Privacy Policy
Effective Date: August 9, 2026
Last Updated: August 9, 2026
Table of Contents
- Who We Are
- What This Policy Covers
- Information We Collect
- How We Use Your Information
- Legal Bases for Processing (EEA/UK)
- How We Share Your Information
- Artificial Intelligence and Automated Processing
- International Data Transfers
- Data Retention
- Your Privacy Rights
- Children's Privacy
- Cookies and Tracking Technologies
- Security
- Do Not Sell or Share My Personal Information (US)
- Changes to This Policy
- Contact Us
1. Who We Are
This Privacy Policy explains how GitSyn, operating as Syn (also known as "GitSyn"), collects, uses, shares, and protects your personal information when you use our platform.
Contact Details:
- Email: dembaduk@gmail.com
- Website: https://gitsyn.cc
2. What This Policy Covers
This Privacy Policy applies to:
- The Syn mobile application (iOS and Android)
- The Syn web application at gitsyn.cc
- All associated services, features, and content (collectively, the "Platform")
This policy does not apply to third-party websites or services that we link to or integrate with. We encourage you to review the privacy policies of any third-party services you access through Syn.
3. Information We Collect
3.1 Information You Provide Directly
| Data Category | Specific Data | When Collected |
|---|---|---|
| Account Information | Email address, password (hashed), display name, username/handle | Registration |
| Profile Information | Biography, avatar photo, skills, GitHub handle, availability status | Profile setup and editing |
| Age Verification | Date of birth | Registration (age gate verification) |
| Location | Latitude and longitude (optional) | When you add location to your profile |
| Content | Posts (text, images, videos, voice notes, documents), projects, stories, comments, poll responses | When you create content |
| Communications | Direct messages (text, images, voice notes, project card shares) | When you send messages |
| AI Interactions | Prompts and instructions you provide to AI Studio assistants | When you use AI Studio features |
| Preferences | Vibe state (e.g., "In the zone," "Stuck," "Exploring"), theme, language, privacy settings, notification preferences | When you adjust settings |
| Financial Information | Processed by Stripe; we store a Stripe customer identifier and purchase records | When you make a purchase |
| Reports | Content or user reports including reason and description | When you report content or users |
3.2 Information Collected Automatically
| Data Category | Specific Data | Purpose |
|---|---|---|
| Device Information | Device model, operating system, app version, unique device identifiers | Crash reporting (Sentry), compatibility |
| Usage Data | Screens viewed, features used, interaction patterns, timestamps | Analytics and product improvement |
| Post Engagement | Views on your posts, reactions received | Content metrics |
| Push Notification Tokens | Firebase Cloud Messaging (FCM) device tokens | Delivering push notifications |
| Log Data | IP address, browser type, referring URLs, access timestamps | Security, fraud prevention |
| Crash Reports | Technical error data, stack traces, device state at time of crash | Debugging and stability (via Sentry) |
3.3 Information from Third Parties
| Source | Data Received | When |
|---|---|---|
| Google (OAuth) | Email address, name, profile picture | When you sign in with Google |
| Apple (OAuth) | Email address (may be relay), name | When you sign in with Apple |
| GitHub (OAuth) | Email address, username, public profile data | When you sign in or link GitHub |
3.4 Sensitive Data
We collect the following categories of data that may be considered sensitive under certain laws:
- Date of Birth: Collected solely for age verification and stored in a restricted database table that is not accessible to other users or the public.
- Precise Location: Latitude and longitude are collected only when you voluntarily add them to your profile. You can remove location data at any time.
- Vibe State Duration: We track how long you remain in a particular vibe state (such as "Stuck") to surface optional mental health support resources. We never sell, share, or monetize this data. You can dismiss these suggestions at any time.
