PRIVACY POLICY

SynaNoteAI.com

Effective Date: February 26, 2026

Last Updated: October 5, 2026


IMPORTANT NOTICE: THIS POLICY EXPLAINS HOW MIARTMEDIA LTD. COLLECTS, USES, DISCLOSES, AND PROTECTS INFORMATION IN CONNECTION WITH THE SYNANOTEAI PLATFORM. BY ACCESSING OR USING THE PLATFORM, YOU ACKNOWLEDGE THAT YOU HAVE READ AND UNDERSTOOD THIS POLICY.


1. ABOUT THIS POLICY AND WHO IT COVERS

1.1 Who We Are

This Privacy Policy is published by MiArtMedia Ltd. ("Company", "we", "us", or "our"), the operator of the SynaNoteAI.com platform (the "Platform"). MiArtMedia Ltd. is incorporated under the laws of Alberta, Canada, and our primary place of business is in Calgary, Alberta.

1.2 Scope

This Policy applies to information collected, processed, or stored in connection with:

- The SynaNoteAI.com web application and all related tools;

- Account registration and session management;

- AI-powered content generation features;

- Administrative dashboards and billing;

- Feedback submissions; and

- Any other interaction with our Platform.

1.3 Who This Policy Covers

This Platform is a Business-to-Business (B2B) service. The primary account holders ("Clients") are businesses operating in the automotive service industry. This Policy applies to:

- Clients — the business entities that hold a Client Account and manage access for their staff;

- Account Users — employees or contractors of a Client who access the Platform via an Account ID (e.g., technicians, service advisors, managers); and

- Visitors — individuals who visit the SynaNoteAI.com website without creating an account.

1.4 Applicable Law

We collect and process personal information in compliance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) (S.C. 2000, c. 5) and its Regulations, including the Privacy Breach of Security Safeguards Regulations. Where applicable, we also comply with the Alberta Personal Information Protection Act (PIPA), the British Columbia Personal Information Protection Act (BC PIPA), and Quebec's Act respecting the protection of personal information in the private sector (Law 25).

The Platform may be accessed by businesses and Account Users located outside Canada, including Australia. The application of Australia's Privacy Act 1988 (Cth) and the Australian Privacy Principles depends on whether MiArtMedia Ltd. has an Australian link and on other facts specified by Australian law. Where Australian privacy law applies, we will handle covered personal information consistently with those mandatory requirements. Nothing in this Policy limits privacy rights that cannot lawfully be excluded.


2. INFORMATION WE COLLECT

2.1 Account and Identity Information

When a Client registers for the Platform, we collect:

- Full name and/or business name;

- Email address (used to sign in and receive account communications);

- Phone number (optional, if provided);

- Business address details (city, province/state, postal code, country) as part of the billing profile; and

- Invoice and billing contact details.

2.2 Account IDs and Sign-In Information

The Platform uses Account Codes for day-to-day tool access. We collect and store:

- Account codes and their associated labels;

- Sign-in cookies that keep you signed in and are not used for advertising or tracking;

- The times your session starts, expires, and was last used; and

- Your IP address when you sign in, to help prevent abuse and protect your account.

2.3 Usage and AI Interaction Data

When an Account User uses an AI tool, we record the Account ID, tool and AI model used, date and time, usage amounts, estimated cost, response time, and whether the request succeeded. Usage amounts include the units used to process your input and generate a response, commonly called tokens. These records support billing, usage reporting, troubleshooting, and service management.

Content handling depends on the feature used:

- Saved Narrative Polish conversations: Narrative Polish saves your messages, generated narratives, clarification questions, titles, summaries, conversation history, usage amounts, and dates. These records are associated with the Account ID used to create them so you can reopen and continue your work.

- Restricted records for service support: For other AI tools, we may retain submitted content and AI responses for troubleshooting, security, reliability, support, and service-quality review. Access to these records is restricted. Private Narrative Polish conversation content is excluded from these separate support records because its history is saved separately.

- De-identified diagnostic knowledge: DTC Analysis results may be used to improve future diagnostic assistance after you confirm that the analysis helped resolve the issue and explain what helped. Completed repair narratives may also qualify when they establish the diagnosis, confirmed cause, correction, and successful verification. Before keeping a case for this purpose, we remove customer and account identifiers, including VINs, contact details, Account IDs, repair-order numbers, and exact mileage. Cases are checked against diagnostic sources and may require administrator review. Original diagnostic content is deleted after processing when the required checks are complete, unless a hold requires retention. Separate usage and billing records remain.

