← Back to Syncademia

Privacy Policy

Last updated: August 19, 2026 · Version 1.3

1. Who we are

Syncademia AI Inc. is an Ontario corporation operating Syncademia AI, a student productivity platform with AI-powered study tools.

Contact: syncademiaai@gmail.com

Mailing address: 251 Lester Street, Waterloo, ON, Canada

2. What data we collect

Account data

  • Full name, email address, password (hashed — never stored in plain text)
  • University, program, year of study (optional)
  • Profile picture (optional)
  • Timezone preference

Usage data

  • Pages visited, features used, time spent
  • Clicks, search queries, navigation patterns
  • Device type, browser, operating system
  • IP address (security and fraud prevention)

Academic data (provided by you)

  • Course names and codes, syllabus files, documents, assignments, due dates, grades
  • Notes, study materials, and flashcard content

AI interaction data

  • Messages to Syncy, AI responses, documents sent for AI processing
  • Quest questions and answers, flashcard generation requests

Payment data

  • Subscription tier and status, billing email via Stripe
  • Last four digits of card (held by Stripe, not by us)
  • We never store full card numbers

Wellness data (optional)

  • Mood check-ins, stress self-assessments, wellness quiz responses

3. How we use your data

  • Provide and improve the Syncademia platform
  • Personalize Syncy with your academic context
  • Generate flashcards, study plans, and Quest content from your materials
  • Send account emails (password reset, billing receipts)
  • Enforce our Terms of Service and prevent abuse
  • Analyze aggregate usage to improve features
  • Comply with legal obligations

4. AI provider disclosure

Important: Syncademia uses artificial intelligence extensively. AI outputs may be inaccurate. Do not rely on Syncy for medical, legal, financial, or professional advice.

AI providers we use

Sent to AI providers

  • Messages to Syncy, uploaded document content for AI processing
  • Course and task context used to personalize responses
  • Flashcard and Quest generation requests

Not sent to AI providers

  • Your password, payment information, or other users' data

We use OpenAI's API under terms that restrict use of API data for training their public models. See OpenAI's current enterprise/API data processing terms for details.

4. Integrations (UW OpenData, optional)

If you choose to connect a University of Waterloo OpenData API key, we store it encrypted at rest on our servers and use it only to sync your course enrollment when you enable that feature. We never display the full key after save.

  • Purpose: fetch your UW course list for enrollment sync you initiate
  • Storage: encrypted at rest; not exposed to other users or the browser
  • Retention: until you remove the key in Settings → Integrations or delete your account
  • Deletion: clear the field and save, or use Remove saved API key

5. Google Calendar (optional)

Google Calendar sync is opt-in and separate from signing in with Google. Signing in with Google does not connect your calendar; connecting requires a second, explicit Google consent screen that you start from Settings → Integrations.

Scopes we request

  • OpenID (openid) — Confirms which Google account authorized the connection.
  • Email address (email) — Shows you which Google account is connected, and matches it to your account.
  • Basic profile (profile) — Displays your name and picture on the connected-account screen.
  • Google Calendar events (https://www.googleapis.com/auth/calendar.events) — Reads your existing events so your Syncademia schedule reflects real conflicts, and creates, updates, or deletes only the events Syncademia itself adds when you sync a task or class.

What we do with events

  • Read events in authorized calendars to detect scheduling conflicts
  • Create events only when you sync a task, assignment, or class
  • Update and delete only the events Syncademia created — we never delete or rewrite events we did not create

Tokens and retention

  • Access and refresh tokens are encrypted at rest and never exposed to the browser
  • Disconnecting the integration deletes the stored tokens
  • Calendar data is not sold, not used for advertising, and not used to train AI models

You can disconnect at any time from Settings → Integrations, or revoke access from your Google Account permissions. Full details are in our Google User Data Policy.

6. Third-party services

ServicePurposeData shared
SupabaseDatabase, auth, storageAccount and app data
StripePaymentsEmail, subscription status
OpenAI / GeminiAI featuresMessages, documents, context
VercelHostingIP addresses, request logs
SentryError monitoringError data, stack traces
Google CalendarOptional calendar syncCalendar events you authorize

We do not use PostHog or advertising analytics SDKs.

7. Data retention

  • Account data: while your account is active
  • Usage logs: up to 90 days
  • AI conversation history: until you delete it or delete your account
  • Wellness check-ins: until you delete them or delete your account
  • Google Calendar tokens: until you disconnect the integration or delete your account
  • Trashed items: permanently deleted 30 days after you delete them
  • Payment records: 7 years (legal requirement)
  • Deleted accounts: anonymized within 30 days of deletion request

8. Your rights

All users

  • Access, correct, delete your data, and withdraw optional consents
  • Export: contact syncademiaai@gmail.com or use Settings → Delete/Export where available

Canadian users (PIPEDA / Quebec Law 25)

  • Right to access, correction, and withdrawal of consent
  • Quebec residents may have additional rights including de-indexing

EU/UK users (GDPR)

  • Access, rectification, erasure, portability, objection, and restrictions on automated decision-making

California users (CCPA/CPRA)

  • Right to know, delete, and non-discrimination. We do not sell personal information.

9. Children's privacy

Syncademia is intended for university students (typically 18+). We do not knowingly collect data from children under 13. Contact syncademiaai@gmail.com if you believe a child created an account and we will delete it.

10. Security

  • Passwords hashed with industry-standard algorithms
  • Data encrypted in transit (TLS 1.2+)
  • Database access restricted by row-level security
  • API keys stored as environment variables, not in source code
  • We will notify affected users within 72 hours of discovering a material security breach

11. Contact

Privacy questions, access requests, or deletion: syncademiaai@gmail.com

We aim to respond within 30 days.

Questions? Contact syncademiaai@gmail.com. We aim to respond within 30 days.