4. How We Use Your Information
| Purpose | Data Used |
|---|---|
| Provide and operate the Platform | Account, profile, content, communications |
| Authenticate your identity | Account credentials, OAuth tokens, biometric preferences |
| Personalize your experience | Preferences, usage data, vibe state, social graph |
| Power the feed algorithm | Your interactions, follows, content engagement, skill and taste vectors |
| Enable AI features | AI Studio prompts, profile context for content embeddings |
| Enable discovery and search | Profile data, content, embeddings (pgvector), location |
| Process payments | Stripe customer ID, purchase records |
| Send notifications | FCM tokens, notification preferences |
| Moderate content | User reports, content data, automated moderation signals |
| Ensure security and prevent abuse | IP addresses, device info, usage patterns, rate limiting data |
| Improve the Platform | Analytics events, crash reports, usage patterns |
| Comply with legal obligations | Account data, communication data (when required by law) |
| Surface mental health resources | Vibe state duration (only for "Stuck" state over 14 days) |
5. Legal Bases for Processing (EEA/UK)
If you are located in the European Economic Area (EEA) or United Kingdom (UK), we process your personal data under the following legal bases under the General Data Protection Regulation (GDPR):
| Legal Basis | Processing Activities |
|---|---|
| Contract (Art. 6(1)(b)) | Account creation, platform operation, content hosting, messaging, payments, core features |
| Consent (Art. 6(1)(a)) | AI feature data processing, push notifications, analytics tracking, location data, marketing communications |
| Legitimate Interest (Art. 6(1)(f)) | Security and fraud prevention, product improvement, content moderation, feed personalization |
| Legal Obligation (Art. 6(1)(c)) | Age verification, tax records, responding to lawful government requests |
You can withdraw consent at any time through your account settings or by contacting us. Withdrawing consent does not affect the lawfulness of processing performed before withdrawal.
6. How We Share Your Information
6.1 Public Information
When you use Syn, certain information is visible to other users by design:
- Your display name, username, avatar, bio, skills, vibe state, and availability
- Posts, projects, comments, and stories you set to "Public" or "Followers"
- Your reaction activity on public posts
You can control the visibility of your content through privacy settings (Private Account, Followers Only, Close Friends, Private).
6.2 Service Providers (Sub-Processors)
We share data with the following service providers who process data on our behalf:
| Provider | Purpose | Data Shared | Location |
|---|---|---|---|
| Supabase, Inc. | Database hosting, authentication, file storage, real-time features | All platform data | AWS (region selected at project creation) |
| Google LLC | OAuth authentication, Firebase Cloud Messaging (push notifications) | Email, name, device tokens | United States |
| Apple Inc. | OAuth authentication, Apple Push Notification Service | Email, name, device tokens | United States |
| GitHub, Inc. (Microsoft) | OAuth authentication, profile linking | Email, username | United States |
| Groq, Inc. | AI language model processing for AI Studio | User prompts, content context | United States |
| Nousearch, Inc. (OpenRouter) | AI language model routing for AI Studio | User prompts, content context | United States |
| Stripe, Inc. | Payment processing | Email, payment method, purchase details | United States |
| Functional Software, Inc. (Sentry) | Error monitoring and crash reporting | Device info, crash data, user identifiers | United States |
6.3 When We May Disclose Your Information
We may disclose your information:
- With your consent or at your direction
- To comply with law, such as a valid subpoena, court order, or government request
- To protect rights and safety, including enforcing our Terms of Service, investigating violations, and preventing harm
- In connection with a business transfer, such as a merger, acquisition, or sale of assets (you will be notified of any change in data controller)
- In aggregated or anonymized form that cannot reasonably identify you
6.4 Information We Do Not Sell
We do not sell your personal information. We do not share your personal information with third parties for their own direct marketing purposes. We do not use your data for advertising. Syn is an ad-free platform.
7. Artificial Intelligence and Automated Processing
7.1 AI Features
Syn includes artificial intelligence features that process your data:
- AI Studio: You can create AI assistants that generate content drafts based on prompts you provide. Your prompts are sent to third-party AI providers (Groq and/or OpenRouter) for processing. Generated drafts are stored on our servers for your review.
