Privacy Notice on the Processing of Personal Data
Agape - website, web application and mobile applications
Synapsia S.r.l. | Via Francesco Fazi 4A, 06034 Foligno PG, Italy | VAT No. and Tax ID 03841040540
Last updated: 12 September 2026
This notice explains which personal data Agape processes, for what purposes, on which legal bases, for how long and subject to which safeguards. It applies to the agapeai.io website, the app.agapeai.io web application and any official Agape mobile applications.
Agape is an artificial intelligence service for everyday activities, study, work and faith. Because of the nature of certain features, content provided by users may reveal religious beliefs or other particularly sensitive information. Such data receive the specific protections described below.
1. Data controller
| Item | Information |
|---|---|
| Controller | Synapsia S.r.l. |
| Registered office | Via Francesco Fazi 4A, 06034 Foligno PG, Italy |
| VAT No. and Tax ID | 03841040540 |
| Privacy contact | privacy@agapeai.io |
| Services | agapeai.io | app.agapeai.io | official Agape mobile applications |
Synapsia S.r.l. determines the purposes and means of processing personal data through Agape and therefore acts as data controller under Regulation (EU) 2016/679 (GDPR).
2. Scope of this notice
This notice applies to:
- visitors to agapeai.io and people who use contact forms or subscribe to updates, when those features are available
- registered users of the Agape web application and mobile applications
- users of free and premium plans
- people who contact support, privacy or reporting channels
The future Community area, public or shared spaces, and services that may be offered by parishes, dioceses or other organisations are not covered by specific rules until those features are activated. Before activation, this notice will be updated and the necessary information about the parties' respective roles and responsibilities under data protection law will be provided.
Third-party websites and services accessed through external links apply their own privacy notices. Synapsia does not control processing carried out by those parties outside Agape.
3. Personal data we process
| Category | Examples |
|---|---|
| Account data | Name, email address, protected credentials, language, country, age range or date of birth where necessary, and account preferences. The chosen interface language is stored in the account profile on the server, as is the Bible reading position where the consent described in section 3.1 has been given. |
| Authentication and security data | IP address, device, operating system, session identifiers, access records, security events, errors and technical logs. |
| Conversations and requests | Prompts, questions, conversation history, stated preferences and feedback on responses. |
| Uploaded content | Documents, images, photographs, audio files and other materials submitted for analysis or generation. The files themselves are not stored on Synapsia's servers, but the name of each attached file is kept in the conversation, with its page count or duration, and becomes the conversation's title when the file is sent without accompanying text. |
| Voice | Audio recordings or streams provided for dictation, transcription or playback, and the resulting transcript. Dictation, on every plan, and read-aloud on the free Base plan are performed by the speech services of the user's browser or operating system: the dictated audio and the text read aloud do not reach Synapsia's servers. |
| Generated outputs | Responses, summaries, translations, transcripts, images and other outputs created at the user's request. |
| Use of faith-related features | Consultation of Scripture and other sources, preferences and progress in the Rosary, Lectio Divina, Novenas or other practices, where saved to the account. |
| Financial data | Plan, subscription status, amounts, currency, invoices and transaction identifiers. Synapsia does not store full payment card details. |
| Communications | Support requests, reports, complaints, marketing preferences and subscriptions to updates. |
| Technical and usage data | Session duration and activity, features used, volumes, performance, crashes, language and theme preferences, and data collected through cookies or similar technologies. |
3.1 Data revealing religious beliefs and other special category data
Agape is also designed for questions about faith and spirituality. A conversation, a devotional preference or the use of particular features may therefore reveal religious beliefs, directly or indirectly. Such information falls within the special categories of personal data referred to in Article 9 GDPR.
Before processing content that may reveal religious beliefs or other special categories of personal data - including content in conversations, uploaded files, preferences or faith-related features - Agape requests, where required, specific and explicit consent that is separate from other consents and can be withdrawn at any time, under Article 9(2)(a) GDPR. Special category data processed on the basis of that consent are not used for advertising, commercial profiling or training general-purpose models.
Giving this consent is optional. Users who do not give it can still use the service: their messages are processed transiently, only for the time needed to generate the answer, and are not stored on Synapsia's servers; nor is their Bible reading position. Images that a user asks Agape to generate are stored in the account's gallery, together with the request, whether or not consent has been given.
