Your data
Security and privacy
Synapse is built to work locally: there's no Synapse account, and the app doesn't send us information about you or how you use it. This is what's encrypted, what verifies what, and what does cross the network.
Encryption at a glance
| What | How |
|---|---|
| Vault (passwords, keys, API keys) | AES-256-GCM, key from your master password via Argon2id (64 MiB, 3 passes); vaults from older versions (PBKDF2-SHA256) are upgraded automatically on the next unlock |
| Encrypted backup file (Back up everything) | AES-256-GCM, key from the backup password via Argon2id (64 MiB, 3 passes); older PBKDF2-SHA256 files still restore |
| Sync between devices and Teams | XChaCha20-Poly1305, with Ed25519/X25519 device keys; encrypted before upload |
| Cloud backup (0.2.6) | A random data key, wrapped separately by your master password (Argon2id) together with a 128-bit Secret Key made on your computer, and by a 24-word recovery phrase |
| Automatic local backups | Not encrypted, and never include passwords, keys or passphrases |
Not you, not Maku. Without it, the vault - and a Cloud backup made from it - stays locked, unless you also have the 24-word recovery phrase from Cloud backup setup. Keep both in a password manager. See Vault and master password and Backups and restore.
Without a master password set, credentials are stored unencrypted on your device - setting one is the single biggest thing you can do to secure a Synapse install.
Verifying a server
Synapse checks every server's SSH host key against known_hosts, the same file OpenSSH
uses. The first connection asks you to confirm the fingerprint; if a server's key ever changes
afterwards, Synapse refuses to connect rather than silently trusting the new one, since that can mean
someone is intercepting the connection. See Hosts and connections.
What leaves your computer
- Your servers - Synapse connects directly from your computer to the hosts you choose, over SSH.
- AI providers, only if you use Relay - if you add an API key for Anthropic, OpenAI, Gemini, xAI or another endpoint, your messages and any terminal output you choose to attach go straight to that provider. Relay never sends your vault's contents, and commands it suggests only run after you approve them unless you turn on auto-run.
- Voice dictation, only if you turn it on - by default, speech is transcribed on your computer and the audio never leaves it. Choosing OpenAI, Gemini or Grok as the engine instead sends each recording to that provider.
- synapse.maku.au - unless you turn update checks off in Settings, Synapse asks whether a newer version exists at startup and every six hours, and Relay fetches a public list of model names at most once a day. These requests carry only your IP address and the app's version - no account, host or usage information.
No telemetry: Synapse contains no analytics, crash reporting or advertising code.
Updates
Synapse checks for updates itself and installs them automatically once you approve. Every update is cryptographically signed, and Synapse only installs one if the signature matches - it won't run an installer that's been tampered with. See Troubleshooting if Windows warns you about the installer itself.
Reporting an issue
If you find a security issue, contact Maku via maku.au. For how the website itself handles data, see the Privacy note.