PRIVACY POLICY
This Privacy Notice for Synodi LLC ("we," "us," or "our") describes how and why we collect, store, use, and share ("process") your personal information when you use our services ("Services"), including when you:
- Visit our website at https://www.synodi.app or any website of ours that links to this Privacy Notice
- Download and use our mobile application (Synodi), or any other application of ours that links to this Privacy Notice
- Use Synodi — one app for the way you actually travel and share expenses
Synodi is a mobile application available on iOS and Android that helps friend groups, families, and social communities plan, organize, and manage shared trips and group experiences.
Group Expense Splitting — Users can create groups, add shared expenses, and calculate who owes what using a proportional participation model. Unlike traditional even-split tools, Synodi supports participation-based splits (dividing costs only among those who were present), lodging splits (prorating costs by nights stayed), and custom splits. The app calculates settlements using either a simplified algorithm that minimizes the number of transactions or a traditional method where each person pays each payer directly. Users can confirm payments as sent or received, store preferred payment handles for third-party services, and track settlement status in real time.
Trip Companion — Users can create private trip spaces and invite participants via unique trip invite links. Each trip includes expense tracking, an interactive event schedule, a collaborative grocery list, a document viewer for host-provided materials such as rental property instructions, and a photo gallery for participants to upload and share trip photos. Trip organizers can customize the visual appearance of their trip using built-in color and font themes. A community board feature allows organizers to enable group content including announcements, polls, shared posts, and an optional social deduction word game for trip participants.
Account Features — Synodi requires users to create an individual account using an email address and password. Users maintain a profile including a display name and payment handle information for third-party payment services. The application sends push notifications related to trip activity including expense updates, payment confirmations, trip invitations, and settlement reminders. Users may control notification preferences globally and on a per-trip basis.
The application does not process financial transactions directly — all payments occur outside the application through third-party payment services chosen by users such as Venmo, Cash App, and Zelle.
Questions or concerns? Reading this Privacy Notice will help you understand your privacy rights and choices. If you do not agree with our policies and practices, please do not use our Services. If you have any questions or concerns, please contact us at hello@synodi.app.
SUMMARY OF KEY POINTS
What personal information do we process? When you visit, use, or navigate our Services, we may process personal information depending on how you interact with us and the choices you make. Learn more about personal information you disclose to us.
Do we process any sensitive personal information? We collect account login credentials (email address and password) and payment handle information (such as your Venmo username or Cash App $cashtag). We do not collect financial account numbers, card numbers, or transaction amounts. Learn more about sensitive information we process.
Do we collect any information from third parties? We do not collect personal information from third-party data brokers, marketing partners, or public databases.
How do we process your information? We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law. Learn more about how we process your information.
With which parties do we share personal information? We may share information in specific situations with specific third parties. Learn more about when and with whom we share your personal information.
How do we keep your information safe? We implement appropriate technical and organizational measures to protect your personal information. However, no electronic transmission over the internet can be guaranteed to be 100% secure. Learn more about how we keep your information safe.
What are your rights? Depending on where you are located, applicable privacy law may give you certain rights regarding your personal information. Learn more about your privacy rights.
How do you exercise your rights? Email us at hello@synodi.app with the subject line "Data Request." We will consider and act upon any request in accordance with applicable data protection laws.
TABLE OF CONTENTS
- 1. WHAT INFORMATION DO WE COLLECT?
- 2. HOW DO WE PROCESS YOUR INFORMATION?
- 3. WHAT LEGAL BASES DO WE RELY ON TO PROCESS YOUR PERSONAL INFORMATION?
- 4. WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?
- 5. DO WE USE COOKIES AND OTHER TRACKING TECHNOLOGIES?
- 6. IS YOUR INFORMATION TRANSFERRED INTERNATIONALLY?
- 7. HOW LONG DO WE KEEP YOUR INFORMATION?
- 8. HOW DO WE KEEP YOUR INFORMATION SAFE?
- 9. DO WE COLLECT INFORMATION FROM MINORS?
- 10. WHAT ARE YOUR PRIVACY RIGHTS?