Withdrawal prevents future processing based on consent and deletes the conversations and generated images stored in the account, together with the related feedback and the stored reading position. The account itself remains active and can continue to be used as described above; consent can be given again at any time.
Users should not provide health data, data relating to criminal convictions and offences, or other highly sensitive information about themselves or others unless it is strictly necessary for the request. Agape is not designed as a medical record, criminal records archive or emergency service.
3.2 Personal data relating to others
Files, photographs and conversations may contain personal data relating to other people. Users must have a lawful reason to share such data, limit it to what is necessary and respect the rights of the individuals concerned. Users must not upload children's data, data relating to criminal convictions and offences, or intimate content relating to others without an appropriate legal basis. Synapsia processes such data only to provide the requested feature, maintain security and comply with legal obligations.
4. Purposes, legal bases and retention
| Purpose | Legal basis | Retention |
|---|---|---|
| Account, authentication and settings | Performance of a contract, Article 6(1)(b) GDPR. | For the duration of the account. After closure, deletion from active systems within 30 days and deletion of residual backup copies within 90 days, unless legal obligations require longer retention. |
| AI responses and general features | Performance of a contract, Article 6(1)(b) GDPR. | Conversations and outputs are kept for as long as the user retains them in the account. They are deleted on request in accordance with the periods stated above. If the consent described in section 3.1 has not been given, messages are processed only for the time needed to answer and are not stored. |
| Faith-related features and content revealing religious beliefs | Performance of a contract, Article 6(1)(b) GDPR; explicit consent for special category data, Article 9(2)(a) GDPR. | For as long as consent remains valid and the content is stored in the account. On withdrawal, the conversations and generated images stored in the account are deleted and the account remains; data are also deleted on request, unless overriding obligations require retention. |
| Documents and images uploaded for a single operation | Performance of a contract, Article 6(1)(b) GDPR; explicit consent where the content includes special category data, Article 9(2)(a) GDPR. | The source file is not stored on Synapsia's servers: it is processed in memory for the time strictly necessary to provide the requested feature and then discarded. The file name is kept in the conversation, where it may also serve as the conversation's title, and follows the conversation's retention. Technical retention by providers follows the applicable contractual terms, subject to legal obligations. |
| Voice and transcription | Performance of a contract, Article 6(1)(b) GDPR; explicit consent where the content includes special category data, Article 9(2)(a) GDPR. | Audio is processed for the time necessary to provide the feature unless the user expressly chooses to save it. The transcript follows the retention period of the conversation. Technical retention by providers follows the applicable contractual terms, subject to legal obligations. |
| Progress in practices and preferences | Performance of a contract, Article 6(1)(b) GDPR; explicit consent where the data reveal religious beliefs, Article 9(2)(a) GDPR. | For the duration of the account or until deleted by the user. |
| Premium plans, payments and invoicing | Performance of a contract and compliance with a legal obligation, Article 6(1)(b) and (c) GDPR. | Accounting and tax records are retained for 10 years or for any different period required by applicable law. Payment data are retained by the relevant provider. |
| Support, complaints and reports | Performance of a contract or the legitimate interest in managing requests and protecting the service, Article 6(1)(b) and (f) GDPR. | Normally for 24 months after closure of the matter; longer where required for a dispute or legal obligation. |
| Security, abuse prevention and continuity | Legitimate interests and, where applicable, compliance with a legal obligation, Article 6(1)(f) and (c) GDPR. | Server logs record timings and other technical measurements only, without the content of messages or files and without user identifiers, and are kept for 30 days; longer only where required for incidents, investigations or the establishment, exercise or defence of legal claims. |
| Promotional emails and updates (not currently active: Agape sends no emails) | Consent, Article 6(1)(a) GDPR. | Until consent is withdrawn and in any event no longer than 24 months after the last interaction, unless renewed consent is documented. |
| Optional usage measurement through non-essential tools | Consent, Article 6(1)(a) GDPR. | For the periods stated in the preference centre and Cookie Policy; never before consent is obtained. |
| Legal obligations and legal claims | Compliance with a legal obligation or legitimate interests, Article 6(1)(c) and (f) GDPR. | For the period required by law or for the duration of the dispute and the relevant limitation periods. |
Where data are necessary to create an account, provide a requested feature, process a payment or protect the service, failure to provide them may prevent use of the relevant feature. Consent for marketing and optional measurement is always voluntary.
