Your data

Security and privacy

Synapse is built to work locally: there's no Synapse account, and the app doesn't send us information about you or how you use it. This is what's encrypted, what verifies what, and what does cross the network.

Encryption at a glance

WhatHow
Vault (passwords, keys, API keys)AES-256-GCM, key from your master password via Argon2id (64 MiB, 3 passes); vaults from older versions (PBKDF2-SHA256) are upgraded automatically on the next unlock
Encrypted backup file (Back up everything)AES-256-GCM, key from the backup password via Argon2id (64 MiB, 3 passes); older PBKDF2-SHA256 files still restore
Sync between devices and TeamsXChaCha20-Poly1305, with Ed25519/X25519 device keys; encrypted before upload
Cloud backup (0.2.6)A random data key, wrapped separately by your master password (Argon2id) together with a 128-bit Secret Key made on your computer, and by a 24-word recovery phrase
Automatic local backupsNot encrypted, and never include passwords, keys or passphrases
Nobody can recover a forgotten master password

Not you, not Maku. Without it, the vault - and a Cloud backup made from it - stays locked, unless you also have the 24-word recovery phrase from Cloud backup setup. Keep both in a password manager. See Vault and master password and Backups and restore.

Without a master password set, credentials are stored unencrypted on your device - setting one is the single biggest thing you can do to secure a Synapse install.

Verifying a server

Synapse checks every server's SSH host key against known_hosts, the same file OpenSSH uses. The first connection asks you to confirm the fingerprint; if a server's key ever changes afterwards, Synapse refuses to connect rather than silently trusting the new one, since that can mean someone is intercepting the connection. See Hosts and connections.

What leaves your computer

No telemetry: Synapse contains no analytics, crash reporting or advertising code.

Updates

Synapse checks for updates itself and installs them automatically once you approve. Every update is cryptographically signed, and Synapse only installs one if the signature matches - it won't run an installer that's been tampered with. See Troubleshooting if Windows warns you about the installer itself.

Reporting an issue

If you find a security issue, contact Maku via maku.au. For how the website itself handles data, see the Privacy note.