Legal
Privacy policy
What DevSyncora collects about you, why, who receives it, how long we keep it, and the rights you have over it.
Last updated: 2 October 2026 In force from: 2 October 2026
The short version
- You sign in with GitHub. We never see a password.
- Every project is private in every workspace until you share it, and you choose how much each workspace sees.
- DevSyncora's servers never fetch your source code. Agents you run with the DevSyncora Bridge work on your own computer, with your own AI account, and you decide who sees their runs.
- Voice and screen sharing are never recorded, and AI voice audio is never stored.
- No analytics, no advertising and no tracking, on this website or in the app. We never sell your information.
- You can export your data or delete your account at any time from your account settings.
This summary is not the whole policy. The sections below are.
Who we are
DevSyncora is run by SyncFac (Pty) Ltd ("SyncFac", "we", "us"), a private company registered in South Africa (registration number 2026/728471/07). We are the responsible party for your personal information under the Protection of Personal Information Act, 2013 ("POPIA"), and its controller under the EU and UK General Data Protection Regulations ("GDPR").
- Information Officer
- [To be confirmed: Information Officer's name]
- Privacy requests
- hello@syncfac.com
- Address
- [To be confirmed: physical address]
This policy covers the DevSyncora web app, this website and the DevSyncora Bridge. It does not cover the services you connect to DevSyncora, such as GitHub, your AI provider or Slack: their own privacy policies apply to them. Our Terms of service explain the rules for using DevSyncora.
What we collect
We collect what DevSyncora needs to work, and nothing more. Most of it comes from you, from what you do in DevSyncora, or from tools you choose to connect.
Your account
- When you sign in with GitHub, we receive your GitHub user id and username, your name, the address of your profile picture, and your email address (your public GitHub email or, if you have none, your primary verified one). Signing in asks GitHub only for your public profile and email addresses.
- We store the access token GitHub gives us, encrypted, so you can choose repositories to connect. It can only do what our read-only GitHub App allows. We never see your GitHub password.
- What you add to your profile: a bio, pronouns, a location, a website, a status message, your avatar's look, desk decorations, and your settings (graphics, sound, voice, notifications and time zone).
Workspaces and communities
- The workspaces you belong to, your role, the invites you create or accept, and requests to join a community (with any note you write).
- Moderation records, such as bans, mutes and removals from a room, and the reports you file.
What you write and share
- Direct messages, sticky notes, shared items, knocks and their replies, challenges and the messages on them, and images you upload.
- Chat in the world is not stored. It is passed live to the people near you and then it is gone. If someone reports a chat line to their workspace admins, the report keeps that line as the reporter saw it.
Presence, games and activity
- Whether you are online, when you were last seen, and where you last stood in each studio.
- Game results, scores and stats, achievements, tournament and ladder places, and the robots you save for Robot Battles.
Voice and screen sharing
Spatial voice and screen sharing travel live through our media server (LiveKit). They are never recorded or stored. We keep your voice settings (such as your push-to-talk key and the volume you set for each person) and any voice moderation by admins.
AI voice
- Standard voice uses your browser's own speech recognition, so your browser's maker (Google, Microsoft or Apple) processes your speech under its own terms. The agent's reply is spoken by your browser.
- HD voice, where a workspace has it (it is not part of the Free plan), sends your speech to our speech providers to turn it into text, and turns the agent's reply into speech.
- We never store AI voice audio. We keep the text of each conversation, which only you can read, and a record that you accepted the first-use notice. What you say is sent to the AI provider that answers for the agent.
AI agents
- Your agents' settings and instructions, the prompts you give them, and each run: its status, summary, findings, token counts and cost estimate, its transcript, any questions or permission requests and your answers, and approvals.
- Runs of workspace agents can be read by the members of that workspace. Runs of your personal agents and Bridge runs are private to you unless you share them with a workspace.
- If you save your own Anthropic or OpenAI API key for a personal agent, we store it encrypted and only ever show its last four characters.
The DevSyncora Bridge
- For each computer you pair: its name, system, Bridge version, which AI tools are installed and signed in, and the folders you link, by name with their git remote and branch. Full folder paths never leave your computer. We store only a hash of the device token. A pairing request records the IP address it came from, and is deleted after 24 hours.
- When you start a run from DevSyncora, the Bridge sends us what the agent says, the commands it runs with their output (up to 4,000 characters each), the names of the files it reads and changes, and, at the end of a turn that changed files, a diff of those changes (up to 16,000 characters). Command output and diffs can contain your code.
- Mirror mode shows sessions you run in your own terminal, at the level you choose: off; presence (the default: only that you are working with an agent); activity (adds tool names and file names); or full (adds short snippets of your prompts and the replies, up to 300 characters).
