Syn App Pty Ltd · Version 1.0 · Effective date: 24 July 2026

Last updated: 24 July 2026

Privacy Policy

1. Introduction

Syn App Pty Ltd (ACN 696 168 171, ABN 18 696 168 171), trading as Synapse Chat (“Synapse Chat”, “we”, “us”, “our”), operates Synapse Chat, a secure messaging application for verified healthcare practitioners in Australia. This Privacy Policy explains how we handle personal information in accordance with the Privacy Act 1988 (Cth) (the Privacy Act) and the Australian Privacy Principles (the APPs). Because Synapse Chat may be used in connection with health information, we comply with the APPs as an APP entity regardless of our annual turnover.

Our privacy-by-design approach. Synapse Chat is designed for de-identified clinical and logistical communication between verified practitioners, for example coordinating theatre lists, requesting urgent assistance, and arranging cover. It is not intended to be used to collect, store or share identifiable patient information, and it is not a clinical record. We have built the platform on the precautionary assumption that identifiable health information may occasionally be entered despite this, and have implemented controls proportionate to that risk, both to prevent it and to respond if it occurs.

By creating an account or using Synapse Chat, you acknowledge that you have read and understood this Policy.

2. About this Policy

This Policy applies to personal information we handle about the people who use Synapse Chat and others who interact with us. We use these terms as defined in the Privacy Act:

  • Personal information: information or an opinion about an identified individual, or an individual who is reasonably identifiable.
  • Sensitive information: a special category of personal information, including health information, attracting a higher level of protection.
  • Health information: information about an individual’s health or a health service provided to them; it is sensitive information.
  • Holds: we “hold” personal information if we have possession or control of a record that contains it.

3. Two kinds of information

It is important to distinguish two categories, because they are handled very differently:

  • (a) Information about you, our user. Information we deliberately collect and hold in order to verify you and provide the service (section 5).
  • (b) Patient information. Information about patients is not information we intend to collect. The platform is designed to keep identifiable patient information off it. If such information is inadvertently entered, our Incident process applies (section 13).

4. Anonymity and pseudonymity

Synapse Chat is a network of verified practitioners, and verified identity is essential to how it works and to the trust it provides. For that reason, you cannot use Synapse Chat anonymously or under a pseudonym. This is a deliberate safeguard: knowing that every participant is an identified, verified colleague is central to the service.

5. Personal information we collect about users

We collect and hold the following kinds of personal information about users:

  • Identity and contact details: your name, mobile number and email address.
  • Professional verification: your AHPRA registration number and verification status; for users without AHPRA registration, the details supporting sponsored verification.
  • Professional profile: your specialty or role, and your hospital or facility affiliations.
  • Account and authentication data: account credentials and device security settings. Where you enable biometric unlock, the biometric data remains on your device and is not collected by us.
  • Message content and metadata: the messages you send and receive (stored in encrypted form) and associated metadata such as sender, recipients, timestamps and delivery or read status.
  • Technical and usage data: device and app information, log data, diagnostics, and information about how you use the app.
  • Compliance records: your acceptance of the user warranty and Terms of Service, any training you complete, and any reports you submit.
  • Support communications: information you provide when you contact us.

How we collect it. We collect personal information directly from you; automatically as you use the app; and from third parties, such as the AHPRA public register (to verify your registration) and our service providers. If you do not provide the information we need to verify you and operate your account, we may not be able to provide Synapse Chat to you.

6. Why we collect, hold and use personal information

We collect, hold, use and disclose personal information to:

  • create your account and verify your eligibility and identity, so that Synapse Chat remains a network of verified practitioners;
  • provide, operate, secure and support the messaging service;
  • maintain the integrity and safety of the network, and investigate misuse, security incidents and user reports;
  • meet our legal and regulatory obligations, including record-keeping and legal-hold;
  • improve the app and our services; and
  • any other purpose you would reasonably expect, or to which you consent.

We only use or disclose your personal information for the purpose for which it was collected, for a directly related purpose you would reasonably expect, or as otherwise permitted by law or with your consent.

7. Sensitive information

Health information is sensitive information and attracts a higher level of protection. Synapse Chat does not seek sensitive information about patients, and we ask users not to enter it (see section 12). We will only collect sensitive information where the individual consents and it is reasonably necessary for our functions, or where an exception under the Privacy Act applies. Your AHPRA registration details are professional information used to verify your eligibility, and are handled as personal information.

