SyncPoint
Back home

Privacy Policy

Last updated: [DATE]

Not legal advice, not final. This draft accurately describes what SyncPoint actually does with your data today, but it has not been reviewed by a lawyer, and it doesn't yet address region-specific requirements (GDPR, CCPA, etc.) that may apply depending on where your users live. Have it reviewed before relying on it with real users.

This policy explains what data SyncPoint (the "Service") collects, why, and where it goes. We've tried to write this in plain language rather than dense legal boilerplate.

1. What we collect

DataWhy we have it
Email addressAccount login, password reset, billing receipts
PasswordStored as a one-way hash - we cannot see or recover your actual password, ever
Subscription tier & Stripe customer/subscription IDsKnowing what plan you're on; billing
Question count per monthEnforcing free-tier usage limits
Squad notes you writeShown to the other members of your Squad

2. Screenshots and questions

When you press the hotkey and ask a question with "include screen" turned on, a screenshot of your screen is captured and sent - along with your question - to our backend, which forwards it to Google's Vertex AI to generate an answer. We do not store your screenshots. They're used only to generate that one answer and are not saved to our database or servers afterward. Google's own data handling for API requests is governed by their own policies, not this one - we don't control that.

If you also enable web-search grounding, your question text is sent to Brave Search to find current information. Search queries are not stored by us beyond what's needed to generate that answer.

3. Clips and highlight reels

Clips and reels you save are stored only on your own computer, in your Videos folder. We never receive or store them - there's currently no feature to upload or share them with us or anyone else.

4. Where your data lives (subprocessors)

We use the following third-party services to run SyncPoint. Each only receives the specific data needed for its function:

  • Google Cloud (Vertex AI) - processes screenshots and questions to generate answers
  • Brave Search - processes search queries when web-search grounding is used
  • Stripe - processes payments and stores your payment method; we never see your full card number
  • Render - hosts our backend server and database
  • Resend - sends password-reset emails

5. Website login storage

The website stores your login session in your browser's local storage (not a tracking cookie) so you don't have to log in on every page. Clearing your browser data will log you out.

6. How long we keep data

We keep your account data for as long as your account is active. If you delete your account, we delete your personal data within a reasonable time, except where we're required to keep billing records for tax/legal purposes.

7. Children's privacy

SyncPoint isn't directed at children under 13, and we don't knowingly collect data from anyone under that age. If you believe a child has created an account, contact us and we'll close it.

8. Your rights

You can ask us to access, correct, or delete your personal data at any time by contacting [YOUR SUPPORT EMAIL]. You can also delete your own squad notes and leave a squad directly from the app.

9. Security

Passwords are hashed with bcrypt and never stored in plain text. Data is transmitted over HTTPS. No system is perfectly secure, but we take reasonable steps to protect your data.

10. Changes to this policy

We may update this policy as the Service changes. We'll post the updated version here with a new "last updated" date.

11. Contact

Questions about this policy or your data? Reach us at [YOUR SUPPORT EMAIL].