Skip to content
Privacy policy

What we hold, and why we hold it

Synclify reads your Instagram account to do its job, so this page has to be specific rather than reassuring. It names all 33 kinds of data the product can hold, the one thing that causes each of them to exist, and every company that touches any of it.

Last updated 2 September 2026

  • We have never sold your personal data, and we do not share it for anybody else's advertising.section 5
  • You can export everything you put in, without asking us, from inside the product.section 9
  • You can have your account and its data deleted, and we act on it within 30 days.section 8
  • OpenAI, Google and xAI do not train their public models on your content. We do use it, stripped of anything that identifies you and combined with other accounts, to improve Synclify itself, and one email stops that without costing you a feature.section 4
  • Nothing is published to your Instagram account until you approve it.section 3
What is held

Eight things because you have an account.

Everything else on this list is here because you switched something on. Turn the switches and see why each row is there. All of it is written out in full below.

Switches

8of 33

8 because you have an account. 25 because you switched something on.

Account

  • Your name and email addressTo have an account to sign in to2.1
  • A hash of your passwordSo the password itself is never stored2.1
  • Your profile picture, bio and roleTo set up the workspace for a creator, a brand or an agency2.1
  • Device, browser, IP and rough locationTo keep the account secure and the service working2.5
  • Your signed-in sessions and failed sign-in attemptsTo show you every device that is signed in and to slow down somebody guessing your password2.5
  • A two-factor secret, if you turn two-factor onTo check the six digit code your authenticator app produces2.1
  • A passkey's public key, if you register oneTo let you sign in with a fingerprint or a face. The private half never leaves your device2.1
  • A push token, if you install the app and allow notificationsTo deliver a notification to that one device2.5

Instagram

  • An access token, encryptedTo call Instagram on your behalf. Encrypted with aes-256-gcm2.2
  • Your username, follower and following countsTo show your own account back to you2.2
  • Your posts, reels, stories and captionsTo analyse what you published and schedule what you have not2.2
  • Media files you upload or scheduleTo hold a post until its publish time2.2
  • Likes, comments, saves, shares and reachTo work out which of your posts did what2.2
  • When your audience is active, in aggregateTo answer what time to post2.2
  • Comments and direct messages on your accountTo reply to the ones you set up a reply for2.2
  • Hourly snapshots of a post's numbersTo notice a post running away from your baseline2.2
  • Drafts the AI wrote for you, kept 365 daysSo the work you paid for is still there when you come back to it8
  • Transcripts of video you gave it, kept 365 daysTo write from what you said on camera without transcribing it twice8

WhatsApp

  • The phone number you linked, and which workspace it runsTo know whose account a WhatsApp message is asking about2.6
  • The messages you send that number and the replies it sends backTo answer you, and to carry a conversation from one message to the next2.6

Competitors

  • Public posts and captions from accounts you namedTo compare your posting against theirs2.4
  • Their public like and comment countsThe two numbers Instagram shows anybody2.4
  • How often and when they postTo find the gaps in what your niche publishes2.4
  • The hashtags they use in publicTo read the vocabulary of your niche2.4

Team

  • Your company name and business typeTo put the right name on a client report2.1
  • Team member names, emails and rolesTo let colleagues sign in and to limit what each can open2.1
  • Which client each team member may seeTo keep one client's data out of another's view2.1

Billing

  • Your billing name and addressTo raise a compliant invoice2.1
  • Invoice and payment historyRetained for statutory accounting periods8

Roadmap

  • The feature you asked for, in your wordsTo read it, answer it, and publish it on the board if we keep it2.3
  • Your email addressTo send you a link to your request and tell you when it moves2.3
  • A one-way hash of your IP addressTo stop one sender filing hundreds. The address itself is never stored2.3
  • Which requests you voted forSo one person counts once, which is what makes the number mean anything2.3

Not held

Your card number

It goes from your browser to Razorpay and never touches our servers. We are told whether a payment succeeded, and the last four digits, and nothing else.