- AI processing: Content submitted to an AI tool, including the saved Narrative Polish context needed for a follow-up, is transmitted to Google's Gemini service to generate the requested response and is subject to Google's data handling terms described in Section 5.2.

We do not sell prompt or conversation content, use it for advertising, or use identifiable prompt content to train our own AI models. Account Users should not submit prohibited sensitive information or unnecessary vehicle-owner identifiers.

2.3A VIN Decoder Data

If you use the Platform's VIN Decoder tool, we send the VIN you provide to the National Highway Traffic Safety Administration's vPIC vehicle decoding service in order to return decoded vehicle information. We do not use the VIN Decoder to look up vehicle-owner identity, and we treat returned vehicle data as reference information for business workflows rather than as independently verified fact.

2.4 Feedback Submissions

If you submit feedback through the Platform, we collect:

- Your feedback message;

- The feedback category, such as a problem report or feature request;

- The surface from which it was submitted (client dashboard or tools interface);

- Information about your browser and device;

- The size of your browser window; and

- An optional screenshot, if you choose to attach one.

Feedback is linked to an Account User reference, not to individually named employees.

2.5 Billing and Financial Data

We collect the following to support invoicing and billing:

- Company legal name and display name;

- Billing email address and phone number;

- Billing address;

- Invoice prefix preferences; and

- Usage totals per billing period.

We do not directly collect or store payment card numbers or banking information in our application. Billing, payment method setup, invoice, and payment processing are handled through Stripe, our third-party payment processor.

2.6 Administrative and Audit Data

We keep security and accountability records of administrative activity, including:

- The administrator’s account identifier and email;

- The action taken (e.g., client suspended, audit log read);

- The account or record affected;

- A record of changes (before/after values, where applicable);

- IP address;

- Browser and device information; and

- The seriousness of the event and when it occurred.

This log exists solely for security, accountability, and compliance purposes. It is accessible only to authorized administrative personnel.

2.7 Technical and Operational Data

We automatically collect certain technical data when you use the Platform, including:

- IP addresses, to prevent abuse and identify security threats;

- Browser and device information, where recorded for support or security;

- If you enable optional analytics, information about pages visited, features used, and broad user roles through Google Analytics 4. We do not send prompts, AI outputs, account or client identifiers, customer or vehicle data, or free-text content to this service;

- Records of service availability checks; and

- Error records and information about the affected requests for troubleshooting, subject to the content-handling practices in Section 2.3.

2.8 Sensitive Information We Do Not Intentionally Seek

We do not intentionally request the following. If an Account User nevertheless submits this information, it may be transmitted and, depending on the feature, retained as described in Sections 2.3 and 6:

- Vehicle owner Personally Identifiable Information (PII): Our Terms of Service prohibit Clients from inputting customer PII unless it is strictly necessary and lawfully submitted. If such data is included in saved Narrative Polish content or an applicable AI diagnostic record, it may be retained under the schedule in Section 6 as well as transmitted to the AI processor;

- Health or financial data about individuals;

- Biometric data; or

- Children's data: The Platform is not directed at persons under the age of 18 and we do not knowingly collect information from minors.


3. HOW WE USE YOUR INFORMATION

We use the information we collect for the following purposes, each grounded in a legitimate legal basis under PIPEDA:

3.1 To Provide and Operate the Platform

- Authenticate Clients and Account Users;

- Process your requests using the relevant AI service;

- Let you save, reopen, continue, organize, and delete Narrative Polish conversations associated with your Account ID;

- Apply service usage limits;

- Manage subscriptions, invoices, payment methods, prepaid token purchases, and usage reporting; and

- Maintain the Client dashboard and admin controls.

Legal basis: Performance of contract; legitimate business interest.

3.2 To Ensure Security and Prevent Fraud

- Detect and respond to unauthorized access attempts;

- Maintain the admin audit log for accountability;

- Apply additional verification and access restrictions for administrators; and

- Suspend accounts that violate the Terms of Service.

Legal basis: Legitimate business interest; compliance with legal obligations.

