This Privacy Policy is also published in Portuguese. Both versions are authoritative; in case of conflict between the two, the Portuguese version prevails for Brazilian data subjects and the English version for all others.
1. Who we are
Graphor is operated by SYNAPSE INOVAÇÃO E TECNOLOGIA LTDA. (“Synapse,” “Graphor,” “we,” “us,” “our”), a company organized under the laws of the Federative Republic of Brazil, with principal place of business in Brazil. For privacy-related communications, including the exercise of data-subject rights, contact us at privacy@graphorlm.com. The privacy mailbox is monitored by Synapse and routed to the responsible team within one business day; substantive responses are provided within the timelines required by applicable law (15 days under LGPD art. 19, II for confirmation and access — Synapse applies the same 15-day window by analogy to the other LGPD art. 18 rights as best practice; one month under GDPR art. 12).2. Scope of this Policy
This Policy applies to:- The Graphor application (
https://app.graphorlm.com) - The Graphor documentation site (
https://docs.graphorlm.com) - The Graphor marketing site (
https://graphorlm.com) - The Graphor REST API, SDKs, and MCP transports
- Customer-facing communications from Synapse (email, support tickets, in-app notifications)
3. Personal data we collect
We collect personal data in the following categories. The legal basis for each is in §5; the retention period in §7.4. How we use personal data
We use each category of personal data only for the purposes listed below. We do not sell personal data, and we do not use it for purposes beyond what is described here without your explicit consent.5. Legal bases for processing
Under LGPD art. 7º and GDPR art. 6, we process personal data on one or more of the following bases:
We do not rely on the “vital interests” or “public task” bases for any processing activity.
6. Sharing of personal data (subprocessors)
We share personal data with the third-party subprocessors listed on our Subprocessors page. The list is versioned, includes the role each subprocessor plays, the categories of data we share with them, the region in which they process data, and the contractual instrument under which we engage them. In summary, subprocessors fall into the following groups:- Cloud infrastructure — Google Cloud Platform (production hosting), Amazon Web Services (AI model serving via Bedrock), Neo4j AuraDB (managed graph store).
- AI model providers — Anthropic (via AWS Bedrock), OpenAI (embeddings), Cerebras (chunk enrichment and fast tier).
- Payment — Stripe (subscriptions and invoicing).
- Authentication — Firebase Authentication (Google sign-in).
- Observability — Self-hosted Langfuse (operational tracing).
- Marketing-site analytics — Google Analytics 4 (consent-gated, marketing site only; governed by the Google Measurement Controller-Controller Data Protection Terms — see §10).
7. Retention and deletion
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, subject to longer retention where required by law — including Brazilian tax retention obligations of 5 years under CTN art. 173 (decadência) and CC art. 206, § 5º (5-year prescrição for credit recovery), plus the specific NFS-e and ICMS retention windows under applicable state and municipal tax law. The specific retention rules per data category — including the infinite-until-explicit-DELETE posture for Customer Content and Conversations and the bounded TTL for observability traces — are documented in detail on the Data Retention page. You can issue a deletion request at any time:- Sources and conversations via the DSR API (
DELETE /api/v1/sources/{file_id}andDELETE /api/v1/conversations/{conversation_id}). - Observability traces via the same DSR API (
DELETE /api/v1/dsr/traces). - Account deletion by emailing privacy@graphorlm.com — Synapse processes account-level deletion within 15 calendar days of request, applying the LGPD art. 19, II confirmation/access timeline by analogy as best practice. See Data Retention §1.
8. AI model use and training
We do not use Customer Content to train any AI model — neither Synapse’s own models nor any subprocessor’s models. This is a contractual commitment that rests on three layers:- Synapse’s Terms of Service: “Synapse does not train AI models using User Content.”
- Each AI subprocessor’s contractual no-training clause, with verbatim citations published on the Model Use and Training page.
- Operational controls: Synapse does not opt in to any provider’s training programs, does not maintain a fine-tuning pipeline on customer corpora, and does not provide a flag through the API that would cause Customer Content to be used for training.
9. Your rights and how to exercise them
Under LGPD art. 18 and GDPR art. 15–22, you have the following rights with respect to personal data we hold about you:
We respond to data-subject requests within the timelines required by applicable law (15 days under LGPD art. 19, II for confirmation and access — Synapse applies the same 15-day window by analogy to the other LGPD art. 18 rights as best practice; one month under GDPR art. 12, with possible extension for complex requests). The first response includes either the requested information or, where we need to verify your identity or scope the request further, a description of the next step.
10. International transfer of personal data
We process personal data in the United States. The relevant production region (us-central1, Iowa, USA) and AI-provider regions are documented on the Data Residency page.
Under LGPD art. 33, II, b (specific or standard contractual clauses) and GDPR art. 44–49, international transfers are covered by:
- Google Cloud Data Processing Addendum, incorporating Standard Contractual Clauses 2021/914 (covers the production cloud infrastructure including identity).
- Google Measurement Controller-Controller Data Protection Terms (applies only on consent-gated marketing-site visits where Google Analytics 4 is loaded).
- AWS Data Processing Addendum, incorporating Standard Contractual Clauses (covers AWS Bedrock).
- OpenAI Data Processing Addendum, with Zero Data Retention enrollment.
- Cerebras Terms of Use and Privacy Policy, with explicit zero-retention commitment.
- Stripe Data Processing Addendum, incorporating Standard Contractual Clauses.
- Neo4j AuraDB Data Processing Addendum, incorporating Standard Contractual Clauses.
11. Security
We protect personal data using industry-standard controls — including encryption at rest (cloud-provider-managed AES-256 by default; customer-managed encryption keys on enterprise request), encryption in transit (TLS 1.2+), logical tenant isolation, per-project API tokens with TTL and audit, and a 72-hour breach-notification SLA. The full inventory is on the Trust Center. No system is completely secure. Where we suffer a confirmed security incident that affects your personal data, we notify you within 72 hours of internal confirmation per our Incident Response commitment.12. Cookies and similar technologies
The Graphor sites use cookies in two categories:- Strictly necessary cookies — required to operate the Service (session cookies, authentication tokens, CSRF protection). These are not subject to consent because they are necessary to provide the Service you requested.
- Analytics cookies — Google Analytics, loaded only after you grant analytics consent via the cookie banner on the marketing site. Analytics cookies are not loaded on the legal routes (
/privacy-policy,/terms-of-service) regardless of consent. You can withdraw your consent at any time via the cookie preferences link in the site footer.
13. Children’s privacy
The Service is not directed to children under the age of majority (typically 18) in their jurisdiction. We do not knowingly collect personal data from such children. If you believe a child has provided personal data to us, please contact privacy@graphorlm.com and we will delete the data.14. Changes to this Policy
We may update this Policy from time to time. When we do, the “Last updated” date in the front matter changes, and the change history below records the change. For material changes, we notify users by email and post a prominent notice on the Service for at least 30 days before the change takes effect.15. Change history
Contact
- Privacy, data-subject requests, and DPA inquiries: privacy@graphorlm.com
- Subscription to privacy-policy and subprocessor change notifications: subprocessors@graphorlm.com
- Customer support: support@graphorlm.com

