Sync13 — Privacy Policy
Effective date: July 1, 2026 Last updated: July 22, 2026
Sync13 ("Sync13", "we", "us") operates the Sync13 platform and its applications (Composer, Cornerstone, Pulse, and related workspace tools) at https://sync13.com. This policy explains what we collect, how we use it, and the choices you have. It covers our use of Google user data with specific care, because Sync13 integrates with Google APIs.
Operator: Wolfgang Schram Contact: wolfbroadcast@gmail.com
1. Information we collect
- Account & identity. When you sign in (including "Sign in with Google"), we receive your name and email address to create and identify your account.
- Content you provide. Documents, files, text, and prompts you upload or create in the apps, and the outputs generated from them.
- Usage & billing metadata. Records of AI model calls (app, model, token counts, timestamps) used to meter spend, plus audit events for security.
- Google connector data (only if you connect a Google or Google Workspace account). Depending on the permissions you grant:
- Email metadata (message headers such as sender, recipient, subject, and timestamps) via the Gmail *metadata* scope.
- Email content, only after separate explicit opt-in, so Pulse can identify requests, deadlines, invoices, commitments, and follow-ups. Message content is not stored as a raw mailbox archive. A copy of the message body is retained only for a limited, user-visible window so that you can check our work and correct a mistake — 30 days by default for mail we process, 7 days for mail we set aside as automated, and never for mail we refuse — after which the body is deleted from our database and our object storage. You can shorten these windows, including to zero, in your settings; they can never exceed a 90-day maximum. What we keep permanently is the *derived record* — the commitment, person, deadline, summary, message identifier, and original date, each with the quoted line it came from — because that record is the product. Derived action context is retained according to your Pulse retention setting.
- Calendar events and contacts (read-only) to build the relationship and scheduling intelligence in Pulse.
- Send permissions — the Gmail *send* scope (to send platform emails such as invitations and notifications on the account owner's behalf) and the Calendar *events* scope (to create events and send calendar invitations, including Google Meet links). The send scope is send-only and cannot read your mailbox.
2. How we use information
We use the information above to: provide and operate the apps; authenticate you and manage roles; generate the deliverables, briefs, and intelligence you request; meter and display AI spend; send platform emails and calendar invitations you or an administrator trigger; maintain security and an audit trail; and improve reliability. AI features are processed through our platform's model funnel; content may be sent to our AI processors (see Section 4) solely to produce your requested output.
3. Google user data — limited use
Sync13's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We use Google user data only to provide and improve the user-facing features described above.
- We do not sell Google user data.
- We do not use Google user data for advertising.
- We do not allow humans to read Google user data except: with your explicit consent, for security or to comply with law, or where the data is aggregated and anonymized for operations.
- We do not transfer Google user data except as necessary to provide or improve these features, to comply with law, or as part of a merger/acquisition with your consent.
4. How information is shared
We do not sell your information. We share it only with service providers that operate the platform under contract:
- Cloudflare — hosting, database (D1), storage (R2), and edge compute.
- Anthropic, OpenAI, and/or Google Gemini — AI model processing for features you invoke (content is sent only to generate your requested output, according to your Included AI or BYOK selection).
- Google — when you use Google-connected features (sign-in, metadata sync, sending email/calendar invites).
We may also disclose information to comply with law or protect the rights and safety of users and the service.
5. Storage, security, and retention
Data is stored on Cloudflare infrastructure. Sensitive credentials (including connector tokens and API keys) are encrypted at rest and are never returned to any client in plaintext. We retain data for as long as your account is active or as needed to provide the service; audit and identity records use a soft-delete posture. You may request deletion (see Section 7); we delete or anonymize data unless we must retain it to comply with law.
What we can and cannot do with your mail
The statements below are also shown inside the product, at the moment each one applies, and on our security page. They are generated from a single source and each is backed by a test that must pass before it can appear anywhere — so this section, the product and the security page cannot disagree.
<!-- CLAIMS:BEGIN — generated by scripts/claims-gate.mjs. Do not edit by hand. -->
When you set up forwarding
- We hold no key to your mailbox. Forwarding is set up inside your own email provider, and you can switch it off there at any time without asking us.
- We can only read what is forwarded to us. We cannot reach into your mailbox for anything else, and we cannot send mail as you.
Your intake address
- We hold no key to your mailbox. Forwarding is set up inside your own email provider, and you can switch it off there at any time without asking us.
- Mail sent to your intake address reaches only your account. No other Sync13 user can read it.
- Anyone not on your accepted-senders list is refused at the door, so even a leaked address cannot put mail into your brief.
- Administering Sync13 does not include reading your mail. No admin screen shows another person’s messages, commitments or brief — the controls cover accounts, access and spend, and nothing else.
When you connect Google
- We hold no key to your mailbox. Forwarding is set up inside your own email provider, and you can switch it off there at any time without asking us.
- You can revoke our access to your Google account at any time from your own Google settings, without contacting us.
- We read message content only when you have turned this on for Pulse and granted the content permission. Either one alone reads nothing.
Mail we set aside
- Anyone not on your accepted-senders list is refused at the door, so even a leaked address cannot put mail into your brief.
- Mail we set aside is never deleted on our judgement. It is held where you can see it, with the reason, and one click overrules us.
The AI processor
- We read message content only when you have turned this on for Pulse and granted the content permission. Either one alone reads nothing.
- To find your commitments, the text of a message is sent to our AI provider under a contract that forbids training on it. While it is being read, it is on their systems, not only ours.
- No person at Sync13 reads your mail, except with your explicit permission, to investigate a security problem, or where the law requires it.
Anything the AI tells you
- To find your commitments, the text of a message is sent to our AI provider under a contract that forbids training on it. While it is being read, it is on their systems, not only ours.
- Everything we tell you carries the exact line it came from, so you can check our work instead of trusting it.
- What we keep permanently is the derived record — the commitment, the person, the date and the quoted line — not a copy of your mailbox.
How long we keep things
- A copy of the message body is kept for 30 days for mail we process, 7 days for mail we set aside, and never for mail we refuse. You can shorten any of these to zero, and they can never exceed 90 days.
- What we keep permanently is the derived record — the commitment, the person, the date and the quoted line — not a copy of your mailbox.
Your access log
- Every time anything reads your mail, a line is written to your access log. We cannot read it without leaving that record.
- No person at Sync13 reads your mail, except with your explicit permission, to investigate a security problem, or where the law requires it.
- Administering Sync13 does not include reading your mail. No admin screen shows another person’s messages, commitments or brief — the controls cover accounts, access and spend, and nothing else.
<!-- CLAIMS:END -->
6. Revoking Google access
You can revoke Sync13's access to your Google account at any time at https://myaccount.google.com/permissions. Revoking access stops future Google data sync and sending.
7. Your rights
You may request access to, correction of, or deletion of your personal data by contacting us at the email above. If you are in a region with applicable data-protection laws, you may have additional rights (access, portability, objection, and complaint to a supervisory authority).
8. Children
Sync13 is not directed to children under 13 (or the minimum age in your jurisdiction) and we do not knowingly collect their data.
9. Changes
We may update this policy; we will revise the "Last updated" date and, for material changes, provide notice within the app.
10. Contact
Questions or requests: wolfbroadcast@gmail.com.