Direct answers to the questions parents, teachers and reviewers ask most.
Written for principals, teachers, parents, trustees, and reviewers. Each answer is a compressed pointer to the fuller document — read the linked page before treating an answer here as complete.
Can I see what my child talks to Aria about? By default, you see summaries, not full transcripts. Because your account's encryption key is derived from your own password, you technically can access more — but the app's default behaviour, and the honesty principle behind it, is to show summaries unless you deliberately look further. See Family Features and Privacy Model.
Is my child's voice recorded or stored? No. Voice input is processed entirely by your browser's own built-in speech recognition (Chrome/Edge, etc.) — Synapse's servers never receive the audio, only the text your browser already converted it to. See Privacy Model.
Can I delete our account and data? Yes, for family accounts — a self-service, permanent, immediate "Delete account and all information" option exists, using real cryptographic erasure. This is not currently available for school-linked (teacher-managed) accounts. See Family Features and Security Architecture.
Can I turn Social Resilience (or the Director tab) off for my child? Yes. Each is a per-child switch in the parent dashboard that only a parent can operate — a child cannot change it for themselves — and switching it off blocks access at the server on every request, not just hiding the button. The defaults differ: as of 11 Aug 2026 Social Resilience is on by default for a newly created child profile, so the switch is there to close it; the Director tab is off by default and you turn it on. Profiles created before that date were not changed and keep whatever setting they had. See Social Resilience and Director Tab (AI Literacy).
Does anyone at Synapse read my child's conversations? No, and for family accounts this is enforced by the encryption rather than by policy: your content is encrypted with a key derived from your password, which exists only in memory while you're signed in, so it isn't in the database or in backups in readable form. There are no admin, staff or support routes in the application at all. Two honest qualifications: the conversation is sent to Anthropic's API to generate Aria's replies, and the developer — who has server and source-code access — is not technically constrained by these controls the way an outside party would be. This is different for school accounts, where an operator with database access can decrypt content. See Privacy Model and Security Architecture.
What if my child talks about something worrying? Aria is designed to flag wellbeing concerns to you, but using a generalised message rather than quoting your child's own words back to you — the aim is giving you enough to act on without your child feeling their private words were reproduced. See Social Resilience and Privacy Model.
Can I see what a student says to Aria? Yes — full transcript access is available to a student's teacher. This was previously ambiguous in early communications and has since been resolved explicitly in favour of transparency. See Teacher Features (School Accounts) and Privacy Model.
Is the "Progress Indicator" the same as PAT? No. PAT is real, teacher-entered formal assessment data. The Progress Indicator is a separate, informal, AI-derived observational view, visually distinct on the dashboard and explicitly captioned as informal. See Curriculum Alignment.
Can I turn features on or off per student? Yes — Social Resilience, the Director tab, and PAT integration all have per-student teacher toggles, and peer matching has a classroom-level one (lib/db.js:203). On school accounts both Social Resilience and Director are opt-in: off until a teacher enables them for that student. Note this deliberately differs from family accounts, where Social Resilience is now on by default for new child profiles — a classroom's default is treated as the school's safeguarding decision, not Synapse's. Teacher toggles control whether a feature is available, not where or when it can be used; there is no school-hours or location control (see Social Resilience).
Who is legally accountable if something goes wrong? As of the last recorded update, this question does not have a fully satisfactory answer — Synapse is built and operated by a single developer with no registered company or formal insurance. The proposed resolution is the school-ownership model, not yet adopted by any school. See Governance Model.
Has this been independently reviewed? Not yet by an outside party. The developer has run his own product through a deliberately harsh internal critique process and published the findings, and has offered to fund an independent technical review if a school proceeds — but that independent review has not happened. See Adversarial Review Process and Governance Model.
Has a Privacy Impact Assessment been done? No, not yet — this has been explicitly identified as outstanding by the developer himself.
Can our school own its own instance of Synapse? This is a live proposal, not a confirmed offering — see School Ownership Model for what it would involve (roughly $40/month VPS cost, plus AI usage, offered to be covered by the developer during a trial).
Has this ever been suspended before? Yes — the pilot was suspended by the developer himself in July 2026 after his own internal review found governance gaps he judged too serious to proceed on, then reinstated after specific fixes. See Pilot Programme.
Does Synapse have unresolved conflicts with Ministry of Education guidance? Yes, at least one structural one: MoE guidance calls for teacher pre-vetting of AI content before it reaches students; Synapse's model is retrospective (teacher can review after, via transcript access). No direct child-facing AI system can fully satisfy pre-vetting; this is acknowledged rather than disputed. See Adversarial Review Process and Risks and Known Limitations.
Is school data actually protected from the developer/operator? Partially. Family-account data is genuinely inaccessible to the operator without the parent's key. School-account data currently is not equally protected — an audit found the classroom's unlock key stored in plaintext, meaning an operator with database access could decrypt school data. This is disclosed, not fixed, as of the last audit. See Security Architecture.
What would you say is the single biggest open risk? The organisational/legal governance gap (single developer, no company, no independent review yet) rather than any specific technical flaw — most technical findings that have surfaced have been found and fixed through the developer's own audit discipline. See Risks and Known Limitations for the full honest list.