Legal
Privacy Policy
Last updated: June 2026
This Privacy Policy explains how Synkron ("Synkron", "we", "us", or "our") collects, uses, and protects information when you use our website and service (the "Service"). By using the Service, you agree to the practices described here.
1. Who We Are
Synkron is an automated documentation tool that connects to your GitLab repositories, analyzes code changes, and proposes documentation updates as merge requests for your review.
2. Information We Collect
Account information. When you sign in with Google through Firebase Authentication, we receive your name, email address, and profile identifier. We never receive or store your Google password.
Repository access credentials. To operate, Synkron uses access tokens that allow it to read repository contents and open merge requests. Webhook tokens are stored as hashed values. Access tokens are stored securely and used only to perform the actions you authorize.
Repository content. When you connect a repository and push code, Synkron processes commit metadata, code diffs, file contents, and documentation files in order to generate documentation updates.
Usage data. We collect operational logs such as pipeline run records, timestamps, status, and error information to run and improve the Service.
Cookies and local storage. We use essential cookies and browser storage to keep you signed in and to operate the Service.
3. How We Use Information
We use the information we collect to:
- Provide and operate the Service, including analyzing code changes and generating documentation merge requests.
- Authenticate you and secure your account.
- Maintain a history of pipeline runs for your dashboard.
- Improve documentation quality through our feedback feature, which learns from edits you make to generated merge requests.
- Diagnose problems, monitor performance, and maintain security.
4. AI Processing
Synkron uses third-party large language models, including the Google Gemini API, to analyze code changes and draft documentation. Relevant portions of your code and documentation are transmitted to these AI providers solely to generate the documentation output. Please do not connect repositories containing secrets, credentials, or content you are not permitted to share with third-party processors. Depending on the AI provider and the plan in use, inputs submitted on a free tier may be used by the provider to improve their models. Review your AI provider's terms for details.
5. Service Providers
We rely on the following providers to operate Synkron, each processing data on our behalf under their own terms:
- Google Cloud Platform (hosting and infrastructure)
- Firebase Authentication (sign-in)
- Google Gemini API (AI processing)
- MongoDB Atlas (database storage)
- GitLab (repository integration)
6. How We Share Information
We do not sell your personal information. We share information only with the service providers listed above as needed to operate the Service, when required by law or to protect the rights and safety of our users, and in connection with a merger, acquisition, or sale of assets, in which case we will notify you.
7. Data Retention
We retain your information for as long as your account is active or as needed to provide the Service. Pipeline run history and learned correction patterns are retained to operate the dashboard and feedback features until you remove the associated repository or delete your account.
8. Security
We take reasonable measures to protect your information, including hashing webhook tokens and restricting access to stored credentials. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
9. Your Rights
Depending on your location, you may have the right to access, correct, export, or delete your personal information, and to object to or restrict certain processing. To exercise these rights, contact us at the email below. If you are in the European Economic Area or the United Kingdom, you also have the right to lodge a complaint with your local data protection authority.
10. Disconnecting and Deletion
You can disconnect a repository at any time from your dashboard, which removes the associated webhook and stops further processing. You can request full deletion of your account and stored data by contacting us.
11. International Data Transfers
Your information may be processed and stored in countries other than your own, including where our service providers operate. We take steps to ensure your information is handled in line with this policy.
12. Children's Privacy
The Service is not directed to individuals under the age of 16, or the minimum age required by your jurisdiction, and we do not knowingly collect their information.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated version with a new "Last updated" date. Continued use of the Service after changes take effect constitutes acceptance.
14. Contact
If you have questions about this Privacy Policy, contact us at contact@synkron.dev.