- The Bridge never reads or sends your Claude or Codex login. What you send to Claude or Codex goes to Anthropic or OpenAI under your own account with them, not through us.
- The Bridge checks this website for updates once a day. Like any visit, the check reaches our web server with your IP address, and it names only the Bridge's version and your type of system. You can turn it off.
Connected tools
- When you connect GitHub, GitLab, Jira, Linear, Vercel, Coolify or a webhook, we keep the metadata of what happened, never the raw message: for example pull request and issue titles, numbers and states, branch names, commit counts and the first line of the latest commit message, deploy and CI results, environment names and links, and the usernames or display names of the people involved.
- We never fetch source code: GitHub only sends push and release events to apps with read access to repository contents, so our GitHub App has that access, but we never use it to read code. We keep what happened (such as commit messages, authors and branches), never file contents. We never keep issue or merge request descriptions, comment bodies, or the email addresses of the people involved.
- OAuth tokens, webhook secrets and the webhook addresses of Slack and Discord channels are stored encrypted (AES-256-GCM), and are never shown again. For Slack and Discord we keep only the channel's posting address: we never read your messages there.
Notifications and email
- Your notification settings, quiet hours and time zone, and the devices you turn push on for (their push address, with the push keys encrypted).
- Your email address and email settings, and a log of the emails we send you (the address, subject and outcome, never the body). If an email bounces or is reported as spam, we stop sending to that address until you confirm it again.
Security records
- Your signed-in sessions: the type of device and browser, the IP address, and when you signed in and were last active. Sign-in tokens are only ever stored as hashes.
- Each workspace's audit log of security-relevant actions, such as role changes, invites, bans and changes to project visibility. Entries record who did what and when, and usually the IP address. They never contain secrets, private project details or what people said.
- Technical logs on our servers, and our web servers' access logs (the page requested, the time, the browser and the IP address). They never contain your messages, tokens or passwords, and the app's logs leave out the parts of addresses that can carry sign-in codes.
Error reports
If error reporting is turned on, an unexpected error sends its type, message and stack trace, the part of DevSyncora it happened in and a pattern of the page address (such as /w/:param/people/:id) to our error reporting service. Reports never include what you typed, request contents, ids or tokens. Errors in your browser are sent from your browser, so the service also sees your IP address.
What we do not collect
- Passwords. You sign in with GitHub.
- Your source code, through our servers or integrations. Bridge runs can carry code, as described above, because you can only follow a run by seeing what it did.
- Recordings of voice, screen shares or AI voice audio.
- Payment details. DevSyncora is free today.
- Special personal information, such as health, religion, ethnicity, sexual orientation or biometric data. We do not ask for it, and we do not create voiceprints.
- Analytics, advertising or tracking data. Neither this website nor the app uses analytics, advertising or tracking tools of any kind.
Please do not put special personal information, or other people's personal information that you have no right to share, into your profile, messages, uploads or prompts.
How we use it, and why we may
POPIA lets us process personal information only for a lawful reason. We follow its eight conditions for lawful processing: we are accountable for your information, collect only what we need for clear purposes, do not use it for unrelated purposes, keep it accurate, are open about it, keep it secure, and let you see and correct it. These are our purposes and their lawful reasons (POPIA section 11, and GDPR Article 6 for people in the EU and UK):
- To provide DevSyncora
- Your account, workspaces, the 3D studio, messages, games, agents, voice, integrations, notifications and digest emails. Reason: we need it to perform our agreement with you.
- To keep DevSyncora and its people safe
- Sessions, audit logs, rate limits, server logs, moderation, reports, blocks and error reports. Reason: our legitimate interest, and yours, in protecting accounts, workspaces and the service from abuse and attack.
- Features you choose to turn on
- AI voice (after its first-use notice), push notifications, posting your moments to Slack or Discord, mirror mode and the tools you connect. Reason: your consent, which you can withdraw at any time by turning the feature off.
- To fix and improve DevSyncora
- Error reports and logs, to find and fix problems. Reason: our legitimate interest in a reliable service.
- To meet legal duties
- Records the law requires, and answering lawful requests from authorities. Reason: legal obligation.
We do not use your information for advertising, we do not sell it, and we do not use it to train AI models. We do not make decisions about you based only on automated processing that have legal or similarly significant effects.
Who can see your information
- People in your workspaces see your profile, presence and avatar, what you write to them, and your projects only at the level you choose for that workspace. Activity from a project you show as "activity only" never names it.