The user can delete the account from within the app. Deletion concerns only the data held on Synapsia's servers, which are erased as described in the table above. Data stored locally on the user's device or in the browser, such as preferences and rosary or novena progress, are not erased: they remain until the user clears the browser's or the app's data or uninstalls the app, as explained in the Cookie Policy.
5. Use of data in artificial intelligence systems
Synapsia does not use users' conversations, files, images, audio or personal outputs to train or improve its own general-purpose models and does not disclose that content to third parties for this purpose. When engaging artificial intelligence providers, Synapsia transmits only the content required to generate a response or perform the requested function and applies the available contractual arrangements and settings to prevent its use for general model training. Limited technical retention for security, abuse prevention or error management follows the periods provided for in the applicable arrangements.
Aggregated or anonymised technical data may be used to measure reliability, response times, errors and performance. Where authorised personnel examine content for support, security or abuse investigations, access is limited to the specific case and logged in accordance with internal procedures.
The Agape interface clearly informs users that they are interacting with an artificial intelligence system. Agape does not make solely automated decisions that produce legal effects or similarly significantly affect a user within the meaning of Article 22 GDPR.
6. Recipients of personal data
Personal data may be processed, to the extent appropriate for the relevant feature, by the following categories of recipients:
- Authorised Synapsia personnel. Development, operations, security, administration, support and compliance, with role-based access.
- Infrastructure and security providers. Hosting, storage, content delivery, network protection, monitoring and backups.
- AI providers. Text processing, web search, embeddings, speech recognition and synthesis, and image generation or analysis.
- Business service providers. Payments, invoicing, email delivery, customer support and subscription management.
- App stores and payment processors. They may act as independent controllers for purchases, refunds, fraud prevention and regulatory obligations.
- Professional advisers and authorities. Consultants, auditors, insurers, regulators and courts where disclosure is necessary or required.
In particular, when a user rates an answer with the feedback buttons, authorised operators can read the rated answer and the user's message immediately before it, together with the email address of the account. Authorised operators can also generate a single-use password-reset link for an account, valid for 60 minutes, and pass it to the account holder to restore access.
Providers processing personal data on Synapsia's behalf are appointed as processors under Article 28 GDPR where required. An up-to-date list of processors may be requested at privacy@agapeai.io.
The main providers currently engaged are the following:
| Provider | Function | Location and safeguards |
|---|---|---|
| OVH | Hosting of the servers, the database and the website | France (European Union) |
| Microsoft Azure Speech | Speech synthesis for read-aloud on premium plans; transcription of attached audio files | European Union, North Europe region (Ireland) |
| Language-model provider | Generation of responses, including web searches carried out within the provider's service; analysis of attached documents, images and audio transcripts | United States; EU-U.S. Data Privacy Framework or standard contractual clauses |
| Image-generation provider | Generation of images on request; transcription of attached audio when the speech service is unavailable | United States; EU-U.S. Data Privacy Framework or standard contractual clauses |
Agape's systems do not currently send emails, so no email-delivery provider currently receives personal data.
7. International transfers
The infrastructure and certain providers may involve processing personal data outside the European Economic Area (EEA). Where the destination country is not covered by an adequacy decision, Synapsia uses appropriate safeguards under Chapter V GDPR, such as the European Commission's standard contractual clauses, transfer impact assessments and supplementary technical measures. Where applicable, Synapsia may rely on an adequacy framework recognised by the European Union.
In particular, the language-model and image-generation providers listed in section 6 are located in the United States, and transfers to them rely on the EU-U.S. Data Privacy Framework or on the European Commission's standard contractual clauses. Hosting (OVH, France) and the speech service (Azure Speech, North Europe region) process data within the European Union.
Information about the safeguards used and an accessible copy of the relevant clauses may be requested at privacy@agapeai.io, subject to any redactions necessary to protect confidential information and security measures.
8. Security
The security measures adopted include:
- encryption of communications in transit and risk-appropriate protection of stored data
- role-based access controls and stronger authentication for privileged access
- separation of environments, vulnerability management and security updates
- logging of administrative access and monitoring of unusual events
- backups, business continuity and incident-response procedures
- periodic provider reviews and data protection agreements
No system is free from risk. In the event of a personal data breach, Synapsia follows the procedures set out in Articles 33 and 34 GDPR and notifies the supervisory authority and affected individuals where the applicable conditions are met.
