Legal

Privacy Policy

Last updated: September 12, 2026

Syncer is an end-to-end encrypted clipboard sync app. This policy explains what we collect, what we deliberately cannot access, and the choices you have. The short version: your clipboard content is encrypted on your device before it ever reaches us, and we cannot read it.

1. Who we are

Syncer ("Syncer", "we", "us") provides a cross-platform clipboard sync service for macOS, Windows, Linux, iOS and Android. The data controller responsible for your information is Burgeon Tech Pvt. Ltd., Kathmandu, Nepal. If you have any privacy question, email us at [email protected].

2. What we collect & why

We aim to collect as little as possible. An account is required to use Syncer so that your devices can find and authenticate one another. Here is everything we handle:

DataWhy we have it
Email addressSign-in and account identity. Authentication supports email one-time codes, Google sign-in, and Apple sign-in.
Device namesThe labels you assign to your paired devices (e.g. "Work MacBook") so you can recognize and manage them.
Encrypted relay blobsTransient, opaque encrypted clipboard payloads passed between your devices. We cannot decrypt them, and they are deleted after delivery.
Encrypted backup blobsOptional PIN-protected backups, when you enable the backup feature. These are encrypted on your device with a key derived from your PIN, which never leaves the device. They are opaque to us.
Basic operational logsMinimal technical information (such as connection timing and error events) needed to run the relay reliably and prevent abuse. These do not contain clipboard content.

To keep the app stable and understand which features are used, we also process a small amount of anonymous technical data: opt-in app-usage analytics (off by default) and crash and performance diagnostics. This data is not linked to your identity and never includes clipboard content, your email, or your keys.

We do not run advertising, we do not sell your data, and we do not perform third-party tracking or analytics profiling of your clipboard content. We do not build usage profiles of what you copy.

3. What we cannot access (the end-to-end guarantee)

Your clipboard content is end-to-end encrypted on your device — sealed with XChaCha20-Poly1305 under a key only your own paired devices hold — before it ever leaves. (The Signal Protocol secures device pairing and key exchange, not the clips themselves.) Our servers relay opaque encrypted blobs and never receive the keys to open them — so we cannot read your clipboard content, and neither can anyone who intercepts it in transit. For the full technical detail, see our Security page.

Concretely, this means:

  • We do not store readable clipboard data on our servers.
  • Relay blobs are deleted after they are delivered to your other devices (delete-on-fetch).
  • Backup blobs are encrypted under a key derived from a PIN that we never see.
  • Because encryption happens before transmission, we do not possess plaintext clipboard content on our servers — so we cannot provide readable clipboard content, including in response to a legal request.

4. Legal basis for processing

Where the EU/UK GDPR applies, we rely on the following legal bases:

  • Performance of a contract — to create your account, authenticate your devices, and relay encrypted clipboard data so the service works.
  • Legitimate interests — to keep the service secure, reliable, and free of abuse, and to communicate essential service information.
  • Consent — for optional communications such as product updates, which you can withdraw at any time.
  • Legal obligation — where we must retain limited records to comply with applicable law.

5. Data retention

  • Encrypted relay blobs are transient and deleted after delivery. Undelivered payloads are purged automatically after 7 days.
  • Clipboard history is stored on your device, not on our servers, and auto-expires on a schedule you control — between 1 and 30 days, defaulting to 7.
  • Encrypted backup blobs persist only while you keep the backup feature enabled, and are removed when you delete the backup or your account.
  • Account data (email, device names) is retained while your account is active and during a 7-day soft-delete recovery window, after which it is deleted.
  • Operational logs are kept only as long as needed for reliability and abuse prevention, then rotated out.

6. Sub-processors

We use a small number of infrastructure providers to operate the service. They process only the limited data described above — and, in the case of relayed clipboard data, only opaque ciphertext they cannot decrypt.

  • Hosting / VPS provider — runs our backend and relay servers.
  • Email delivery provider — sends sign-in codes and essential account emails.
  • Push-notification providers — Apple (APNs), Google and Firebase (FCM) — deliver wake/delivery signals to your devices. These signals do not contain readable clipboard content.
  • Analytics & crash-diagnostics providers — process the anonymous usage and crash/performance data described in section 2. They never receive clipboard content, your email, or your keys.

We may update this list as our infrastructure evolves; material changes will be reflected here.

7. International data transfers

Our providers may process data in countries other than yours. Where required, such transfers are covered by appropriate safeguards (such as Standard Contractual Clauses). Because clipboard content is end-to-end encrypted, any relayed clipboard data crossing borders remains opaque ciphertext throughout.

8. How we protect data

Beyond end-to-end encryption of clipboard content, we use transport encryption (TLS) for all connections, per-device keys, device pairing and approval, and the ability to revoke a device's access. For a fuller technical description, see our Security page.

9. Children

Syncer is not directed to children. You must be at least 13 years old (or 16 where required by local law, such as in parts of the EU) to create an account. We do not knowingly collect data from children below these ages; if you believe a child has provided us data, contact us and we will delete it.

10. Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to withdraw consent. Because of our architecture, some of these are built in:

  • Access & export — your clipboard history lives on your device and can be viewed and exported there. You can request a copy of the account data we hold (email, device names).
  • Deletion — you can delete your account, which soft-deletes it and starts a 7-day recovery window before permanent removal, after which associated account data and backups are erased. Contact us to expedite or confirm deletion.
  • Correction — update your device names in-app, or contact us to correct account details.

To exercise any right, email [email protected]. You also have the right to lodge a complaint with your local data protection authority.

11. Cookies

The Syncer marketing site uses minimal, essential cookies/local storage only — for example to remember your preferences on this site. We do not use advertising or cross-site tracking cookies. The apps themselves do not use web cookies to track you.

12. Changes to this policy

We may update this policy as the product and law evolve. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify you. Continued use of Syncer after an update means you accept the revised policy.

13. Contact

Questions, requests, or concerns about privacy? Email [email protected]. The responsible entity is Burgeon Tech Pvt. Ltd., Kathmandu, Nepal.