Legal
Privacy policy
Synapse is designed to touch as little health information as possible. This page describes what we collect, how we store it, how it is shared, and the choices you have.
Pilot version — under counsel review. Synapse is operating a limited South Carolina pilot. This policy describes how the product behaves today. Material changes will be posted here with a new effective date and, where the change affects how your information is used, sent to the email on your account.
Effective August 5, 2026.
What we collect
Account information. Name, email address, phone number, role (patient, referring physician, cash-pay provider, employer admin), and for physicians and providers the practice details and credential identifiers needed to verify them.
Referral information. Patient name and date of birth, the requested service, the selected provider and location, the listed cash price, urgency, and the status history of the referral.
Insurance plan details you enter. If you use the savings calculator, the plan figures you type in — deductible, amount met, coinsurance, copay, out-of-pocket maximum, an optional plan nickname, and any insured price you record for a procedure. We do not ask for and do not want your member ID, policy number, group number, or insurer login. Signed out, these figures stay on your device; signed in, they are saved to your account and readable only by you, and you can delete them at any time from the savings calculator.
Usage information. Searches run, options saved and shared, pages viewed, device and browser type, and approximate location derived from IP address.
What we deliberately do not collect
The referral record has no field for diagnosis, clinical history, imaging, lab results, or treatment notes, and the product does not ask for them. Clinical detail that a provider needs to deliver care moves physician-to-provider through their own channels, outside Synapse. If you type clinical detail into a free-text field, please remove it — we do not want it and it is not needed to route a referral.
How referral information is shared
Submitting a referral discloses the referral record to the cash-pay provider you selected, in their Synapse dashboard and in a notification email to the address that provider has on file. The referring physician and the patient both see the referral and its full status history.
Employer admins see aggregate usage and seat status for their organization. They do not see which service any individual employee searched for, saved, or was referred to.
Synapse staff may access referral records to operate the service — verifying providers, investigating a support request, or responding to a security incident. Those accesses are written to an audit log.
We do not sell personal information, and we do not accept payment for search ranking or placement.
Service providers
Synapse runs on third-party infrastructure for hosting, database storage, authentication, and email delivery. Those vendors process information only to provide those functions to us. We do not use consumer advertising or ad-retargeting trackers.
Security
Information is encrypted in transit and at rest. Access is scoped by role, and every referral status change is recorded in an append-only history with the actor, the time, and the reason. No system is perfectly secure; if we learn of a breach affecting your information, we will notify you and the applicable regulators as required by law.
Retention
Referral records and their status history are retained while your account is active and for as long as needed to resolve disputes, meet recordkeeping obligations, and comply with law. Search and usage logs are retained for a rolling operational window. Closing an account removes it from active use; referral history that another party to the referral also relies on is retained on their side of the record.
Your choices
You can view and correct your account information, remove saved options, unsubscribe from non-essential email, and ask us to export or delete your data. Transactional messages about a referral you are party to cannot be turned off while that referral is open. To make a request, contact us using the details below and we will respond within 30 days.
Children
Synapse accounts are for adults. A parent or guardian may act on behalf of a minor patient; minors do not create their own accounts.
Contact
Questions, requests, or corrections: privacy@synapse.health. We will confirm receipt and tell you what we need to verify your identity before acting on a data request.