9. Children and young users
Agape is intended for people aged 18 or over. Users under 18 may not register for or independently use the service. If Synapsia becomes aware that an account belongs to a younger person, it may suspend the account, request verification and delete data that are not subject to a legal retention requirement.
Agape does not solicit personal data relating to children and asks all users not to include such data in conversations or files unless doing so is lawful and strictly necessary.
10. Data subject rights
| Right | Meaning |
|---|---|
| Access | To know whether personal data are being processed and receive a copy. |
| Rectification | To correct inaccurate data and complete incomplete data. |
| Erasure | To obtain erasure in the circumstances set out in Article 17 GDPR. |
| Restriction | To restrict processing temporarily in the circumstances provided by law. |
| Objection | To object to processing based on legitimate interests and, at any time, to direct marketing. |
| Data portability | To receive data provided to Synapsia in a structured format and transmit them to another controller where the applicable conditions are met. |
| Withdrawal of consent | To withdraw consent at any time, as easily as it was given, without affecting processing carried out before withdrawal. |
| Complaint | To lodge a complaint with the Italian Data Protection Authority or the competent supervisory authority in the country of residence or work. |
Requests may be sent to privacy@agapeai.io. Synapsia may request reasonable information to verify identity and will respond within the statutory time limits. The Italian Data Protection Authority is available at www.garanteprivacy.it.
11. Cookies and similar technologies
The website and application do not set cookies; they use browser storage and similar technologies. Strictly necessary technologies support security and operation of the service. Optional technologies are activated only with consent where required. The Agape Cookie Policy describes the technologies used, their duration and the controls available to users.
12. Changes to this notice
This notice may be updated when the service, providers or applicable law change. The current version and effective date are published on the website. Agape gives appropriate notice of material changes affecting ongoing processing and seeks renewed consent where required.
13. Contact details
- Email: privacy@agapeai.io
- Post: Synapsia S.r.l., Via Francesco Fazi 4A, 06034 Foligno PG, Italy
Last updated: 12 September 2026
Cookie Policy
Agape website, web application and native apps
Synapsia S.r.l. | Via Francesco Fazi 4A, 06034 Foligno PG, Italy | VAT No. and Tax Code 03841040540
Last updated: 12 September 2026
This policy describes the cookies and similar technologies used by agapeai.io, app.agapeai.io and the Agape native applications for iOS and Android, their purposes and the choices available to users. It forms part of the Agape Privacy Notice.
1. Data Controller
The data controller is Synapsia S.r.l., Via Francesco Fazi 4A, 06034 Foligno PG, Italy, VAT No. and Tax Code 03841040540. Privacy contact: privacy@agapeai.io.
2. What are cookies and similar technologies
Cookies are small files that a website may store on a user's device. Technologies such as local storage, local app storage and authentication tokens may perform similar functions, for example remembering a language, a display theme or a functional state, or enabling access to an account. In native apps, certain technical data may be stored in secure operating-system storage, such as Keychain on iOS and Keystore on Android. In this policy, the term technologies includes these tools where relevant.
3. Categories used
Agape classifies technologies according to their function. As of the date of this update, only technical and functional technologies are used; no analytics, tracking, advertising or profiling tools are used.
- Strictly necessary. Enable authentication, account security and continuity of access to the service. Where strictly necessary for the requested function, they do not require consent.
- Preferences and local functions. Remember settings or states selected or used by the user, such as language, theme, completion of onboarding, reading position, rosary and novena progress, voice playback speed and interface configuration. They are not used for advertising, tracking or profiling.
- Statistics and analytics. Agape does not currently use cookies, SDKs or other device-side technologies to measure use of the website or app.
- Marketing, tracking and profiling. Agape does not currently use technologies in this category.
4. Technologies currently used
As of the date of this update, Agape does not set any cookies on the website, the web app or through the native apps. The website and web app use local storage, and the website also uses session storage, for the functions shown in the table below. The web app stores the authentication token in local storage; the native apps store the token in the encrypted storage provided by the operating system (Keychain on iOS and Keystore on Android). Neither the server nor the reverse proxy sets cookies.
