Welcome to the Privacy Policy for Prima Terra S.R.L. ("we," "us," or "our"). We operate the website located at synapsemail.app (the "Website") and develop the Synapse desktop email application (the "Application").
Our corporate philosophy is rooted in Privacy by Architecture, not by Promise. This Privacy Policy outlines how we treat data across both our zero-knowledge Application and our promotional Website.
1. Data Controller Details
In compliance with the European Union General Data Protection Regulation (GDPR) and the Italian Privacy Code (Legislative Decree no. 196/2003, as amended), the Data Controller for any personal data collected via our digital touchpoints is:
Prima Terra S.R.L.
Corso Castelfidardo 22, 10128 Torino, Italy
Contact Email: support+synapseprivacy@primaterra.biz
2. The Synapse Application Architecture (Zero-Knowledge)
The Application is a Windows-exclusive, local-first software program executed entirely on your personal computer hardware.
A. Zero Cloud Exposure
- No Centralized Syncing: All email synchronization, full-text database caching, and operational protocols occur locally on your physical machine.
- No Metadata Transmission: Prima Terra does not operate or maintain cloud infrastructure to process, store, index, or intercept your email content, subject lines, metadata, or contacts.
B. On-Device AI Inference
- Localized Processing: All AI-driven functionality, including smart reply drafting and semantic search, utilizes local embedded language models (such as Qwen) accelerated exclusively by your device's physical CPU, GPU, or NPU.
- No Model Training: Your communications are never transmitted to Prima Terra or any third-party AI provider, and are never utilized to train, tune, or refine machine learning models.
C. Hardware-Grade Security
- Cryptographic Vaulting: Your sensitive credentials, application configurations, passwords, and OAuth tokens are isolated in a local SQLCipher-encrypted database vault.
- TPM 2.0 Binding: This cryptographic vault is sealed directly to your physical computer's Windows Trusted Platform Module (TPM 2.0) chip. Prima Terra holds no master keys and cannot recover this data under any circumstances.
3. Website Processing & Marketing Activities
When you interact with our Website or subscribe to our newsletter, we collect limited personal data. This data is entirely separate from the Synapse Application.
A. Newsletter Subscription Data
- Data Collected: Your email address and, optionally, your name.
- Delivery Infrastructure: We host our email marketing system locally using the Sendy platform, routing final delivery via Amazon Web Services (AWS) Simple Email Service (SES) nodes located within the European Union.
- Italian Garante Pixel Compliance: In strict adherence to the Italian Data Protection Authority's (Garante per la protezione dei dati personali) guidelines, we disable individualized behavioral email tracking pixels by default. Aggregate email campaign statistics are fully anonymized.
- Legal Basis: Processing is based strictly on your explicit, affirmative consent (GDPR Article 6(1)(a)).
- Retention & Opt-Out: We retain your email address until you withdraw consent. You may unsubscribe instantly at any time by clicking the "unsubscribe" link embedded in our emails or by contacting support+synapseprivacy@primaterra.biz.
4. Website Cookies, Analytics, and Advertising Pixels
To optimize our web presentation and measure marketing performance, our Website integrates deployment scripts from third-party platforms.
A. Implemented Tools
- Google Analytics (GA4): Used to evaluate aggregate traffic patterns and website usage statistics on synapsemail.app.
- Meta Pixel: Used to measure the efficacy of advertising campaigns and deliver relevant marketing placements on Meta-affiliated platforms.
B. Prior Blocking & Consent Framework
- Strict Prior Blocking: In compliance with European and Italian cookie laws, all Google Analytics and Meta Pixel scripts are blocked by default and will not execute or drop cookies upon landing on our Website.
- Granular Consent: These tracking mechanisms will only activate if you provide explicit, affirmative, and granular consent via our Consent Management Platform (CMP) cookie banner.
- Absolute Separation: No behavioral analytics or tracking profiles generated by these website tools are ever transmitted to, combined with, or visible to the Synapse Application.
5. Third-Party Application Integrations
The Application permits the utilization of productivity plugins (including but not limited to Asana and ClickUp).
- Direct Local Routing: These integrations operate via localized token data-tasking protocols.
- No Proxy Storage: Data exchanged via these integrations routes directly from your local hardware to the respective third-party secure APIs. Prima Terra never serves as an intermediary proxy host, does not view these transfers, and assumes no liability for the data processing practices of external software vendors.
6. Your Rights Under the GDPR
As a data subject located within the EEA, you possess the following rights regarding the personal data we hold about you (i.e., your newsletter registration):
- Article 15 GDPR (Right of Access): Request a copy of your personal data.
- Article 16 GDPR (Right to Rectification): Correct inaccurate or incomplete data.
- Article 17 GDPR (Right to Erasure / "Right to be Forgotten"): Request permanent deletion of your data from our Sendy/AWS databases.
- Article 21 GDPR (Right to Object): Object to direct marketing at any moment.
To exercise these rights, submit an explicit request to support+synapseprivacy@primaterra.biz. We will process your verified request within 30 days.
7. Security Limitations & User Responsibility
While the Synapse Application establishes local, hardware-grade protective barriers (SQLCipher and TPM 2.0 binding), the overall security posture depends on the integrity of your local machine.
Legal Disclaimer: Prima Terra S.R.L. cannot protect your data against local device compromise. You maintain sole and exclusive responsibility for implementing operating system security controls (such as strong Windows account credentials and BitLocker drive encryption), maintaining physical possession of your hardware, and keeping your machine free of malicious software, rootkits, or unauthorized remote management vectors.
8. Amendments to This Policy
We reserve the right to modify this Privacy Policy to align with architectural evolutions or updated directives from the Italian Garante. Any updates will be published on this webpage with a revised effective date.