Synology Services Data Collection Disclosure

SERIOUS
FIRST SEEN 2026-08-26 · VERSION 20260826_rev01 · COMPARED WITH 20260811_rev01

What changed, in plain language

Synology added a whole new section for "DSM Agent," an AI chat assistant built into DSM. It collects your questions, conversation history, and device details, and — if you turn on an optional setting — can read what's on your DSM screen, including file names, paths, account names, and settings. Some of this data is sent to outside AI providers (Google, OpenAI, Microsoft Azure) to generate answers. Conversations are kept on Synology's AI server for 31 days, but data copied into "service quality analytics" has no fixed deletion date. Nothing else in the document changed.

Changes that may affect you

AI can read your open screens, including file names and account namesSERIOUS
DATA COLLECTION

If you turn on the on-screen information setting, the AI reads whatever DSM apps you have open — file lists, folder paths, account names, and configuration settings. Synology admits this can include personal or confidential information. It's optional and off by default, but it's a big step up from a chatbot that only sees what you type.

If you enable this feature, DSM Agent may read information displayed in application interfaces currently open on your DSM desktop to understand the context of your request and provide more relevant responses.

What you can do — Leave the on-screen information feature turned off unless you need it, and close windows showing sensitive files or account details before using it.

Your questions and conversations can go to Google, OpenAI, and MicrosoftSERIOUS
DATA SHARING

Synology may send your chat content to outside AI companies — Google's Gemma model when Synology's own AI is unavailable, and OpenAI and Microsoft Azure for text matching. Once your data leaves Synology, it's covered by those companies' privacy rules, not Synology's. The disclosure doesn't say whether the on-screen information is included in what gets sent.

Certain data may also be processed by the third-party service providers listed below for the specific purposes described.

What you can do — If you don't want your questions leaving Synology's servers, disable DSM Agent in Package Center.

New collection of chat content and device detailsMATERIAL
DATA COLLECTION

Using DSM Agent means Synology collects what you type, your full conversation, and details about your hardware and software. This is data Synology didn't collect before this feature existed. It's tied to identifiers like your User ID and Storage ID, so it isn't anonymous.

DSM Agent uses a randomly generated session ID, as well as technical identifiers such as Storage ID, User ID, and Message ID, to associate messages with the relevant conversation

What you can do — Disable DSM Agent in Package Center if you'd rather not have chat data collected.

Analytics copy of your conversations has no deletion deadlineMATERIAL
DATA RETENTION

Conversations on the AI server get deleted after 31 days, which is clear and reasonable. But a separate copy — including your actual conversation records and session IDs — goes to an analytics server with no fixed time limit. It's kept as long as Synology considers it necessary, which they decide themselves.

Retained for the duration of the applicable service analysis or issue investigation and deleted when no longer necessary for those purposes

What you can do — Submit a deletion request to Synology if you want your DSM Agent conversation data removed.

You're responsible for keeping credentials out of the chatMINOR
USER OBLIGATIONS

Synology tells you not to type passwords, codes, private keys, or tokens into DSM Agent, and not to leave them on screen if screen-reading is on. That puts the burden on you to avoid an easy mistake, rather than on the system to filter it out.

DSM Agent does not require you to provide passwords, verification codes, private keys, access tokens, or other sensitive credentials.

What you can do — Never paste passwords, API keys, or recovery codes into the DSM Agent chat window.

Changelog

  1. + ADDEDNew AI assistant "DSM Agent" added to the covered services list

    DSM Agent was added to the list of Synology services this disclosure covers. It's an AI chat feature inside DSM that answers questions about how to use and troubleshoot your system.

    Synology DSM Agent is an interactive AI feature integrated into DSM that helps users obtain operating guidance, troubleshooting recommendations, and other information related to DSM services.

  2. + ADDEDDSM Agent collects your questions, chat history, and device details

    When you use DSM Agent, Synology collects what you type, the whole conversation, and information about your device like the DSM version, product model, and how much memory it has.

    This includes the questions you enter, conversation content, and device information such as the DSM version, product model, and physical memory capacity.

  3. + ADDEDOptional setting lets the AI read what's on your screen

    If you switch this on, DSM Agent can read the app windows open on your DSM desktop — including file names, folder paths, account names, and settings. Synology says this may include personal or confidential information. It's off unless you enable it.

