Privacy Policy

Effective August 29, 2026 · Version 1.10

Privacy Policy

Effective Date: August 29, 2026 Version: 1.10

Synergy In Construction, LLC ("SynC™," "we," "us," or "our"), a Florida limited liability company, is committed to protecting your privacy and ensuring transparency about how we collect, use, disclose, and safeguard your personal information. This Privacy Policy describes our practices regarding the information we collect through our platform, website, and related services (collectively, the "Services"). You can reach us about anything in this Policy at privacy@synergyinconstruction.com; our full contact details are in Section 14.

By accessing or using the Services, you agree to this Privacy Policy. If you do not agree, please do not use the Services.

1. Information We Collect

We collect information in several ways when you use our Services:

1.1 Information You Provide Directly

Account Registration Information:

  • Full name (first and last name)
  • Email address
  • Password (hashed and securely stored — see Section 6.1)
  • Phone number (optional)
  • Job title and role
  • Company name and information
  • Profile information

User Content and Project Data:

  • Construction project specifications and documents
  • Equipment datasheets and technical information
  • Project files, drawings, and attachments
  • Comments, annotations, and collaboration messages
  • AI chat interactions and queries
  • Custom templates and saved preferences
  • SynC Standards wiki contributions

Conversations with the AI assistant. Your conversations with the AI assistant are stored on our servers rather than only in your browser, so that a conversation survives a page reload and remains available to you afterwards. What we store for each conversation is:

  • the messages you send;
  • the assistant's replies; and
  • a plain-language record of the actions the assistant took in the course of the conversation — for example that it read a particular standard, or that it made a change you approved — together with the outcome of any change you approved.

Where an action produced a machine payload, that payload is reduced to identifying information before the conversation is stored. We keep what identifies the thing the assistant acted on, not the raw data it returned. This is the same form the conversation is displayed in: the assistant's actions are shown to you as that plain-language record, never as raw payloads.

We also record which inference provider and model served each exchange, so that the record of what happened is complete.

A conversation carries the context it was started in — for example the project you were working in — and, when you reopen the assistant in that same context shortly after using it, we restore your most recent conversation there. The Services show you that this has happened and let you start a new conversation instead. Section 5.1 states how long a conversation is kept, Section 4.2A states who can see it, and Section 8.1 states what you can do with it.

Payment Information:

  • Billing name and address
  • Payment method details (processed securely through third-party payment processors)
  • Purchase history and subscription information

Communications:

  • Email correspondence with our support team
  • Feedback, surveys, and reviews
  • Contact form submissions

1.2 Information Collected Automatically

When you access or use the Services, we automatically collect:

Usage Information:

  • Pages viewed and features accessed
  • Time spent on pages and in the application
  • Click patterns and navigation paths
  • Search queries and AI interaction history
  • Feature utilization and engagement metrics
  • Files uploaded, downloaded, and shared

Wiki search. When you search the public SynC wiki without signing in, we record what you searched for and which result you opened, so that we can see which standards are missing or hard to find. These records include no IP address, device or browser identifier, and no link to any account; they are never used to build a profile of you, and they are deleted after 90 days. Searches you run while signed in are ordinary account activity, are associated with your account as described under Usage Information above, and are deleted on the same 90-day schedule.

Email we send you. We send email through a third-party delivery service (Section 4.1), and that service applies tracking to the messages it sends on our behalf.

  • Every link in an email we send is rewritten before the message goes out. A link you follow resolves first through our email-delivery processor's tracking domain, awstrack.me, which records the click and then redirects you to the real destination. This is why a link in one of our emails shows an awstrack.me address when you hover over it rather than a synergyinconstruction.com one. What is recorded is that a link in a particular message was followed, which link it was, and the technical details accompanying that request, including your IP address and the date and time.
  • Where open tracking is enabled on our email-delivery account, opening a message is also recorded. That feature works by including a small invisible image in the HTML version of a message; your email program requests that image when it displays the message, and the request records that the message was opened, when, and the same kind of technical detail. Configuring your email program not to load remote images prevents it. The link rewriting described above is part of the message itself and is not affected by that setting.

These records are held by our email-delivery processor. No email interaction record is written to your SynC account or to our application database. Section 4.1 describes that processor and what it receives, Section 5.1 states what we can and cannot say about how long it keeps this data, Section 8.1 states what you can do about it, Section 10.1 explains why none of it is a browser cookie, and Section 12.3 explains that it applies to transactional email and not only to marketing email.

Project Sharing and Distribution Analytics:

  • Share link creation, acceptance, and forwarding activity
  • Access records tracking which users have accepted shared project access
  • Records of the removal of a recipient's access and of the deletion of a distributed project
  • Sharing chain data (how access has been forwarded through delegation)

Device and Technical Information:

  • IP address and geolocation (city/region level)
  • Browser type and version
  • Operating system and device type
  • Screen resolution and display settings
  • Unique device identifiers
  • Referring URLs and exit pages

Cookies and Similar Technologies: We use cookies, web beacons, pixels, and similar tracking technologies to:

  • Maintain your session and keep you logged in
  • Remember your preferences and settings
  • Analyze usage patterns and improve Services
  • Prevent fraud and enhance security
  • Deliver personalized content and recommendations

For more information, see Section 10 (Cookies and Tracking Technologies).

1.3 Information from Third Parties

Third-Party Integrations:

  • Information from services you connect to SynC (with your permission)
  • Data from authentication providers (e.g., Google, Microsoft)

Business Partners:

  • Information from companies that collaborate with you on projects
  • Referral information from partners

Public Sources:

  • Publicly available business information
  • Industry data and construction standards

2. How We Use Your Information

We use the information we collect for the following purposes:

2.1 Service Delivery and Operations

  • Provide, maintain, and improve the Services
  • Create and manage your account
  • Process transactions and subscriptions
  • Store and organize your project data and User Content
  • Store your conversations with the AI assistant so that they survive a page reload and remain available to you, and restore a recent conversation when you reopen the assistant in the context it belongs to (see Sections 1.1 and 5.1)
  • Enable collaboration features with team members
  • Provide customer support and respond to inquiries
  • Send transactional emails (account notifications, password resets, etc.)

2.2 AI and Machine Learning

We use artificial intelligence and machine learning to deliver certain features of the Services:

AI Feature Delivery:

  • Process your queries and requests through AI services
  • Generate AI-assisted content and recommendations
  • Analyze specifications and documents using natural language processing
  • Provide predictive analytics and intelligent suggestions
  • Make content searchable by meaning as well as by keyword (semantic search)
  • Continue a stored conversation where you left it, which requires transmitting that conversation to the inference provider again (see Section 4.1A)
  • Generate a short title for each stored conversation, so that a list of your conversations is navigable. The title is produced by a separate, small inference request over the conversation's own content (see Section 4.1A)

We Do Not Train Models on Your Content:

  • We do not use User Content to train, fine-tune or improve any generative AI model, or any general-purpose or foundation model, whether ours or a third party's, and whether or not it has been anonymized or aggregated. The scope of that commitment, its conditions, and its limited exceptions are set out in Terms of Service §5.3.1 — which governs if this summary and it ever differ
  • We may build models inside the Services that classify, score, match, rank or flag content — for example identifying what kind of value a datasheet field holds. Terms of Service §5.3.1 states the conditions such a model must meet: it produces structured outputs rather than text, it is never distributed outside the Services, and neither it nor its outputs reproduce your content to anyone not already authorized to see it
  • The principal exceptions are content you deliberately submit for inclusion in the public SynC Standards library, which is a Contribution under our Contributor License Agreement, and feedback you direct to SynC about the Services or about a published Standard, which is governed by Terms of Service §8.5
  • We do measure how the Services are used, and structural facts derived from content, in ways that cannot reconstruct your content — see Terms of Service §5.3.2
  • Your messages to the AI assistant are User Content, and the commitment above applies to them. Storing a conversation does not create a training use: a stored conversation is transmitted to an inference provider only in order to continue that conversation or to generate its title (Section 4.1A), under the same constraints as any other request
  • There is no training opt-out to request, because there is no training use to opt out of

Third-Party AI and Embedding Services:

  • Delivering AI-assisted features and semantic search requires transmitting the content you are working with to service providers that perform inference and text-embedding on our behalf
  • Our configuration excludes providers that retain your content for their own purposes or train on it, and we do not contract directly with the individual inference hosts. Section 4.1A describes the controls we apply, and Terms of Service §5.3.3 states the commitment, which governs
  • Our current providers and the jurisdictions in which they process content are published at synergyinconstruction.com/legal/subprocessors. That list changes from time to time; our obligations under Terms of Service §5.3.3 do not

2.3 Analytics and Service Improvement

  • Monitor and analyze usage patterns and trends
  • Conduct research and development for new features, using the usage data and structural statistics described in Terms of Service §5.3.2 — not the content of your specifications (see Terms of Service §5.3.1)
  • Perform statistical analysis and create aggregated reports
  • Measure effectiveness of features and user experience
  • Identify and fix technical issues and bugs
  • Optimize performance, speed, and reliability
  • Identify gaps in the SynC Standards library — which standards are missing, or present but hard to find — from what visitors search for and which results they open (see Section 1.2)
  • Maintain a citation index derived from published documents — which published document cites which SynC Standard, and at which clause — used to resolve citations for readers of the citing document, to warn Wiki editors about the impact of an edit on documents that cite the edited clause, and to produce the aggregate citation counts described in Section 4.5

2.4 Personalization

  • Customize your experience based on preferences and usage
  • Provide relevant recommendations and content
  • Remember your settings and preferences
  • Display personalized dashboards and workflows

