SYNC

Effective 6 October 2026 · Last updated 8 October 2026

Privacy Policy

SYNC is a private space for two people. This policy explains, in plain English, what we collect, why, who can see it, how long we keep it and the choices you have.

The short version
  • What you share in SYNC is visible to you and your partner only. It isn't public, and we don't sell it or use it for advertising.
  • There are no ads, no advertising trackers and no third-party analytics in the app.
  • Location sharing is off unless you turn it on, and even then we only store an approximate (about 1 km) position.
  • Nudity and sexual content are not allowed, even between partners. You can report anything or anyone, and block or disconnect at any time. We are also rolling out automatic image safety checks in a later update. No person at SYNC ever looks at your photos (see section 6).
  • No one at SYNC can view what you and your partner share: not your photos, messages, voice notes, letters, moods or location. Our admin tools only show account details and the dates and details of safety decisions.
  • Almost everything you write or record is end-to-end encrypted: only your phone and your partner's phone can read it. Not SYNC, not our administrators, not Supabase and not any other service provider. Photos are stored encrypted at rest (see section 10).
  • Keys live on your phones. If you lose every way back in (your phone, your partner's phone, your Apple or Google backup and your recovery code), nobody can recover your past shared things, including us.
  • You can delete your account, and what you created, from inside the app at any time.

1. Who we are

SYNC ("SYNC", "we", "us"), based in Surat, Gujarat, India, provides the app. We are the controller (in India, the data fiduciary) of the personal data described here. You can reach us at syncapp.noreply@gmail.com.

2. What we collect

Information you give us

Information we can read, and information we can't

Most of what you share is encrypted so that we can't read it. What stays readable to us is: your name, email address and sign-in details; dates and times (for example when something was sent, or when a plan is scheduled); one-tap reactions; account status and moderation records (scores and warning counts); and the messages you send to support. Section 10 has the full picture.

Information collected automatically

What stays on your phone

When you add a date night to your calendar, SYNC writes it to your device calendar; we only store the event's ID so we can update it later. We never upload your calendar. Likewise, we only access your camera, microphone and photo library when you choose to take, record or pick something. We don't access your contacts.

We don't use analytics or advertising SDKs, and we don't track you across other companies' apps or websites.

3. How we use it and why

We only use your data to provide SYNC, keep it safe, and talk to you about your account. Where the GDPR or UK GDPR applies, our legal bases are:

PurposeDataLegal basis (GDPR / UK GDPR)
Create and run your account, sign you in, connect you with your partner, show your partner what you share, send notifications you've allowedAccount, profile, pairing, shared content, device and notification dataPerformance of our contract with you (Art. 6(1)(b))
Share your approximate location with your partnerApproximate locationYour consent (Art. 6(1)(a)). Switch it off any time in Settings
Gentle Days health featuresPeriod dates, wellbeing check-insYour explicit consent (Art. 9(2)(a))
Keep accounts and SYNC safe: new-device alerts, rate limits, abuse prevention, CAPTCHADevice, technical and pairing dataLegitimate interests in protecting you and the service (Art. 6(1)(f))
Keeping SYNC safe: handling reports, warnings and account closure; recognising banned people who sign up again; preserving and reporting known child sexual abuse material. Once we switch on automatic photo safety checks (a later update), checking uploaded photos for nudity and sexual contentReports you send us; moderation records; scrambled identifiers (email, Apple / Google sign-in ID, app install ID); photos, only once automatic checks are enabledLegitimate interests in a safe service and enforcing our Terms (Art. 6(1)(f)); legal obligation where we must report or preserve CSAM (Art. 6(1)(c))
Answer support requests, appeals and requests for a person to review a safety decisionWhat you send us; the details of the decision (dates, warning count), never the photoContract / legitimate interests
Understand, in totals only, how many people use SYNC and which features they use, so we can improve itDays you opened the app; counts of what is created (never its content)Legitimate interests in running and improving the service (Art. 6(1)(f))
Comply with law, respond to lawful requests, establish or defend legal claimsAs neededLegal obligation (Art. 6(1)(c)); legitimate interests

We don't sell your personal data, share it for cross-context behavioural advertising, or use it to build advertising profiles. We don't use your content to train AI models.