| Name | Scope | Technology | Purpose | Retention | Category |
|---|---|---|---|---|---|
| agape_lang | Website | Local storage | Remembers the language selected on the website | Until browser data is cleared | Functional preference |
| agape_alba | Website | Session storage | Records that the opening animation has already been viewed so that it is not repeated | Until the browser tab or window is closed | Functional preference |
| agape.token | Web app | Local storage | Signed JWT token for authentication and access to the service | 30 days; also invalidated when the password is changed | Strictly necessary |
| Authentication token | Native iOS/Android apps | iOS Keychain / Android Keystore | Signed JWT token for authentication and access to the service | 30 days; also invalidated when the password is changed | Strictly necessary |
| agape.language | Web app and native apps | Local storage | Remembers the language selected in the app; the language is also stored in the user's account on the server | Until browser data is cleared or the app is uninstalled | Functional preference |
| agape.language.adopted | Web app and native apps | Local storage | Keeps the automatically adopted language when no language has been explicitly selected | Until browser data is cleared or the app is uninstalled | Functional preference |
| agape.theme | Web app and native apps | Local storage | Remembers the light or dark theme | Until browser data is cleared or the app is uninstalled | Functional preference |
| agape.onboarded | Web app and native apps | Local storage | Records completion of onboarding | Until browser data is cleared or the app is uninstalled | Functional |
| agape.reading | Web app and native apps | Local storage | Stores the Bible reading position; where the consent described in the Privacy Notice has been given, it is also stored in the user's account on the server | Until browser data is cleared or the app is uninstalled | Functional |
| agape.rosary | Web app and native apps | Local storage | Stores rosary progress on the device | Until browser data is cleared or the app is uninstalled | Functional |
| agape.novena.<id> | Web app and native apps | Local storage | Stores the progress of a novena; one entry is created for each novena started | Until browser data is cleared or the app is uninstalled | Functional |
| agape.voiceRate | Web app and native apps | Local storage | Remembers the voice playback speed | Until browser data is cleared or the app is uninstalled | Functional preference |
| agape.sidebar.width | Web app only | Local storage | Remembers the width of the sidebar | Until browser data is cleared | Functional preference |
| agape.sidebar.collapsed | Web app only | Local storage | Remembers whether the sidebar is expanded or collapsed | Until browser data is cleared | Functional preference |
5. Consent and optional technologies
As of the date of this update, Agape does not use cookies, analytics, tracking, advertising, profiling tools or third-party SDKs on the user's device. Technologies that are strictly necessary for authentication and security are used to provide the requested service. The other local storage entries listed in the table are used exclusively for the functional purposes indicated and not to track the user across different services.
If optional technologies requiring consent under applicable law are introduced in the future, they will be activated only after a valid choice by the user, and a mechanism will be made available to change or withdraw that choice as easily as it was given.
6. Managing data through the browser or device
On the website and web app, users can delete local data through their browser settings. Doing so may reset the language, theme, onboarding status, reading position and other preferences and, in the case of the web app, log the user out by deleting the authentication token. In the native apps, local preferences are stored on the device; the authentication token is stored in the encrypted storage provided by the operating system. The token is valid for 30 days, and changing the password invalidates all previously issued tokens.
Deleting the Agape account erases the data held on Agape's servers but does not clear data stored locally on the device or in the browser, such as language and theme preferences, onboarding status, reading position, rosary and novena progress and voice playback speed; logging out does not clear them either. Users can remove them by clearing the browser's site data or the app's data, or by uninstalling the app.
7. Third parties and transfers
As of the date of this update, no external provider sets cookies or similar technologies directly in the user's browser or on the user's device. External services used by Agape for the language model, voice synthesis on premium plans, transcription of attached audio, image generation and web search are called exclusively from Agape's servers and do not load resources directly onto the user's device. There are no third-party SDKs, analytics systems, user-side CDNs or active payment systems that set cookies. Any server-side data processing carried out through external providers is described in the Privacy Notice and does not constitute device-storage technology governed by this policy.
Two functions work differently. Dictation, on every plan, and read-aloud on the free Base plan use the speech services built into the user's browser or operating system, for example those of Apple on iOS, Google on Android or the browser vendor on the web. The dictated audio and the text read aloud are processed by those services under their providers' own terms and do not reach Agape's servers.
8. Updates
This policy is updated whenever the technologies actually used change. Before introducing a new optional technology, Agape will assess its purpose, update the information provided to users and, where required by applicable law, obtain consent before activation. The date of the current version is shown at the beginning and end of this document.
9. Contact
For requests concerning cookies and similar technologies: privacy@agapeai.io or Synapsia S.r.l., Via Francesco Fazi 4A, 06034 Foligno PG, Italy.
Last updated: 12 September 2026