8 of 33 categories of data are held with these switches on. 8 of them exist because you have an account.

Who else touches it

Thirteen companies, and what each one sees.

Not one of them receives everything. The right-hand column is where each row was read from, so you can check any single line of this table without having to take the rest of it on trust.

Companies that process Synclify data, what each does, what each can see, and where the use is evidenced.
CompanyWhat it doesWhat it can seeRead from
Meta PlatformsInstagram and WhatsApp, through the official APIsThe requests we make on your behalf, and the WhatsApp messages between you and your workspace's numberMeta's official interfaces for Instagram and WhatsApp Business
VercelRuns the web applicationRequests, in transitHosting
SupabaseThe databaseEverything stored, encrypted at restManaged database, encrypted at rest
Amazon Web ServicesStores media filesImages and video you upload or scheduleObject storage
RazorpayTakes paymentsYour billing details and the card, which we never seeCard form hosted by them, not by us
AppleSubscriptions bought inside the iPhone appThe subscription, not the accountApp Store in-app purchase
OpenAIWrites drafts and analyses contentThe text of the post it is asked aboutBusiness plan, not used to train public models
GoogleGemini reads images and translatesThe image or text it is asked aboutBusiness plan, not used to train public models
xAIGenerates the pictures the studio makesThe description it is given, and any reference image you uploadGrok image model, in use since 22 August 2026
Google FirebaseSends push notifications to the appA device token and the notification textDevice token only
Google Sign-InSigning in with a Google account, if you choose itYour name and email addressOnly if you choose to sign in with Google
Our mail serverSends account email and the weekly digestYour email address and the messageOur own mail server, no marketing platform
Google AnalyticsCounts visits to this marketing websiteWhich pages were opened on synclify.ai, and the browser and country they were opened fromThis website only. Not in the product, and it never sees an account

There is no advertising network and no session recorder anywhere in this list. The one analytics product on it, Google Analytics, counts visits to this website; it is not in the software you sign in to, and it never sees your account.

The policy

The document, in full.

Every section carries one plain sentence above its text. The plain sentence is there to help you find what you came for. The text under it is the part that binds.

Contents14 sections
  1. 1Introduction
  2. 2Information we collect
  3. 3How we use your information
  4. 4Artificial intelligence
  5. 5Sharing and disclosure
  6. 6Law enforcement and government requests
  7. 7Security
  8. 8How long we keep it
  9. 9Your rights
  10. 10Cookies
  11. 11International transfers
  12. 12Children
  13. 13Changes to this policy
  14. 14Contact

Introduction

This explains what Synclify holds about you, why, and what you can make us do about it.

Synclify is an Instagram operations tool. To do its job it reads your Instagram account, stores what it read, and works on it. This policy explains what that means in practice: what is collected, why each thing is collected, who else it reaches, how long it stays, and the rights you have over it.

It applies to the Synclify web application, the Synclify iPhone application, and this website. It applies whether you are a creator running one account, a brand buying collaborations, or an agency managing accounts for other people.

By using Synclify you agree to this policy. If you do not agree with it, do not connect an account. Where this policy and any other page on this website disagree, this policy is the one that governs.

This policy is written to be read. Every section below carries a plain-English line above the formal text. The plain line is there to help you find the part you want; the text underneath it is the part that binds.

Information we collect

Eight things because you have an account, everything else only because you switched something on, and one group you can trigger without an account at all by asking us for a feature.

The list above names every category of personal data the product holds. The subsections here describe each group and what causes it to exist.

