Zephr / Legal
Privacy Policy
This policy describes what Zephr collects, where it is stored, how it is protected, and the rights you have over it. It is written to match the product as it actually ships today — planned controls are labelled planned.
What this policy covers
This policy applies to every Zephr product and surface, including the open-source local engine, the code-agent integrations, and the managed cloud dashboard and API. It covers two data modes that are deliberately distinct: the local device and the managed cloud.
If you use Zephr inlocal mode, your memory data is stored in a SQLite database on your own device and is under your control. If you sign up for the managed cloud, your account data and the data you sync to a shared workspace are stored on Zephr's managed infrastructure (hosted Postgres, with pgvector for semantic recall), isolated per tenant.
Information you give us
When you create a Zephr account, we collect the minimum needed to operate the service and secure your account.
Account data (managed cloud)
When you sign up we collect youremail address, a password (hashed and stored by our authentication provider, never by us in plaintext), and an optional display name. This happens through the signup flow at /signup and the /api/cloud/auth/signup route, and the account is created with the Supabase Auth service.
Memory and evidence data
Zephr's core purpose is to store memories and beliefs about your work — signed records of what you asked, what was done, and the provenance/evidence that backs each claim. This includes:
- Memories and belief records you or an agent capture, with their provenance (the source that produced each claim).
- An observation/evidence ledger that records how each belief was formed, including the evidence chain.
- Continuity payloads (signed handoffs) that let a new agent session pick up where a prior one ended.
- API keys and connection metadata for integrations you deliberately connect.
Local mode
In local mode this memory data stays in a SQLite database on your device. Nothing is transmitted to Zephr unless you explicitly sync it to the managed cloud.
Storage and isolation
Where your data lives depends on the mode you use. Each is described accurately below.
On your device (local mode)
Local-mode memories, beliefs, and the evidence ledger are stored in a local SQLite database on your machine. You control this data and can remove it by removing the local store.
Managed cloud
Data you sync to the managed cloud is stored in Zephr's hosted Postgres database, isolated per tenant (workspace), with pgvector used for semantic recall. Qdrant is retired as the primary engine. Vector rows hold identifiers, hashes, and references so they can be traced back to their source and rebuilt from Postgres.
Encryption at rest in the managed cloud is planned, not yet fully shipped. The roadmap calls for per-tenant envelope encryption (each tenant's sensitive fields — belief content, evidence text, continuity payloads — encrypted with a per-tenant key wrapped by a key-management service, with crypto-shred on erasure). As of this policy's publication the managed-cloud path does not yet encrypt every sensitive column in that way, and we state that plainly rather than overclaim. We apply transport encryption (TLS) to data in transit today.
Subprocessors and third parties
Where Zephr relies on a service provider to operate, that provider processes data as a subprocessor under our instructions, and we do not allow training on your content.
Current subprocessors
- Supabase (Auth + hosted Postgres) — account creation, authentication, and hosted database storage for the managed cloud.
- pgvector (in hosted Postgres) — semantic recall over the managed cloud memory store. Qdrant is retired as the primary engine.
AI/embedding providers (planned posture)
Any future calls to third-party AI or embedding providers are treated as subprocessed tenant-data processing, governed by a data-processing addendum, a checked-in provider allowlist, and per-org policy (ADR-027). Providers must offer zero-training and zero/short-retention terms, and unknown providers fail closed. Today the only enabled local path is on-device processing.
Planned
Access by Zephr staff
Zephr staff access production data only as needed to operate and secure the service, under least-privilege controls. Access is logged.
Purpose and lawful basis
We process your data only for the purposes described here, and on the stated lawful bases.
- To create and authenticate your account (performance of the contract / legitimate interest in operating the service).
- To store and retrieve your memories and evidence so the product works as intended (performance of the contract).
- To secure the service, including rate-limiting signup and API abuse prevention (legitimate interest).
- To respond to your requests and, where you opt in, to send operational notices (consent / legitimate interest).
We donot sell your personal data. We do not use your memory content for advertising. Any telemetry is opt-in and does not include prompt or memory content.
CalOPPA disclosure and CCPA scope
CalOPPA requires a posted policy and a Do Not Track statement for operators that collect personal information from California residents. CCPA/CPRA applies only if statutory thresholds are met.
Do Not Track
We do not currently respond to browser Do Not Track (DNT) signals. The authentication cookie is required to keep you signed in. We do not run third-party advertising pixels on the core product, so there is no advertising tracker for DNT to switch off. If we add optional analytics, it will be opt-in and described here.
CCPA / CPRA
Those laws apply to for-profit businesses that meet at least one 2026 threshold (inflation-adjusted gross revenue of about $26.625 million; buying, selling, or sharing personal information of 100,000 or more California consumers or households; or deriving 50% or more of revenue from selling or sharing personal information). Synapsic LLC does not currently meet those thresholds. If that changes, we will update this policy and honour the statutory rights (know, delete, correct, opt out of sale/share). We do not sell personal information.
How we notify of material changes
Material changes are dated on this page. Where the law requires, we will also notify account holders (typically by email to the address on the account).
Access, export, and erasure
We are building the tooling that lets you exercise the rights below, and we state its current status honestly.
Access and correction
You can access the memories and data in your workspace through the product. Where you need a corrected record, you can update or remove it through the product or by contacting us.
Export / portability
Zephr's design goal is that you can leave with everything, machine-readably, in the open continuity format. An export capability is part of the roadmap. Planned It is not yet exposed through a self-serve dashboard in every surface; contact us and we will arrange an export of your data.
Erasure (right to be forgotten)
We have designed an end-to-end erasure pipeline (delete the source record, emit a tombstone, remove corresponding vectors, and crypto-shred encryption keys) but it is in progress / planned for the managed cloud, not yet fully wired into every live write path. That means we cannot promise instant deletion today. Planned
To request erasure of your account and data, contact [email protected]. We will process verified requests and, where a deletion pipeline is not yet automated, we will action it manually within a reasonable time frame.
Withdrawing consent
Where we rely on consent (for example, optional telemetry or optional hosted-AI processing once available), you can withdraw it at any time without affecting the core service.
How long we keep data
We keep data only as long as needed to operate the service and meet legal obligations.
- Account and memory data: retained while your account is active and you keep the data.
- Backups: retained for a bounded window (target ≤30 days) so that erasure completes within a documented period once fully automated.
- Signup/security logs: retained briefly to detect abuse, and not used to profile you.
When you delete data, residual plaintext vectors in backups/snapshots may persist for up to the backup window. This residual is documented, not denied.
What we do not claim
No certification or overclaim appears on this page, because Zephr holds none today.
Zephr isnot certified under SOC 2, ISO 27001, HIPAA, or similar programs, and nothing on this page or elsewhere implies otherwise. The published security audit reaches a CONDITIONAL GO for beta, not an unconditional pass. Where a control is planned, we say planned.
Updates and how to contact us
We may update this policy as the product and the law evolve.
Material changes will be reflected here with an updated date, and where required we will notify account holders. Questions, requests, and erasure requests:
Synapsic LLCUnited StatesInterim US mailing — street / PO box to be replaced[email protected]Last reviewed 2026-08-27 · change history