8. Contacts and finding colleagues

You can invite colleagues to Synapse Chat by selecting them from your device contacts or by sharing an invite link. Invitations are sent from your device, not from our systems: we do not upload, copy or store your address book, and we do not receive the contact details of a person you invite unless and until they create an account. Using this feature is optional; you can decline the contacts permission and still use Synapse Chat.

9. Device permissions

Synapse Chat may ask permission to use certain device features. You can grant or decline these and change them at any time in your device settings:

  • Contacts: to help you find colleagues on Synapse Chat (see section 8).
  • Camera and photos: only when you choose to capture or attach an image. (Remember the warranty: do not send images containing identifiable personal health information.)
  • Notifications: to alert you to new messages.
  • Face ID / biometrics: to secure access to the app; biometric data stays on your device.

10. Analytics, crash reporting and notifications

We use a limited amount of technical tooling to keep Synapse Chat reliable and to deliver messages:

  • crash and performance diagnostics, to identify and fix problems;
  • basic, privacy-respecting usage analytics, to understand how features are used and improve them; and
  • a push-notification service, to deliver message alerts.

Message alerts are delivered using the Apple and Google push-notification services; notification payloads are generic and do not include message content or sender details. A current list of the third-party providers we use for diagnostics and analytics is available from our Privacy Officer on request. Any such provider is bound to handle data only for our purposes. We do not use analytics to read the content of your messages.

11. Synapse Chat is not a clinical record

Synapse Chat is not a clinical record-keeping system and must not be used as a patient’s medical record. Clinical information that needs to be recorded must be transcribed to the patient’s official medical record. We surface this obligation to every user during onboarding.

12. Keeping identifiable information off the platform

To prevent identifiable patient information from being entered in the first place, we apply layered “privacy-by-design” controls designed to add minimal daily friction:

  • Verified users only: access requires identity verification (AHPRA registration, or sponsored verification for eligible non-AHPRA staff).
  • A user warranty: before using Synapse Chat, every user must agree that they will not send photos or upload files containing identifiable personal health information, will de-identify by default, and will keep clinical information in the patient’s medical record. We give concrete examples of what must never be entered (for example patient records, clinical notes, diagnostic information, or anything attributable to an identifiable patient).
  • De-identification guidance and cues: in-app guidance and structured, non-identifying ways to refer to a case (for example “Bay 3” or “List 2 / case 4”), so that a patient’s name is never the natural thing to type.
  • Reminders and optional training: an on-screen reminder to de-identify, and an optional “Synapse Chat Safety” training module (with a completion certificate) covering de-identification in practice.
  • User reporting: a simple in-app way to report a message that should not have been sent, so we can address it through our governance process.

We keep records of warranty acceptance, training completion and user reports as evidence of the steps we take.

13. If personal or health information is inadvertently provided

Because we do not routinely scan message content (see section 14), we rely on the controls above and on user reporting to become aware that identifiable information has been entered (an “Incident”). If we become aware of an Incident, we will:

  • assess the matter promptly;
  • where required, take reasonable steps under APP 5 to notify the affected individual of the relevant matters, and that the information has been deleted;
  • delete or de-identify the information where we are able to do so; and
  • assess whether the Incident is an eligible data breach under the Notifiable Data Breaches (NDB) scheme, that is, whether it is likely to result in serious harm. If it is, we will notify the affected individual(s) and the Office of the Australian Information Commissioner (OAIC) as required. Where we are able to remediate quickly so that serious harm is not likely, notification may not be required.

We maintain a documented incident-response procedure to support a consistent and timely response.

14. How we hold and protect information

We take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure:

  • Australian hosting: personal information is hosted on infrastructure located in Australia.
  • Encryption: messages are encrypted in transit and at rest.
  • Key custody: we hold the encryption keys. This means Synapse Chat is not “end-to-end encrypted.” We hold the keys deliberately, so that we can meet legal-hold obligations and respond to lawful requests (for example, a court order), capabilities that true end-to-end encryption would prevent.
  • No routine scanning: although we are technically able to decrypt, we do not routinely decrypt or scan the content of users’ messages. We consider a standing capability to bulk-decrypt and scan all messages to be itself a security and privacy risk. Decryption of specific content occurs only where necessary, such as to comply with a specific legal process.
  • Access controls: access to systems, and any decryption capability, is restricted to authorised personnel and is controlled and logged.