Information you give us

When you register and as you use the product, you provide:

  • Account information: your name, email address, and a password, which is stored only as a hash. If you sign in with Google we receive your name and email address from Google instead.
  • Sign-in credentials you add yourself: a two-factor secret if you turn two-factor authentication on, and the public key of any passkey you register. A passkey's private half is created by your device and never leaves it, so we cannot use a passkey to sign in as you.
  • Profile information: a profile picture, a short bio, and the role you chose, which is creator, brand, or agency.
  • Business information: your company name and business type, and for agency accounts the names, email addresses and roles of team members you invite, and which clients each of them may see.
  • Billing information: your billing name and address. Card details are entered into Razorpay's own form and are never received by, transmitted through, or stored on our systems.
  • Content: captions, images, video, drafts, notes, contracts and invoices that you create or upload inside the product.

Instagram data

None of this exists until you connect an Instagram account, and all of it stops being refreshed the moment you disconnect. We read it through Meta's official Graph API using a token you grant and can revoke, which we store encrypted with aes-256-gcm.

  • Profile data: username, follower count, following count, biography, profile picture, and account type.
  • Content: your posts, reels, stories, captions, hashtags, and the media files attached to them.
  • Performance data: likes, comments, saves, shares, reach, impressions, video views and watch time on your own content.
  • Audience data: aggregate demographics and activity patterns for your followers, as Instagram reports them. We do not receive, and cannot see, the identity of individual followers beyond those who interact with you publicly.
  • Interactions: comments and direct messages sent to your account, which is what makes an automated reply possible.
  • Hourly snapshots of a post's numbers, kept so the product can tell the difference between a post doing well and a post doing well for you.

We request the narrowest set of Instagram permissions that makes the features you use work. You can review and revoke them at any time from Instagram's own settings, without going through us.

Feature requests and the public roadmap

The roadmap on this website takes an email address, and it is the only place we collect anything from somebody who does not have a Synclify account. You reach it by choosing to, and nothing on it is required to use the product.

  • What you asked for, why you want it, and how you do it today: the words you type into the form. If we publish the request on the board, the title and your description appear there. Your email address never does.
  • Your email address: to reply, to send you a private link to your own request, and to tell you when its status changes. It is not added to a mailing list, because there is no mailing list.
  • A one-way hash of your IP address: to stop one sender filing hundreds of requests. The address itself is never stored, and the hash cannot be reversed to recover it or used to locate you.
  • If you vote on a request, a six digit code sent to your address proves it is yours. That record is your address, whether it has been verified, and which requests you voted for.

A line you leave when voting may be published on the board, but never with your name or address attached to it. Nothing you submit becomes public at all until a person at Synclify has read it and chosen to publish it.

If your address matches a Synclify account we note that the request came from a customer, so we can weigh it properly. We do not attach your request to your account records, and deleting your account does not delete a request you filed.

Competitor data

If, and only if, you use the competitor features, we collect publicly available information from the Instagram accounts you specifically name. We do not select these accounts for you and we do not collect anything about an account you have not entered.

  • Public posts, captions and hashtags.
  • The like and comment counts Instagram displays publicly.
  • Posting frequency and the times of day they publish.

We do not collect, infer, estimate or display private metrics for any account that is not yours. Reach, impressions, saves, shares and audience demographics for a competitor are not available to us and the product will not produce a figure for them. Where a comparison is shown, the figure being compared is always yours.

Information collected automatically

When you use the product we record technical information needed to run it and keep it secure:

  • Device and browser type, operating system, and for the mobile app a device identifier used to deliver push notifications.
  • IP address, and the approximate location it implies, at city level.
  • Which pages and features you used, and when.
  • Errors and failures, so a broken feature can be found and fixed.
  • Your signed-in sessions, so you can see every device that holds one and end any of them, and failed sign-in attempts on your address, so somebody guessing your password is slowed down.

We do not operate an advertising network or a session recorder, and there is no third-party product-analytics service in the software you sign in to. The marketing website you are reading this on is separate, and it does use Google Analytics to count visits to its pages. That is the whole of its involvement: it runs on the website only, it is not in the product, and it never sees your account, your posts or your Instagram data.