2.5 Communication

  • Send important service announcements and updates
  • Notify you of new features and improvements
  • Request feedback and conduct surveys
  • Provide educational content and best practices
  • Send marketing communications (with your consent, where required)

2.6 Security and Fraud Prevention

  • Detect, prevent, and investigate fraud and security incidents
  • Protect against unauthorized access and malicious activity
  • Monitor for violations of our Terms of Service
  • Ensure platform integrity and user safety
  • Comply with legal obligations and enforce our policies

2.7 Legal Compliance

  • Comply with applicable laws, regulations, and legal processes
  • Respond to lawful requests from public authorities
  • Protect our rights, privacy, safety, and property
  • Resolve disputes and enforce agreements

3. Legal Basis for Processing (GDPR Compliance)

For users in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal information based on the following legal grounds:

Contract Performance:

  • Processing necessary to provide the Services you've requested
  • Account creation and management
  • Transaction processing
  • Transmitting the content in scope for your request to an inference provider in order to answer a question you have asked of the AI assistant, and transmitting a search query to a text-embedding provider in order to run a search you have asked for (see Section 4.1A)
  • Storing your conversations with the AI assistant so that they remain available to you, restoring a recent conversation when you reopen the assistant in the context it belongs to, and transmitting a stored conversation to an inference provider when you continue it — each of which is what the conversation-history feature you are using consists of (see Sections 1.1, 4.1A and 5.1)

Legitimate Interests:

  • Improving and optimizing our Services
  • Fraud prevention and security
  • Analytics and business intelligence
  • Direct marketing to existing customers
  • Detecting, diagnosing, and remediating errors and service-impacting incidents through our error-monitoring processor (see Section 4.1)
  • Measuring product engagement, conversion funnels, and feature usage through our product-analytics processor (see Section 4.1), subject to your consent for any non-essential cookies that processor sets
  • Understanding which construction standards our public wiki fails to answer, from search-and-click records that carry no identifier and are deleted after 90 days (see Section 1.2)
  • Maintaining durable records of project distribution events (share-link creation, acceptance, forwarding, access removal, and deletion of a distributed project), including where the recipient is not a SynC user, as reasonably necessary for the establishment, exercise, or defense of legal claims arising from the distribution of project content (see Sections 5.1 and 5.2)
  • Building and maintaining the search index, including converting content into numeric vectors when it is created or changed rather than only when a search is run, so that content is searchable by meaning as well as by keyword (see Section 4.1A)
  • Maintaining the citation index and displaying the aggregate citation counts described in Section 4.5, so that the maintainers and readers of a cited standard can see that citations of it exist — disclosed, where the viewer cannot read the citing documents, only as a bare count of citation occurrences (see Sections 4.5 and 5.1)
  • Measuring whether the email we send is delivered and acted on, through the delivery reporting and link tracking applied by our email-delivery processor to the messages it sends for us (see Sections 1.2 and 4.1)
  • Generating a short title for each stored conversation so that a list of conversations is navigable, and enforcing the limits described in Section 5.1 on how many conversations we store for you and how long each may run, so that the volume of conversation content we hold stays bounded

Consent:

  • Marketing communications to prospects (you may withdraw consent)
  • Non-essential cookies and tracking, including the product-analytics processor's cookies and session-replay recordings (you may manage preferences)

Legal Obligation:

  • Compliance with applicable laws and regulations
  • Responding to legal requests

You have the right to object to processing based on legitimate interests. See Section 8 for more information about your rights.

4. How We Share Your Information

We do not sell your personal information to third parties. We share your information only in the following limited circumstances:

4.1 Service Providers and Processors

We engage trusted third-party service providers to perform functions on our behalf, including:

Our processors change over time. The processors described in this Section are those we use as of the Effective Date of this Policy. We may add, replace, or discontinue processors from time to time; where we do, the categories of data, purposes, and safeguards described in this Section continue to apply to any processor performing the same function. The processors described here reflect our current arrangements and are not an exhaustive or permanent list. A current list of our third-party subprocessors is published at synergyinconstruction.com/legal/subprocessors and is also available on request at privacy@synergyinconstruction.com, and we will update this Policy in accordance with Section 13 when changes are material.

Infrastructure and Hosting:

  • Cloud hosting and compute providers
  • Content delivery networks (CDNs) and DNS providers
  • Object storage, data storage, and backup services

AI and Machine Learning:

  • Inference providers, and inference routers which may select a downstream inference host per request from a set we control (see Section 4.1A)
  • Text-embedding providers, which power semantic search (see Section 4.1A)

Business Operations:

  • Payment processors, where and when payment functionality is enabled
  • Transactional email delivery services (see Email Delivery below for our current email processor)
  • Customer support platforms
  • Analytics services (see Web Analytics, Product Analytics, and Error Monitoring below for our current analytics and observability processors)
  • Authentication providers, where you choose to sign in through a third party

Web Analytics — our current web-analytics processor (Cloudflare Web Analytics):

  • Processor: Cloudflare, Inc., based in the United States, with global processing infrastructure
  • Purpose: Aggregate, privacy-respecting measurement of site traffic and performance for our public website and wiki (e.g., page views, referrers, country-level visitor distribution, page load timing)
  • Categories of data received: URL of the page visited, referring URL, anonymized browser and operating system family, country (no precise geolocation), and basic connection performance metrics
  • What is NOT received: Cloudflare states that Web Analytics is cookieless — that it does not set cookies, does not assign visitor identifiers, and does not perform cross-site tracking. On that basis, no persistent identifier is created in your browser by this processor.
  • Where deployed: The analytics beacon is loaded only on the production hostname (synergyinconstruction.com). It is not loaded in local development or on staging environments.
  • Consent banner: Because the beacon is cookieless and does not create or read any persistent identifier on your device, it does not require consent under the ePrivacy Directive's cookie rule. No consent banner is required for this processor.
  • Cloudflare privacy commitments: https://www.cloudflare.com/web-analytics-privacy/

Product Analytics — our current product-analytics processor (PostHog):

  • Processor: PostHog, Inc., based in the United States. SynC uses PostHog's US-region cloud instance (app.posthog.com), so product-analytics event data and session recordings are transferred to and processed in the United States.
  • Purpose: Measure how visitors and signed-in users move through the application — page views, feature interactions, conversion funnels (e.g., from a wiki standard page to a created project), and qualitative diagnosis of drop-off via session replay
  • Categories of data received:
    • Event data: Event names (e.g., wiki.cta.shown, wiki.cta.clicked, project.created, datasheet.revision_saved), URLs of pages visited, referring URLs, browser and operating system family, screen size, country-level geolocation derived from IP address, and a per-browser distinct identifier
    • Identification: Once you sign in or create an account, we associate your distinct identifier with your user ID and email address via PostHog's identify mechanism so that pre-signup and post-signup activity can be analyzed as a single journey
    • Session replay: PostHog records DOM-level interactions on the application (mouse movement, clicks, navigation, scroll, and the rendered page structure) so that we can diagnose user-experience issues and conversion drop-off
  • What is NOT received / how sensitive data is protected:
    • Input masking: Session replay is configured to mask user-typed text by default. Password fields are always masked. Form inputs, text areas, and other typed content are masked unless explicitly marked as safe to record. As a result, the content you type into specifications, datasheets, AI chat, or other input fields is not captured in session recordings.
    • DOM redaction: Elements containing sensitive content can be excluded from recording via the ph-no-capture CSS class. We use this mechanism to suppress capture of high-sensitivity surfaces.
    • No payment data: Payment card details are entered into our payment processor's hosted fields and are not present in the DOM available to PostHog.
  • Where processed: United States (PostHog US cloud at app.posthog.com)
  • Cookies set: PostHog sets first-party cookies (including ph_<project>_posthog) on your browser to maintain the distinct identifier across sessions. These are non-essential cookies and are subject to your consent where required (see Section 10).
  • Session replay opt-out / right to object: You may object to session replay or to product-analytics processing at any time by contacting privacy@synergyinconstruction.com (see Section 8).
  • PostHog privacy policy: https://posthog.com/privacy
  • PostHog Data Processing Addendum: https://posthog.com/dpa

Error Monitoring — our current error-monitoring processor (Sentry):

  • Processor: Functional Software, Inc. d/b/a Sentry, based in the United States. SynC uses Sentry's US-region ingestion endpoint, so error data is transferred to and processed in the United States.
  • Purpose: Detect, diagnose, and remediate frontend (JavaScript) and backend (server) errors and service-impacting incidents
  • Categories of data received: Error message and stack trace, the URL and HTTP method of the request that triggered the error, browser and operating system information, and a breadcrumb trail of recent user actions in the application leading up to the error
  • What is NOT received:
    • We configure Sentry with sendDefaultPii: false, so Sentry does not receive your IP address or your browser cookies by default
    • Sensitive HTTP headers are automatically scrubbed before transmission, including Authorization, Cookie, and Set-Cookie
    • Request and response body fields with sensitive names — including password, secret, token, api_key, access_token, and refresh_token — are automatically scrubbed before transmission
    • Routine 4xx client errors (e.g., validation failures, "not found," "unauthorized") are filtered server-side before transmission and are not sent to Sentry; only 5xx server errors and uncaught exceptions are reported
  • Where processed: United States (US-region ingest at ingest.us.sentry.io)
  • Sentry privacy policy: https://sentry.io/privacy/
  • Sentry Data Processing Addendum: https://sentry.io/legal/dpa/

Email Delivery — our current transactional-email processor (Amazon SES):

