Privacy policy
Last updated 6 October 2026
Resync stores what it needs to run your chats and nothing more. This page explains what that means in practice, including how model providers fit in.
1. Overview
This policy explains what Resync collects, why we collect it, and what you can do about it. We collect the minimum we need to run the product.
We do not sell your data. We do not run advertising trackers.
2. Data we collect
We collect data in three ways: what you give us, what the product generates, and what your browser sends.
- Account data: your email address, display name, and a bcrypt hash of your password
- Content: your messages, prompts, attachments, generated images, and saved memories
- Usage data: message counts, token counts, and model choices tied to your account
- Technical data: your IP address for rate limiting, and cookies for your session and theme
- Integration data: calendar events or repository details you ask a tool to read, kept only long enough to answer
3. How we use your data
We use your data to sign you in, to show your history, to send your prompt to the model you chose, and to enforce plan limits.
We use aggregated usage to understand which models work well, to fix bugs, and to plan capacity. We do not use your messages to train our own models.
4. Legal bases
Where the GDPR applies, we rely on these bases: performance of a contract for the core service, legitimate interests for security and abuse prevention, and consent for optional features such as integrations.
6. Model providers
When you send a message, the prompt and the context needed for that reply go to the provider of the selected model. Their privacy policy applies to that request.
We do not send your full history to a provider unless the reply needs it. Incognito chats are never written to our database.
8. Retention
Chats and memories stay until you delete them. Session records expire thirty days after your last sign in, and reset links expire after thirty minutes.
When you delete your account we remove your profile, sessions, reset tokens, and stored chats. Backups roll over within thirty days.
9. Security
Passwords are hashed with bcrypt and never stored in plain text. Session tokens are stored as SHA-256 hashes, so a database leak does not hand over live sessions.
Traffic is encrypted in transit. Access to production data is limited to the people who need it to run the service.
10. Your rights
Depending on where you live, you can ask to access, correct, export, or delete your data, and you can object to some processing. Most of this you can do yourself from settings.
You can also complain to your local data protection authority. We would rather you talked to us first.
11. International transfers
Our infrastructure and model providers may process data outside your country. Where required, we rely on standard contractual clauses or an equivalent safeguard for those transfers.
12. Children
The service is not aimed at children under 13, and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will remove it.
13. Changes to this policy
We will update this page when our practices change and revise the date at the top. For material changes we will tell you in the app or by email.
14. Contact
Privacy questions and requests go to [email protected]. We aim to reply within thirty days.