Privacy Policy
Version 3. Effective 2026-09-28.
Controller: Syncropic Inc., a Delaware Public Benefit Corporation ("Syncropic", "we", "us", "our"). In effect from: 2026-09-08. Last updated: 2026-09-28. Privacy contact: legal@syncropic.com.
This policy explains what personal data we process when you use Syncropel, the hosted coordination workspace at syncropel.com, and our websites (together, the "Service"); why we process it; who receives it; how long we keep it; and the rights you have over it. It applies to the hosted Service. If you run the software yourself on infrastructure you control, none of your workspace or assistant content reaches us, and this policy applies only to our websites and to any account you hold with us.
We have not appointed a Data Protection Officer because the law does not require one for our processing; the privacy contact above handles every request. Section 6 states our position on a representative in the European Economic Area (EEA) and the United Kingdom (UK).
1. What we process and why
| Category | What it includes | Why we process it | Legal basis (GDPR and UK GDPR) |
|---|---|---|---|
| Account data | your email address, your name if you give one, sign-in identifiers and session information from our authentication provider | to create, secure and support your account, and to send you notices about the Service | contract (Article 6(1)(b)) |
| Workspace content | the records, threads, runs, files and settings that you and your members put into your workspace | to provide the Service you asked for: storing, backing up, displaying and sharing your content as you direct | contract (Article 6(1)(b)); where you put other people's personal data into your workspace, you are the controller of it and we process it under our Data Processing Agreement |
| Assistant content | the prompts you send to the assistant, which can include content from your records, and the responses it returns | to run the assistant you invoked (section 2) | contract (Article 6(1)(b)) |
| Billing data | billing contact details, subscription and payment status; your payment method is held by our payment processor, not by us | to charge for paid plans and to keep the records that tax and accounting law require | contract (Article 6(1)(b)) and legal obligation (Article 6(1)(c)) |
| Operational telemetry | limited service events such as errors, health signals and the resource use of your workspace, and error reports from the web application (an error message with identifiers and secrets removed, the page, and technical details about your browser; never your workspace content) | to keep the Service reliable, secure and free of abuse, and to fix defects | legitimate interests (Article 6(1)(f)) |
| Request logs | request metadata at our network edge: IP address, timestamps, request path, browser or client identifier | security, rate limiting and abuse prevention | legitimate interests (Article 6(1)(f)) |
| Support correspondence | email you send us and our replies | to answer you and to keep a record of what was agreed | contract (Article 6(1)(b)), or legitimate interests (Article 6(1)(f)) where you are not yet a customer |
| Product news email | your email address, only if you opt in | to tell you about the Service | consent (Article 6(1)(a)); withdraw at any time using the link in each email |
Where we rely on legitimate interests, we have weighed them against your rights: the data is limited, kept briefly (section 4), and used only to keep the Service running safely. You may object (section 5).
Your workspaces on one page. Your "You" page is put together in your own browser: it asks each of your workspaces for what it holds about you, using that workspace's own key, and we do not keep a combined copy. Three things follow from how we run the Service:
- Because we run the network edge and the hosted workspaces, our systems can see that one browser opened those workspaces. This is part of the request logs described above.
- Because we deliver the emails your workspaces send you, we can see which workspaces send you mail.
- We keep the list of workspaces your account owns or is linked to, so that we can show them to you and deliver invites and emails. The people who run our infrastructure could technically read that list. We do not give it to any workspace or organization, and we delete it when you delete your account.
You need to give us an email address to create an account; without it we cannot provide the Service. Everything else you give us is your choice. We do not make decisions about you based solely on automated processing that have legal or similarly significant effects on you.
We do not sell personal information and we do not share it for cross-context behavioural advertising, as those terms are defined in the California Consumer Privacy Act. We do not use your workspace content or assistant content to train AI models, and we do not use it for advertising.