  • Processor: Amazon Web Services, Inc., based in the United States. SynC sends email through Amazon Simple Email Service ("Amazon SES") in a US region, so the messages we send you and the delivery and interaction data described below are processed in the United States.
  • Purpose: Deliver the email the Services send — account verification, invitations, share-link notices, notifications, and required legal notices — and see whether that mail is delivered, bounces, is reported as spam, or is acted on
  • Categories of data received: Your email address and the content of the message we are sending you; the delivery outcome of that message (delivered, bounced, or complained-of); and the email interaction data described in Section 1.2 — that a link in a message was followed and which link it was, together with the IP address, date and time, and client information accompanying that request. Where open tracking is enabled on our account, that a message was opened, with the same accompanying details
  • Link rewriting, and what you will see: Links in the email we send are rewritten so that they resolve through this processor's tracking domain, awstrack.me, which records the click and then redirects you to the destination on our site. The address shown when you hover over a link in our email is therefore an awstrack.me address rather than a synergyinconstruction.com one. We state this plainly because it is visible to you and an unfamiliar address in an email is a reasonable thing to want explained.
  • What is NOT received: Nothing you enter into the Services is transmitted to this processor other than the content of the message being sent to you. Your specifications, datasheets, project content, and conversations with the AI assistant are not sent to it, except to the extent a notification we send you quotes the item it is notifying you about. Email interaction data is not written to your SynC account or to our application database.
  • Where processed: United States
  • Tracking is configured at the processor, not in the Services. Link rewriting and open tracking are settings on our email-delivery account rather than features built into the application, so they apply to mail we send regardless of which part of the Services generated it. Section 8.1 states what this means for objecting to them.
  • AWS privacy notice: https://aws.amazon.com/privacy/
  • AWS GDPR Center (including the AWS Data Processing Addendum): https://aws.amazon.com/compliance/gdpr-center/

Search telemetry is first-party. The wiki-search records described in Section 1.2 are stored in our own database and are not disclosed to any of the processors named above, nor to any other third party.

These service providers have access to personal information only to perform services on our behalf, under contractual terms that limit their use of it to providing the service to us. For the downstream AI inference and embedding hosts, the controls we apply are described in Section 4.1A.

4.1A AI Inference and Embedding — What Leaves Our Servers

Two features transmit content to a third party.

AI assistant (inference). Your prompt and the project or standards content relevant to your request are transmitted to an inference provider. The assistant operates under your own permissions and can read only what your account is entitled to read.

Continuing a stored conversation transmits that conversation to an inference provider again, because the provider holds no memory of it between requests. What is transmitted is the stored form described in Section 1.1 — the prose of the exchange, with machine payloads already reduced. Generating a conversation's title is a separate, small request over that same content. Opening the assistant to read a conversation you already had transmits nothing: displaying stored history is a read from our own database, not a request to a provider.

Semantic search (text embedding). To make content searchable by meaning rather than only by keyword, text is converted into numeric vectors by a third-party embedding service. The vectors are stored in our database. Our configuration excludes embedding endpoints that retain submitted text for their own purposes or use it for training; the current hosts, and the specific controls applied to them, are published on the subprocessor list. This covers public SynC Standards content and your own standards and project specifications, so search works the same way over private content. Search queries you type are embedded the same way.

How we constrain the processing. For each request, our configuration is designed to:

  • prohibit logging and training at the provider, by excluding endpoints that log or train on submitted content from serving the request;
  • restrict processing to a set of hosts we have vetted, and disable automatic failover, so that an outage produces a failed request rather than a silent reroute to a host we have not vetted;
  • fail closed — if no host satisfies our constraints the request fails, search falls back to keyword matching, and AI features return an error, rather than the constraint being relaxed to complete the request.

These are the categories of control we apply. The specific mechanisms, and the hosts they apply to, are published on the subprocessor list and may change; Terms of Service §5.3.3 states what we will do if a change materially reduces the level of protection. Where an engagement requires zero-data-retention processing or a restricted set of processing jurisdictions, contact privacy@synergyinconstruction.com.

What a request carries. A request carries only the content in scope for that request — never your credentials or your payment details, and never your whole account. Where you are working in a project shared with you, the request carries that project's content, which you are authorized to read.

Retention on our side. Embedding vectors, and a cache of query vectors, are stored in our own database under the "Derived Search Data" retention rules in Section 5.1. Vectors are derived data: deleting the underlying content removes it from the search index. Stored conversations are retained under the "AI Assistant Conversations" rules in the same Section.

4.2 Collaboration and Sharing Features

When you use collaboration features, we share information with:

  • Team members and colleagues you invite to projects
  • Companies and organizations you collaborate with
  • Users you grant access to specific documents or projects through share links

You control what information is shared through your permission settings and project configurations.

Your conversations with the AI assistant are not part of this. They are not shared with anyone through the collaboration features, and they are not affected by your permission settings or project configuration. Section 4.2A states the rule that applies to them instead.

4.2A Conversations with the AI Assistant Are Private to You

A conversation is private to the person who had it, and stays that way. The Services provide no means by which anyone other than you can view one of your conversations: there is no sharing control, no copy of it visible to your team, your company, a project owner, or another participant in a project you both work on, and no administrative view of your conversations inside the product. Conversation content is never included in a published document, in a revision record, or in any export of project content. We do not intend to add a sharing surface for conversations; if that ever changed, it would be a material change to this Policy and Sections 13.1–13.3 would apply.

This is a statement about what the Services do, not a claim that the stored records are beyond our reach. Like every other category of information described in this Policy, stored conversations sit in our database, and our personnel may access them where it is necessary to operate, secure, or repair the Services, to answer your own request under Section 8, or in the circumstances described in Section 4.7. Access of that kind is limited on a need-to-know basis under Section 6.1.

Your own past conversations are retained as your record. A conversation is kept for you, and keeping it does not depend on your still having access to the material it discusses. If your access to a project or a document ends — because a share link was removed, because your role changed, because you left a company, or because the content itself was deleted — the conversations you had before that remain in your account until they are deleted under Section 5.1 or you delete them yourself.

We do not tell you that a stored conversation contains no project content, because that would not be true. Reducing machine payloads (Section 1.1) removes the raw data an action returned; it does not remove the assistant's prose, and prose written about a specification necessarily restates parts of it. What this Policy gives you instead is specific and checkable: a bounded retention period, a record that is visible to no other user of the Services, and the ability to delete any conversation yourself at any time, immediately (Sections 5.1 and 8.1).

4.3 Company Profile Visibility

When your company creates a profile on the Services, the following information is visible to other authenticated users through the company search and discovery features:

  • Company name
  • Company type(s)
  • Company description
  • City, state, and country (no street address is disclosed)
  • Website URL

This visibility enables essential platform functionality, including allowing users to join their company, discover collaborators, and invite companies to bid on or participate in projects. Individual user information (names, emails, phone numbers) is not exposed through company search.

4.4 SynC Standards Attribution

When you contribute to SynC Standards, your contributor attribution — which may include your display name, account identifier, and the name of your affiliated organization at the time of contribution — is displayed on adopted revisions in accordance with the CC-BY-SA 4.0 license attribution requirements. The treatment of contributor attribution is governed by our separate Contributor License Agreement ("CLA"), Section 2A.

If you delete your account, your public-facing contributor attribution is removed from the SynC Standards Wiki and from any project that has imported your contribution by reference, so that a member of the public can no longer identify you as the contributor (CLA §2A.3). Your contribution itself remains in the public repository under CC-BY-SA 4.0 (see Section 5.1). Separately, SynC retains a limited, non-public, access-restricted record linking each contribution to the contributor who made it, kept only as reasonably necessary to establish, exercise, or defend legal claims and to maintain the integrity of the attribution and licensing chain required by CC-BY-SA 4.0 (CLA §2A.4). Because that retained record makes it possible, in principle, to re-associate an otherwise public-anonymized contribution with you, the overall treatment of your contributor-attribution data is pseudonymization rather than anonymization for the purposes of data-protection law. The retained record remains personal data, and this Privacy Policy and applicable data-protection law continue to apply to it.

4.5 Aggregated Statistics

We may share aggregated statistics about how the Services are used — of the kind described in Terms of Service §5.3.2 — with research partners and academic institutions, industry organizations and standards bodies, business partners, and the public, including in industry reports and benchmarks.

We do not share your content, or any adaptation or excerpt of it, with those recipients, whether or not identifying details have been removed. De-identifying content does not make it shareable. See Terms of Service §5.3.1.

Citation counts shown inside the Services. Separate from the third-party sharing above, the Services display one aggregate statistic to other users. When you publish a document on the main site — a standard in your company, project, or personal library — each citation it makes to a SynC Standard is recorded in a citation index at the moment of publication (Section 5.1 states the retention rule). On a SynC Standard's page, and through the corresponding API, the Services may show how many citations point at that standard or at a clause of it, including citations made in documents the viewer has no right to read. Where the viewer cannot read the citing documents, the disclosure is a single number of citation occurrences and nothing else: no titles, no authors, no organizations, and no other detail of the response varies with those documents. The number counts occurrences rather than documents, so it does not reveal whether one document cites a standard nine times or nine documents cite it once. A citing document is named, linked, or excerpted only to viewers who are already authorized to read that document. Because SynC Standards pages are public, the number itself is public: an observer who watches it change over time can infer that some published document citing the standard was published, revised, or deleted, but not whose document, which document, or what it says. Drafts and unpublished content are never counted.

