Privacy Policy
Synthibase is a synthetic data platform. We do not store, process, or transmit real patient health information (PHI). All data you generate is synthetic and fictional. We collect only the minimum account information needed to operate the service.
1. Who We Are
Synthibase ("we," "us," or "our") is a synthetic clinical data platform operated for healthcare implementation teams. Our platform generates fictional X12 EDI and HL7 v2 transactions for testing purposes. We are not a covered entity or business associate under HIPAA because we do not process real protected health information.
For privacy questions, contact us at: privacy@synthibase.com
2. Information We Collect
We collect the following categories of information:
- Account information: Your name, email address, organization name, and role when you request access or are onboarded.
- Usage data: Pages visited, features used, transactions generated (counts only, not content), and timestamps.
- Technical data: IP address, browser type, operating system, and session identifiers for security and debugging.
- Communications: Any emails or messages you send us for support purposes.
Important: Synthibase generates synthetic, fictional data only. We do not collect, store, or process real patient names, medical record numbers, dates of birth, Social Security numbers, or any other protected health information. Do not enter real patient data into Synthibase.
3. How We Use Your Information
We use the information we collect to:
- Provide, operate, and improve the Synthibase platform
- Authenticate your identity and manage your account
- Send service-related emails (account approval, password reset, important updates)
- Monitor for security threats and prevent abuse
- Analyze aggregate usage patterns to improve the product
- Comply with legal obligations
We do not sell your personal information. We do not use your information for advertising purposes.
4. Data Storage and Security
Your account data is stored securely using Supabase, which provides enterprise-grade PostgreSQL database hosting with encryption at rest and in transit. Authentication is handled through Supabase Auth with industry-standard security practices.
Generated synthetic transactions are stored in your organization's isolated data partition. No data is shared between organizations.
We implement reasonable technical and organizational measures to protect your information, including:
- TLS encryption for all data in transit
- Encryption at rest for all stored data
- Role-based access controls
- Organization-level data isolation
5. Data Retention
We retain your account information for as long as your account is active or as needed to provide services. Generated transaction data is retained for the duration of your account unless you delete it.
Upon account deletion, we will delete your personal information within 30 days, except where we are required to retain it for legal or compliance purposes.
6. Third-Party Services
We use the following third-party services to operate Synthibase:
- Supabase — database, authentication, and file storage
- Vercel — application hosting and deployment
- Anthropic — AI-powered scenario generation (your prompts are processed server-side; we do not send identifying information to Anthropic)
- Resend — transactional email delivery
Each of these providers maintains their own privacy policies and security certifications.
7. Your Rights
Depending on your location, you may have the following rights regarding your personal information:
- Access: Request a copy of the personal information we hold about you
- Correction: Request correction of inaccurate information
- Deletion: Request deletion of your account and associated data
- Portability: Request your data in a portable format
- Objection: Object to certain types of processing
To exercise any of these rights, contact us at privacy@synthibase.com.
8. HIPAA Considerations
Synthibase is designed as a synthetic data platform and does not constitute a HIPAA covered entity or business associate under normal use. However:
- Do not enter real patient information into any field in Synthibase
- All member records, encounter data, and transactions should use fictional identifiers
- If your organization requires a Business Associate Agreement (BAA), contact us to discuss your specific compliance requirements
9. Cookies
Synthibase uses essential cookies only — specifically authentication session cookies required to keep you logged in. We do not use tracking, analytics, or advertising cookies. You cannot opt out of essential cookies as they are required for the platform to function.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by displaying a notice in the application. Your continued use of Synthibase after changes become effective constitutes your acceptance of the updated policy.
11. Contact Us
For privacy questions, data requests, or concerns, please contact us at:
Email: privacy@synthibase.com
Website: synthibase.com