WhatsApp

None of this exists until you link a handset to a workspace, and it stops the moment you unlink it. WhatsApp runs through Meta's official Business API, so Meta carries the messages in the same way it carries anything else sent on WhatsApp.

  • The phone number you linked and the workspace it runs, which is what lets a message from that handset reach your account and no other.
  • The messages you send that number and the replies it sends back, kept so a conversation can carry from one message to the next.

A message from a number that is not linked to a workspace is not answered and nothing about it is kept.

How we use your information

To run the features you turned on, to bill you, and to keep the service up. Nothing else.

We use the data described above for the following purposes and no others:

  • To provide the product: publishing scheduled posts, showing your analytics, running the automated replies you configured, and keeping your workspace working.
  • To generate the drafts, analyses and suggestions you ask for, as described in section 4.
  • To compare your account against the competitor accounts you chose to track.
  • To bill you, collect payment, and produce invoices and receipts.
  • To send you service messages: security alerts, billing notices, failures that affect you, and the weekly digest if you have not turned it off.
  • To answer you when you contact support.
  • To detect and prevent fraud, abuse, and unauthorised access.
  • To meet legal, tax and accounting obligations.

Nothing is published to your Instagram account, and no message is sent from it, until you approve it. The product drafts, schedules and prepares, and every one of those shows you a preview and waits for you to tap approve. Scheduling is publishing with a delay, so it waits for the same tap.

We do not use your data to build advertising profiles, and we do not use it to make decisions about you that produce legal effects without a person involved.

Where you are in a jurisdiction that requires a lawful basis to be named, ours are: performance of a contract, for everything needed to deliver the product you signed up for; legitimate interests, for security, fraud prevention and service improvement; consent, for optional marketing messages, which you may withdraw at any time; and legal obligation, for tax and accounting records.

Artificial intelligence

Your content is sent to OpenAI, Google and xAI to produce a draft or a picture. It is not used to train their public models, and you can opt out of it improving ours.

Synclify uses AI models to write drafts, read images, analyse your content, generate pictures and translate. Three providers are used and all three are named in the processor table above: OpenAI, Google through Google's Gemini models, and xAI for the pictures the studio makes.

What is sent to them is the specific content the task requires. Asking for a caption on a post sends that post. Asking what your last month looked like sends the figures for that month. Your whole library is not uploaded, and your password, payment details and access tokens are never sent to a model.

What the models do with it

We use these providers through their business API terms, under which content sent by us is not used to train their publicly available models. We do not control those providers' own policies and we link them rather than restating them, because a restatement can go stale without anybody noticing.

Improving Synclify

We may use your content in anonymised and aggregated form to improve how Synclify itself works: to measure whether an analysis was accurate, and to test changes. Aggregated means combined with other accounts so that nothing traces back to you.

You can opt out of this entirely by emailing support@synclify.ai. Opting out does not reduce any feature you have paid for.

What AI output is

Everything an AI model produces in Synclify is a suggestion. It can be wrong, and it can be confidently wrong. You are responsible for reading anything before you publish it. Where the product does not have the data to answer something, it is built to say so rather than to estimate, but that is a design commitment and not a guarantee about every possible output.

Sharing and disclosure

We do not sell your data. Thirteen named companies process parts of it to make the product work, and that list is above.

We do not sell your personal data, and we do not share it for anybody else's advertising. We have never done either.

Your data reaches other companies only in the circumstances below:

  • Processors: the thirteen companies named in the table above, each of which sees only the part described beside it, and each of which is bound to use it only to provide that service to us.
  • Meta: requests we make to Instagram on your behalf, which is the mechanism by which the product works at all.
  • Inside your own organisation: if you are on a team or agency account, the people you invited can see what their role permits. The account owner controls this.
  • Legal requirements: where we are compelled, subject to the review process in section 6.
  • A business transfer: if Synclify is acquired or merged, your data may transfer with it. You would be told before it did, and this policy or one at least as protective would continue to apply.
  • With your consent: anything else, and only after you have agreed to it.