4. Health information (Gentle Days)

Gentle Days lets you note period dates and how you're feeling, and choose whether your partner sees them. This is health information, which the law treats as especially sensitive. We only process it because you choose to use the feature (your explicit consent). It's private to you unless you switch on sharing in Gentle Days settings, and you can stop sharing, or delete your entries, at any time. We never use it for anything except showing it to you and, if you choose, your partner. Period dates, check-ins and messages in Gentle Days are end-to-end encrypted: only your phone and, if you share them, your partner's phone can read them. We can't.

5. What your partner can see

SYNC is built for two. When you're connected, your partner's phone can open and show:

Some things are deliberately hidden until the right moment, like a sealed letter before its opening time or a daily answer before both of you have replied.

Because shared things are encrypted end to end, your partner's phone holds the key to open them; we don't. Your partner can also save things you share (for example by taking screenshots, or saving a photo to their phone). We can't control copies made outside SYNC.

If you disconnect

6. Safety checks of photos

SYNC has a zero-tolerance rule on nudity and sexual or adult images, even between partners (see our Terms). SYNC is a private two-person app: the only person who can send you a photo is the partner you paired with. There is no public feed and no strangers. No person at SYNC ever looks at your photos.

7. Who we share data with

We share personal data only with service providers ("processors") that help us run SYNC. Each one is bound by contract to use it only on our instructions:

ProviderWhat they doLocation
SupabaseDatabase, sign-in, file storage, real-time updates, server functions. It holds your encrypted content as scrambled data it can't read, plus the account details listed in section 2Data stored in Mumbai, India (AWS); server functions may run in other regions, where a photo being checked is processed in memory only
Microsoft (PhotoDNA Cloud Service), planned, once our access is approved and enabledWill compare uploaded photos with fingerprints of known child sexual abuse material. The photo would be processed only for this matchUnited States
Expo (650 Industries)Delivers push notifications and app updatesUnited States
Apple Push Notification service / Google Firebase Cloud MessagingDelivers notifications to iPhone / AndroidUnited States / global
Apple (iCloud Keychain) / Google (account backup)If you leave it on, keep an encrypted backup of the key that restores your shared things on a new phone. This is your own Apple or Google account storage. SYNC never receives it, and you can turn it off in SettingsWherever your Apple or Google account stores it
Google (Gmail)Sends account and security emails from syncapp.noreply@gmail.comUnited States
Cloudflare (Turnstile)Checks that sign-ins come from a person, not a botGlobal

Notifications only carry your first name and a fixed message (for example "Priya is thinking of you"). They never include your notes, letters or photos.

Other services you choose to use: Sign in with Apple and Google sign-in are run by Apple and Google under their own privacy policies. When you search for a song to attach to a letter, the search words go directly from your phone to Apple's public iTunes Search service. No SYNC account information goes with them.

Legal and safety: we may disclose data if required by law or a valid legal request, to report child sexual abuse material, or to protect someone's life or safety. If SYNC is ever involved in a merger or acquisition, your data may transfer to the new owner under this policy, and we'll tell you first.

8. Where your data is stored

Your account and content are stored in India (Mumbai). Some providers above process data in other countries, including the United States. When personal data from the EEA, UK or Switzerland is transferred to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum) included in our providers' data processing agreements, plus the safeguards described in section 10. You can ask us for a copy of the relevant safeguards.

9. How long we keep it

DataHow long
Your account, profile and the content you createUntil you delete it or delete your account
Your shared space after a disconnectArchived for 3 months (or until either of you deletes it sooner), then permanently deleted
LocationOnly your latest approximate position is kept; it's wiped the moment you turn sharing off
The encrypted backup of your keys that your recovery code unlocks (we can't open it)Until you delete your account
Security emails queueDeleted 30 days after sending
Device recordsYour 20 most recent devices, until you delete your account
Days you opened the app400 days, or until you delete your account
An account closed automatically for breaking our TermsYou can still sign in for 14 days to ask for a review or save your things; then the account is deleted as if you had deleted it yourself (unless a review reopens it). Accounts in the child-safety process below are kept as the law requires
Once automatic checks are enabled: records of photos that weren't shared, without a warning (hash, scores)12 months; longer where needed for an open appeal or legal claim
Warnings, pauses and bans, with their records and the scrambled identifiers used to recognise returning accountsKept permanently (warnings don't expire), including after you delete your account. A warning overturned on review stops counting
Sealed copies of photos that led to a warning (no one at SYNC can open them; used only so a review can be carried out)14 days, or until the 14-day window of a closed account ends, then deleted
Known child sexual abuse material we must preserve and report by law (sealed, never viewed by SYNC)At least 1 year, or longer if the law or the authorities require
BackupsBackups rotate every 7 days. After that, deleted data is gone from backups too
Support emailsUp to 2 years after the conversation ends