2. The assistant and AI model providers
When you or one of your members invokes the assistant, the prompt (which can include content from the records and threads in your workspace) is sent through our systems to a third-party AI model provider, which generates the response. This is the most sensitive data path in the Service, so we state it plainly:
- The AI model providers we use, and the category of data each receives, are listed at https://syncropic.com/legal/subprocessors. We name a provider on that list before sending any request to it, and give the notice described in section 3.
- Under our contracts with them, our AI model providers may not use your prompts or the assistant's responses to train their models, and may retain them only for a limited period for safety and abuse monitoring.
- You can keep assistant content out of our managed inference path in two ways. Bring your own key: if you supply your own key for an AI model provider, your requests go to that provider under your own agreement with it and do not pass through our managed inference. Self-host: if you run the software on infrastructure you control, none of your workspace or assistant content reaches us.
- The prompts and responses are stored in your workspace as records, like any other content, so that you and your members can see what the assistant did. They stay under your control and are exported and deleted with the rest of your workspace.
3. Who receives your data
We share personal data only with the following recipients.
- Service providers acting on our instructions (our subprocessors). They process data only to provide their service to us, under written data-protection terms. They fall into these categories: a network edge provider that routes requests to the Service and protects it against abuse; hosting providers that run your workspace and its storage; storage providers that hold backups and content you choose to publish; an authentication provider that handles sign-up, sign-in and sessions; a payment processor that handles billing; an email delivery provider that sends account emails about your workspace and your billing; and AI model providers that serve the assistant. Our current subprocessors, the category of data each processes and the location where it does so, are listed at https://syncropic.com/legal/subprocessors. We give at least 30 days' notice, by updating that page and by email to workspace owners, before adding or replacing a subprocessor, except where a replacement is needed urgently to keep the Service running, in which case we notify you as soon as practicable.
- People you authorise. Members you add to your workspace, and recipients of permissions or public links you create, see what you share with them. That is your action, not ours, and you can revoke it.
- Authorities, when the law requires it. We disclose data to authorities only when required by a valid legal order. We tell you before doing so unless the law forbids it or the request involves an emergency, and we push back on requests that are overbroad.
- A successor to our business. If Syncropic is merged, acquired or sells the Service, your data may be transferred to the successor, who must honour this policy. We will tell you before that happens.
We do not share your data with anyone else, and we do not sell it.
4. How long we keep data, and how deletion works
- Workspace content is kept until you close your workspace, or until you erase it, where the erasure feature is available and your erasure settings cover it.
- Individual records cannot be edited or deleted one at a time once they are created: the Service keeps a workspace's history intact. Where the erasure feature is available to your workspace, content concerns an identified person, and your erasure settings cover that content, it makes the content permanently unreadable everywhere it was stored or published; a permanent marker that the erasure took place remains. To remove everything, close your workspace.
- Closing your workspace. When you close your workspace, we delete the workspace and its storage within 7 days. Backup copies expire within 30 days after that. Export everything first: deletion begins when you close. If we terminate your workspace, the Terms of Service give you 30 days to export before deletion begins.
- Account data is kept while you have an account and is deleted within 30 days after you close your workspace and account, except for the minimum we must keep to meet legal obligations or to show that a deletion request was honoured.
- Billing records are kept for as long as tax and accounting law requires, by our payment processor and in our own accounts.
- Operational telemetry is kept for no more than 30 days.
- Request logs are kept for no more than 30 days.
- Support correspondence is kept for as long as needed to resolve your request and any related dispute.
- Assistant content held by AI model providers is retained by them only for the limited period stated in their terms, which we summarise on the subprocessor list.
Every period above that is stated as a number is a ceiling. We do not keep data longer to keep our options open.
5. Your rights
You can export your data yourself at any time, and you can close your workspace to delete it. For anything else, email legal@syncropic.com.
If you are in the EEA, the UK or another place with similar law, you have the right to access your personal data, to have it corrected, to have it deleted, to restrict or object to its processing, to receive it in a portable form, and to withdraw consent where consent is the basis for processing (withdrawal does not affect processing that already took place). We will respond within one month. For a complex request we may extend by up to two further months and will tell you if so. Requests are free of charge unless they are manifestly unfounded or excessive. We will verify your identity before acting. You also have the right to complain to your local supervisory authority (in the UK, the Information Commissioner's Office).
