Legal

Privacy Policy

Last updated: April 2026 Applies to: HeartFirst by Shyntesy and its products and websites

Who we are

HeartFirst is a heart risk education platform developed by Shyntesy. We create digital education products and resources that help people clarify hidden and incomplete heart risk, navigate risk, and take early prevention action.

Products we develop include Clarify heart risk, Navigate heart risk, and Prevent heart risk.

For the purposes of this Privacy Policy, "HeartFirst", "Shyntesy", "we", "us", and "our" refer to Shyntesy as the data controller responsible for deciding how personal data is collected and used.

Contact: [email protected] or send a quick message.

Educational tool only — not medical advice. HeartFirst provides organisational and educational resources to help you understand heart risk. It does not provide medical diagnosis, treatment, or personalised health advice. Always discuss your situation and next steps with your healthcare team.

Privacy snapshot: We collect only what we need to develop, deliver, and improve useful products. We do not sell your data, share it with advertisers, or run third-party advertising on our products. We store your data securely and will delete or anonymise it on request where we are legally able to do so.

What data we collect and why

DataWhy we collect itLegal basis
Email address To deliver your purchased product and send the welcome email sequence Contract performance
Name (if provided) To personalise delivery emails Contract performance
Payment data Processed by our payment provider. We do not store card details. Contract performance
Purchase history To manage your access, process refund requests, and apply purchase credits Contract performance / Legitimate interest
Email delivery and engagement data To confirm that essential product emails are delivered, troubleshoot access issues, and understand whether our communications are useful. Where tracking requires consent, we will request it or disable this tracking. Legitimate interest / consent where required
Support correspondence To resolve your queries and improve our products Legitimate interest
Website and technical usage data To understand site performance, protect the website, identify errors, and improve the user experience. Where we use analytics, we aim to use privacy-respecting tools and avoid advertising-based tracking. Legitimate interest / consent where required

Marketing communications

If you subscribe to updates, download a free resource, or purchase a product, we may send you relevant product updates, educational content, or service messages. You can unsubscribe from marketing emails at any time. We will still send essential transactional emails where needed to deliver a product, respond to a request, process a refund, or meet a legal obligation.

What we do not do with your data

Cookies

We use cookies and similar technologies to enhance your experience, analyse site performance, and remember your preferences. You can manage your cookie preferences at any time. For full details, see our Cookie Policy.

Important note on health‑related data and our secure records feature

To make your experience seamless across our products—for example, moving from Clarify heart risk to Prevent heart risk—we offer a secure records feature. This means health‑related information you enter (such as cholesterol results, family history, risk factors, and similar data) can be stored centrally against your account so you never have to re‑enter the same information twice.

Zero‑knowledge architecture – we cannot see your data. Because we have no legitimate interest, need, or right to access your health information, we have designed this feature with complete client‑side encryption. Your data is encrypted on your device using a key derived from your account credentials, before it is transmitted to our servers. This encrypted data is stored in our secure, encrypted PostgreSQL database (hosted on Neon), but it remains entirely unreadable to us.

The decryption key never leaves your device. We do not store, have access to, or possess the ability to derive your decryption key. This means Shyntesy literally cannot see the health data, even if compelled by a court order, a rogue employee, or a server breach – because the decryption key never leaves your device.

Not even Shyntesy can access it – nor anyone else. Because your data is encrypted with a key that only you hold, it is inaccessible to everyone – including your partner, spouse, insurer, employers, hackers, our own staff, or any third party. Your health records are truly private between you and your device, end‑to‑end. We have built this system so that you never have to trust us with your sensitive information – only your own device and your own login credentials.

What this means for you: Because we cannot decrypt your data, we also cannot recover it if you lose access to your account or device. Please keep your login credentials secure and consider backing up any critical information locally. If you encounter a technical issue with the records feature, our support team can assist with the infrastructure (sync, storage, retrieval) but cannot help you recover or decipher the actual content of your records – because we never had the ability to read it in the first place.

Your control: You can delete your encrypted records at any time via your account settings. Because the data is encrypted with a key we do not hold, deletion is permanent and unrecoverable by us.

Legal basis: We process this data on the basis of your explicit consent (which you give when you choose to save information) and our legitimate interest in delivering the products you have requested (contract performance). However, because the data is encrypted client‑side before we receive it, our "processing" is limited to storing opaque, unreadable ciphertext – giving you the strongest possible privacy protection under GDPR, UK GDPR, and CCPA.

Who we share data with

Payment providers

We use PCI-compliant payment providers such as Stripe and, where available, PayPal, to process payments. These providers collect and process payment information directly. We receive confirmation of successful payment but do not store card details.

Email service providers

We use email service providers to send transactional emails, product delivery messages, support replies, and, where you have subscribed or where otherwise permitted by law, product updates. Your email address is shared with providers only for these purposes.

Cloudflare

Our websites are served and protected by Cloudflare. Cloudflare may process limited technical data (IP addresses, request metadata) as part of its CDN and security services. See Cloudflare’s privacy policy.

Legal requirements

We may disclose your data if required to do so by law, court order, or regulatory authority.

Data retention

We retain your data for as long as necessary to deliver your purchased product, honour your guarantee period, and comply with our legal obligations. In practice:

You can request deletion of your personal data at any time (subject to legal retention requirements) by emailing [email protected] or send a quick deletion request.

Your rights

Depending on where you are located, you may have the following rights in relation to your personal data.

Right of access
Request a copy of the personal data we hold about you.
Right to rectification
Ask us to correct inaccurate or incomplete data.
Right to erasure
Ask us to delete your personal data, subject to legal retention requirements.
Right to restrict processing
Ask us to limit how we use your data in certain circumstances.
Right to data portability
Request your data in a structured, machine-readable format.
Right to object
Object to processing based on legitimate interest, including direct marketing.
Right to withdraw consent
Where we rely on consent, you can withdraw it at any time.

To exercise any of these rights, email [email protected] or send a quick rights request. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.

California residents

Under the California Consumer Privacy Act (CCPA), you have the right to know what personal data we collect, request deletion, and opt‑out of the sale of your data. We do not sell your data, and we do not share it with third parties for cross‑context behavioural advertising. If you are a California resident and wish to exercise your rights, please contact us at [email protected] or send a quick CCPA request.

Security

We take reasonable technical and organisational measures to protect your personal data against unauthorised access, loss, or destruction. Our websites are served over HTTPS. Payments are handled by leading payment processors using industry-standard encryption. We do not store payment card data.

No method of transmission over the internet is completely secure. If you have concerns about a specific data security matter, please contact us.

International transfers

Our service providers may process data outside your country of residence, including outside the UK, EU, or European Economic Area. Where this happens, we rely on appropriate safeguards such as adequacy decisions, Standard Contractual Clauses, or equivalent lawful transfer mechanisms.

Links to other sites

Our website may contain links to external services or resources. We are not responsible for the privacy practices of those third‑party sites. We encourage you to read their privacy policies before providing any personal data.

Children

Our products are intended for adults. We do not knowingly collect personal data from anyone under the age of 16. If you believe a child has provided us with personal data, please contact us and we will delete it.

Changes to this policy

We may update this policy as our practices evolve or legal requirements change. Significant updates will be noted with a revised date at the top of this page. Where a change materially affects how we use personal data, we will provide additional notice where required by law.

Data enquiries and rights requests

For any privacy-related question, rights request, or concern, contact us at [email protected] or send a quick message.

We will acknowledge your request within 5 business days and respond fully within 30 days. If your request is complex or you have made multiple requests, we may extend this by a further 60 days with notice.

For detailed enquiries that require attachments or a full‑page form, visit our contact page.