Skip to main content
This Privacy Policy is also published in Portuguese. Both versions are authoritative; in case of conflict between the two, the Portuguese version prevails for Brazilian data subjects and the English version for all others.

1. Who we are

Graphor is operated by SYNAPSE INOVAÇÃO E TECNOLOGIA LTDA. (“Synapse,” “Graphor,” “we,” “us,” “our”), a company organized under the laws of the Federative Republic of Brazil, with principal place of business in Brazil. For privacy-related communications, including the exercise of data-subject rights, contact us at privacy@graphorlm.com. The privacy mailbox is monitored by Synapse and routed to the responsible team within one business day; substantive responses are provided within the timelines required by applicable law (15 days under LGPD art. 19, II for confirmation and access — Synapse applies the same 15-day window by analogy to the other LGPD art. 18 rights as best practice; one month under GDPR art. 12).

2. Scope of this Policy

This Policy applies to:
  • The Graphor application (https://app.graphorlm.com)
  • The Graphor documentation site (https://docs.graphorlm.com)
  • The Graphor marketing site (https://graphorlm.com)
  • The Graphor REST API, SDKs, and MCP transports
  • Customer-facing communications from Synapse (email, support tickets, in-app notifications)
This Policy does not apply to third-party services that integrate with Graphor on your behalf (your CI/CD pipeline, your downstream applications). Those services are governed by their own privacy notices.

3. Personal data we collect

We collect personal data in the following categories. The legal basis for each is in §5; the retention period in §7.

4. How we use personal data

We use each category of personal data only for the purposes listed below. We do not sell personal data, and we do not use it for purposes beyond what is described here without your explicit consent. Under LGPD art. 7º and GDPR art. 6, we process personal data on one or more of the following bases: We do not rely on the “vital interests” or “public task” bases for any processing activity.

6. Sharing of personal data (subprocessors)

We share personal data with the third-party subprocessors listed on our Subprocessors page. The list is versioned, includes the role each subprocessor plays, the categories of data we share with them, the region in which they process data, and the contractual instrument under which we engage them. In summary, subprocessors fall into the following groups:
  • Cloud infrastructure — Google Cloud Platform (production hosting), Amazon Web Services (AI model serving via Bedrock), Neo4j AuraDB (managed graph store).
  • AI model providers — Anthropic (via AWS Bedrock), OpenAI (embeddings), Cerebras (chunk enrichment and fast tier).
  • Payment — Stripe (subscriptions and invoicing).
  • Authentication — Firebase Authentication (Google sign-in).
  • Observability — Self-hosted Langfuse (operational tracing).
  • Marketing-site analytics — Google Analytics 4 (consent-gated, marketing site only; governed by the Google Measurement Controller-Controller Data Protection Terms — see §10).
Subscribe to subprocessors@graphorlm.com to be notified at least 30 days before any material subprocessor change takes effect, except where an immediate change is required to remediate a security incident. We do not sell personal data and do not share it for behavioral advertising.

7. Retention and deletion

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, subject to longer retention where required by law — including Brazilian tax retention obligations of 5 years under CTN art. 173 (decadência) and CC art. 206, § 5º (5-year prescrição for credit recovery), plus the specific NFS-e and ICMS retention windows under applicable state and municipal tax law. The specific retention rules per data category — including the infinite-until-explicit-DELETE posture for Customer Content and Conversations and the bounded TTL for observability traces — are documented in detail on the Data Retention page. You can issue a deletion request at any time:
  • Sources and conversations via the DSR API (DELETE /api/v1/sources/{file_id} and DELETE /api/v1/conversations/{conversation_id}).
  • Observability traces via the same DSR API (DELETE /api/v1/dsr/traces).
  • Account deletion by emailing privacy@graphorlm.com — Synapse processes account-level deletion within 15 calendar days of request, applying the LGPD art. 19, II confirmation/access timeline by analogy as best practice. See Data Retention §1.
Billing records are retained for as long as required by Brazilian tax and accounting law, even after account deletion.

