Privacy note
Last updated 28 September 2026 · applies to Synapse 0.2 and later, and synapse.maku.au
Synapse is an SSH client made by Maku. It is built to work locally: there is no Synapse account, and the app does not send us information about you or how you use it. This note explains what the app stores, what it connects to, and what this website collects.
What the app stores on your device
- Hosts and settings - the servers you save (name, address, port, username, options), your workspaces, snippets, preferences and command history are stored on your computer.
- Credentials - passwords, private keys, key passphrases and AI API keys are kept in the Synapse vault, separate from the host list. If you set a master password, the vault is encrypted with AES-256-GCM using a key derived from that password (Argon2id, 64 MiB, 3 passes; vaults from older versions are upgraded automatically on the next unlock). If you don’t set one, credentials are stored unencrypted on your device - we recommend setting a master password.
- Automatic backups - Synapse keeps recent backups of your hosts, groups, workspaces, snippets and settings in its own folder on your computer, without passwords or keys. They never leave your device.
- Unless you turn on Cloud backup or sync (below), we never receive a copy of any of this, and even then only in a form we can't read. We can’t recover a forgotten master password.
What the app connects to
- Your servers - Synapse connects directly from your computer to the hosts you choose, over SSH.
- AI providers, only if you use Relay - if you add an API key for Anthropic, Google, OpenAI, xAI or another endpoint (or point Relay at a local model), your messages and any terminal output you choose to attach are sent directly to that provider and handled under its privacy terms. Relay never sends your vault contents, and commands it suggests only run after you approve them unless you turn on auto-run.
- Voice dictation, only if you turn it on - by default speech is transcribed on your computer and the audio never leaves it. The speech model is downloaded once from Hugging Face (huggingface.co), where the whisper.cpp project publishes it, when you choose to. If you pick OpenAI, Gemini or Grok as the engine instead, each recording is sent to that provider with your API key and handled under its privacy terms. Recordings are kept in memory only and discarded after transcription.
- synapse.maku.au - unless you turn update checks off in Settings, Synapse asks this site whether a newer version exists when it starts and every six hours. Relay settings also fetch a public list of AI model names from it, at most once a day. These requests carry only what any web request does (your IP address and the app's version); no account, host or usage information is sent. Updates are signed, and only install when you choose.
- No telemetry - the app contains no analytics, crash reporting or advertising code.
Sync between devices
Sync between devices and Teams are optional and off until you switch them on. They are end-to-end encrypted: your hosts, snippets, settings and vault are encrypted on your device (XChaCha20-Poly1305) before anything is uploaded, and the keys never leave your devices. Devices are paired with a one-time code and a matching verification code shown on both screens.
- What our server stores - encrypted records with random ids and version numbers, each device's public key, and the encrypted list of devices or team members. We can't read any of it: no host names, passwords, keys or other content.
- What it can see - how many records you have and their approximate sizes, when devices connect, and the IP address of each request. The mailbox keeps the IP address only as a salted hash for rate limiting; like any request to this site, it also appears in the standard web server logs described below.
- Removing data - "Delete sync data from the mailbox" in the app erases it from the server. Removing a device or team member replaces the encryption key so it can't read anything new.
- Unused data is deleted - if none of the devices or members in a sync space or team connects to the server for 400 days, it is deleted with everything in it. Your devices keep their own copies.
- Agents on your phone - only if you turn on "Show agents on my phone" in the Agent hub, your desktop also syncs a short summary of your AI agents (name, host, status and any question waiting for you, with secrets removed) as encrypted records, and receives your answers the same way. No terminal output is included.
- Your own server - you can run the same mailbox on your own hosting and point Synapse at it instead.
Cloud backup
Cloud backup is optional and off until you switch it on. Synapse encrypts a copy of your hosts, settings and vault on your computer (XChaCha20-Poly1305) before sending it to our backup server at synapse.maku.au. The key that opens it is itself locked with your master password together with a Secret Key made on your computer, or with your 24-word recovery phrase. None of these ever leaves your computer, so we can't read your backup, and because of the Secret Key nobody who gets a copy of our server's data can open it by guessing your password. Your Secret Key and recovery phrase are in the Emergency Kit Synapse shows you to save.
- Your email address - to link the backup to you, we store a keyed hash of your email address, not the address itself. We use the address only to send you a one-time code when you set up, restore or delete your backup. These emails are plain text, with no tracking and no marketing.
- What our server keeps - the latest encrypted backup and the three before it, with their size (rounded) and upload time, until you delete them. Deleting your backup in Synapse removes it straight away. A backup that no computer has uploaded to or checked on for 400 days is deleted.
- Emails we send - besides one-time codes, we email you a short notice when your backup is set up on another computer or deleted with an emailed code, so you'd know if it wasn't you. To do this without keeping your address, it's stored only with the short-lived (15 minute) sign-in token and sealed with a key that only your app has.
- What the Secret Key id is - the first five characters after "S1-" of your Secret Key are a random label, not part of the secret. We store it with your backup so Synapse can tell you which Emergency Kit to use.
- If you lose your keys - if you lose your master password or your Secret Key, and also your recovery phrase, nobody, including us, can open the backup.
This website
- No cookies, analytics, trackers or third-party scripts. Fonts are served from this site.
- Our web server keeps standard access logs (IP address, date and time, the page or file requested, and your browser’s user agent) to keep the site secure and working. We don’t use them to build profiles or share them with anyone for marketing.
Questions
If you have a question about privacy or want to report a security issue, contact Maku via maku.au.