify your request as required by law, and you may use an authorized agent.

Other U.S. state privacy rights. Residents of states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah, Texas, and others) have rights to access, correct, delete, and obtain a portable copy of their personal information, and to opt out of sale or targeted advertising (which we do not conduct). Exercise these rights through our contact form at /legal/contact; where available, you may appeal a decision by replying to our response.

9. International Transfers

We and our providers may process and store information in the United States and other countries that may have different data-protection laws than yours. Where required, we rely on appropriate safeguards for international transfers.

10. Children’s Privacy

The Service is intended for users 18 and older and is not directed to children. We do not knowingly collect personal information from children under 18 (or the minimum age in your jurisdiction). If you believe a child has provided us personal information, contact us and we will delete it.

11. Changes to this Policy

We may update this Policy from time to time. If we make material changes, we will provide notice (for example, by re-prompting acceptance at next sign-in or by other reasonable means) and update the “Last updated” date. Your continued use after changes take effect constitutes acceptance.

12. Contact Us

For privacy questions or requests, reach Synafe LLC through our contact form at /legal/contact. [If applicable, identify your EU/UK representative or Data Protection Officer here.]