4.6 Business Transfers

If SynC is involved in a merger, acquisition, asset sale, bankruptcy, or other business transaction, your information may be transferred as part of that transaction. We will notify you via email and/or prominent notice on our Services before your personal information is transferred and becomes subject to a different privacy policy.

4.7 Legal Requirements and Protection

We may disclose your information if required to do so by law or in good faith belief that such action is necessary to:

  • Comply with legal obligations, court orders, or subpoenas
  • Protect and defend the rights or property of SynC
  • Prevent or investigate possible wrongdoing in connection with the Services
  • Protect the personal safety of users or the public
  • Protect against legal liability

4.8 With Your Consent

We may share your information for other purposes with your explicit consent or at your direction.

5. Data Retention

5.1 Retention Periods

We retain your information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.

Account Information:

  • Retained for the duration of your active account
  • Retained for up to 90 days after account deletion for backup and recovery purposes
  • Certain information may be retained longer to comply with legal obligations

User Content and Project Data:

  • Retained for the duration of your active account
  • Retained for up to 30 days after account deletion to allow for data export
  • May be retained in backup systems for up to 90 days after deletion

SynC Standards Contributions:

  • Contributions licensed under CC-BY-SA 4.0 are retained as part of the public standards repository even after account deletion, as they are licensed to the public
  • Following account deletion, your public-facing contributor attribution is removed (pseudonymized as described in Section 4.4); SynC retains a limited, non-public, access-restricted record linking each contribution to you only as reasonably necessary for legal-claims and licensing-integrity purposes (CLA §2A.4). The retention rule for that linking record is stated below under Contributor Attribution Records

Two categories of records below carry retention rules of different kinds, and the difference is deliberate. A record of a distribution event documents that something happened on a date; its evidentiary value runs out with the limitation periods for claims about that event, so it carries a time period. A record of contribution provenance answers who authored content that is still published; its justification does not decay with time but ends when the content is no longer public, so it carries a condition tied to the content's lifecycle, with a fixed tail.

Project Distribution and Access Records:

Records of project distribution events — the creation of a share link, a recipient's acceptance, forwarding of access, the removal of a recipient's access, and the deletion of a distributed project (Section 1.2) — are durable evidence, for every party to a distribution, of what project content was shared, with whom, and when. They are the platform's equivalent of the construction industry's transmittal record.

  • Each record is retained for up to fifteen (15) years from the date of the event it documents. The period runs separately for each record and is not extended, restarted, or shortened by later activity in the same project.
  • These records are not deleted when a project is deleted or when an account is closed. They are maintained append-only precisely so that no party to a distribution — including the project owner — can later alter or erase the evidence of what was distributed. Deleting a distributed project removes it from the owner's workspace and ends recipients' access; the distribution records survive the deletion.
  • At the end of the retention period, we redact the personal identifiers from the record rather than delete the record: the fact that a distribution event occurred is retained, and the identity of the persons involved in it is removed. Under this Policy's Effective Date, the earliest records reach the end of their retention period in 2041.
  • This retention period is SynC's chosen policy, not a statutory retention requirement imposed on SynC. It is calibrated to the statutes of repose for construction-defect claims in U.S. jurisdictions — which run as long as roughly fifteen years, and in some states without limit — so that the record remains available for the period in which a dispute about a distributed specification could plausibly arise. Record-retention obligations imposed by licensing boards on design professionals are obligations of those professionals, not of SynC; these records can help our customers meet them, but that is not their legal basis.

These records frequently include the personal information of a person who is not a SynC customer — a share-link recipient need have no other relationship with SynC. Section 5.2 describes how deletion requests interact with these records.

Contributor Attribution Records:

The limited, non-public record linking each SynC Standards contribution to its contributor (Section 4.4, CLA §2A.4) is retained under a condition tied to the contribution's public availability, not a fixed period:

  • The linking record for a contribution is retained for as long as that contribution remains available in the public SynC Standards corpus, plus six (6) years thereafter.
  • A contribution remains available in the public corpus while any adopted revision containing it remains publicly accessible through the Services — including in public revision history and in superseded or retired standards, which remain publicly accessible as historical records. Because adopted revisions are permanent public records (Terms of Service §5A.6.1), a contribution leaves the public corpus only if every publicly accessible revision containing it is revoked or otherwise permanently removed from public availability (Terms of Service §5A.6.3), or if the public corpus itself is discontinued. In practice, therefore, this record is retained for as long as the contribution remains published.
  • While the contribution is public, this record is what enables SynC to maintain the attribution and licensing chain that CC-BY-SA 4.0 requires and to establish, exercise, or defend legal claims relating to the contribution. A fixed retention period would be wrong in both directions: destroying the record while the contribution is still published would destroy SynC's ability to honor the license it granted the public, and holding it long after the content is gone would retain personal data without a purpose.
  • The six-year tail after a contribution leaves the corpus is calibrated to the limitation periods of the claims the record exists to defend — contract claims arising under the Contributor License Agreement and copyright claims relating to the contribution.

Derived Search Data (Section 4.1A):

  • Embedding vectors for indexed content are retained for as long as the content they derive from. They are derived data: deleting the content removes it from the search index, and no separate deletion request is needed for the vectors.
  • Query-vector cache. We keep a cache of search queries and the vectors computed for them, so that a repeated query does not require another call to the embedding provider. The cache is shared across all users and keyed by the text of the query itself. It carries no account identifier and no link to the person who ran the search. Entries are evicted on a least-recently-used basis rather than after a fixed period. Because an entry holds no identifier of any kind, it cannot be located by, or associated with, you — including in response to an access or deletion request.
  • Query text recorded as search telemetry is retained under the Search Telemetry rule below.

Derived Citation Data (Section 4.5):

  • The citation index is derived data, rebuilt from published content. Publishing a document replaces its index entries in full, so the entries describe only the current published revision; deleting a document removes its entries at the moment of deletion. No separate deletion request is needed for them.
  • An index entry records the citation as authored — the citation marker's text, its position in the document, and the SynC Standard and clause it points to — together with which document it appears in. It carries no account identifier; who owns the citing document is determined from the document itself, under the same access rules that protect the document.
  • Deprecating a published document without deleting it does not remove its entries: a deprecated document still cites what it cites, and the maintainers of the cited standard remain entitled to the count.
  • Drafts and unpublished working copies are never indexed.

AI Assistant Conversations (Sections 1.1, 4.1A and 4.2A):

A conversation with the AI assistant is retained for 180 days from its last activity — not from when it was created. Sending or receiving a message in a conversation is activity, and it restarts the 180 days. A conversation you keep using is therefore never deleted while you are using it, and a conversation you stop using is deleted 180 days after the last message in it. Deletion at the end of that period is automatic.

  • This period is measured from last activity because a working conversation must not expire underneath you. Continuing a conversation is the way to keep it; copying it out (Section 8.1) is the way to keep it permanently. We do not offer, and do not intend to offer, an action whose only effect is to exempt a conversation from this period — a retention period a user can switch off is not a retention period.
  • We do not warn you before a conversation expires. There is no notice, no email, and no expiry countdown shown against individual conversations. This Policy is the disclosure; the Services may additionally state the period where your conversations are listed.
  • You may delete any of your conversations at any time, and deletion is immediate and final. There is no trash, no holding state, and no recovery period: a conversation you delete is gone from the Services at once and cannot be restored to you. As with other User Content, a copy may persist in backup systems for up to 90 days.
  • We limit how many conversations we store for you, and how long a single conversation may run. These are backstops against runaway storage rather than everyday behaviour, and they carry no interface. When you are at the limit and start a new conversation, the conversation you have gone longest without using is deleted to make room for it. The current limits are available on request at privacy@synergyinconstruction.com.

This period is separate from, and runs independently of, the periods stated above for account deletion. The two must not be read together:

  • Deleting your account does not immediately delete your conversations. They are retained through the period in which your account can still be restored, precisely so that restoring your account restores them intact.
  • Conversations are deleted when your account is permanently deleted, whether or not their 180 days have run.
  • While your account exists, the 180-day rule is the only rule that ends a conversation, other than your own deletion of it.

Usage and Analytics Data:

  • Typically retained for 24-36 months for trend analysis
  • May be retained indefinitely in aggregated form that does not identify you
  • Cloudflare Web Analytics data is retained by Cloudflare under their published retention policies; because Cloudflare states that no visitor identifier is created, we have no means of re-associating this data with you

Search Telemetry (Section 1.2):

  • Search-and-click records are deleted 90 days after collection by an automated daily job. This applies to signed-in searches and to anonymous public-wiki searches alike
  • Because a click is recorded on the search record itself rather than separately, deleting the record removes the query and the click together
  • Anonymous search records carry no identifier of any kind, so they cannot be located by, or associated with, you or your device — including in response to an access or deletion request

Product Analytics Data (PostHog):

  • Event data is retained by PostHog under the retention policy applicable to our PostHog plan (typically 7 years for events, configurable down to 30 days)
  • PostHog's retention schedule for session recordings is shorter — typically 30 days under the default for our plan, after which PostHog states that recordings are deleted
  • Upon a verified deletion request (see Section 8), we will delete or anonymize identified product-analytics data associated with your user ID via PostHog's delete-person API

Email Interaction Data (Sections 1.2 and 4.1):

  • Delivery and interaction records for the email we send are held by our email-delivery processor and are not stored in our own database, so there is no copy of them in your SynC account for this Section to reach
  • We are not able to state a retention period for them, and we will not invent one. How long that processor keeps this data is determined by its own service configuration and published terms rather than by a setting we maintain, and we do not currently hold a documented figure for it. We will state the period here once we have established it, under Section 13
  • Because these records sit with the processor rather than with us, a request about them is handled as described in Sections 8.1 and 8.4 rather than by deleting a row in our database