3.3 To Improve the Platform

- Analyse aggregated, anonymized usage patterns to understand which tools are most valuable;

- Build and use a private database of sanitized, verified automotive DTC diagnostic patterns to improve future DTC analyses, while separating verified evidence from general AI inference;

- Review feedback submissions to prioritize product improvements; and

- Monitor AI model cost efficiency; and

- Measure high-level marketing traffic and general feature usage if you have enabled optional analytics.

We do not use identifiable prompt content to train our own AI models. The private DTC knowledge process described in Section 2.3 derives sanitized technical cases rather than retaining customer-specific prompt content as shared knowledge.

We use submitted information to provide the requested narratives, analyses, and communications. AI output must be reviewed before use. Processing your content does not give us permission to publish or redistribute it beyond the uses described in this Policy and the Terms of Service.

Legal basis: Legitimate business interest.

3.4 To Communicate With You

- Send transactional emails such as account notifications, invoice delivery, password reset links, and usage alerts;

- Respond to support requests; and

- Send marketing communications only where you have provided express consent under CASL.

Legal basis: Performance of contract; express consent (marketing only).

3.5 To Comply With Legal Obligations

- Respond to lawful government requests or court orders;

- Maintain records required under Canadian tax law; and

- Cooperate with OEM audit or compliance verification processes where required.

Legal basis: Legal obligation.


4. COOKIES AND TRACKING TECHNOLOGIES

4.1 Sign-In Cookies and Preferences

We use necessary cookies to keep you signed in and maintain access to your account. Sign-in cookies expire automatically and are cleared when you sign out. Tool sessions normally expire after 24 hours, although the duration may vary with account security settings. We also store your optional analytics choice so the Platform can remember it.

Blocking sign-in cookies may prevent authenticated features from working. These cookies are not used for advertising.

4.2 Optional Analytics and GA4

We use Google Analytics 4 (GA4) only if you explicitly enable optional analytics through our consent banner. GA4 is used for limited traffic and product-usage measurement, such as:

- visits to public pages and interactions with sign-up or similar links; and

- general information about which features you open while signed in.

We intentionally do not send prompts, AI outputs, account IDs, client IDs, customer names, vehicle identifiers, invoice details, or other free-text/private app content to GA4.

If you decline optional analytics, GA4 does not load on your device through our Platform. To choose again, clear this website’s cookies in your browser and respond to the consent banner on your next visit.

4.3 Third-Party Cookies

If you enable optional analytics, Google may set cookies or use similar browser storage through GA4 to distinguish visits and measure aggregate usage. We do not use advertising cookies, cross-site tracking pixels, or social media widgets on the Platform. Our use of Google Gemini to process AI requests does not place Gemini cookies in your browser.


5. HOW WE SHARE YOUR INFORMATION

We do not sell, rent, or trade personal information. We share information only in the circumstances described below.

5.1 Within Your Organization

Clients who hold a Client Account can view usage dashboards and usage records for all Account IDs under their account. Individual employees are not identified by name in usage logs — only by Account ID. Clients are responsible for ensuring their internal access policies comply with applicable privacy laws.

5.2 Sub-Processors and Third-Party Service Providers

Hosting update — October 5, 2026: Application hosting and primary database, authentication, and file storage operate on MiArtMedia-managed infrastructure in Alberta, Canada, using self-hosted Supabase software. Cloudflare provides network delivery and security. External providers and separately retained migration rollback resources may process data outside Canada as described below.

We engage the following sub-processors. By using the Platform, you consent to the transfer of data to these providers, which may involve cross-border transfers outside Canada:

Sub-ProcessorPurposeLocationData Shared
Google LLC (Gemini API)AI content generationUnited States (Google Cloud)Prompt content submitted by Account Users
Google LLC (Google Analytics 4)Optional traffic and general feature-usage analyticsUnited StatesPages visited, features used, and browser and device information
National Highway Traffic Safety Administration (NHTSA) / vPICVIN decoding lookup for the VIN Decoder toolUnited StatesVINs submitted by Account Users when using the VIN Decoder
Supabase Inc.Frozen migration rollback copy, unavailable for new application writes while retainedUnited States (AWS)The separately retained Cloud copy of account data, usage events, session data, audit logs, saved Narrative Polish conversations, and restricted AI diagnostic records
Cloudflare Inc.Network delivery and securityGlobal networkApplication requests and network connection data processed during delivery
DigitalOcean LLCTemporary legacy DNS continuity during nameserver cache expiryUnited StatesDNS requests and related connection metadata while the legacy DNS zone remains retained
Stripe Inc.Billing and payment processingUnited StatesBilling contact details, transaction records, payment-method references and invoice information

