Your information

Privacy notice

Scope of this notice

This notice applies to the public SyncString website, beta-interest correspondence, and the authenticated private-beta portal operated by Qualy Studios. SyncString remains under development. Beta 1 access is free, and paid checkout is intentionally disabled until live Stripe, tax, webhook, and production entitlement checks are complete. Before paid subscriptions or materially different provider-data processing begins, we may provide supplemental product notices or beta terms describing those practices.

Information we receive

  • Beta interest: your email address, plan interest, optional message, and consent time.
  • Sign-in and membership: identity details supplied by the site’s sign-in service, such as account identifier, email address, display name, organization, license state, and assigned administrator role.
  • Portal configuration: provider and account identifiers, selected contact or calendar scopes, connection settings, preferences, organization policies, tenant records, service requests, confirmations, and audit history.
  • Directory provisioning: if an organization activates SCIM, its directory may send user and group identifiers, names, work email addresses, active status, selected enterprise attributes such as department or cost center, and group memberships used to apply the organization’s explicit licensing rules.
  • Provider authorization: encrypted Google or Microsoft OAuth tokens, granted scopes, expiration information, and the provider account email. Beta 1 requests Google and Microsoft scopes that permit contact and calendar-event creation, updates, and deletion. SyncString restricts that authority in product: no contact-delete path exists, provider event deletion requires an explicitly selected event and a server-side safety switch, and iCloud remains read-only. For iCloud, a user may provide an Apple app-specific password; SyncString does not request an Apple Account password.
  • Provider snapshots and change plans: selected contact and calendar records, provider identifiers, calendar and account identity, organizer and recurrence details, provider versions, completeness signals, managed-object markers, proposed before-and-after values, and per-item results needed to preview, confirm, apply, resume, or report a provider operation.
  • Mutation audit history: before a confirmed Google or Microsoft change, SyncString records the actor, confirmation, target provider object, expected version, pre-change or pre-delete content, operation marker, attempt, and outcome. This record is separate from the shorter Activity list.
  • Contact indexing: only after you explicitly enable Contact Groups contact indexing, SyncString stores contact names, email addresses, phone numbers, organization names, labels, provider, connection id, and provider record ids from authorized accounts so group rules can match real contacts. Turning indexing off deletes stored contact inventory and related sync tokens.
  • Backups and restore previews: before a provider write pass, SyncString creates the supported backup it describes in the confirmation. Contact backup coverage depends on the connected provider. Calendar backup records contain availability metadata and are not a full copy of titles, notes, attendees, locations, conference details, or attachments; they cannot recreate a deleted event. Restore into a provider is not included in Beta 1.
  • Technical information: hosting and network providers may process IP address, device or browser details, request time, requested pages, authentication state, and security logs needed to deliver and protect the service.

The hosted portal does not collect payment-card or bank-account details during Beta 1. Provider access requires account membership, provider authorization, and the relevant in-product action, opt-in, or confirmation.

How we use information

  • Provide authenticated portal access and enforce user, organization, license, and administrator boundaries.
  • Save requested connections, preferences, policies, tenant configuration, service requests, and explicit confirmations.
  • Complete provider authorization, connection checks, complete provider reads, Contact Group matching, backups, restore previews, itemized change previews, confirmed Google or Microsoft creates and updates, and deliberate calendar-event deletion.
  • Detect incomplete reads and concurrent edits, pause unsafe or ambiguous operations, resume item-level failures without blind create retries, and maintain managed-object and audit records.
  • Respond to questions, manage beta interest, secure and debug the service, prevent abuse, and meet legal obligations.

Cookies and local storage

We do not use advertising or cross-site tracking cookies. The site’s sign-in service uses strictly necessary authentication technology, and provider authorization uses short-lived, HTTP-only state cookies to protect the consent flow. The light/dark appearance control stores a preference locally in your browser. Hosting providers may use additional strictly necessary technologies to deliver and protect the service.

Storage, sharing, and retention

Portal configuration, managed-object records, operation checkpoints, and mutation audit history are stored in the site’s hosted database. Google and Microsoft token payloads, plus any iCloud app-specific password submitted through the connection form, are encrypted before storage using a server-held encryption secret; no security measure is perfect. Requested recovery backups are held in encrypted SyncString object storage until their displayed expiry date. Provider-native exports remain with the provider and do not pass through SyncString. We do not sell personal information or share it for cross-context behavioral advertising. We may disclose information to hosting, identity, communications, payment, and other service providers working on our behalf; when legally required; to protect rights or safety; or as part of a business transaction.

Calendar event-search filters and result detail expire after 24 hours. Expired searches are unavailable to the portal, and the scheduled worker physically removes their search and result rows. Deletion previews, provider-mutation audits, and deletion-proof records are separate records and are not part of that short-lived search cache.

The workspace Activity view retains the latest 200 portal activity items. Provider-mutation, organization, admission, security, support, and deletion-proof records may be retained separately as reasonably needed for beta operation, recovery evidence, account administration, security, legal obligations, and the purposes described above. Provider credentials are removed from SyncString when the corresponding supported connection is removed. Stored contact inventory and incremental-read sync tokens are removed when contact indexing is turned off or the related connection is removed. That contact-data purge does not remove provider credentials, backups, suppression entries, audit history, or data at Apple, Google, or Microsoft.

Your choices and rights

Depending on where you live, you may have rights to request access, correction, deletion, or a copy of personal information, or to appeal a request decision. Email support@syncstring.app or visit Support to make a request. You may also use the Account tab inside the beta portal for privacy or deletion help. We may verify your identity before completing it. Removing a connection deletes the saved SyncString authorization for that provider; it does not delete contacts, calendars, or events at Apple, Google, or Microsoft. Provider calendar-event deletion is a separate deliberate action that identifies the exact event or selected set, shows an itemized preview, and asks for confirmation.

Children

SyncString and this website are not directed to children under 13, and we do not knowingly collect personal information from children under 13.

Security and changes

We use reasonable safeguards appropriate to the information we handle, but no method is completely secure. We may update this notice as the website, beta, and product evolve. The date above shows the latest revision.

Contact

Qualy Studios
United States
support@syncstring.app