Back to home

Privacy Policy

Last updated: August 7, 2026

1. Who We Are

Syncro is operated by Paulo Cristo, an individual software developer based in the European Union. For the purposes of EU data protection law (GDPR), Paulo Cristo acts as the data controller for personal data processed through this service.

Contact: paulocristo@me.com

2. Data We Collect

We collect the minimum data required to provide the service:

Account data

When you sign in with Google OAuth, we receive your name, email address and avatar from the provider. On the web, authentication is handled by NextAuth; on mobile, by Supabase Auth.

Wellness & check-in data

Mood scores, eye breaks, hydration, posture scores, focus sessions and daily snapshots that you record in the app. This data is associated with your account and used to show your personal history and 7-day trends.

Location & presence data

When you use the community globe, we determine your approximate country and city from your IP address so your location can be shown on the map. We also store a "last seen" timestamp to show who is currently active.

Community data

Chat messages you post in the community rooms.

Billing data

If you subscribe to a paid plan, purchases are processed by the Apple App Store or Google Play (via RevenueCat). We do not store your card numbers or full payment details.

Cookies & analytics

We use essential cookies for authentication (session tokens). We do not use advertising cookies. See Section 7 for details.

3. Legal Basis for Processing (GDPR)

Under the GDPR, we rely on the following legal bases:

  • Contract performance (Art. 6(1)(b)): Processing account and wellness data is necessary to provide the service you signed up for.
  • Legitimate interests (Art. 6(1)(f)): Security monitoring, fraud prevention, and product improvement.
  • Consent (Art. 6(1)(a)): Non-essential processing, where applicable.
  • Legal obligation (Art. 6(1)(c)): Where required by applicable law (e.g. invoicing, tax records).

4. How We Use Your Data

  • To authenticate you and maintain your account
  • To display your wellness history and 7-day mood trends
  • To show the community globe and active users
  • To enable community chat
  • To process subscriptions and in-app purchases
  • To send essential transactional emails (e.g. account notices)
  • To improve and debug the service

We do not sell your data. We do not use your data for advertising or share it with third parties for their own marketing purposes.

5. Data Retention

Account data is kept for as long as your account is active. You can delete your account at any time from the app's Settings page. Upon deletion, personal data is removed within 30 days, except where retention is required by law (e.g. invoicing records, kept for up to 7 years under EU VAT rules).

Wellness and presence data is retained for as long as your account is active and is deleted when your account is deleted.

6. Your Rights Under GDPR

If you are in the EU/EEA, you have the following rights:

  • Access: Request a copy of the data we hold about you.
  • Rectification: Correct inaccurate data.
  • Erasure ("right to be forgotten"): Request deletion of your data.
  • Restriction: Ask us to limit how we use your data.
  • Portability: Receive your data in a machine-readable format.
  • Objection: Object to processing based on legitimate interests.
  • Withdraw consent: Withdraw any consent you have given at any time.

To exercise any of these rights, email us at paulocristo@me.com. We will respond within 30 days. You also have the right to lodge a complaint with your national data protection authority.

7. Cookies

Essential cookies (always active)

We use a session cookie for authentication (your sign-in session token) and a CSRF protection token. These are required for the service to work.

Other cookies

We do not use third-party advertising cookies or cross-site tracking cookies.

8. Third-Party Services

We use the following sub-processors:

  • Supabase — Database, authentication and backend hosting. Supabase Privacy Policy
  • Google — OAuth sign-in.
  • RevenueCat — Subscription and in-app purchase management (Apple App Store / Google Play).
  • Vercel — Web hosting.

All sub-processors are contractually bound to process data only as instructed and to maintain appropriate security measures.

9. International Transfers

Our hosting providers may store data on servers located in the EU and the United States. If any data transfer outside the EEA occurs, it is protected by Standard Contractual Clauses (SCCs) or equivalent safeguards under GDPR Chapter V.

10. Security

We implement appropriate technical and organisational measures: HTTPS in transit, secure session handling, access controls and regular dependency audits. No transmission over the internet is 100% secure — if you discover a security issue, please disclose it responsibly to paulocristo@me.com.

11. Changes to This Policy

We may update this policy as the service evolves. Material changes will be communicated by email or in-app notice at least 14 days before they take effect. The "last updated" date at the top always reflects the current version.

12. Contact

Questions about this privacy policy? Email us at paulocristo@me.com.