Google Gemini API: Prompts submitted to AI tools are transmitted to Google's Gemini service for processing. Google's use of this data is governed by the [Google Cloud Platform Terms of Service](https://cloud.google.com/terms) and the [Google Generative AI Additional Terms](https://policies.google.com/terms/generative-ai). As of the effective date of this Policy, Google does not use Gemini API data to train its models without separate agreement. However, once data is transmitted to Google's API, it is outside MiArtMedia Ltd.'s control and processed solely under Google's own policies and agreements. MiArtMedia Ltd. makes no representations or warranties regarding Google's data handling practices and accepts no liability for how Google processes, stores, uses, or retains transmitted data, regardless of any representations Google makes in its own policies. Clients and Account Users should not submit personal vehicle owner information, health data, or other sensitive personal information as part of prompts.

Google Analytics 4: If you opt into optional analytics, limited page-view and event data is transmitted to Google Analytics 4 for aggregate reporting. We configure these events to exclude prompts, AI outputs, account identifiers, client identifiers, vehicle/customer data, and free-text private app content. GA4 data is processed under Google's analytics terms and privacy practices.

NHTSA vPIC: If you use the VIN Decoder, the VIN you submit is transmitted to the National Highway Traffic Safety Administration's public vPIC service so the Platform can return decoded vehicle details. vPIC is an external public data source operated by the U.S. government. MiArtMedia Ltd. does not control the availability, completeness, or handling practices of that service after transmission.

Database and authentication: MiArtMedia Ltd. operates the primary database, authentication, and file storage in Alberta, Canada, using self-hosted Supabase software. Saved Narrative Polish conversations and applicable AI diagnostic records are stored there. A separately retained Supabase Cloud copy in the United States is frozen and unavailable for new application writes while retained as a migration rollback resource; that Cloud processing is subject to Supabase's [Privacy Policy](https://supabase.com/privacy) and [Data Processing Agreement](https://supabase.com/legal/dpa). Cloudflare provides network delivery and security through its global network.

Cross-Border Transfers: You acknowledge that by using the Platform, your data may be transferred to, stored, and processed in the United States and other jurisdictions outside Canada, where privacy laws may differ from those in your province or territory. We have implemented contractual safeguards (data processing agreements with sub-processors) consistent with PIPEDA requirements for cross-border transfers.

5.3 Legal Disclosures

We may disclose personal information if required by law, regulation, court order, or governmental authority, or if we believe in good faith that such disclosure is necessary to:

- Comply with a legal obligation;

- Protect and defend the rights or property of MiArtMedia Ltd.;

- Prevent or investigate possible wrongdoing in connection with the Platform; or

- Protect the personal safety of users or the public.

We will, where legally permissible, provide reasonable notice to the affected Client before complying with such a request.

5.4 Business Transfers

If MiArtMedia Ltd. is involved in a merger, acquisition, asset sale, or bankruptcy proceeding, personal information held by us may be transferred as part of that transaction. We will provide notice via the Platform or by email before personal information is subject to a different privacy policy as a result of such a transaction.

5.5 Resellers and Authorized Partners

The Platform supports multi-client reseller accounts. If you access the Platform through an authorized reseller, that reseller may have access to your account's usage and billing data as part of their administrative role. The reseller's use of your data is governed by any agreement between you and the reseller. MiArtMedia Ltd. is not responsible for the reseller's data handling practices beyond the scope of the Platform.


6. DATA RETENTION

We retain personal information only for as long as necessary to fulfil the purposes for which it was collected, or as required by law.

Data CategoryRetention Period
Client account and identity dataDuration of active subscription + 30 days post-termination
Account IDs and configurationsDuration of active subscription + 30 days post-termination
Sign-in session credentialsExpire automatically and are removed during scheduled cleanup
Usage records (excluding submitted content and AI responses)24 months from the date of creation
AI response diagnostic records, including content where applicableUp to 24 months from creation, unless deleted earlier or retained longer for an active security investigation, legal hold, or legal obligation
De-identified diagnostic cases and associated evidence and review recordsRetained while useful and periodically reviewed; rejected or replaced cases may be retained as non-identifying review and integrity records
Saved Narrative Polish conversations and messagesUntil deleted through the conversation controls, or for the duration of the active subscription plus up to 30 days following termination
Admin audit logs36 months from the date of creation
Feedback submissions24 months from the date of submission, or until resolved
Invoice and billing records7 years (as required under Canadian tax law)
Records of requests exceeding service limits90 days

After the applicable retention period, data is deleted or anonymized. We are not a data archiving service and Clients are responsible for maintaining their own backups of all compliance-critical records (warranty narratives, RO documentation, etc.).