- 11. CONTROLS FOR DO-NOT-TRACK FEATURES
- 12. DO UNITED STATES RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS?
- 13. DO OTHER REGIONS HAVE SPECIFIC PRIVACY RIGHTS?
- 14. DO WE MAKE UPDATES TO THIS NOTICE?
- 15. HOW CAN YOU CONTACT US ABOUT THIS NOTICE?
- 16. HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?
1. WHAT INFORMATION DO WE COLLECT?
Personal information you disclose to us
We collect personal information that you provide to us.
We collect personal information that you voluntarily provide when you register on the Services, participate in activities on the Services, or otherwise contact us.
Personal Information Provided by You. The personal information we collect may include the following:
- Names and display names
- Email addresses
- Passwords (stored in encrypted form)
- Payment handle information (such as your Venmo username, Cash App $cashtag, or Zelle-linked phone number or email — stored as text only; we do not access your payment accounts)
Sensitive Information. We collect account login credentials (your email address and encrypted password) necessary to authenticate your account. We do not collect financial account numbers, credit or debit card numbers, bank routing numbers, or transaction data.
Payment Processing. Synodi does not process payments directly. All payments between users occur through third-party payment services of the user's choosing (such as Venmo, Cash App, or Zelle). We store only the payment handle you choose to display to other users (for example, your Venmo username) so that other group members know how to pay you. We do not collect, store, or have access to your payment account credentials, card details, or transaction history.
All in-app purchases (such as trip unlocks) are processed by Apple App Store and Google Play. You may find their privacy policies here: https://www.apple.com/legal/privacy/en-ww/ and https://policies.google.com/privacy. Synodi LLC does not collect, store, or process payment card information related to in-app purchases. We do not have access to your payment details.
Application Data. If you use our application, we may collect the following information if you choose to provide us with access or permission:
- Camera and Photo Library Access. We may request access to your device's camera and photo library to allow you to upload receipt photos and trip photos. If you wish to change our access, you may do so in your device's settings.
- Push Notifications. We may request to send you push notifications regarding your account and trip activity, including expense updates, payment confirmations, and settlement reminders. If you wish to opt out, you may turn off notifications in your device's settings.
- Mobile Device Data. We automatically collect certain device information such as your mobile device model, operating system version, device identifiers, and IP address. This information is needed to maintain the security and operation of our application and for troubleshooting purposes.
All personal information that you provide to us must be true, complete, and accurate, and you must notify us of any changes to such personal information.
Information automatically collected
Some information is collected automatically when you visit or use our Services.
We automatically collect certain information when you visit, use, or navigate the Services. This information does not reveal your specific identity but may include device and usage information such as your IP address, device characteristics, operating system, language preferences, and information about how and when you use our Services. We use IP address information to determine your approximate country or region for the purpose of applying applicable privacy laws. We do not collect precise GPS location data.
- Log and Usage Data. Our servers automatically collect log data when you access or use our Services, including your IP address, device information, browser type, and information about your activity in the Services such as date and time stamps and features accessed.
- Device Data. We collect information about the device you use to access the Services, including device model, operating system, device identifiers, and IP address.
Cookies and tracking on our website
Our website at synodi.app uses Google Analytics to understand how visitors interact with our site. Google Analytics uses cookies — small text files stored on your device — to collect information such as pages visited, time spent on the site, and general geographic location based on IP address. This information is used in aggregate form and is not linked to your Synodi account.
You can opt out of Google Analytics tracking by installing the Google Analytics Opt-out Browser Add-on at https://tools.google.com/dlpage/gaoptout. Our mobile application does not use cookies.
When you log in to your Synodi account via synodi.app (available January 2027), your session is maintained using authentication tokens managed by Supabase. These function similarly to cookies and are necessary for the operation of your account session.
2. HOW DO WE PROCESS YOUR INFORMATION?
We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law.
We process your personal information for the following purposes:
- To facilitate account creation and authentication. We process your email address and encrypted password to create and maintain your account.
- To deliver our Services. We process your information to provide the expense splitting, trip companion, and community features you use.
- To respond to user inquiries and offer support. We process your information to respond to your questions and resolve issues.