Error Monitoring Data:

  • Error events transmitted to Sentry are retained according to Sentry's standard retention for our plan and are used solely to diagnose and remediate errors
  • Scrubbed and filtered as described in Section 4.1 prior to transmission

Legal and Compliance Data:

  • Retained as required by applicable law (typically 3-7 years for financial records)
  • Retained as necessary to resolve disputes or enforce agreements

5.2 Deletion Requests

You may request deletion of your personal information at any time (see Section 8). Upon deletion:

  • We will delete or anonymize your personal information within 30 days
  • Backups may retain data for up to 90 days
  • We may retain certain information as required by law or for legitimate business purposes
  • Anonymous wiki-search records cannot be removed on request because they carry no identifier linking them to you; they are deleted for everyone at 90 days (see Section 5.1)
  • Entries in the query-vector cache (Section 5.1) likewise carry no identifier linking them to you and cannot be singled out on request; they are evicted on a least-recently-used basis
  • Your conversations with the AI assistant are deleted when your account is permanently deleted. They are not exempt from a deletion request and are not retained past it. They are, however, deliberately not deleted at the moment you ask to close your account: they are kept through the period in which the account can still be restored, so that restoring it recovers them, and are then deleted with the account. You do not have to wait for that — you can delete any conversation yourself at any time, immediately (Section 5.1)
  • SynC Standards contributions licensed under CC-BY-SA 4.0 remain part of the public repository; following account deletion your public-facing attribution is removed (pseudonymized) as described in Section 4.4, while a limited, non-public linking record is retained for legal-claims and licensing-integrity purposes (CLA §2A.4), for the period stated in Section 5.1 (Contributor Attribution Records)
  • Project distribution and access records are retained on their own schedule notwithstanding a deletion request. These records (Section 5.1) are kept as reasonably necessary to establish, exercise, or defend legal claims arising from the distribution of project content. On that basis they are exempt from deletion on request — under GDPR Article 17(3)(e) and CCPA §1798.105(d)(1) where those laws apply, and on the same reasoning where they do not — for the fifteen-year period stated in Section 5.1 and no longer, after which the personal identifiers in them are redacted. This exemption is limited to the distribution records themselves: it does not extend to any other category of personal information we hold about you, and a deletion request remains fully effective as to everything else within the 30-day commitment above. If you are a share-link recipient with no other relationship to SynC, these records are the only category of your personal information to which this exemption applies.

6. Data Security

6.1 Security Measures

We implement technical and organizational measures appropriate to the size and nature of our operations to protect your information, including:

Technical Safeguards:

  • Encryption in transit (TLS 1.2+) for all traffic between your browser and the Services
  • Passwords hashed using bcrypt; credentials are never stored or logged in plain text
  • Automated daily database backups with tiered retention
  • Secure API authentication and rate limiting
  • Access to production systems restricted to authorized personnel and protected by key-based authentication

Organizational Safeguards:

  • Access to personal information limited on a need-to-know basis
  • Data processing agreements with the third-party processors we engage directly; for the downstream AI inference and embedding hosts, the controls described in Section 4.1A
  • Incident response procedures, including the breach notification practices described in Section 6.3

6.2 Limitations

While we take reasonable measures to protect your information, no security system is impenetrable. We cannot guarantee absolute security of data transmitted over the internet or stored on our systems. You are responsible for:

  • Maintaining the confidentiality of your account credentials
  • Using strong, unique passwords
  • Enabling two-factor authentication (if available)
  • Reporting any suspected security incidents

6.3 Security Incidents

In the event of a data breach affecting your personal information, we will notify you and the relevant authorities without undue delay, within the timeframes required by applicable law.

7. International Data Transfers

7.1 Cross-Border Transfers

SynC is based in the United States. If you access the Services from outside the United States, your information will be transferred to, stored, and processed in the United States and other countries where our service providers operate.

These countries may have data protection laws that differ from those in your country of residence.

Specifically, the third-party processors disclosed in Section 4.1 as of the Effective Date include:

  • Cloudflare, Inc. (Web Analytics) — global processing infrastructure with US headquarters
  • PostHog, Inc. (Product Analytics) — US-region cloud (app.posthog.com) with US headquarters
  • Functional Software, Inc. d/b/a Sentry (Error Monitoring) — US-region ingestion endpoint
  • Amazon Web Services, Inc. (Email Delivery, Amazon SES) — US region

As described in Section 4.1, this list reflects our current processors and is not exhaustive or permanent; a current subprocessor list is published at synergyinconstruction.com/legal/subprocessors and is available on request.

Inference and text-embedding requests are restricted to processing hosts we have vetted, with automatic failover disabled, so that hosts outside that set are excluded by configuration rather than by preference. The jurisdictions in which those hosts process content are published on our subprocessor list.

7.2 GDPR Protections

Where we transfer the personal data of users in the EEA, UK, or Switzerland, we rely on appropriate safeguards for international data transfers, which may include:

  • Standard Contractual Clauses (SCCs) approved by the European Commission, where required
  • Adequacy decisions where applicable
  • Additional technical and organizational measures to ensure data protection

7.3 Data Processing Addendum

Business customers may request a Data Processing Addendum (DPA) to formalize our data protection commitments. Contact privacy@synergyinconstruction.com to request a DPA.

8. Your Privacy Rights

Depending on your location, you may have certain rights regarding your personal information:

8.1 Rights for All Users

Access and Portability:

  • Request a copy of the personal information we hold about you
  • Receive your data in a structured, machine-readable format

Correction:

  • Update or correct inaccurate or incomplete personal information
  • You can update most information directly in your account settings

Deletion:

  • Request deletion of your personal information (subject to certain exceptions)
  • Note: SynC Standards contributions licensed under CC-BY-SA 4.0 remain in the public repository; your public-facing attribution is removed (pseudonymized) on account deletion as described in Section 4.4
  • Note: Anonymous wiki-search records (Section 1.2) and query-vector cache entries (Section 5.1) hold no identifier, so we have no way to find the ones that came from you; search records are deleted for everyone at 90 days, and cache entries are evicted on a least-recently-used basis
  • Note: Records of project distribution events are retained for the period stated in Section 5.1 and are exempt from deletion during that period as described in Section 5.2, because they are kept to establish, exercise, or defend legal claims arising from distributed project content

Your Conversations with the AI Assistant:

  • List and revisit. You can see your own conversations, most recently used first, and reopen any of them
  • Rename. Titles are generated automatically (Section 2.2); you can replace one with your own
  • Copy. You can copy a conversation out of the Services as readable text — the exchange and the plain-language record of what the assistant did, which is what you saw. This is the way to keep a conversation beyond the retention period in Section 5.1
  • Delete. You can delete any of your conversations at any time. Deletion takes effect immediately and is not staged: there is no trash and no recovery window, so a deleted conversation cannot be restored to you
  • Access. If you ask us for a copy of the personal information we hold about you, that includes your stored conversations
  • These controls are available to you whether or not your account currently has access to the AI assistant. If AI access ends, you keep the ability to read, copy, and delete the conversations you already have; you are simply unable to start or continue one

Opt-Out of Product Analytics and Session Replay:

  • Request that your activity not be captured by our product-analytics processor (PostHog), including session replay
  • Contact privacy@synergyinconstruction.com to opt out
  • You may also control non-essential cookies via your browser settings and the opt-out mechanisms described in Section 10

Objecting to Email Tracking:

  • You may object to the email tracking described in Section 1.2 by contacting privacy@synergyinconstruction.com, and you may object to it under Section 8.2 if you are in the EEA, the UK, or Switzerland
  • The Services provide no per-recipient setting that turns email tracking off, and we are not describing one here, because one does not exist. If you object, we will consider what we can do for the mail we send you and tell you the answer. We are not promising in advance that we can exclude your messages from it
  • Two things you can do without us, stated so that you can judge them for yourself. Link rewriting is applied to a message when it is sent, so the only way a click is not recorded is not to follow the link — you can instead reach the same place by signing in to the Services directly. Where open tracking is enabled, configuring your email program not to load remote images prevents the open from being recorded; that control is yours and does not depend on us
  • Note: most of the email SynC sends is transactional and cannot be unsubscribed from (Sections 12.2 and 12.3), so opting out of marketing communications does not end email tracking

A note on AI training. Earlier versions of this Policy offered a right to opt out of having your User Content used to train AI models. That right has been removed because the use it applied to is now prohibited outright: we do not use your content to train generative or foundation models, for ourselves or for anyone else, so there is nothing to opt out of. Terms of Service §5.3.1 states the full scope of that prohibition, the conditions under which we may build models that classify or score content without generating text, and its exceptions — which are the ones summarized in Section 2.2 (content you submit to the SynC Standards library, and feedback you direct to SynC), together with any separate written agreement you execute, which we will never require as a condition of providing the Services to you.