An agency using Synclify to manage your account is a separate controller of the data it holds about its own clients. Its arrangement with its clients is its own, and we are not a party to it.

A brand cannot see what an agency paid a creator, and a creator cannot see a brand's other collaborations. There is no cross-organisation visibility in the product and nothing in this policy should be read as creating any.

Law enforcement and government requests

We check that a request is lawful before we answer it, we push back when it is not, we give only what is demanded, and we write all of it down.

Most privacy policies do not publish this. We do, because a commitment nobody can read is not a commitment. When a government body or law enforcement agency asks us for user data, the following applies to every request without exception.

We review whether it is lawful first

No user data is disclosed until the request has been reviewed. Each one is checked to confirm that it:

  • Comes from an authority with genuine jurisdiction over us.
  • Is legally valid and follows the proper process for its type.
  • Complies with the law that applies to it.
  • Is specific, rather than a broad sweep for data about many people at once.

We challenge requests we believe are unlawful

Where a request appears to be unlawful, disproportionate or overly broad, we will:

  • Refuse it and require a proper legal basis.
  • Ask for an overly broad request to be narrowed before we answer any of it.
  • Take legal advice where the position is not clear.
  • Tell the affected user, wherever we are legally permitted to tell them.

We give the minimum

Where we are lawfully required to disclose data, we disclose only the specific items the order names. We do not supply additional context, adjacent records, or anything that was not asked for, and we do not treat a request for one thing as permission to hand over an account.

We write it down

We keep a record of every government and law enforcement request: what was asked for, by whom, under what authority, what we decided, the reasoning, and what was ultimately disclosed.

Security

Encrypted in transit and at rest, access tokens encrypted separately, and access to production limited.

The measures below are the ones actually in place. We have deliberately not listed certifications we do not hold or audits we have not had.

  • All traffic between you and Synclify uses TLS. The site and application are served over HTTPS only.
  • Data is encrypted at rest in the database.
  • Instagram access tokens are encrypted separately with aes-256-gcm, an authenticated cipher, so a token cannot be silently altered as well as not being readable.
  • Passwords are stored only as hashes. We cannot read your password, and neither can anybody who obtains the database.
  • Access to production systems is limited to the engineers who need it, and is authenticated.
  • Permissions inside the product are enforced on the server for every request, not only hidden in the interface.

No system is perfectly secure and anybody who tells you otherwise is selling something. We cannot guarantee absolute security. If a breach affects your personal data we will notify you and the relevant supervisory authority within the time limits the applicable law sets.

If you believe you have found a security problem, email support@synclify.ai and say so in the subject line. We will not pursue anybody who reports a genuine vulnerability to us in good faith and gives us a reasonable chance to fix it.

How long we keep it

Each kind of data has a deadline, and the product deletes it automatically rather than us remembering to.

Data is kept for as long as your account is active, and then for the periods below:

  • Account data: until you delete your account.
  • Instagram content and performance data: while your account is active, and removed when the account is deleted.
  • Competitor data: kept for a limited period and then discarded, because a snapshot of somebody else's public posting is stale quickly and there is no reason to hold it longer.
  • AI drafts and transcripts: a 365 day window, and what happens at the end of it differs by kind. The Trust page sets out which are deleted and which are kept whole.
  • WhatsApp messages: kept while the handset is linked, and removed when you unlink it.
  • Technical logs: kept for a short period for security and debugging.
  • Invoices and payment records: kept for the statutory accounting period, which we cannot shorten at your request because the law requires them.

When you delete your account we remove your personal data from our production systems within 30 days, except records we are legally required to keep. Backups are cycled out on their own schedule and are not used to restore deleted accounts.