- To send administrative communications. We may process your information to send you details about changes to our terms and policies and other service-related information.
- To send push notifications. We send notifications related to your trip activity, including expense updates, payment confirmations, trip invitations, and settlement reminders, based on your notification preferences.
- To protect our Services. We may process your information as part of our efforts to keep our Services safe and secure, including fraud monitoring and prevention.
- To identify usage trends. We may process information about how you use our Services to improve them.
- To comply with legal obligations. We may process your information where required by applicable law.
3. WHAT LEGAL BASES DO WE RELY ON TO PROCESS YOUR PERSONAL INFORMATION?
We only process your personal information when we have a valid legal reason to do so.
If you are located in the EU or UK:
The GDPR and UK GDPR require us to explain the legal bases we rely on to process your personal information:
- Performance of a Contract. We process your personal information when necessary to fulfill our contractual obligations to you, including providing our Services.
- Legitimate Interests. We may process your information when reasonably necessary to achieve our legitimate business interests, such as improving our Services, maintaining security, and diagnosing technical issues, provided those interests do not outweigh your fundamental rights and freedoms.
- Consent. We may process your information if you have given us permission for a specific purpose, such as receiving marketing communications. You can withdraw your consent at any time by contacting us at hello@synodi.app.
- Legal Obligations. We may process your information where necessary for compliance with our legal obligations, such as cooperating with law enforcement or defending our legal rights.
If you are located in Canada:
We may process your information if you have given us specific permission to do so, or in situations where your permission can be inferred. You can withdraw your consent at any time by contacting us at hello@synodi.app.
4. WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?
We share information only in the specific situations described in this section.
- Service Providers. We share information with third-party service providers who assist us in operating our Services, including Supabase (database and authentication infrastructure). These providers are bound by contractual obligations to keep your information confidential and use it only for the purposes for which we have engaged them.
- Analytics Providers. We use Google Analytics on our website (synodi.app) to understand how visitors interact with our site. Google Analytics receives anonymized usage data. We do not share your Synodi account data with Google Analytics.
- Business Transfers. We may share or transfer your information in connection with a merger, sale, financing, or acquisition of all or a portion of our business.
- Legal Requirements. We may disclose your information where required by law, court order, or governmental authority, or where necessary to protect the rights, property, or safety of Synodi, our users, or others.
We do not sell your personal information. We do not share your personal information with third-party advertising networks.
5. DO WE USE COOKIES AND OTHER TRACKING TECHNOLOGIES?
Our website uses Google Analytics cookies. Our mobile application does not use cookies.
Website (synodi.app): Our website uses Google Analytics, which places cookies on your device to collect anonymized information about how visitors use the site. No personally identifiable information is collected through these cookies. You can opt out at https://tools.google.com/dlpage/gaoptout. When our web login launches (January 2027), session authentication tokens will also be used to maintain your logged-in state. These are necessary for account security and cannot be disabled while using the web app.
Mobile Application: The Synodi mobile app does not use cookies or web beacons. Session management in the app is handled through Supabase authentication tokens stored securely on your device.
We do not use tracking technologies for advertising purposes and do not permit third-party advertising networks to place tracking technologies on our Services.
6. IS YOUR INFORMATION TRANSFERRED INTERNATIONALLY?
We may transfer, store, and process your information in countries other than your own.
Our infrastructure is provided by Supabase, with servers located in the United States. If you are a resident of the European Economic Area (EEA), United Kingdom (UK), or Switzerland, please be aware that your information will be transferred to and processed in the United States, which may not have data protection laws as comprehensive as those in your country.
We have implemented appropriate safeguards for international transfers, including relying on Supabase's Data Processing Addendum, which incorporates the European Commission's Standard Contractual Clauses. Our Standard Contractual Clauses can be provided upon request by emailing hello@synodi.app.
7. HOW LONG DO WE KEEP YOUR INFORMATION?
We keep your information for as long as necessary to fulfill the purposes outlined in this Privacy Notice.
We retain your personal information for as long as your account is active or as needed to provide our Services. Following account deletion, we will delete or anonymize your personal information within 30 days, except where a longer retention period is required by law (such as for tax, accounting, or legal compliance purposes).