Deleting your account

You can delete your account in the app: Settings → Delete Account. Or follow the steps on our account deletion page. When you do:

10. How we protect it

End-to-end encryption: what we can and can't see

SYNC uses end-to-end encryption. That means the things you share are scrambled on your phone before they leave it, and can only be unscrambled on your partner's phone. Our servers, our administrators, Supabase and our other service providers only ever hold the scrambled version.

WhatWho can read it
End-to-end encrypted: texts and notes, letters (including "Open when" letters), moods, captions, plans and date-night details, goals, countdowns, playlists, vision-board notes, Gentle Days and period data, messages to your partner, game answers and words, reflections, voice notes, and your approximate (city-level) locationOnly the two partners' phones. Not SYNC, not our administrators, not Supabase and not any service provider
Photos and videos: stored encrypted with keys kept separate from our databaseOnly the couple's phones are given the key to view them. No SYNC staff can view them. See the note below
Readable by SYNC: your name, email address and sign-in data; dates and times; one-tap reactions; account status and moderation records (scores, warning counts); messages you send to supportSYNC, to run your account and keep it safe

An honest note on photos. Photos are encrypted at rest and tightly access-controlled, but they are not end-to-end encrypted like your messages. We plan to add automatic image safety checks in a later update, which would need our server to read an image automatically before your partner sees it; they are not running today. No screen or tool in SYNC lets any person open photos.

Your keys, and getting back in

Other protections

No system is perfectly secure. If a breach affects your personal data, we'll notify you and the relevant authorities as the law requires.

11. Your rights and choices

Depending on where you live, you can ask to access your data, correct it, delete it, download a copy (portability), restrict or object to some processing, and withdraw consent at any time (this doesn't affect what we did before). Many of these you can do yourself in the app: Download my things (it runs on your phone, opens your own encrypted things and gives you a copy), edit your profile, turn off location sharing or Gentle Days sharing, change notification settings, disconnect, or delete your account. For anything else, email syncapp.noreply@gmail.com. If you ask us for a copy of your data, we can send the account details we hold (section 2), but we can't open your encrypted content, so use Download my things for that. We'll reply within one month (or sooner where the law requires), and may need to confirm it's really you first. You won't be treated differently for using your rights.

Automated decisions: if warnings or account closures are ever decided by automated means (for example once automatic photo checks are enabled), you have the right to contest them, to give your point of view, and to ask for a person to review the decision. The person reviews the details of the decision (dates and what you tell us), never the photo. Ask in the app with Ask for a review, or follow the steps on our support page.

You can also complain to a data protection authority. For example: your local EU supervisory authority, the UK Information Commissioner's Office (ico.org.uk), or the Data Protection Board of India. We'd appreciate the chance to help first.

12. Region-specific information

India (Digital Personal Data Protection Act, 2023)

European Economic Area and United Kingdom

Our legal bases are listed in section 3 and international transfers in section 8.

California and other US states

13. Children

SYNC is only for adults aged 18 or older. We don't knowingly collect data from anyone under 18. If you believe a child is using SYNC, tell us at syncapp.noreply@gmail.com and we'll delete the account. Our Child Safety Standards explain how we prevent and respond to child sexual abuse and exploitation.

14. Changes to this policy

If we make important changes, we'll tell you in the app or by email before they take effect, and update the date at the top. Earlier versions are available on request.

15. Contact

SYNC
Surat, Gujarat, India
Privacy questions: syncapp.noreply@gmail.com
Support: syncapp.noreply@gmail.com