Start with 25 free Setup Credits to set up your business and AI workforce.

Permissions, Safety & Security

Last updated: October 4, 2026

SynaBot is an AI workforce for small business. Your AI workers prepare work, but you stay in control of anything that leaves your business. This page explains what SynaBot can and cannot do with your accounts, how your data is kept separate, and how to report a security issue.

Does SynaBot act without my approval?

No. External actions — such as saving a Gmail draft, creating a calendar event, adding a Google Sheets record, creating a Drive document or scheduling a social post — are shown to an owner or admin with their Credit cost and run only after approval. Team members can prepare work but cannot approve priced or external actions; viewers have read-only access.

What Google and Gmail access does SynaBot request?

  • Gmail: read permitted mailbox context and save drafts. SynaBot does not request Gmail send permission, so it cannot send email from your account.
  • Google Calendar, Drive and Sheets: create approved events, documents and records you have asked for.
  • Google Analytics and Search Console: read-only, for the website mapped to the business you select.

Google connection credentials are encrypted and used only on our servers. See the Privacy Notice for the full Google OAuth and Limited Use disclosure.

How is one business kept separate from another?

Each business has its own AI workforce, Business DNA, connections, work history and Credits. Connections are scoped to the signed-in user and the selected business, and database access rules prevent one business's records being read from another. Credits cannot be transferred between businesses.

How do I revoke a connection?

Owners and admins can disconnect any connected account from the business settings. Disconnecting requests revocation from Google and removes the stored connection credentials and related mappings. You can also remove SynaBot's access at any time from your Google Account permissions page.

Who handles payments?

Checkout is handled by Stripe. SynaBot never sees or stores your full card number.

How do I report a security vulnerability?

Email security@synabot.ai with:

  • A clear description of the issue and its potential impact;
  • Steps to reproduce (URLs, request payloads, screenshots);
  • Your name or handle if you would like credit.

We aim to acknowledge security reports within 1 business day and to provide an initial assessment within 7 days.

Safe harbor

If you make a good-faith effort to comply with this policy, we will not pursue or support legal action against you for your research. Please:

  • Only test against your own accounts or accounts you have explicit permission to test;
  • Do not access, modify or destroy other users' data;
  • Do not run automated scans that degrade the Service for other users;
  • Give us a reasonable time to remediate before any public disclosure.

Out of scope

  • Reports produced solely by automated scanners without a demonstrable impact;
  • Missing security headers or best-practice recommendations with no exploit path;
  • Social engineering of SynaBot staff, customers or vendors;
  • Denial-of-service attacks and physical attacks on infrastructure;
  • Issues in third-party services (for example Stripe or Google) — please report those to the vendor directly.

What happens if personal data is affected?

If we determine that personal data has been affected by a security incident, we will notify affected users and, where required, the relevant regulator, in line with applicable law and our Privacy Notice.

Contact

SynaBot Inc., 16192 Coastal Highway, Lewes, Delaware 19958, USA — security@synabot.ai.