When we have no ongoing legitimate business need to process your personal information, we will delete or anonymize it. If deletion is not immediately possible (for example, because your information has been stored in backup archives), we will securely isolate it from further processing until deletion is possible.
8. HOW DO WE KEEP YOUR INFORMATION SAFE?
We implement appropriate technical and organizational security measures to protect your personal information.
We use Supabase as our database and authentication infrastructure, which maintains SOC 2 Type II certification and implements industry-standard encryption for data at rest and in transit. We enforce Row Level Security policies to ensure users can only access data from groups and trips they belong to. Passwords are stored in encrypted form and we do not have access to your plaintext password.
Despite our safeguards, no electronic transmission over the internet or information storage technology can be guaranteed to be 100% secure. We cannot guarantee that unauthorized third parties will never be able to defeat our security measures. You should only access the Services within a secure environment and should use a strong, unique password for your Synodi account.
9. DO WE COLLECT INFORMATION FROM MINORS?
We do not knowingly collect data from or market to children under 18 years of age.
We do not knowingly collect, solicit data from, or market to children under 18 years of age. By using the Services, you represent that you are at least 18 years of age, or that you are the parent or legal guardian of a minor and consent to that minor's use of the Services. If we learn that personal information from a user under 18 has been collected, we will deactivate the account and take reasonable measures to promptly delete such data. If you believe we may have collected information from a child under 18, please contact us at hello@synodi.app.
10. WHAT ARE YOUR PRIVACY RIGHTS?
Depending on your location, you may have rights that allow you greater access to and control over your personal information.
EEA, UK, Switzerland, and Canada: You have the right to request access to and obtain a copy of your personal information, request correction or erasure of your personal information, restrict or object to our processing of your personal information, and request data portability where applicable. To make such a request, email hello@synodi.app with the subject line "Data Request."
Withdrawing consent: Where we rely on your consent to process your personal information, you may withdraw that consent at any time by contacting us at hello@synodi.app. Withdrawal of consent does not affect the lawfulness of processing that occurred before the withdrawal.
Opting out of marketing communications: You can unsubscribe from marketing emails at any time by clicking the unsubscribe link in those emails or by contacting us at hello@synodi.app. We may still send you service-related communications necessary for the operation of your account.
Account information: You may review or update your account information by logging into your account settings at any time. To delete your account, you may do so through the account deletion feature within the app, or by emailing hello@synodi.app. We will process account deletion requests within 30 days.
UK residents: If you are unhappy with how we have handled your personal information, you may contact the Information Commissioner's Office at ico.org.uk/make-a-complaint or by calling 0303 123 1113.
EEA residents: You have the right to complain to your Member State data protection authority at https://ec.europa.eu/justice/data-protection/bodies/authorities/index_en.htm.
Swiss residents: You may contact the Federal Data Protection and Information Commissioner at https://www.edoeb.admin.ch/edoeb/en/home.html.
If you have questions or comments about your privacy rights, please email us at hello@synodi.app.
11. CONTROLS FOR DO-NOT-TRACK FEATURES
Most web browsers and some mobile operating systems include a Do-Not-Track ("DNT") feature you can activate to signal your preference not to have your online browsing activities monitored and collected. No uniform technology standard for recognizing and implementing DNT signals has been finalized, and we do not currently respond to DNT signals. If a standard is adopted that we are required to follow, we will update this Privacy Notice accordingly.
Global Privacy Control: We recognize and honor Global Privacy Control (GPC) signals. If you use a browser or extension that supports GPC, we will treat this as a valid request to opt out of the sale or sharing of your personal information for targeted advertising purposes under applicable state privacy laws, including CCPA. We do not sell personal information or use it for targeted advertising, so GPC signals will have no material effect on your experience.
12. DO UNITED STATES RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS?
If you are a resident of California, Colorado, Connecticut, Oregon, or other US states with applicable privacy laws, you may have specific rights regarding your personal information.