8.2 Additional Rights for EEA, UK, and Swiss Users (GDPR)

Right to Restriction:

  • Request restriction of processing in certain circumstances

Right to Object:

  • Object to processing based on legitimate interests
  • Object to direct marketing at any time

Right to Withdraw Consent:

  • Withdraw consent for processing based on consent (does not affect prior processing)

Right to Lodge a Complaint:

  • File a complaint with your local data protection authority

8.3 California Residents (CCPA/CPRA Rights)

California residents have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

Right to Know:

  • Request disclosure of categories and specific pieces of personal information collected
  • Request disclosure of categories of sources, purposes, and third parties with whom we share information

Right to Delete:

  • Request deletion of personal information (subject to exceptions)

Right to Opt-Out:

  • We do not sell personal information, but you may opt out of sharing for cross-context behavioral advertising

Right to Correct:

  • Request correction of inaccurate personal information

Right to Limit Use of Sensitive Personal Information:

  • Request limitation of use of sensitive personal information (if applicable)

Right to Non-Discrimination:

  • You will not receive discriminatory treatment for exercising your privacy rights

Authorized Agent:

  • You may designate an authorized agent to make requests on your behalf

8.4 How to Exercise Your Rights

SynC operates exclusively online and has a direct relationship with the users of the Services. Requests may be submitted by email, and signed-in users may also exercise most rights directly through account settings:

We will respond to verifiable requests within:

  • 30 days for most requests
  • 45 days for CCPA requests (with possible 45-day extension)
  • As required by applicable law

We may need to verify your identity before processing your request.

9. Children's Privacy

The Services are not intended for children under the age of 18, and we do not knowingly collect personal information from children under 18. If we become aware that we have collected personal information from a child under 18, we will take steps to delete such information promptly.

If you believe we have collected information from a child under 18, please contact us immediately at privacy@synergyinconstruction.com.

10. Cookies and Tracking Technologies

10.1 Types of Cookies We Use

Strictly Necessary Cookies:

  • Essential for the Services to function (e.g., session management, authentication)
  • Cannot be disabled without impairing functionality

Functional Cookies:

  • Remember your preferences and settings
  • Enhance user experience and personalization

Analytics Cookies:

  • Collect information about how you use the Services
  • Help us improve performance and user experience
  • Our product-analytics processor (PostHog) sets first-party cookies on your browser to maintain a distinct identifier across sessions and to enable session replay. These are non-essential cookies. See Section 4.1 for the full disclosure of what PostHog receives and how sensitive content is masked.

Note on Web Analytics: Our current public-site web analytics processor (Cloudflare Web Analytics) is cookieless and does not set, read, or rely on any cookie or other persistent identifier on your device. See Section 4.1 for details. This is distinct from our product-analytics processor (PostHog), which does set cookies; the two processors serve different purposes and are deployed on different surfaces.

Note on Wiki Search: The wiki-search records described in Section 1.2 do not involve a cookie or any other identifier stored on your device. Nothing is written to your browser to produce them. The same is true of the query-vector cache described in Section 5.1.

Note on Email Tracking: The tracking applied to the email we send you (Section 1.2) uses a rewritten link and, where enabled, an invisible image in the message. Neither is a browser cookie, neither is covered by the cookie controls in Section 10.2, and no cookie opt-out reaches them. They are carried inside the message, are applied by our email-delivery processor when it sends the message, and operate in your email program rather than on our site — so declining cookies here has no effect on them, and clearing cookies does not remove them. Section 4.1 states what our email-delivery processor receives; Section 8.1 states what you can do about it.

Marketing Cookies:

  • Track your activity across websites for targeted advertising
  • Only used with your consent (where required)

10.2 Cookie Management

You can control cookies through:

  • Browser Settings: Most browsers allow you to refuse cookies or delete existing cookies
  • Direct Opt-Out: You may opt out of non-essential cookies — including the product-analytics processor's cookies and session replay — at any time by contacting privacy@synergyinconstruction.com (see Section 8.1). Where applicable law requires a consent mechanism for non-essential cookies, we will provide one before such cookies are set.
  • Opt-Out Tools: Industry opt-out tools like Network Advertising Initiative or Digital Advertising Alliance

Note: Disabling certain cookies may limit functionality of the Services.

10.3 Do Not Track

Some browsers support "Do Not Track" (DNT) signals. Currently, there is no industry standard for how to respond to DNT signals. We do not currently respond to DNT signals.

11. Third-Party Links and Services

The Services may contain links to third-party websites, applications, or services that are not operated by SynC. This Privacy Policy does not apply to those third-party services.

We are not responsible for the privacy practices of third parties. We encourage you to review the privacy policies of any third-party services you access.

Third-Party AI and Embedding Services: When you use AI-assisted features or semantic search, the content in scope for your request is processed by third-party providers on our behalf, subject to the constraints described in Section 4.1A and the commitments in Terms of Service §5.3.3. Our current providers, the jurisdictions in which they process content, and links to their own privacy policies are published at synergyinconstruction.com/legal/subprocessors.

12. Marketing Communications

12.1 Types of Communications

With your consent (where required), we may send you:

  • Product updates and new feature announcements
  • Educational content and best practices
  • Industry news and insights
  • Special offers and promotions
  • Invitations to webinars and events

12.2 Opting Out

You may opt out of marketing communications at any time by:

Note: You cannot opt out of transactional emails (e.g., account notifications, password resets, billing statements) that are necessary for the Services.

12.3 Tracking Applies to All of Our Email, Not Only Marketing

The link rewriting and open tracking described in Section 1.2 are applied by our email-delivery processor to the messages it sends for us. They are not limited to marketing email, and unsubscribing from marketing does not remove them from anything else.

Most of the email SynC sends is transactional, not marketing — account verification, company and project invitations, share-link notices, notifications you have switched on, and required notices about your account or your legal agreements with us. Section 12.2 states that you cannot opt out of transactional email; it follows that opting out of marketing communications under Section 12.2 does not stop that mail and does not stop it being tracked.

Section 8.1 states what you can do about the tracking itself, including what we can and cannot offer.

13. Changes to This Privacy Policy

13.1 Updates

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors.

13.2 Notice of Material Changes

When we make material changes, we will notify you by:

  • Posting the updated Privacy Policy with a new Effective Date
  • Sending email notification to your registered email address
  • Displaying a prominent notice in the Services

13.3 Your Acceptance

Continued use of the Services after changes become effective constitutes your acceptance of the updated Privacy Policy. If you do not agree to the changes, you must discontinue use of the Services.

13.4 Review History

Previous versions of this Privacy Policy are available upon request by contacting privacy@synergyinconstruction.com.

13.5 Changes from Version 1.2

Version 1.3 (effective May 27, 2026) carries v1.2 forward in full and adds disclosures for one newly added third-party data processor:

  • PostHog (Product Analytics + Session Replay) — a product-analytics and session-replay processor used to measure feature usage, conversion funnels, and qualitative drop-off across the application. Added to Section 4.1 with full disclosure of categories of data received (event data, identified user association after login, and session recordings), processing location (United States, PostHog US cloud at app.posthog.com), session-replay input masking (typed text masked by default, password fields always masked, ph-no-capture DOM redaction), and the fact that PostHog sets first-party cookies on your browser.
  • Section 3 (Legal Basis) was updated to add product-analytics processing under Legitimate Interests (subject to consent for non-essential cookies) and to call out the product-analytics processor's cookies and session-replay recordings under Consent.
  • Section 5.1 (Data Retention) was updated to add retention notes for PostHog event data and session recordings, and to describe the deletion mechanism for identified product-analytics data.
  • Section 7.1 (Cross-Border Transfers) was updated to add PostHog as an additional US-based recipient of transferred data.
  • Section 8.1 (Rights for All Users) was updated to add an explicit opt-out for product analytics and session replay.
  • Section 10.1 (Cookies) was updated to disclose that PostHog sets first-party cookies (in contrast to the cookieless Cloudflare Web Analytics processor), and Section 10.2 was updated to note that you can decline non-essential cookies (including PostHog) where required by law.
  • Section 15.3 (CCPA categories disclosed) was updated to reflect that Internet activity is now disclosed to web-analytics, product-analytics, and error-monitoring providers.

No other substantive changes were made; all prior obligations, definitions, and user rights from v1.2 remain in effect.

13.6 Changes from Version 1.3

Version 1.4 (effective May 29, 2026) carries v1.3 forward in full and makes one clarifying change to how third-party processors are described. It does not add, remove, or change any processor, data category, processing purpose, safeguard, or user right.

  • Section 4.1 (Service Providers and Processors) now states expressly that the named processors are those used as of the Effective Date, that the list is not exhaustive or permanent, that the categories of data, purposes, and safeguards described continue to apply to any processor performing the same function if a processor is later added, replaced, or discontinued, and that a current subprocessor list is available on request. The three analytics/observability processor headings (Web Analytics, Product Analytics, Error Monitoring) were reworded to identify each named vendor as our current processor for that function rather than as the sole permanent provider.
  • Section 7.1 (Cross-Border Transfers) was conformed to describe the listed processors as those disclosed as of the Effective Date and to cross-reference the non-exhaustive framing in Section 4.1.

This change was made so that adding, replacing, or discontinuing a processor in the ordinary course — for the same function and within the same categories of data, purposes, and safeguards already disclosed — does not render this Policy inaccurate. A change of that kind is not, in itself, a material change; material changes (for example, a new category of data, a new processing purpose, or a new transfer destination) continue to be handled under Sections 13.1–13.3. No other substantive changes were made; all prior obligations, definitions, and user rights from v1.3 remain in effect.

13.7 Changes from Version 1.4

Version 1.5 (effective June 9, 2026) carries v1.4 forward in full and makes the corrections described below. It does not add or remove any processor, data category, or processing purpose, and it does not reduce any user right. Several descriptions of our practices were corrected to match what we actually do — in each case the correction makes the Policy more accurate, not the practice less protective.