8. AI model use and training

We do not use Customer Content to train any AI model — neither Synapse’s own models nor any subprocessor’s models. This is a contractual commitment that rests on three layers:
  1. Synapse’s Terms of Service: “Synapse does not train AI models using User Content.”
  2. Each AI subprocessor’s contractual no-training clause, with verbatim citations published on the Model Use and Training page.
  3. Operational controls: Synapse does not opt in to any provider’s training programs, does not maintain a fine-tuning pipeline on customer corpora, and does not provide a flag through the API that would cause Customer Content to be used for training.
The Model Use and Training page describes the full picture: which providers serve which inference tier, what data reaches each provider, and what each provider commits to do with that data.

9. Your rights and how to exercise them

Under LGPD art. 18 and GDPR art. 15–22, you have the following rights with respect to personal data we hold about you: We respond to data-subject requests within the timelines required by applicable law (15 days under LGPD art. 19, II for confirmation and access — Synapse applies the same 15-day window by analogy to the other LGPD art. 18 rights as best practice; one month under GDPR art. 12, with possible extension for complex requests). The first response includes either the requested information or, where we need to verify your identity or scope the request further, a description of the next step.

10. International transfer of personal data

We process personal data in the United States. The relevant production region (us-central1, Iowa, USA) and AI-provider regions are documented on the Data Residency page. Under LGPD art. 33, II, b (specific or standard contractual clauses) and GDPR art. 44–49, international transfers are covered by:
  • Google Cloud Data Processing Addendum, incorporating Standard Contractual Clauses 2021/914 (covers the production cloud infrastructure including identity).
  • Google Measurement Controller-Controller Data Protection Terms (applies only on consent-gated marketing-site visits where Google Analytics 4 is loaded).
  • AWS Data Processing Addendum, incorporating Standard Contractual Clauses (covers AWS Bedrock).
  • OpenAI Data Processing Addendum, with Zero Data Retention enrollment.
  • Cerebras Terms of Use and Privacy Policy, with explicit zero-retention commitment.
  • Stripe Data Processing Addendum, incorporating Standard Contractual Clauses.
  • Neo4j AuraDB Data Processing Addendum, incorporating Standard Contractual Clauses.
Customers in the European Economic Area, Switzerland, or the United Kingdom: the Standard Contractual Clauses referenced above include the modules required for processor-to-processor and controller-to-processor transfers under GDPR art. 46(2)(c). Copies are available under NDA via privacy@graphorlm.com.

11. Security

We protect personal data using industry-standard controls — including encryption at rest (cloud-provider-managed AES-256 by default; customer-managed encryption keys on enterprise request), encryption in transit (TLS 1.2+), logical tenant isolation, per-project API tokens with TTL and audit, and a 72-hour breach-notification SLA. The full inventory is on the Trust Center. No system is completely secure. Where we suffer a confirmed security incident that affects your personal data, we notify you within 72 hours of internal confirmation per our Incident Response commitment.

12. Cookies and similar technologies

The Graphor sites use cookies in two categories:
  • Strictly necessary cookies — required to operate the Service (session cookies, authentication tokens, CSRF protection). These are not subject to consent because they are necessary to provide the Service you requested.
  • Analytics cookies — Google Analytics, loaded only after you grant analytics consent via the cookie banner on the marketing site. Analytics cookies are not loaded on the legal routes (/privacy-policy, /terms-of-service) regardless of consent. You can withdraw your consent at any time via the cookie preferences link in the site footer.
We do not use marketing or advertising cookies, and we do not participate in cross-site behavioral advertising networks.

13. Children’s privacy

The Service is not directed to children under the age of majority (typically 18) in their jurisdiction. We do not knowingly collect personal data from such children. If you believe a child has provided personal data to us, please contact privacy@graphorlm.com and we will delete the data.

14. Changes to this Policy

We may update this Policy from time to time. When we do, the “Last updated” date in the front matter changes, and the change history below records the change. For material changes, we notify users by email and post a prominent notice on the Service for at least 30 days before the change takes effect.

15. Change history

Contact