No method of transmission or storage is completely secure; while we strive to protect your information, we cannot guarantee absolute security.

15. Message content, retention and deletion

  • You can delete messages from your own view in the app.
  • For legal-hold and compliance reasons, an encrypted copy may be retained on our systems after you delete it from your view. Because we do not routinely read content, we are generally unable to locate and remove an individual stray message on request, which is why our controls focus on preventing identifiable information from being entered in the first place.
  • We retain personal information only for as long as necessary for the purposes described in this Policy, or as required by law, after which we take reasonable steps to destroy or de-identify it.
  • If you close your account, we will delete or de-identify your personal information, except where we are required to retain it (for example, for legal-hold).

Retention periods: encrypted message content is retained for up to 12 months after you delete it from your view or close your account, after which it is destroyed. Account, verification and compliance records (such as warranty acceptance, training completion and user reports) are retained for 7 years after account closure, consistent with our legal and professional-context obligations. Where a specific legal hold applies (for example, litigation, a regulatory investigation or a court order), the affected records are preserved until the hold is lifted, and the periods above resume when it ends.

16. Use, disclosure and who can see your information

  • Other users: when you communicate on Synapse Chat, your name, specialty, verification status and the messages you send are visible to the other participants in that conversation.
  • Service providers: we disclose personal information to trusted providers who help us run Synapse Chat (such as hosting, identity-verification and infrastructure providers), under contractual obligations to protect it and use it only for our purposes.
  • Legal and safety: we may use or disclose personal information where required or authorised by law, to respond to lawful requests by courts, regulators or law-enforcement, to meet legal-hold obligations, or to protect the safety of any person.
  • No sale, no advertising: we do not sell personal information, and we do not use it for third-party advertising.

17. Government-related identifiers

We do not adopt or use government-related identifiers (such as Medicare or Individual Healthcare Identifier (IHI) numbers) as a means of identifying you. We ask users not to enter patient government identifiers at all. Your AHPRA registration number is used only to verify your professional eligibility.

18. Overseas disclosure

Synapse Chat is hosted in Australia and we do not routinely disclose personal information to overseas recipients. Limited technical disclosures do occur in operating the service: for example, the Apple (United States) and Google (United States) push-notification services receive device tokens and generic alert payloads (not message content) in order to deliver notifications to your device. Where a service provider we use is located overseas, or we are otherwise required to disclose information overseas, we take reasonable steps under APP 8 to ensure the recipient handles it consistently with the APPs.

19. Access, correction and keeping information accurate

You may request access to the personal information we hold about you, and ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading (APP 12 and APP 13). Please contact our Privacy Officer (section 23). We will respond within a reasonable period and within any timeframe required by law, and may need to verify your identity first. In limited circumstances we may decline a request as permitted by the APPs, in which case we will explain why and how you may complain.

We also take reasonable steps to ensure the personal information we hold is accurate, up to date and complete. You can help by keeping your profile details current.

20. Direct marketing

Synapse Chat is a professional tool, not an advertising platform. We do not use your information for third-party advertising. Any limited service communications we send will include a way to opt out.

21. Children and young people

Synapse Chat is intended for registered healthcare practitioners and other verified professionals, and is not directed at, or intended for use by, anyone under 18. We do not knowingly collect personal information from children. If you believe a minor has provided us with personal information, please contact our Privacy Officer.

22. Complaints

If you believe we have breached the APPs or otherwise mishandled your personal information, please contact our Privacy Officer (section 23). We will acknowledge your complaint, investigate it, and respond within a reasonable period. If you are not satisfied with our response, you may complain to the OAIC:

Office of the Australian Information Commissioner · www.oaic.gov.au · 1300 363 992 · GPO Box 5288, Sydney NSW 2001.

23. Contact us

For any privacy question, request or complaint, contact our Privacy Officer:

Privacy Officer, Syn App Pty Ltd
Email: support@synapsechat.app (mark your message “Attention: Privacy Officer”)
Post: 255 David Low Way, Peregian Beach QLD 4573

24. Changes to this Policy

We may update this Policy from time to time. The current version will be available in the app and on our website, showing its effective date. We will notify users of material changes.