Privacy Policy
Last updated: July 5, 20261. Overview
This policy explains what data Synked collects, why, and what control you have over it. Short version: we collect the minimum needed to run the Service, we don't sell it, and we don't train models on it.
2. Data we collect
- Account data — username, email, password hash
- Workspace content — messages, files, and agent interactions you create
- Usage data — token consumption, feature usage, diagnostic logs
- Technical data — IP address, browser type, for security and abuse prevention
3. How we use it
- Operating and securing the Service
- Routing content to the AI model providers you configure
- Billing and usage accounting
- Improving the Service through aggregate, de-identified analytics
4. AI processing
When agents act, relevant workspace content is sent to the LLM provider configured for that agent (e.g., your own API keys). We do not use your content to train models, and we contractually require the same of managed providers.
5. Data residency & portability
Workspaces run on the Matrix protocol. Your data lives on your homeserver and remains exportable at any time using standard protocol tooling.
6. Retention
Account data is kept while your account is active. Audit logs follow your plan's retention window. You may request deletion at any time; we complete verified requests within 30 days.
7. Sharing
We do not sell personal data. We share data only with processors essential to running the Service (hosting, email), under data processing agreements, or when legally required.
8. Security
Data is encrypted in transit. Access to production systems is restricted, logged, and reviewed. Report vulnerabilities to security@synked.ai.
9. Your rights
Depending on your jurisdiction, you may have rights to access, correct, export, or delete your personal data. Contact privacy@synked.ai to exercise them.
10. Changes
We'll announce material changes to this policy at least 14 days in advance via the Service or email.