Synopal

Privacy

Updated 20 September 2026.

What sync stores

When you sign in, Synopal stores your account identifier, verified email and chosen display name, plus the projects, conversations, files, preferences and activity you sync. It does not upload OpenAI credentials, unfinished drafts, Android permission grants or native Codex session identifiers.

How it is protected

Connections use HTTPS. Synced record contents and files use server-side encryption at rest. This is not end-to-end encryption: the service can decrypt data to serve your signed-in devices. Account identity information is managed separately by Keycloak.

Providers and retention

Google is optional for sign-in. Resend delivers verification and password-reset emails. Infrastructure is hosted with Hetzner. Operational logs are limited in size and exclude record bodies and authorization headers; identity security events are retained for seven days. Encrypted backups are retained for fourteen days.

Your controls

You can manage identity sessions through Account settings and delete your account from Synopal. Deletion immediately blocks sync and removes live synced content; identity deletion is retried if the identity provider is temporarily unavailable. Existing encrypted backups expire according to their retention period.

Privacy contact: contact@synopal.net