operome.dev

Privacy Policy

This policy explains what personal data SynapseLayer processes when you visit operome.dev, use a demonstrator, submit an assessment or contact us.

Effective 27 July 2026

1. Who is responsible for your data

operome.dev is operated under the SynapseLayer name (“SynapseLayer”, “we”, “us”). For the processing described in this policy, SynapseLayer is the data controller unless a different role is stated when data is collected.

For privacy questions or to exercise your rights, email rk@synapselayer.ai. You can also find current company information at synapselayer.ai.

2. Data we collect

Depending on how you use the Service, we may collect:

  • Account and contact data: your email address, account identifier, authentication records, consent choices and communications with us.
  • Inputs and outputs: text, questionnaire answers, selected options, files, public URLs, intended-purpose descriptions, evaluation facts, generated materials, results, traces, exports and result identifiers.
  • EU AI Act Classifier audit data: every value entered or selected and relevant interface action; proposed and confirmed facts; extraction, registration and classification events; client and server times; IP address; browser user-agent; referring page; page path; submitted source URL; session identifier; and evaluation identifier where available. This includes an email address as it is typed into the result-unlock form, before the consent box is selected or the form is submitted. Events are initially associated with a pseudonymous browser session. If you submit the form, the session is also associated with your email and the email may be used for the contact you authorised. If you abandon the form, the typed email remains part of the restricted audit record but is not used as a contact address on that basis.
  • Miami demonstrator audit data: property and project details, addresses, values entered or selected, chat messages, generated answers and outcomes, and relevant interface actions; together with client and server times, IP address, browser user-agent, referring page, page path and a pseudonymous session identifier. If you submit an email, the session and its earlier events may be associated with it.
  • Other demonstrator submissions: information supplied to request API access, receive an assessment, join a demonstration or ask us to contact you.
  • Technical and usage data: IP address, approximate location derived from it, date and time, visited pages, referring link, device, operating system, browser, screen information, session activity, security events and diagnostic records.
  • Browser storage: cookie identifiers, authentication state, display preferences, saved demo state and other local settings described below.

Please do not submit confidential information, credentials, special-category data, or personal data about another person unless the relevant screen expressly requests it and you are authorised to provide it.

3. How we use personal data and our legal bases

  • To provide the feature you request: operate accounts and demonstrators, retrieve a submitted public URL, generate and deliver outputs, register results and respond to support requests. We rely on performance of a contract or steps you ask us to take before entering one.
  • To maintain integrity, safety and security: preserve evaluation evidence, prevent abuse, enforce rate limits, investigate errors and protect users and the Service. This includes recording values as they are entered—including an email typed into the classifier unlock form before submission—to support security monitoring, investigation and reconstruction of the interaction. We rely on our legitimate interests in running a secure, trustworthy demonstration environment. We do not rely on consent for this audit logging; consent requested by the form governs registration and contact.
  • To improve the Service: understand how features are used, diagnose problems and improve questions, interfaces and technical performance. We rely on our legitimate interests, while taking account of the nature of the data and your rights.
  • To communicate with you: send requested results, access information or operational messages, and contact you about a product or assessment where you have agreed to that contact. We rely on the requested service, consent where the screen asks for it, or our legitimate interests for closely related operational communications.
  • To meet legal requirements: comply with law, protect legal rights and respond to lawful requests. We rely on legal obligations and our legitimate interests in establishing, exercising or defending legal claims.

Where processing is based on consent, you may withdraw it at any time. Withdrawal does not make earlier processing unlawful.

4. Website analysis and AI providers

If you submit a public website to the EU AI Act Classifier, we retrieve pages associated with that URL. The submitted URL and retrieved public-page text may be sent through our managed AI service to the model provider disclosed in the review screen. The current configuration may change and can use providers such as OpenAI, Anthropic or Google.

Generative AI is used only to propose facts from public material. You must review those proposals. The final classifier result is produced from confirmed facts by versioned, deterministic operome rules rather than by a generative AI model. See the EU AI Act Classifier Conditions for important limitations.