7. SECURITY SAFEGUARDS

We implement technical, administrative, and organizational safeguards appropriate to the sensitivity of the personal information we process. These include:

- Encryption of information sent between your browser, our service, and our service providers;

- Sign-in protections and controls that restrict access to account information;

- Restrictions that limit access to saved Narrative Polish conversations to the Account ID that created them;

- Additional verification and access restrictions for administrative accounts;

- Controls to detect and limit abusive requests;

- Records of administrative activity for security and accountability; and

- Access limited according to users’ roles and authorized responsibilities.

Despite these safeguards, no method of transmission or storage is 100% secure. In the event of a privacy breach that creates a real risk of significant harm, we will notify affected individuals and the Office of the Privacy Commissioner of Canada as required under PIPEDA's breach reporting obligations.


8. YOUR RIGHTS AND CHOICES

8.1 Right of Access

You have the right to request access to the personal information we hold about you, including confirmation of whether we hold information, the categories of information held, how it is used, and to whom it has been disclosed. Requests can be directed to the contact information in Section 11.

8.2 Right of Correction

You have the right to request correction of inaccurate or incomplete personal information we hold about you. Clients can update their account information and billing profile directly through the Platform dashboard.

8.3 Right of Withdrawal of Consent

Where we process personal information on the basis of consent (e.g., for marketing communications), you may withdraw consent at any time by:

- Using the unsubscribe link included in every marketing email; or

- Contacting us directly at the address in Section 11.

Withdrawal of consent does not affect the lawfulness of processing prior to withdrawal. Withdrawal of consent to processing that is necessary to provide the Platform will result in termination of your account.

8.4 Right to Request Deletion

You may request deletion of your personal information. We will fulfil such requests subject to:

- Our legal obligations to retain certain data (e.g., tax records, audit logs during litigation hold); and

- The need to retain data to detect and prevent security incidents or fraud.

Upon account termination, Client data is retained for 30 days to allow for data export or account recovery, after which it is deleted per our retention schedule.

Account Users can delete an individual Narrative Polish conversation or use Delete all conversations to delete all saved Narrative Polish history associated with the current Account ID. These controls delete the selected active conversation records and messages from the application. They do not delete separate billing, security, audit, or diagnostic records that we are required or permitted to retain under this Policy.

8.5 Right to Lodge a Complaint

If you believe we have not handled your personal information in accordance with PIPEDA or applicable provincial privacy law, you have the right to lodge a complaint with the Office of the Privacy Commissioner of Canada:

- Website: [www.priv.gc.ca](https://www.priv.gc.ca)

- Telephone: 1-800-282-1376

- Mailing address: 30 Victoria Street, Gatineau, QC K1A 1H3

Residents of Alberta may also contact the Office of the Information and Privacy Commissioner of Alberta at [www.oipc.ab.ca](https://www.oipc.ab.ca).

Residents of British Columbia may also contact the Office of the Information and Privacy Commissioner for British Columbia at [www.oipc.bc.ca](https://www.oipc.bc.ca).

If Australian privacy law applies to our handling of your personal information, you may also be entitled to contact the Office of the Australian Information Commissioner at [www.oaic.gov.au](https://www.oaic.gov.au).

We ask that you contact us first to attempt to resolve any concerns before escalating to a regulatory authority (see Section 11).


9. CLIENT RESPONSIBILITIES

As a B2B platform, a significant portion of any personal information that flows through the Platform is submitted by Clients and Account Users, not collected directly by us. In this regard:

9.1 You Are the Data Controller for User-Submitted Content

Clients are responsible for ensuring that:

- Any personal information submitted as part of AI prompts (e.g., customer names, vehicle VINs linked to identifiable individuals) is handled in compliance with PIPEDA and any applicable provincial privacy law;

- Account Users understand that Narrative Polish conversation content is saved until it is deleted or reaches the retention limit in Section 6;

- Their employees and contractors using the Platform are informed that their Account ID usage activity is logged; and

- They have obtained any necessary consents from their customers before submitting customer-related information to the Platform.