- Feed Algorithm: We use automated ranking to personalize your feed based on your interactions, follows, skill relevance, taste overlap, and other signals. This constitutes automated profiling.
- Content Embeddings: We generate mathematical representations (embeddings) of content and profiles to power discovery features like "People Like This" and visual search.
- AI Involvement Tags: Posts may carry labels indicating the level of AI involvement (Human-built, AI-assisted, AI-hybrid, AI-directed).
- Content Moderation: We may use automated tools to detect potentially violating content before human review.
7.2 AI Copilot (Admin Feature)
Platform administrators may configure AI-powered content suggestion systems ("Copilot") that can generate draft posts. All AI-generated content goes through a human review queue before any publication.
7.3 Your Rights Regarding Automated Processing
Under GDPR Article 22, you have the right not to be subject to decisions based solely on automated processing that produce legal effects or similarly significantly affect you. You may:
- Request information about the logic involved in automated decisions
- Request human review of an automated decision
- Contact us at dembaduk@gmail.com to exercise these rights
7.4 Data Sent to AI Providers
When you use AI Studio, the following data may be processed by third-party AI providers:
- Your prompts and instructions
- Content context you provide within the AI Studio interface
We do not send your direct messages, private profile data, location, or financial information to AI providers. AI providers process data under their own privacy policies and our data processing agreements.
8. International Data Transfers
Our service providers are primarily located in the United States. If you are located outside the United States, your data will be transferred to and processed in the United States and potentially other countries.
For users in the EEA, UK, or Switzerland, we rely on the following transfer mechanisms:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- The service provider's participation in recognized data transfer frameworks
9. Data Retention
We retain your personal data only for as long as necessary for the purposes described in this policy, or as required by law.
| Data Category | Retention Period |
|---|---|
| Account and profile data | Until you delete your account, plus 30 days for backup propagation |
| Posts and projects | Until you delete them or delete your account |
| Soft-deleted posts | 90 days, then permanently deleted |
| Stories | Automatically deleted after 24 hours |
| Direct messages | Until conversation or account deletion |
| AI drafts | 90 days after generation |
| Analytics data | 24 months, then anonymized or deleted |
| Crash reports | 90 days (Sentry default) |
| Push notification tokens | Until app uninstall or token refresh |
| Payment records | 7 years (tax and legal requirements) |
| Admin audit logs | 3 years |
| Location data | Until you remove it or delete your account |
When you delete your account, we permanently delete your data through cascading database deletion. This action is irreversible.
10. Your Privacy Rights
10.1 Rights for All Users
Regardless of your location, you can:
- Access your profile data through the app
- Edit your profile and preferences at any time
- Delete your account and all associated data through Settings
- Control your post visibility (Public, Followers, Close Friends, Private)
- Block or mute other users
- Manage notification preferences
- Toggle privacy settings (private account, follower visibility)
10.2 European Economic Area and United Kingdom (GDPR)
If you are in the EEA or UK, you have the following additional rights:
- Right of Access (Art. 15): Request a copy of your personal data
- Right to Rectification (Art. 16): Correct inaccurate data
- Right to Erasure (Art. 17): Request deletion of your data ("right to be forgotten")
- Right to Restriction (Art. 18): Request restriction of processing
- Right to Data Portability (Art. 20): Receive your data in a structured, machine-readable format
- Right to Object (Art. 21): Object to processing based on legitimate interest, including profiling for feed personalization
- Right to Withdraw Consent (Art. 7): Withdraw consent at any time without affecting prior processing
- Right Regarding Automated Decisions (Art. 22): Not be subject to solely automated decisions with significant effects
How to exercise these rights: Email dembaduk@gmail.com with your request. We will respond within 30 days (extendable by 60 days for complex requests).
Supervisory Authority: You have the right to lodge a complaint with your local data protection authority.