Categories of Personal Information We Collect
| Category | Examples | Collected |
|---|---|---|
| A. Identifiers | Name, email address, account name, IP address | YES |
| B. Personal information as defined in the California Customer Records statute | Name, contact information | YES |
| C. Protected classification characteristics | Gender, age, race, ethnicity | NO |
| D. Commercial information | Transaction history, purchase history, financial details | NO |
| E. Biometric information | Fingerprints, voiceprints | NO |
| F. Internet or other similar network activity | Browsing history, search history, app usage data | YES |
| G. Geolocation data | Precise device location | NO |
| H. Audio, electronic, sensory, or similar information | Images uploaded by users (receipt photos, trip photos) | YES |
| I. Professional or employment-related information | Job title, work history | NO |
| J. Education information | Student records | NO |
| K. Inferences drawn from collected personal information | User preferences or characteristics | NO |
| L. Sensitive personal information | Account login credentials (email and encrypted password); payment handle information | YES |
We collect sensitive personal information only as necessary to provide our Services — specifically, account login credentials to authenticate your account and payment handle information (such as your Venmo username) to display to other group members. We do not use sensitive personal information for any purpose beyond what is necessary to operate the Services.
We will retain collected personal information for as long as your account is active, and for up to 30 days following account deletion, except where a longer period is required by law.
Your Rights
You have rights under applicable US state privacy laws, including:
- Right to know whether we are processing your personal data
- Right to access your personal data
- Right to correct inaccuracies in your personal data
- Right to request deletion of your personal data
- Right to obtain a copy of the personal data you previously shared with us
- Right to non-discrimination for exercising your rights
- Right to opt out of the sale of personal data or its use for targeted advertising (we do not sell personal data or use it for targeted advertising)
Oregon residents may additionally request a list of specific third parties to which we have disclosed personal data, in accordance with Oregon's Consumer Privacy Act.
How to Exercise Your Rights
To exercise any of these rights, email hello@synodi.app with the subject line "Data Request" and describe your request. We will verify your identity and respond within the timeframe required by applicable law. You may also designate an authorized agent to submit a request on your behalf with appropriate written authorization.
Appeals
If we decline to take action regarding your request, you may appeal by emailing hello@synodi.app with the subject line "Data Request Appeal." We will inform you in writing of the outcome. If your appeal is denied, you may submit a complaint to your state attorney general.
California "Shine The Light" Law
California Civil Code Section 1798.83 permits California residents to request information about personal information disclosed to third parties for direct marketing purposes. We do not disclose personal information to third parties for direct marketing purposes.
13. DO OTHER REGIONS HAVE SPECIFIC PRIVACY RIGHTS?
Australia and New Zealand
We collect and process your personal information in accordance with Australia's Privacy Act 1988 and New Zealand's Privacy Act 2020. If you believe we are unlawfully processing your personal information, you have the right to submit a complaint to the Office of the Australian Information Commissioner at https://www.oaic.gov.au/privacy/privacy-complaints or to the Office of New Zealand Privacy Commissioner at https://www.privacy.org.nz/your-rights/making-a-complaint/.
Republic of South Africa
If you are unsatisfied with how we address any complaint regarding our processing of your personal information, you may contact the Information Regulator of South Africa at enquiries@inforegulator.org.za.
14. DO WE MAKE UPDATES TO THIS NOTICE?
Yes, we will update this notice as necessary to stay compliant with relevant laws.
We may update this Privacy Notice from time to time. The updated version will be indicated by an updated date at the top of this Notice. If we make material changes, we will notify you either by posting a prominent notice on our Services or by sending you a direct notification. We encourage you to review this Privacy Notice periodically.
15. HOW CAN YOU CONTACT US ABOUT THIS NOTICE?
If you have questions or comments about this notice, please email us at hello@synodi.app.
Synodi LLC
Portland, Oregon
United States
16. HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?
Based on the applicable laws of your country or state of residence, you may have the right to request access to the personal information we collect from you, correct inaccuracies, or delete your personal information. You may also have the right to withdraw your consent to our processing of your personal information.
To make any of these requests, email hello@synodi.app with the subject line "Data Request." We will respond within the timeframe required by applicable law. You may also delete your account directly through the account deletion feature within the Synodi app.