  • Contributor-attribution treatment corrected and clarified as pseudonymization. Sections 4.4, 5.1, 5.2, and 8.1 were corrected to describe accurately what happens to your SynC Standards contributor attribution when you delete your account. The prior text stated that contributions remain in the public repository "with attribution." In fact, on account deletion your public-facing attribution is removed so that the public can no longer identify you (CLA §2A.3), while SynC retains a limited, non-public, access-restricted record linking each contribution to its contributor only as reasonably necessary for legal-claims and licensing-integrity purposes (CLA §2A.4). Because that retained record can in principle re-associate a contribution with you, the overall treatment of your contributor-attribution data is pseudonymization rather than anonymization for data-protection purposes. The contribution content itself continues to be retained under CC-BY-SA 4.0. This conforms the Privacy Policy to the Contributor License Agreement, Section 2A.
  • Entity-name correction. The data controller is now identified consistently as "Synergy In Construction, LLC, a Wyoming limited liability company" (preamble and Section 14.1), correcting the prior description "a Wyoming corporation" to match the legal entity named in the Contributor License Agreement and the Terms of Service.
  • Security-practices disclosure conformed to actual practice (Section 6.1). The list of technical and organizational safeguards was corrected to describe the measures we actually maintain (TLS 1.2+ in transit, bcrypt password hashing, automated daily backups with tiered retention, restricted key-based production access, need-to-know access, processor data processing agreements, and incident response procedures). Claims of practices not currently performed — regular third-party security audits and penetration testing, intrusion detection and prevention systems, formal employee training programs, and at-rest encryption — were removed so the Policy does not overstate our security posture.
  • Breach notification (Section 6.3). Reworded to commit to notification "without undue delay, within the timeframes required by applicable law," rather than "typically within 72 hours" — the 72-hour period under GDPR applies to notifying the supervisory authority, not affected users.
  • Cookie controls (Sections 8.1, 10.2). The reference to a "Cookie Preference Center available in your account settings" was removed because that control does not currently exist. The Policy now accurately describes the available controls: browser settings, a direct opt-out via privacy@synergyinconstruction.com, and a commitment to provide a consent mechanism before non-essential cookies are set where applicable law requires one.
  • Data-protection contact (Section 14.3). Retitled from "Data Protection Officer" to "GDPR and Data-Protection Inquiries" and clarified that SynC has not designated a formal DPO (one is not currently required); voluntarily claiming a DPO would trigger formal GDPR obligations that do not reflect our current operations.
  • DPIA statement (Section 15.4). Corrected from a claim that DPIAs "have been conducted" to a forward-looking commitment to conduct them where required by law before undertaking high-risk processing, noting that no such processing occurs as of the Effective Date.
  • AI-training current-practice statement (Section 2.2). States that as of the Effective Date we do not train AI models on User Content, and commits to obtaining opt-in consent where applicable law requires it before such use — aligning the Policy's consent legal basis (Section 3) with the opt-out mechanism and with Terms of Service §5.3.3.

No other substantive changes were made; all prior obligations, definitions, and user rights from v1.4 remain in effect.

13.8 Changes from Version 1.5

Version 1.6 (effective August 3, 2026) carries v1.5 forward in full and makes two changes: the entity's state of organization and contact block are updated for a redomestication, and a new disclosure is added for anonymous wiki-search telemetry. It does not remove any user right, and it does not add or remove any third-party processor.

  • The entity redomesticated from Wyoming to Florida. Synergy In Construction, LLC completed a statutory conversion from a Wyoming limited liability company to a Florida limited liability company, effective upon the entity becoming active in Florida on August 2, 2026. A statutory conversion changes the entity's state of organization; it does not create a new entity. The same legal entity continues, with the same Employer Identification Number, and remains the data controller for all personal information it held before the conversion. No personal information is transferred to, or disclosed to, any new or different entity as a result — the conversion is not a business transfer under Section 4.6, and Section 4.6's notice obligation is not triggered by it. The controller is accordingly now identified as "Synergy In Construction, LLC, a Florida limited liability company" (preamble and Section 14.1). This change does not affect any party's rights. Note that this Policy contains no governing-law or venue clause; the corresponding governing-law and venue changes were made in the Terms of Service (v1.5, §17).
  • The street address was removed; contact is by email (preamble, Sections 8.4 and 14.1). SynC no longer publishes a street address in this Policy. The controller's identity and contact details required by GDPR Article 13 are given in Section 14.1 as the entity's legal name, its form and state of organization, its country, and the privacy mailbox privacy@synergyinconstruction.com. Requests to exercise your rights are submitted to that same mailbox (Section 8.4), which is the address this Policy already designated for every privacy request, opt-out, subprocessor-list request, and DPA request. No method of contact available to you under v1.5 has been withdrawn other than postal mail, and no right is narrowed: every right in Section 8 is exercised exactly as it was before.
  • New disclosure: anonymous wiki-search telemetry (Sections 1.2, 2.3, 3, 4.1, 5.1, 5.2, 8.1, 10.1). This Policy now discloses that when you search the public SynC wiki without signing in, we record what you searched for and which result you opened, so that we can see which standards are missing or hard to find. These records include no IP address, device or browser identifier, and no link to any account; they are never used to build a profile of you, and they are deleted after 90 days. The disclosure is carried through to the legal basis (legitimate interests, Section 3), the purpose (Section 2.3), retention (Section 5.1), and cookies (Section 10.1 — nothing is stored on your device to produce these records). Section 4.1 states that this telemetry is first-party and is disclosed to no processor. This does not narrow any right, but it does record one limit on the deletion and access rights in Section 8.1: because an anonymous search record holds no identifier, we have no means of finding the records that came from any particular person, so we cannot single them out in response to a request; they are deleted for everyone at 90 days. Searches you run while signed in continue to be ordinary account activity associated with your account, and are covered by the same 90-day deletion.
  • Section 8.4 additionally notes that SynC operates exclusively online and has a direct relationship with users of the Services, which is the basis on which an email address serves as the designated method for submitting requests under the CCPA.

No other substantive changes were made; all prior obligations, definitions, and user rights from v1.5 remain in effect. The addition of a previously undisclosed collection practice is a material change, and notice is given under Sections 13.1–13.3 by posting this Policy with a new Effective Date, sending email notification to registered users, and displaying a prominent notice in the Services.

13.9 Changes from Version 1.6

Version 1.7 (effective August 7, 2026) carries v1.6 forward in full and accompanies Terms of Service v1.6, which replaced permanent "Vested Access" for share-link recipients with owner-revocable access. This version states retention rules for two categories of records this Policy already disclosed collecting but did not give retention periods. It does not add or remove any processor and does not change what is shared with any third party. Section 1.2's description of distribution records is extended to name two event types the platform now records — the removal of a recipient's access, and the deletion of a distributed project — which are first-party records in the same category this Policy already disclosed (share-link creation, acceptance, and access records).

  • Retention period stated for project distribution and access records (Sections 3, 5.1, 5.2, 8.1). Section 5.1 now states that records of project distribution events (Section 1.2) are retained for up to fifteen years from the event, per record; that they survive project deletion and account closure; and that at the end of the period the personal identifiers in them are redacted rather than the records deleted. Section 5.2 now states expressly that these records are exempt from deletion requests for that period — and no longer — because they are kept to establish, exercise, or defend legal claims arising from distributed project content, and that the exemption reaches no other category of personal information. Section 3 adds the corresponding legitimate-interests basis. Previously, these records had no stated retention period, and Section 5.2's 30-day deletion commitment was unqualified as to them; stating the rule and its limit resolves that tension in the text rather than leaving it to interpretation.
  • Retention rule stated for contributor-attribution records (Sections 5.1, 5.2). The non-public record linking a contribution to its contributor (Section 4.4) previously had a purpose limit but no stated retention rule. Section 5.1 now states it: the record is retained for as long as the contribution remains available in the public SynC Standards corpus, plus six years, with "remains available" defined by the permanence of adopted revisions. This is a condition tied to the content's lifecycle rather than a fixed period, and Section 5.1 now explains why the two categories of records carry rules of different kinds.
  • No automated deletion mechanism is claimed. The earliest distribution records reach the end of their retention period in 2041. This Policy states the retention rule; it does not describe an automated redaction mechanism, and none is asserted to exist.

The statement of a previously unstated retention period — including that certain records are retained after project deletion and account closure and are exempt from deletion requests for a defined period — is a material change, and notice is given under Sections 13.1–13.3 by posting this Policy with a new Effective Date, sending email notification to registered users, and displaying a prominent notice in the Services. No other substantive changes were made; all prior obligations, definitions, and user rights from v1.6 remain in effect.

13.10 Changes from Version 1.7

Version 1.8 carries v1.7 forward in full and accompanies Terms of Service v1.7, in which SynC withdrew its reserved right to use customer content as AI training or research material. This version does two things: it conforms this Policy to that withdrawal everywhere the reserved right appeared, and it closes a live disclosure gap by describing the AI-inference and text-embedding processing that this Policy did not previously describe accurately.

No user right is narrowed by this version except the AI-training opt-out, which is removed because the practice it opposed is now prohibited outright for everyone. Every other change either strengthens a commitment or corrects a description to match what we actually do.

What was disclosed inaccurately, and is now fixed. v1.7 §4.1 named our AI processors as "Grok by xAI, Google Gemini, OpenAI, Anthropic," and §11 repeated that list. In production the platform routes inference through an inference router, which was named nowhere in the Policy and which selects a downstream host per request — so the operative data policy is the selected host's, not the router's. Separately, semantic search converts content into numeric vectors through a third-party embedding service, which v1.7 did not disclose at all, and the index it builds covers customer content: company libraries, project specifications, and customized standards. The disclosure was therefore simultaneously over-inclusive (naming vendors not in use) and incomplete (omitting the two that are). New Section 4.1A describes both flows and the controls applied to them; the vendor instances now live on the published subprocessor list, where they can be kept current without a version bump.