- People who visit a public community, signed in or not, see only what its owners published: never its member list or anyone's activity, and projects only when their owners made them public there.
- Workspace owners and admins see their workspace's audit log (without IP addresses), the reports members send them, and the join requests to their community.
- Slack and Discord channels a workspace connects receive moments only from people who opted in, and only what every member of that workspace may see.
- Our service providers, listed below, process information only on our instructions and only to run DevSyncora.
- Authorities, when the law requires it, and a company that takes over DevSyncora (we would tell you first).
We never sell or rent your personal information.
Service providers
These companies process personal information for us (as "operators" under POPIA and "processors" under the GDPR). Some depend on how DevSyncora is set up, so a few are marked "if enabled".
- Hosting
- [To be confirmed: hosting provider]: the servers that run DevSyncora, its database and uploaded images.
- Backups
- [To be confirmed: backup storage provider]: daily, encrypted copies of our database, kept for 14 days.
- Resend, or the mail service we connect to: sends address confirmations and digest emails.
- Voice
- LiveKit, run by us or by LiveKit as a cloud service: carries spatial voice and screen shares live, without recording them.
- AI models
- Anthropic and OpenAI: answer for workspace agents and spoken AI voice turns. They receive prompts, what you say to an agent, and the project details you may see. For personal agents that use your own API key, they work under your account with them.
- Speech, for HD voice (if enabled)
- Deepgram (speech to text) and Cartesia (text to speech): receive your speech and the agent's reply while you talk to an agent in HD.
- Sign-in and GitHub
- GitHub: signs you in and runs the GitHub App that sends repository activity. Profile pictures are loaded from GitHub, so GitHub can see when your browser loads one.
- Push notifications
- The push services of browsers and phones (Google, Apple, Mozilla and Microsoft): carry notifications to your devices. Notifications never carry project details.
- Error reporting (if enabled)
- Sentry or GlitchTip: receive error reports as described above.
- Payments (later)
- Stripe will process payments once paid plans launch. Paid plans are not available yet.
Services you connect yourself, such as GitLab, Jira, Linear, Slack, Discord, Vercel, Coolify, your browser's speech recognition and your own AI provider accounts, are not our providers: they handle your information under their own terms.
Sending information outside South Africa
Our servers are in [To be confirmed: country where the servers are]. Several of our providers, such as Anthropic, OpenAI, Deepgram, Cartesia, Resend, GitHub and the push services, process information in other countries, mostly the United States and the European Union.
Under section 72 of POPIA, we only send personal information out of South Africa when the recipient is bound by law, binding corporate rules or an agreement that protects it as well as POPIA does, or when the transfer is needed to perform our agreement with you, or you have agreed to it. For people in the EU and UK, transfers rely on an adequacy decision or on safeguards such as the European Commission's standard contractual clauses and the UK addendum to them. You can ask us for details at hello@syncfac.com.
How long we keep it
We keep personal information only as long as we need it for the purposes above, or as the law requires.
- Your account and profile
- Until you delete your account.
- Direct messages you send
- Until you delete your account. Messages other people sent you are theirs, and stay with them.
- Notes, shared items, projects and their activity
- Until you, or a workspace admin where allowed, delete them, the workspace is deleted, or you delete your account.
- Agent runs and transcripts, and AI voice transcripts
- Until the agent is deleted, you delete your account, or the workspace is deleted.
- Notifications
- Until you delete your account, or the workspace is deleted.
- Game results
- For as long as the workspace exists. When you delete your account, your scores stay without your name.
- Sessions
- Deleted a day after they expire (30 days after you were last active), or 30 days after you sign a device out.
- Bridge pairing requests
- 24 hours.
- Push devices
- Until you turn push off, or after 90 days without use.
- Email log
- 90 days.
- Audit log
- For as long as the workspace exists. The IP address in an entry is deleted after 12 months.
- Server logs
- Rotated by size and overwritten as new logs arrive, so they are kept only briefly.
- Error reports
- Up to 90 days, at the error reporting service.
- Data exports
- Deleted when you download them, or after 24 hours.
- Backups
- 14 days. Anything deleted from DevSyncora is gone from our backups within 14 days.
When you delete your account
We erase your profile, settings, email, integrations and their tokens, projects, memberships, notes, shared items, the direct messages you sent, notifications, challenges, ladder places and achievements, personal agents and every run you requested, AI voice conversations, devices, keys, sessions, email settings and log, blocks, uploads and data exports. Workspaces you owned alone are deleted with you.
Your account itself becomes an anonymous placeholder named "Deleted user", with no email address, so that the history other people still see (audit entries, activity lines, reports and game scores, which keep their points without your name) still reads correctly.