    This may include settings displayed in Control Panel, file lists in File Station, and related information such as file names, paths, account names, or configuration details, which may contain personal data or confidential information.

  4. + ADDEDYour data may be sent to Google, OpenAI, and Microsoft

    Most processing happens on Synology's own servers, but your questions and conversations can be sent to Google's Gemma model when Synology's AI is down, and to OpenAI and Microsoft Azure to help the system match your question to relevant content.

    Certain data may also be processed by the third-party service providers listed below for the specific purposes described. Only the data necessary for the applicable purpose will be transmitted.

  5. + ADDEDRetention: 31 days on the AI server, open-ended on the analytics server

    Conversations on Synology's AI server are deleted automatically after 31 days. But a copy kept for "service quality analysis" has no set deadline — it stays as long as Synology decides it's needed. Chats stored on your own NAS are yours to delete anytime.

    Retained for the duration of the applicable service analysis or issue investigation and deleted when no longer necessary for those purposes

  6. + ADDEDYou can request deletion or turn the feature off

    You can disable DSM Agent in Package Center at any time, clear local chat records from your NAS yourself, and ask Synology to permanently delete your conversation data.

    To delete DSM Agent conversation data, you may submit a deletion request to Synology. Once your request has been verified, the relevant data will be **permanently removed**.

  7. + ADDEDWarning not to type passwords into the AI

    Synology tells you not to enter passwords, verification codes, private keys, or access tokens into the chat, and not to leave them visible on screen if you turned on the screen-reading feature.

    Do not enter such information in your questions or conversation content, or display it in an application interface when using the optional on-screen information feature.