Clients are also solely and entirely responsible for all content submitted as prompts to any AI tool on the Platform. MiArtMedia Ltd. has no ability to screen, moderate, or assess prompt content for accuracy, legality, third-party IP compliance, confidentiality obligations, or any other consideration prior to transmission. All consequences — legal, regulatory, contractual, or otherwise — arising from the content of prompts submitted by Clients or Account Users are the Client's sole responsibility.

9.2 Prohibition on Sensitive Personal Information

Clients agree not to submit the following categories of data to AI tools on the Platform:

- Social Insurance Numbers or government-issued identification numbers;

- Health records or medical information;

- Financial account numbers or payment card data;

- Passwords or authentication credentials; or

- Any personal information about children under the age of 18.

9.3 Prohibition on Unauthorized Third-Party Content and Prompt Responsibility

Clients agree not to submit to the Platform any content that infringes the intellectual property rights of a third party or that they do not have the legal right to submit for AI processing. This includes, without limitation, excerpts from proprietary OEM manuals, technical service bulletins obtained under restricted licence, DMS-exported data subject to a vendor's terms of service, content from subscription databases (including ALLDATA, Mitchell1, Identifix, or equivalent services), or any other materials protected by copyright, trade secret, or confidentiality agreement.

User-submitted content is transmitted to Google's Gemini service for processing. Depending on the feature, content may also be stored as saved Narrative Polish history or in restricted AI diagnostic records as described in Sections 2.3 and 6. Storage does not authorize publication, redistribution, or use beyond the purposes described in this Policy. MiArtMedia Ltd. has no practical ability to screen prompt content for third-party IP compliance before processing. Clients are solely responsible for ensuring that submitted content complies with applicable copyright laws, licence agreements, confidentiality obligations, and third-party terms of service. MiArtMedia Ltd. accepts no liability for claims arising from content a Client or Account User was not authorized to submit, subject always to liability that cannot lawfully be excluded.

9.4 Reseller Obligations

Clients acting as resellers who manage sub-accounts on behalf of other businesses are solely responsible for ensuring those downstream businesses are informed of the data practices described in this Policy.


10. CHANGES TO THIS POLICY

We may update this Privacy Policy from time to time to reflect changes to our practices, legal requirements, or the features of the Platform. When we make material changes, we will:

- Update the "Last Updated" date at the top of this Policy;

- Post a notice on the Platform; and/or

- Send an email notification to the primary account email on file.

Your continued use of the Platform after the effective date of any changes constitutes your acceptance of the revised Policy. If you do not agree to the revised Policy, you must stop using the Platform and request account deletion.

The July 18, 2026 update is material because it documents saved Narrative Polish conversation content and expands the international-user disclosures. We will provide notice through the Platform and/or the primary account email before or when these practices are made available in production.


11. CONTACT INFORMATION AND PRIVACY OFFICER

For questions, access requests, correction requests, deletion requests, or complaints related to this Privacy Policy, please contact:

MiArtMedia Ltd.

Attn: Privacy Officer

Email: [email protected]

Phone: 403-990-9070

Website: https://synanoteai.com/

We will acknowledge receipt of your request within 10 business days and respond substantively within 30 days, or notify you if additional time is required pursuant to PIPEDA.


12. DEFINITIONS

For clarity, the following definitions apply throughout this Policy:

- "Account ID" means a unique identifier code issued to a Client that grants access to the Platform's tools.

- "Account User" means any individual who accesses the Platform using an Account ID issued by a Client.

- "AI Content" means any text, analysis, or other output generated by an AI model in response to a user prompt.

- "Client" means the business entity holding a Client Account with MiArtMedia Ltd.

- "Personal Information" has the meaning given under PIPEDA: any information about an identifiable individual.

- "Platform" means the SynaNoteAI.com application, including all associated APIs, dashboards, and tools.

- "Prompt" means any text or structured data submitted by an Account User to an AI tool on the Platform.

- "Sub-Processor" means a third-party service provider engaged by MiArtMedia Ltd. to process personal information on its behalf.


*SynaNoteAI Privacy Policy · MiArtMedia Ltd. · Effective February 26, 2026*

Document Date: October 8, 2026