Retention is enforced by scheduled deletion in the product rather than by anybody remembering to run it. The specific windows are set out on our Trust page, along with the one category the product refuses to touch: the drafts, captions and scripts you made, which are your own work and are kept whole rather than being stripped of their identifying parts.

Your rights

You can see it, correct it, take it out, or have it deleted, and using those rights costs you nothing.

Depending on where you live, you have some or all of the following rights. We apply them to everybody regardless of location, because operating two standards is how the lower one becomes the real one.

  • Access: ask for a copy of the personal data we hold about you.
  • Correction: have inaccurate data corrected. Most of it you can correct yourself in Settings.
  • Deletion: have your data deleted, subject only to records we are legally required to keep.
  • Portability: receive your data in a structured, machine-readable format. Export is built into the product and you do not need to ask us.
  • Restriction: ask us to stop processing something while a dispute about it is resolved.
  • Objection: object to processing we carry out on the basis of legitimate interests.
  • Withdraw consent: for anything you consented to, including marketing and the AI improvement use in section 4.2.
  • Complain: to your local data protection authority, at any time, without going through us first.

To use any of these, email support@synclify.ai. We will respond within 30 days. We will not charge you, and we will not ask you why.

We may ask you to confirm who you are before we act on a request, which is a protection for you rather than an obstacle: handing an account's data to somebody who merely claims to own it is itself a breach.

Cookies

The ones that keep you signed in, a small number that tell us which features get used, and one on the marketing site that counts visits. No advertising cookies.

We use cookies and equivalent local storage for:

  • Keeping you signed in between visits, which is required for the product to work at all.
  • Remembering your preferences, such as which view you last had open.
  • Understanding which features are used, so that unused ones can be removed.
  • Counting visits to the marketing website, through Google Analytics. This one is on synclify.ai only and never inside the product.

Visitors in the United Kingdom, the European Economic Area and Switzerland are counted without that last cookie. Google Analytics is told not to store anything on your device in those places, so it reports those visits as totals rather than as people, and there is nothing to ask your permission for.

We do not set advertising cookies and we do not permit third parties to set them on our pages. Google's advertising and personalisation storage is switched off for every visitor everywhere, not only the ones the law requires it for, because we run no ads and nothing here should feed one. You can block or delete cookies in your browser; blocking the essential ones will stop you being able to stay signed in.

International transfers

Your data crosses borders because the companies that run the service do, and there are safeguards for that.

Synclify is operated from India. Several of the processors named above operate in the United States and the European Union, so your data is transferred internationally in the course of running the service.

Where a transfer is made out of a jurisdiction that restricts it, we rely on the appropriate safeguard for that jurisdiction, which for transfers out of the European Economic Area and the United Kingdom means the Standard Contractual Clauses. You may request details of the safeguard applying to a particular transfer.

Children

Synclify is for people aged 18 and over.

Synclify is not intended for anybody under 18 and we do not knowingly collect personal data from children. Instagram's own terms set a minimum age of 13; ours is higher because the product handles contracts, invoices and payments.

If you believe a child has created an account, tell us and we will delete it and the data attached to it.

Changes to this policy

If we change something that matters, we email you before it takes effect.

We may update this policy. The date at the top of this page is the date of the current version.

For a change that materially affects your rights or expands what we collect, we will email you before it takes effect and give you the opportunity to close your account instead. For corrections and clarifications we will update the page and move the date. Continuing to use Synclify after a change takes effect means you accept it.

Contact

One address, and a person reads it.

For anything in this policy, to use one of the rights in section 9, to opt out of the use described in 4.2, or to report a security problem, email support@synclify.ai.

If you are in the European Economic Area or the United Kingdom you also have the right to complain directly to your national data protection authority, and you do not have to contact us first.

Contact

Ask us for any of it and we will not ask why.

Access, correction, export, deletion, or opting out of section 4.2. One address, and a person reads it. We respond within 30 days and there is no charge.

support@synclify.ai

Terms of serviceWhat happens to the data