Full text changes — 20260811_rev01 to 20260826_rev01

COLOUR MARKS THE SEVERITY OF A FLAGGED CLAUSE · + AND − MARK ADDED AND REMOVED

1919- [Active Insight](https://www.synology.com/)
2020- [MailPlus](https://www.synology.com/)
2121- [Synology Store](https://www.synology.com/)
2222- [C2](https://www.synology.com/)
2323- [Synology AI Advisor](https://www.synology.com/)
2424- [Synology Deep Search](https://www.synology.com/)
25- [DSM Agent](https://www.synology.com/)
2526
2627## Synology Account
2728
2829A Synology Account is the personal account you use to access Synology services, such as QuickConnect, Synology DDNS, Technical Support, Package Activation, Active Insight, and DiskStation Manager ("**DSM**") configuration. You will need to associate your Synology Account with your Synology device to enable those Synology services. Data collected by corresponding Synology services can also be found on this Service Data Processing Policy. Please read the relevant sections for more information.
2930
3031By creating a Synology Account, you will automatically receive our eNews from time to time. You may choose to opt-out from our eNews Service by changing the settings on your Synology Account newsletter page or by clicking on the "unsubscribe" link in the corresponding newsletters. However, if you are an EU resident other than a business user, you will only receive our eNews when your consent is validly provided and you may withdraw your consent at any time by using the methods described above.
493494
494495### How we store your data
495496
496497GPS coordinates submitted through Photo Location Search are processed only for the time necessary to provide the requested place names and are not retained by Synology. Photo Location Search can be disabled at any time in the Deep Search settings to stop further GPS data transmission.
497498
498499The storage and retention of your Synology Account information and promotional access details are governed by Synology's [Privacy Statement](https://www.synology.com/company/legal/privacy).
500
501## DSM Agent
502
503Synology DSM Agent is an interactive AI feature integrated into DSM that helps users obtain operating guidance, troubleshooting recommendations, and other information related to DSM services. To understand the context of user questions and provide relevant responses, DSM Agent collects and processes the data necessary to provide the service after obtaining user consent. Certain data may be processed with the assistance of third-party service providers. You may stop using this service at any time by disabling DSM Agent in Package Center.
504
505### Data we collect
506
507DSM Agent may process the following data to provide its features, maintain service quality, and improve the service:
508
509- **Conversation content and system information:** This includes the questions you enter, conversation content, and device information such as the DSM version, product model, and physical memory capacity. Conversation content is processed to understand your requests, maintain conversation context, and generate relevant responses. System information is processed to provide operating guidance, troubleshooting recommendations, and compatibility information relevant to your system environment.
510- **On-screen information:** If you enable this feature, DSM Agent may read information displayed in application interfaces currently open on your DSM desktop to understand the context of your request and provide more relevant responses. This may include settings displayed in Control Panel, file lists in File Station, and related information such as file names, paths, account names, or configuration details, which may contain personal data or confidential information. DSM Agent does not access on-screen information when this feature is disabled and does not proactively access application interfaces that are not open or the contents of files.
511- **Technical identifiers:** DSM Agent uses a randomly generated session ID, as well as technical identifiers such as Storage ID, User ID, and Message ID, to associate messages with the relevant conversation, maintain conversation continuity, provide relevant services, and locate your data when you exercise your right to access or delete it.
512- **Interaction statistics:** DSM Agent records interactions with certain action buttons in the conversation window, such as Support, Inquiry, Feedback. This data is used only in aggregated form to understand feature usage, maintain service quality, and improve DSM Agent, and cannot be used to identify a specific user.
513
514Note: DSM Agent does not require you to provide passwords, verification codes, private keys, access tokens, or other sensitive credentials. Do not enter such information in your questions or conversation content, or display it in an application interface when using the optional on-screen information feature.
515
516### How we use your data
517
518DSM Agent uses the data described above to understand your requests, generate relevant AI responses, provide operating guidance and troubleshooting recommendations, maintain service functionality and stability, and analyze and improve the user experience.
519
520To provide DSM Agent services, your questions, conversation content, necessary system information, and, if you enable the optional feature, on-screen information are primarily transmitted to and processed on Synology servers. Certain data may also be processed by the third-party service providers listed below for the specific purposes described. Only the data necessary for the applicable purpose will be transmitted.
521
522- **Gemma 4 deployed on the Gemini Enterprise Agent Platform:** May be used to generate AI responses when Synology's AI service is unavailable. For more information about Google's privacy and data protection practices, please refer to the [Google Cloud Privacy Resource Center](https://cloud.google.com/privacy) and [Google Privacy Policy](https://policies.google.com/privacy).
523- **OpenAI and Microsoft Azure embeddings:** Used to create text embeddings that help the system understand and match relevant content. For more information about the applicable service providers' privacy and data protection practices, please refer to the [OpenAI Privacy Policy](https://openai.com/policies/row-privacy-policy/) and [Microsoft Azure Privacy Policy](https://azure.microsoft.com/explore/trusted-cloud/privacy).
524
525Synology restricts access to the processed data based on the principle of least privilege. Only authorized personnel who require access for development, maintenance, troubleshooting, or service quality improvement may access relevant data within the scope necessary for their responsibilities. Such access is subject to internal access control and audit mechanisms.
526
527Synology may use interaction statistics and other de-identified or aggregated service data to prepare internal service quality reports, analyze feature usage, investigate service issues, and improve DSM Agent. These reports do not contain information that can directly identify a specific user and are accessible only to authorized personnel.
528
529### How we store your data
530
531Synology implements reasonable and appropriate technical and organizational security measures, including encryption, access controls, and audit mechanisms, to reduce the risk of unauthorized access, use, alteration, or disclosure.
532
533The storage location and retention period for each type of data are as follows:
534
535| Data type | Storage location | Retention period |
536| --- | --- | --- |
537| Conversation records, system information, Session IDs, Message IDs, relevant on-screen information (if enabled), and interaction records | Synology AI Server | 31 days; automatically deleted upon expiration |
538| Service quality analytics data (including conversation records and associated Session IDs) | Analytics server | Retained for the duration of the applicable service analysis or issue investigation and deleted when no longer necessary for those purposes |
539| Conversation records (local) | User's NAS device | Controlled by the user and may be manually cleared at any time |
540| Session ID / Storage ID / User ID (local) | User's NAS device / browser local storage | Not transmitted to external servers and may be cleared by the user at any time |
541
542
543
544To delete DSM Agent conversation data, you may submit a deletion request to Synology. Once your request has been verified, the relevant data will be **permanently removed**. You may also clear locally stored conversation records directly from your NAS device at any time.