Privacy Policy
Synchroneers is a private journal for dreams, synchronicities, visions and readings. This page describes what the app collects, where it is processed, and how to get it back or delete it. It describes the app as it actually behaves; where a guarantee is enforced by the server rather than by the app, that is said plainly.
Who we are
Synchroneers is made by Synchronous Labs Ltd, a company registered in England and Wales (company number 17477151), registered office Unit 13, Freeland Park, Wareham Road, Poole, BH16 6FH, United Kingdom. Synchronous Labs Ltd is the data controller for the personal data described here, and is registered with the Information Commissioner's Office. In this policy, "we" and "us" means Synchronous Labs Ltd.
What we collect
| Data | Why | Legal basis |
|---|---|---|
| Email address, display name, and the identifier from your sign-in provider | To create and authenticate your account. | Contract (to provide your account) |
| Your entries: title, body, kind, the time it happened, and any voice note or dream image attached to one | They are the product. They are stored so you can read them back. | Contract |
| Interpretations you request, and a count of how many you have used | To return the reading and to enforce the monthly allowance. | Contract, and your explicit consent for sending entry text to OpenAI |
| How you use the app: openings, sign-ins, readings finished, the paywall being shown, and a subscription starting. No entry text, no reading text, no search terms | To see which parts of the app are used and where people give up. You can turn this off at any time in Settings. | Consent |
| Birth date, time and place, if you enter them | To place the Moon in a house on the home screen. They are stored on your device only and are never uploaded to us. To find the place you type, its name (and nothing else about you) is sent to OpenStreetMap's place search. | Not applicable (never leaves your device, apart from the place search) |
| Posts, comments and follows, if you share to your feed or a Collective | To show them to the people you shared them with. | Contract |
Sensitive information
Your entries may include personal things, such as details about your health or beliefs. We use them only to run your journal. Entry text is sent to OpenAI only if you agree to AI reflections, which the app asks the first time you ask for a reading (or for a dream image or a transcription), and only for the features that need it: when you ask for a reading or a dream image, when the app suggests tags and emotions for an entry you have saved, and, for a voice note, the recording when you ask for it to be transcribed. You can turn AI reflections on or off at any time in Settings.
Who processes it
- Google Firebase - authentication and app attestation. Holds your sign-in identity, and on Android delivers the daily reminder through Firebase Cloud Messaging. Firebase Authentication is processed in the United States.
- Supabase - the database and file storage holding your entries. Hosted in the EU (Ireland).
- OpenAI - generates readings, dream images, transcriptions and tag suggestions, processed in the United States, and only if you agree to AI reflections. It receives the text of the entry involved; for the Pattern Researcher lens, which looks for patterns across your journal, it also receives your recent entries. It never receives your email address or name. OpenAI does not use this text to train its models, and keeps it for up to 30 days for safety checks before deleting it.
- RevenueCat - keeps track of whether your membership is active. It receives your account identifier and what the store tells it about the purchase. It never sees a card number; Apple and Google take the payment, and we never see one either. Processed in the United States.
- Mixpanel - product analytics, processed in the United States, and only if you agree to it. It receives the usage events listed below, your account identifier, and your email address and display name so support can find you. Nothing you write is sent to it.
- Expo - delivers the daily reminder notification, if you turn it on. It receives your device's notification token and the reminder text, never anything you wrote. Processed in the United States.
- OpenStreetMap Foundation - its place search looks up the birth place you type, if you add birth details. It receives the place name only. The foundation is based in the United Kingdom.
International transfers
OpenAI, Mixpanel, RevenueCat, Google Firebase and Expo may process your data in the United States. Where your data leaves the UK or EEA, we rely on the UK Extension to the EU-US Data Privacy Framework where the provider is certified, or on standard contractual clauses with the UK International Data Transfer Addendum.
Analytics
The app counts what you do in it, never what you write. It records these actions: opening and leaving the app, which screen you are on, the introduction cards you see and the choice you make at the end of them, signing in or creating an account and how, a sign-in that fails, saving an entry (its kind, not its words), starting and finishing a reading and reaching the monthly limit, using a feature, being shown the paywall and what you choose on it, claiming the founding offer, starting a subscription, signing out, your answers to the questions the app asks when you start, and the link or campaign that brought you to the app, if any.
To find faults, it also records when a reading, a save, a sync or an enrichment fails. Those records hold an error code and a few facts about the attempt - which stage failed, which kind of entry, which lens, how many tries - and never an error message, because a message can repeat what you wrote.
Each record carries only what it needs - which kind of entry, which lens, which plan - and never the words you wrote or the words you were sent back. Your profile there holds your subscription status and plan, how you signed up, when you were first and last seen, and where you came from. Your IP address is not used to place you on a map.
Nothing is counted until you agree. When you first sign in, the app shows how it uses your data and asks whether you are willing to be counted. If you leave Usage analytics unticked, nothing is sent, and anything the app held back while you were getting started is discarded. You can change your answer at any time in Settings. To have what has already been counted for your account deleted, write to admin@synchroneers.io, or delete your account, which removes it automatically.
Private entries and AI
Marking an entry private controls who else can see it: a private entry is never shown to anyone but you. It does not stop you asking for an interpretation of it; the reading is for you alone. The server checks that an entry belongs to you before anything about it is sent for an interpretation, and deleting an entry deletes its interpretations too.
Your birth date and time are never sent to AI. They never leave your device.
The free allowance
Every account gets twenty interpretations per calendar month, counted on the server. Reopening a reading you already have costs nothing.
Sharing is a copy
Sharing an entry creates a separate record, posted to your feed for the people who follow you, and to any Collectives you choose. Nobody gains access to the entry the post was made from. Deleting the post does not delete your entry, and deleting your entry does not delete the post.
Deleting your account
Settings → Delete account removes, in this order: every file you own across all three storage buckets (attachments, avatars and exports); every row keyed to you in the database, by cascade from your profile; and finally the sign-in identity itself. The order is deliberate - if any step fails, the account still signs in and the deletion can be retried, rather than leaving you locked out of data that still exists.
It also deletes your analytics profile and events held by Mixpanel, and your customer record held by RevenueCat. Your posts, comments, likes and follows are deleted with your account. A Collective you created passes to its longest-standing member if it still has others in it; if it no longer has other members but others have posted in it or belonged to it, it is archived without an owner and their posts stay; otherwise it is deleted. Apple and Google keep their own purchase records under their own policies.
Your rights
If you are in the UK or the EU, you have the right to access, correct, export, restrict, or delete your personal data, and to object to processing. Deleting your account is available in the app. For a copy of your data, or anything else, contact us at the address below. You may also complain to your national supervisory authority; in the UK that is the Information Commissioner's Office.
Retention
Entries are kept until you delete them or delete your account. Interpretation usage counters are kept per calendar month. Deleted accounts are removed at the time of the request, not on a schedule. Analytics events are kept for two years. Text sent to OpenAI for an interpretation is kept by OpenAI for up to 30 days for safety checks, then deleted.
Children
Synchroneers is not intended for children under 13, and we do not knowingly collect their data.
Changes
If this policy changes in a way that affects how your data is handled, the date at the top changes with it.
Contact
Synchronous Labs Ltd
Unit 13, Freeland Park, Wareham Road, Poole, BH16 6FH, United Kingdom
admin@synchroneers.io