SyncO Privacy Policy

Last updated: August 9, 2026

This Privacy Policy explains what data SyncO collects, why we collect it, how we use it, and your choices. It applies to the SyncO mobile app and legal pages hosted at legal.sync0.dev.

1. Who We Are

SyncO is provided by Downlabs ("we", "us", "our"). Support contact: support@sync0.dev.

2. Data We Collect

2.1 Account and profile data

2.2 User content and activity

2.3 Subscription and purchase data

2.4 Device and app data

2.5 Data from connected services

3. Why We Use Data

4. Third-Party Processors We Use and Why

Provider Purpose Data involved
Supabase Authentication, database, and storage backend Account/profile data, app state, usage records, avatar files, subscription status
Apple App Store and Google Play Billing Subscription purchase and entitlement management Product IDs, purchase tokens, transaction IDs, renewal status, and subscription period data
Google Mobile Ads Ad serving and monetization for free tier Ad identifiers, device/network signals, ad interactions
OpenAI Chat responses and AI image generation Text prompts, conversation context, image prompts, generation parameters, and generated image output
Amazon Bedrock Nova Sonic Voice transcription, voice responses, and text-to-speech Voice recordings, transcriptions, assistant text, and generated audio output
OpenAI-compatible endpoint (BYOK optional) Optional custom routing for supported AI features when you configure your own key Data depends on the selected provider and feature, such as prompts, conversation context, or image prompts
Exa Web search and deep research retrieval Research queries and source retrieval requests
Composio Connected app actions and MCP tool routing Action requests, toolkit connection state, tool inputs/outputs

5. Permissions We Request and Why

6. BYOK (Bring Your Own Key)

If you enable BYOK, your custom provider keys and model settings are stored locally on your device and used to route requests to your selected providers. You are responsible for your own provider account terms, billing, and data handling for those requests.

BYOK is enabled by default in the app settings. If no custom key is saved for a supported feature, SyncO uses the configured SyncO service key for that provider. You can disable BYOK or clear custom keys in Settings.

7. Third-Party AI Integration and Consent

Important: SyncO uses third-party AI services to provide core functionality. Before using any AI feature, you must explicitly consent to the data processing described below.

7.1 Explicit Consent Requirement

When you first attempt to use an AI-powered feature (chat, voice, image generation, or research), SyncO will display a consent screen explaining what data will be processed and by which providers. You must tap "I Understand and Agree" to proceed. You may revoke this consent at any time in Settings, which will disable AI features until consent is granted again.

7.2 Data Sent to Third-Party AI Providers

When you use AI features, the following data is transmitted to our third-party AI service providers:

7.3 Third-Party AI Service Providers

Provider Services Used Data Types Processed Data Protection
OpenAI Chat completions using gpt-4o-mini and image generation using gpt-image-1 Text prompts, conversation context, image prompts, style parameters, and generated image content Subject to OpenAI API data processing and retention terms
Amazon Bedrock Nova Sonic Voice transcription, voice responses, and speech playback Voice recordings, transcriptions, assistant text, and generated audio output Subject to AWS service terms and data protection controls
OpenAI-compatible endpoint (BYOK optional) Optional custom processing through your configured endpoint Data depends on your selected provider and enabled feature Provider and retention terms are determined by your selected BYOK provider
Exa Web search and deep research Research queries, search terms Query data not stored; results sourced from public web
Composio Third-party app integrations and tool routing Tool requests, action payloads, connection metadata OAuth-based authentication; minimal data retention

7.4 Data Protection Assurances

8. Data Sharing

We do not sell personal data. We share data only with service providers listed above to operate app features, billing, ads, and security.

9. Data Retention

10. Your Choices and Rights

11. Security

We use reasonable administrative, technical, and organizational safeguards designed to protect data in transit and at rest. No method of transmission or storage is 100% secure.

12. Children

SyncO is not directed to children under 13 (or the minimum age in your country). Do not use the service if you are below the applicable age.

13. International Processing

Your data may be processed in countries where our providers operate. By using SyncO, you acknowledge that cross-border transfers may occur.

14. Policy Updates

We may update this Privacy Policy from time to time. The "Last updated" date reflects the latest version.

15. Contact

For privacy requests or questions, contact: support@sync0.dev