10.3 California (CCPA/CPRA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act:
- Right to Know: Request the categories and specific pieces of personal information we collect
- Right to Delete: Request deletion of your personal information
- Right to Correct: Request correction of inaccurate personal information
- Right to Opt-Out: Opt out of the "sale" or "sharing" of personal information (see Section 14)
- Right to Limit Use of Sensitive Personal Information: Limit how we use your sensitive personal information
- Right to Non-Discrimination: We will not discriminate against you for exercising your rights
How to exercise these rights: Email dembaduk@gmail.com or use the in-app privacy controls.
Categories of personal information we collect: Identifiers, personal information categories listed in the California Customer Records statute, internet or electronic network activity, geolocation data, audio/visual information, professional information, inferences.
We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising.
10.4 Brazil (LGPD)
If you are in Brazil, you have rights under the Lei Geral de Proteção de Dados, including confirmation of processing, access, correction, anonymization, portability, deletion, information about sharing, and the ability to revoke consent. Contact dembaduk@gmail.com to exercise your rights.
10.5 India (DPDP)
If you are in India, you have rights under the Digital Personal Data Protection Act, 2023, including the right to information about processing, correction and erasure of data, grievance redressal, and nomination of a representative. Contact dembaduk@gmail.com.
10.6 Canada (PIPEDA)
If you are in Canada, you have the right to access and correct your personal information, and to withdraw consent for non-essential processing. Contact dembaduk@gmail.com.
11. Children's Privacy
Syn is not directed at children. We do not knowingly collect personal information from children under the age of 13 (or 16 in the European Economic Area).
We implement an age gate during registration that requires users to confirm they meet the minimum age requirement. If we become aware that we have collected personal information from a child below the applicable minimum age without proper consent, we will take steps to delete that information promptly.
If you are a parent or guardian and believe your child has provided personal information to us, please contact us at dembaduk@gmail.com and we will delete the child's account and data.
12. Cookies and Tracking Technologies
Our web application uses cookies and similar technologies. For detailed information, please see our Cookie Policy.
In summary:
- Strictly Necessary Cookies: Authentication session management (cannot be disabled)
- Functional Storage: Local data caching for offline access and performance
- Analytics: Screen views and interaction tracking (requires consent in the EEA/UK)
13. Security
We implement reasonable technical and organizational measures to protect your personal data, including:
- Encryption in transit (TLS/HTTPS)
- Encrypted credential storage (flutter_secure_storage using platform keychains)
- Row-level security policies restricting database access
- Restricted access to sensitive data (e.g., date of birth stored in isolated table)
- Rate limiting to prevent abuse
- Administrative access controls with role-based permissions and audit logging
Regarding Direct Messages: Direct messages are currently encrypted in transit (TLS) and at rest (database encryption), but are not end-to-end encrypted. This means that authorized platform administrators may access message content for content moderation and legal compliance purposes.
No method of transmission or storage is completely secure. While we strive to protect your personal information, we cannot guarantee absolute security.
14. Do Not Sell or Share My Personal Information (US)
We do not sell your personal information. We do not share your personal information with third parties for cross-context behavioral advertising. Syn is an ad-free platform.
If you are a California resident and wish to exercise your right to opt out, you may contact us at dembaduk@gmail.com.
15. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will:
- Update the "Last Updated" date at the top of this policy
- Notify you via email or in-app notification
- For material changes, provide at least 30 days notice before the changes take effect
Your continued use of the Platform after the effective date of changes constitutes your acceptance of the updated policy. If you do not agree with the changes, you should stop using the Platform and delete your account.
16. Contact Us
If you have questions about this Privacy Policy, wish to exercise your privacy rights, or have concerns about our data practices, please contact us:
- Email: dembaduk@gmail.com
- Website: https://gitsyn.cc
For users in the EEA or UK, you also have the right to lodge a complaint with your local data protection supervisory authority.
This Privacy Policy was last reviewed on August 9, 2026. It should be reviewed and updated whenever significant changes are made to the Platform's data practices or when new features are launched.