5. Who receives personal data

We disclose data only where reasonably necessary to:

  • infrastructure and database providers, including Lovable and Supabase, which host and operate parts of the Service;
  • AI and public-page processing providers used for a feature you request, with the configured model disclosed where the classifier performs website analysis;
  • email delivery providers, including Resend where configured, for requested messages and administrator notifications;
  • StatCounter, which provides website audience measurement as described below;
  • professional advisers, contractors and service providers bound by appropriate confidentiality or data-protection duties; and
  • courts, regulators, law enforcement or other parties where required by law or reasonably necessary to protect rights, safety or the Service.

We do not sell your personal data. If the business or Service is reorganised, financed, sold or transferred, relevant data may be disclosed under appropriate safeguards.

6. International transfers

Some providers may process data outside the United Kingdom or European Economic Area. Where data-protection law requires it, we use an applicable adequacy decision, contractual safeguards such as approved standard contractual clauses, or another lawful transfer mechanism. You may contact us for more information about safeguards relevant to your data.

7. Cookies and local storage

The Service currently uses the following browser technologies:

  • Authentication and security: Supabase authentication and related storage keep signed-in users authenticated and protect restricted tools.
  • Classifier audit cookie: a secure, HttpOnly pseudonymous identifier, kept for up to 180 days, links EU classifier events from the same browser session.
  • Miami demonstrator audit cookie: a secure, HttpOnly pseudonymous identifier, kept for up to 180 days, links inputs, actions and outcomes from the same browser session on the Miami demonstrator. If you later submit an email, the session and its earlier events may be associated with it.
  • Classifier remembered-access cookie: a separate secure, HttpOnly identifier, kept for up to 180 days, lets the server retrieve an email previously supplied by that browser when you explicitly revise an assessment. The cookie does not contain the email address.
  • Preferences and demo state: cookies or local storage remember settings such as theme, sidebar state, progress and locally saved demonstration data. The sidebar preference lasts up to seven days; local items generally remain until you clear them or the application replaces them.
  • StatCounter analytics: StatCounter receives technical and usage data such as IP address, time, visited page, referrer, device and browser information. Its unique-visitor cookies distinguish first-time and returning visits. StatCounter states that its third-party is_unique cookie can last five years and its first-party sc_is_visitor_unique cookie can last two years. See StatCounter’s cookie information.

You can block or delete cookies and local storage using your browser settings, but some functionality may then stop working or forget your preferences. Browser controls can also be used to block third-party analytics cookies.

8. Retention

We keep personal data only for as long as reasonably necessary for the purposes described above, taking account of the nature of the data, security and evidential needs, user expectations and applicable legal requirements.

  • Account and project data is normally kept while the account or service relationship is active and for a reasonable period afterwards for backups, security and legal claims.
  • Classifier registrations and classifier or Miami demonstrator audit events are kept while reasonably needed to preserve the integrity of results, provide support, prevent abuse, improve the demonstrators and meet legal requirements. We periodically review whether continued retention is necessary.
  • Contact and assessment submissions are kept while we deal with the request and for a reasonable follow-up and record-keeping period.
  • Browser cookies expire as described above. You may remove local storage and cookies sooner through your browser.

Provider backups and security logs may remain for a limited additional period before deletion or irreversible anonymisation.

9. Security

We use technical and organisational measures intended to protect data, including access controls, restricted administration areas, encrypted transport, pseudonymous browser tokens and database permissions. No internet service is completely secure, and we cannot guarantee that unauthorised access or loss will never occur.

Registered classifier permalinks may be accessible to anyone who receives the link. Do not register or share information you are not authorised to disclose.

10. Your rights

Depending on where you live and the circumstances, you may have rights to request access, correction, deletion, restriction or portability of your personal data; object to certain processing; and withdraw consent. You may also complain to the data-protection authority where you live or work, or where you believe an infringement occurred. In the United Kingdom, this is the Information Commissioner’s Office.

Email rk@synapselayer.ai to make a request. We may need to verify your identity and may retain limited information where required by law or to protect another person’s rights.

11. Automated results

Demonstrators can automatically calculate informational results from the facts supplied. They are not used by SynapseLayer to make decisions about you that produce legal or similarly significant effects. You remain responsible for reviewing outputs and deciding whether and how to use them.

12. Children

The Service is intended for professional users and is not directed to children. Do not use it to submit personal data about a child.

13. Other sites and changes to this policy

Links to other sites are provided for convenience. Their operators control their own privacy practices. We may update this policy when the Service or legal requirements change. The effective date shown at the top identifies the current version.