Sync Privacy Policy

Last updated: June 21, 2026

This policy explains what personal data the Sync mobile app (the "App", "we") collects, why, and what your rights are. Sync is a social game where two friends answer the same questions blind, predict each other's answers, then reveal their sync score.

1. Data controller

Publisher: Tommy Girardi
Contact: girardi.tommy@gmail.com

2. Data we collect

CategoryExamplesPurpose
Account identityEmail and identifier from Sign in with Apple or Google; usernameCreate and secure your account
Profile photoAn image you choose (optional)Personalize your profile
Game contentYour answers, predictions, duels, group rooms, friendships, referral codes, streaksRun the game and compute scores
NotificationsPush notification token (Expo / Apple APNs / Google FCM)Notify you (a friend answered, daily question…)
Usage dataUsage events, device type, app version, analytics identifier (via PostHog)Measure usage and improve the app
Technical dataLogs and technical identifiers needed to operateSecurity and reliability

Camera access is used only to scan a friend's QR code; no image is stored. Photos access is used only to set your profile picture.

3. Legal basis (GDPR)

4. Sharing and processors

We do not sell your data. We use service providers that process data on our behalf:

ProviderRole
SupabaseAuthentication, database, photo storage, server functions
ExpoPush notification delivery service
Apple / GoogleSign-in (Sign in with Apple / Google), push delivery (APNs / FCM)
PostHogProduct analytics

Some providers may process data outside the EU; where applicable, such transfers are covered by appropriate safeguards (standard contractual clauses).

5. Data visible to other users

Your username and profile photo are visible to your friends and room members. After a duel "reveal", your answers become visible to the relevant partner. Until the reveal, answers stay private.

6. Retention

We keep your data while your account is active. If you delete your account, your personal data (profile, friendships, duels, answers) is deleted (see §7). Some technical logs may be kept for a limited time for security.

7. Deleting your account and data

You can delete your account directly in the app: Profile tab → "Delete my account". This cascades deletion of your profile, friendships, duels and answers. You can also request deletion by email at girardi.tommy@gmail.com.

8. Security

Traffic is encrypted in transit (HTTPS/TLS). Data access is restricted at the database level (row-level security): a user can only read their own data, and a partner's answers are never exposed before the reveal.

9. Your rights

Under GDPR you have rights of access, rectification, erasure, restriction, objection and portability. To exercise them, email girardi.tommy@gmail.com. You may also lodge a complaint with your data protection authority.

10. Children

Sync is not directed to children under 13 (or the minimum age applicable in your country). We do not knowingly collect their data.

11. Changes

We may update this policy. For material changes we will notify you in the app. The date at the top reflects the latest version.

12. Contact

girardi.tommy@gmail.com