Synoru Life OS

Privacy policy

Version 2026-09-20

This policy explains what personal data Synoru Life OS processes, on what basis, for how long, to whom it is disclosed and what rights the user has.

The document is missing the service provider’s details ([missing: fill in under Settings]). Fill them in under Settings → Legal information; until they are there, the document must not be shown to customers.

1. Data controller

The data controller is [missing: fill in under Settings], address [missing: fill in under Settings], email [missing: fill in under Settings].

No data protection officer has been appointed, as the scale of processing does not require one. For all data questions, contact the email address above.

2. What data is processed

Account data: email address, name (if provided), a cryptographic derivative of the password (we do not store the password itself), sign-in sessions and a browser identifier.

Data entered by the user: tasks, projects, goals, calendar entries, financial transactions, account balances, purchases, health and sport records, nutrition records, notes and conversations with the assistant.

Integration data: what connected sources send (e.g. sleep, heart rate and workout records from a wearable device). Access keys are kept only on the server side and are not shown in the browser.

Notification data: if notifications to a device are enabled, the provider address supplied by the browser and two encryption keys are stored. They are used only to send the reminder text; the provider cannot read it. When notifications are turned off, the record is deleted.

Technical data: system run logs (analysis cycles, timing of integration and AI calls, error types). Keys are removed from AI call errors.

3. Purposes and legal bases of processing

Providing the service: planning, finance tracking and analysis. Legal basis — performance of a contract (GDPR Art. 6(1)(b)).

Account security, abuse prevention and fixing technical errors. Legal basis — legitimate interest (GDPR Art. 6(1)(f)).

Health, sport and nutrition data are special categories of data. They are processed only with the user’s explicit consent (GDPR Art. 9(2)(a)). Consent can be withdrawn at any time by no longer keeping such records and deleting them; withdrawal does not apply retroactively.

Compliance with legal obligations, e.g. retention of accounting documents if the service becomes paid (GDPR Art. 6(1)(c)).

4. AI model providers

The AI assistant works only when the user connects a model provider (e.g. Anthropic, OpenAI, Google, xAI or a self-hosted model). If none is connected, no data is sent anywhere.

Not the whole database is sent, only the context selected for the specific request. Health and nutrition areas are included only when the user mentions them or adds them themselves. Access keys never enter the model context.

Each answer saves a copy of the context used, so that it is possible to see later exactly what was sent.

Processing carried out by the provider is governed by the provider’s own terms; you should read them before connecting.

5. Data processors and recipients

Data is not sold and is not passed to third parties for advertising purposes.

Data processors may include: the server hosting provider; providers of integrations connected by the user (e.g. a wearable device manufacturer, a calendar service); the AI model provider, if connected; an email sending service, if used for notifications.

Data processing agreements are concluded with processors where required by GDPR Article 28.

6. Transfers outside the EU/EEA

Some providers (e.g. of AI models) may process data outside the EU/EEA. In such cases, the European Commission’s standard contractual clauses or an adequacy decision are relied on.

The user can choose not to use the AI assistant at all — then this transfer does not take place.

7. Retention periods

Account data and data entered by the user are kept for as long as the Service is used and are deleted within 30 days of the account being closed or a deletion request.

Sign-in sessions expire automatically; technical logs are kept for up to 12 months.

Accounting documents, if any arise, are kept for the period required by law.

8. Cookies

Only the strictly necessary session cookie is used to keep you signed in. It is httpOnly, so it is not accessible to scripts, and it expires when you sign out or the session ends.

No analytics, advertising or tracking cookies are used, so there is no separate cookie consent banner.

9. Security measures

Passwords are stored only as a cryptographic derivative (scrypt). The session cookie is httpOnly and sameSite.

Integration and AI provider keys are kept only in the server environment; they never reach the browser, logs, audit or AI context.

Access to internal system tools is restricted to the owner role and checked on the server.

10. Notification of a security breach

In the event of a personal data breach posing a risk to the user’s rights, the supervisory authority is notified within 72 hours, and where the risk is high, the user is notified as well.

11. User rights

The user has the right to access their data, to rectify it, to erase it, to restrict processing, to object to processing, to withdraw consent and the right to data portability.

All your data can be downloaded in JSON format from the “Legal information” section in Settings — without passwords, sessions or integration access keys.

Send requests by email to [missing: fill in under Settings]; a reply is given within 30 calendar days. You can also lodge a complaint with the data protection supervisory authority in your country.

12. Children

The Service is intended for adults. Accounts are not created for persons under 16; if such an account becomes known, it is deleted.

13. Changes to this policy

When this policy changes, a new version is published and a signed-in user is asked to read it. The consent is stored with the date and version number.

Terms of usePrivacy policySign in