How we protect it
Connections to DevSyncora are encrypted (HTTPS). Provider tokens, API keys and webhook secrets are encrypted at rest with AES-256-GCM; sign-in tokens, office PINs and device tokens are stored only as hashes. Every privacy rule is enforced on our servers, down to what the live connection to the 3D studio carries. Backups are encrypted and kept in a private storage bucket. More on the Security and privacy page.
If a security compromise means someone may have gained access to your personal information without authority, we will tell the Information Regulator and you as soon as reasonably possible, as section 22 of POPIA requires (unless a public body responsible for investigating crime asks us to delay). For people in the EU and UK, we notify the relevant authority within 72 hours where the GDPR requires it, and you without undue delay if the risk to you is high.
Your rights
You have the right to:
- know whether we hold personal information about you, and get a copy of it (access);
- have it corrected, or deleted if it is inaccurate, out of date, incomplete, excessive or unlawfully held;
- object to our processing it on the basis of our legitimate interests, and to direct marketing at any time;
- withdraw your consent, where we rely on it;
- complain to the Information Regulator (see below).
Do it yourself
- Get a copy of your data: Account, Privacy, Your data.
- Correct your profile: Account, Profile.
- Delete your account: Account, Security.
- Control who sees each project, per workspace, in its settings; turn notifications, email and push off in Account, Notifications; disconnect tools in Integrations; set your mirror level in Agents.
Or ask us
Email hello@syncfac.com. We may need to confirm it is you (for example, by asking you to write from the email address on your account). We answer within 30 days, and it is free. A formal request for records under the Promotion of Access to Information Act follows our PAIA manual (see below).
If you are in the EU or the UK
The GDPR and UK GDPR give you the rights above, and also the right to restrict our processing and to receive your data in a portable format (the data export is a JSON file). Our lawful reasons are listed in How we use it, and our transfers are covered in Sending information outside South Africa. We answer requests within one month. You may complain to the data protection authority where you live or work (in the UK, the Information Commissioner's Office), though we would like the chance to help first.
Children
DevSyncora is only for people aged 18 and over. We do not knowingly collect personal information about anyone under 18. If you believe a child has an account, tell us at hello@syncfac.com, and we will close it and delete its data.
Marketing
We do not send marketing. The emails we send are part of the service: address confirmations, and a digest of what you missed in your workspaces. If your GitHub account gives us a verified email address, the weekly digest starts on; you can change it or turn it off in Account, Notifications, Email, or with the unsubscribe link in every digest.
If we ever want to send you direct marketing by email or any other electronic means, we will ask for your consent first, as section 69 of POPIA requires, and every message will let you opt out. We never give your details to anyone else for their marketing.
Cookies and local storage
This website uses no cookies and stores nothing in your browser. It loads nothing from other companies.
The DevSyncora app uses two cookies, both essential to signing in, so there is nothing to opt into:
- dsy_refresh
- Keeps you signed in. It holds a sign-in token that scripts on the page cannot read, is sent only to our sign-in service, and expires 30 days after you were last active.
- dsy_oauth_nonce
- Ties a GitHub sign-in to the browser that started it. Lasts 10 minutes.
The app also keeps a few settings in your browser's local storage: the workspace you last opened, the microphone and speakers you chose, whether this browser receives push notifications, and your Robot Battles robot. The short-lived token that proves who you are to our servers is kept only in memory, never in storage.
There are no analytics, advertising or tracking cookies.
PAIA manual
Our manual under section 51 of the Promotion of Access to Information Act, 2000 explains the records we hold and how to request access to them. It is available free of charge on request from hello@syncfac.com.
Complaints
If you are unhappy with how we handle your information, please tell our Information Officer at hello@syncfac.com first. We will try to put it right.
You also have the right to complain to the Information Regulator:
- Website
- inforegulator.org.za
- Complaints
- POPIAComplaints@inforegulator.org.za
- General enquiries
- enquiries@inforegulator.org.za
- Telephone
- 010 023 5200
- Address
- Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191
Changes to this policy
We will update this policy when DevSyncora or the law changes. The date at the top shows when it last changed. If a change materially affects you, we will tell you at least 30 days before it applies, by email (if you have a confirmed address) or in DevSyncora.
Paid plans are not available yet. When they launch, payments will be handled by Stripe, and this policy will say what Stripe receives before anyone can buy.
Contact us
- Privacy requests and the Information Officer
- hello@syncfac.com
- Help with your account
- support@syncfac.com
- Developers, integrations and the Bridge
- build@syncfac.com
- Post
- SyncFac (Pty) Ltd, [To be confirmed: registered address for legal notices]