If you live in California or another US state with a consumer privacy law, you may ask us to tell you what personal information we hold about you, to delete it, to correct it, or to give you a copy in a portable form. We will respond within 45 days. We will not treat you differently for exercising a right. You may use an authorised agent, in which case we will ask for proof of the authorisation and verify your identity. We do not sell or share personal information, so there is nothing to opt out of and we do not provide a "Do Not Sell or Share" link.
Members and other people whose data is in a customer's workspace. If your personal data is in someone else's workspace, that customer is the controller of it. Contact them first; if you contact us, we will pass your request to them and help them answer it.
6. Where data is processed, and international transfers
Your workspace is hosted in the United States, and our subprocessors process data in the locations stated on the subprocessor list. If you need your workspace hosted in the EU, contact us; we do not offer it yet.
If you are in the EEA or the UK, your data is transferred to the United States and to the other locations stated on the subprocessor list. Where we act as a processor for a customer in the EEA or UK, transfers are covered by the EU Standard Contractual Clauses and the UK International Data Transfer Addendum, which are incorporated into our Data Processing Agreement. Where we collect your account data directly, we are subject to the GDPR and UK GDPR for that data, and our providers are bound by their own transfer safeguards (the Standard Contractual Clauses and, where they have self-certified, the EU-US Data Privacy Framework). Syncropic has not self-certified under the Data Privacy Framework and does not rely on it. You can ask for a copy of the transfer safeguards we rely on by emailing legal@syncropic.com.
Syncropic Inc. has no establishment in the EEA or the UK. We have not appointed a representative under Article 27 of the GDPR or the UK GDPR because our processing of EEA and UK residents' data is currently occasional, involves no special-category data at scale, and is low risk. We will appoint one if that changes.
7. Children
Our Terms of Service require every user to be at least 16. The Service is not directed to children under 16, and we do not knowingly collect personal data from anyone under 13. If we learn that a user is under 16, we will close the account and delete its data. Contact legal@syncropic.com if you believe a child has given us personal data.
8. Security
We protect your data with measures appropriate to its sensitivity. In summary:
- Each customer's workspace is isolated from every other customer's workspace, and nothing crosses between workspaces except by a permission you grant.
- Data is encrypted in transit on every external connection.
- Workspace storage and backups are encrypted at rest by our hosting and storage providers.
- Access to your workspace is controlled by credentials that are scoped per member, and credentials and keys are stored separately from your content.
- Automated members run with restricted permissions, limited to what you give them, and with their spending and running time bounded.
- Backups are taken daily and rotated, and restore procedures are tested.
- Operational telemetry is limited and is kept for no more than 30 days.
No system is perfectly secure. If a personal-data breach affects you, we will notify you and, where required, the relevant regulators without undue delay and within the time the applicable law requires. Report a security concern to legal@syncropic.com.
9. Cookies and similar technologies
We use only cookies and similar storage that are strictly necessary to run the Service: sign-in and session cookies set by our authentication provider, security cookies (for example to prevent request forgery and to enforce rate limits at our network edge), and a cookie or local setting that remembers your preferences. We do not use advertising cookies and we do not currently run analytics that store identifiers on your device. If we add analytics that do, we will ask for your consent first where the law requires it.
The web application can send error reports to a telemetry workspace that we operate, so that we can fix defects. A report contains the error message with identifiers and secrets removed, the page, and technical details about your browser; it never contains your workspace content. These reports are kept for no more than 30 days and are not sent to any third-party analytics service.
10. Changes to this policy
We may update this policy. We will email the workspace owner at least 30 days before a material change takes effect, and we post every version, with its date, at the address where you are reading this. Changes required by law may take effect sooner, and we will tell you as soon as practicable.
11. Contact
Syncropic Inc., a Delaware Public Benefit Corporation. Privacy requests: legal@syncropic.com. Legal notices: legal@syncropic.com.