Privacy

Last updated 2026-09-15

We collect the minimum data we need to run Synk and we don't sell it.

What we collect

Your account: an email address and a password hash — or, if you sign in with Google or GitHub, the name, email address and avatar they hand us and nothing more — plus your handle, and a display name, bio, avatar and website if you add them. Your content: collections, items, uploaded files, comments and chat messages. Your activity: session metadata (IP address, browser, timestamps), a log of sensitive actions (sign-in, password change, sharing, suspension, reports), and the notification channels you choose. When you sign up we also keep how you found us — the site or campaign link that sent you, or whose referral link you followed; that person sees how many sign-ups their link brought, never who.

Location

Location sharing is off unless you turn it on, and it is never required to use Synk. While it is on, your device sends its position to us so the people you have chosen can see you on a map. You choose who: everyone you are connected to, a list you pick, or one of your group chats. Sharing with a group is mutual — the people in it who are also sharing with it can see you, and you can see them; anyone in the group who is not sharing sees nothing. You choose how precisely, and you choose for how long — an hour, eight hours, or until you switch it off.

We blur your position before storing it. The precise reading your device reports is used to work out which cell of a grid you are in, and only that cell's centre is saved — so the exact location never reaches our database and cannot be recovered from it, by us or by anyone who obtained a copy. The grid is offset by a secret unique to you, so two people in the same place do not land on the same point. Stored positions are encrypted.

We keep one position per person: the latest one, overwritten each time. There is no location history, and we do not build one. A stored position expires within 30 minutes of your last update, or when your sharing window closes, whichever comes first, and expired positions are deleted. Switching sharing off deletes your stored position immediately. Closing your account deletes it along with your sharing settings.

We do not collect location in the background — only while Synk is open in front of you. We do not use your location for advertising, analytics, or personalisation, and we do not share it with anyone except the people you selected. There is no public map, no shareable location link, and no administrator view of where anyone is. Location sharing requires an account holder aged 16 or over, and a date of birth is asked for only to check that.

Messages

Messages and their attachments are stored encrypted and belong to the conversation they are in. A message you delete is replaced by a note that it was removed. When you close your account your messages stay in the other people's history under a "Deleted account" label, rather than rewriting what their thread said. We don't look at messages unless a participant reports one.

Payments

If you subscribe, Stripe or PayPal takes the payment and holds your card or account details; we never see them. We keep the subscription's identifier, plan and dates, a record of each payment with a link to its receipt, and we keep those payment records after an account is closed for as long as tax law requires.

Email

We email you to confirm an address, reset a password, or tell you about your account or a payment — those can't be switched off. Security notices and missed chat messages are notifications, on by default and yours to turn off in your settings; the mail carries a link to them. We don't send marketing email.

Who we share data with

The companies that run pieces of Synk for us, each for its piece only: Hetzner hosts the server, in Germany; Cloudflare fronts the site and runs the anti-bot check on the abuse-report form; Postmark sends our email; Bugsnag receives error reports and Better Stack our server logs, which can carry a request's technical details (an IP address, a URL, a user id) but never your files or messages; Amazon S3, in Frankfurt, stores your uploaded files, encrypted at rest, and our backups, encrypted before they leave the server; Google's Firebase Cloud Messaging carries the Android app's push notifications, so it receives your phone's push token and each notification's title and text, which for a mention quotes the comment. Your browser also talks directly to a few services when a page needs them — OpenFreeMap for map tiles, Gravatar for a profile-picture fallback, and jsDelivr and Hugging Face to fetch the in-browser dictation model — and each sees your IP address the way any website does. If you choose a server-side dictation engine, that recording is sent to the transcription provider named beside it and nowhere else. We don't sell your data and we don't share it with advertisers.

Cookies

Ours keep you signed in and hold the session that protects forms, which also remembers the campaign link a visit arrived on until you close the browser. Following a referral link sets one more, for 90 days, so the person who shared it is credited if you sign up: it names their account and nothing about you, and signing up removes it. Your theme, where the music player was, the command palette's recent searches and the dictation model you chose stay in your browser's own storage — or the app's, on a phone — and never reach us. Cloudflare, which fronts the site, may set its own security cookies. None of them is for advertising, and none follows you to another site.

On a phone

The Synk apps for iPhone and Android open the same site and keep nothing the site does not, apart from the push token above. They ask the system for the camera, the microphone, your location or, on Android, permission to send notifications only when you use the feature that needs it — attaching a photo, dictating, sharing where you are, turning notifications on — and you can refuse any of them and keep using the rest.

How we count visits

We count page views ourselves, on our own server, and share the numbers with nobody. For each page shown we keep the path, the site the visit came from, the time, and a code made from your address and browser under a key that changes every day and is then thrown away — so we can tell how many people came on a given day, and nobody, including us, can turn a code back into a person afterwards. There is no cookie for it, no third-party script, and nothing an advertiser could use. A browser that sends the Global Privacy Control signal is not counted at all. If you are signed in, the view is tied to your account the way any request you make is.

Retention

The activity log is pruned after 365 days, and page-view counts after 400 days. Trashed collections and items are deleted for good after 30 days, the notifications in your bell after 30 days, exports after 3 days, and a stored map position within 30 minutes. Backups are kept for up to 30 days (the database) and up to six months (uploaded files), encrypted.

Your data

You can download everything you own — collections, items, files and your profile — as one archive from your settings, and export any collection on its own. Closing your account, also from your settings, is immediate and irreversible: your collections, uploads, sessions, connections and location data are deleted, and your name, handle and email are stripped from what remains. Your comments and messages stay in other people's threads under a "Deleted account" label, and payment records are kept as tax law requires.

Close your account

Contact

Privacy questions: [email protected].