  • Section 2.2 rewritten. The "AI Training and Model Improvement" block — which permitted using User Content to train models after removing identifiers, and permitted aggregating the result with other users' data — is deleted in full and does not survive in any form. The "Current Practice and Your Rights Regarding AI Training" block, which reserved the right to begin training and offered an opt-out, is also deleted. In their place, §2.2 states that we do not use User Content to train generative, general-purpose, or foundation models, whether or not it has been anonymized or aggregated, and defers to Terms of Service §5.3.1 for the scope of that commitment, its conditions, and its exceptions, which govern if the two ever differ. This is deliberate: two documents each defining "training" is how the two documents come to disagree. §2.2 also discloses that we may build models inside the Services that classify, score, or flag content, and states the three conditions §5.3.1 imposes on them — structured outputs rather than generated text, never distributed outside the Services, and no reproduction of your content to anyone not already authorized to see it. The prohibition is narrower than an earlier draft of this version, which barred any machine-learning model at all and would have foreclosed ordinary product features that cannot reproduce a specification. The commitment customers rely on — that specifications are not fed to language models — is unchanged. The "Third-Party AI Services" block is replaced with one covering both inference and embedding and pointing at the published subprocessor list.

  • New Section 4.1A (AI Inference and Embedding — What Leaves Our Servers). Describes what is transmitted for the AI assistant and for semantic search, states that embedding covers your own standards and project specifications and not only public content, and states the three categories of control applied to each request: logging and training prohibited at the provider, processing restricted to vetted hosts with automatic failover disabled, and fail-closed behaviour so that a constraint is never relaxed in order to complete a request. It states what a request carries — only the content in scope, never credentials or payment details — and where the resulting vectors are stored.

  • Section 4.1 processor categories corrected. The AI bullets naming four vendors are replaced with two functional categories (inference providers and routers; text-embedding providers). Several other illustrative vendor examples were removed because they named services not in use — email delivery, customer support, authentication, and additional cloud platforms are now described by function. The payment-processor entry is now expressly conditional, because no payment processor is integrated. The "processors change over time" paragraph now points to the published subprocessor list in addition to the on-request list.

  • Section 3 (Legal Basis) conformed. The Consent basis for "AI training using anonymized User Content" is deleted; there is no such processing. Two entries are added to describe the §4.1A processing: contract performance for transmitting content to answer a request you made or to run a search you asked for, and legitimate interests for building and maintaining the search index, because content is embedded when it is created or changed rather than only when a search is run.

  • Section 4.5 narrowed and retitled "Aggregated Statistics." v1.7 §4.5 permitted sharing "aggregated, anonymized, or de-identified data" with research partners, industry organizations, business partners, and the public. Read against the definition of anonymization then in force, that could be read to permit publishing de-identified customer specification text. §4.5 now permits sharing only aggregated statistics of the kind described in Terms of Service §5.3.2, and states expressly that we do not share your content, or any adaptation or excerpt of it, whether or not identifying details have been removed.

  • Section 5.1 retention conformed, and a gap filled. The "Anonymized Data" block — "retained indefinitely," "cannot be re-associated with you" — is deleted, because there is no such category. A new "Derived Search Data" block states retention for the two things semantic search actually creates: embedding vectors, retained for as long as the content they derive from and removed from the index when that content is deleted; and a query-vector cache, which is shared across all users, keyed by the text of the query, carries no account identifier and no link to the person who ran the search, and is evicted on a least-recently-used basis rather than after a fixed period. This also repairs a cross-reference: §4.1A points to Section 5 for a retention rule that Section 5 did not previously contain.

  • Sections 5.2 and 8.1 conformed. The statement "Anonymized data in AI models cannot be removed" is deleted from both, as is the Opt-Out of AI Training right in §8.1. §8.1 now carries a short note explaining why that right was removed rather than deleting it silently. Both Sections gain a note that query-vector cache entries, like anonymous search records, carry no identifier and therefore cannot be singled out in response to a request — a limit on the deletion right that arises from the absence of an identifier, not from a retention policy.

  • Section 7.1 (Cross-Border Transfers). States that inference and embedding requests are restricted to vetted hosts with automatic failover disabled, so that other hosts are excluded by configuration rather than by preference, and that the jurisdictions those hosts process in are published on the subprocessor list. The jurisdictions are deliberately not named in this Policy: the host set is a configuration value, and naming it here would make this Policy inaccurate on a deploy.

  • Section 11 conformed. The four-vendor AI list, which survived verbatim from v1.7 and had the same defects as the §4.1 list, is replaced with a pointer to the subprocessor list.

  • Section 15.3 corrected. v1.7 stated that commercial information had been "collected and disclosed" to payment processors in the preceding twelve months. No payment processor is integrated with the Services, so no such disclosure occurred. This was over-disclosure rather than under-disclosure, so the risk was low, but it is corrected here.

  • Accuracy corrections carried over from v1.7. Four descriptions were corrected to match what we can actually state. §2.3 listed "conduct research and development for new features" as a purpose applying to all collected information, including your specifications — which contradicted the new prohibition on using content as research material; it is now limited to usage data and structural statistics. §7.2 asserted that Standard Contractual Clauses are implemented for international transfers; it now states that we rely on appropriate safeguards, which may include SCCs where required. §4.1 and §5.1 stated a processor's conduct as fact ("deleted by PostHog," "cannot be re-associated with you"); these are now attributed to the processor, because we can contract and configure but cannot know. §1.1 described your password as "encrypted," which is not what happens — §6.1 correctly says hashed with bcrypt, and §1.1 now says hashed. None of these changes any practice; each removes a statement we could not stand behind.

  • Drafting annotations removed. The inline reviewer's notes carried in the v1.7 reference file were editorial annotations addressed to counsel, not disclosures, and were already excluded from the published v1.7 by the publishing migration's content guard. They are not carried into this version's text. No operative sentence they annotated is changed by their removal.

Notice of these changes. The withdrawal of the reserved AI-training right, the removal of the corresponding opt-out, and the disclosure of a previously undisclosed category of processing (text embedding) are material changes, and notice is given under Sections 13.1–13.3 by posting this Policy with a new Effective Date, sending email notification to registered users, and displaying a prominent notice in the Services. No other substantive change is made; all other obligations, definitions, and user rights from v1.7 remain in effect.

13.11 Changes from Version 1.8

Version 1.9 carries v1.8 forward in full. It accompanies the citation feature, under which a document published on the main site can cite a SynC Standard by clause, and it makes one substantive addition: it discloses the citation index that feature maintains and the aggregate citation counts the Services can display from it. This version takes effect no later than the first release that serves those counts.

No user right is narrowed by this version. Nothing previously permitted is withdrawn and nothing previously prohibited is permitted; the changes disclose a new category of derived processing and state its retention rule.

  • Section 4.5 extended. A new passage describes the one aggregate statistic the Services display to other users: the number of citation occurrences pointing at a SynC Standard, which may include citations made in documents the viewer cannot read. It states the limits that bound the disclosure — a bare number of occurrences, with no titles, authors, organizations, or any other detail that varies with the hidden documents; occurrences rather than documents, so the number cannot distinguish one document with many citations from many documents with one; citing documents named or linked only to viewers already authorized to read them — and states plainly what an observer of the public number can infer over time and what they cannot.
  • Section 2.3 extended. The citation index is added to the processing purposes: resolving citations for readers of the citing document, warning Wiki editors about the impact of an edit on documents that cite the edited clause, and producing the Section 4.5 counts.
  • Section 3 extended. A legitimate-interests entry is added for maintaining the citation index and displaying the Section 4.5 counts, in the same form as the entry for the search index.
  • Section 5.1 extended. A "Derived Citation Data" block states the retention rule in the same form as Derived Search Data: index entries are derived from published content, replaced in full on each publication of the citing document, removed at the moment that document is deleted, and never created from drafts. It also states the one asymmetry — deprecating a document without deleting it leaves its entries in place, because a deprecated document still cites what it cites.
  • Self-references now render as links. Four references to the subprocessor list (Sections 2.2, 4.1, 7.1, and 11) were written as bare text and did not render as links; they are now markdown links to the same page. No wording is changed.
  • Section 13.10's closing drafting note shortened. Its final clause pointed readers at internal review records that do not ship with this Policy; the clause is removed. No operative term is affected.

Notice of these changes. The disclosure of a new category of derived processing — an aggregate statistic visible to other users and to the public, derived in part from documents their viewers cannot read — is announced under Sections 13.1–13.3 by posting this Policy with a new Effective Date, sending email notification to registered users, and displaying a prominent notice in the Services. All other obligations, definitions, and user rights from v1.8 remain in effect.

13.12 Changes from Version 1.9

Version 1.10 carries v1.9 forward in full. It accompanies Terms of Service v1.8 and the AI chat-history feature, under which your conversations with the AI assistant are stored on our servers instead of existing only in your browser. This version discloses what is stored, states the retention rule that governs it, and states who can see it. It takes effect no later than the first release that stores conversations on production.

No user right is narrowed by this version. Nothing previously permitted is withdrawn and nothing previously prohibited is permitted. The changes disclose a new category of stored content, state its retention rule and its limits, and record the controls you have over it.

What is new is the storage, not the collection. v1.9 §1.1 already disclosed that we collect "AI chat interactions and queries," and §1.2 already listed "AI interaction history" as usage information. What that text did not say is that a conversation is now kept — as a durable record, on our servers, for a stated period — rather than living in your browser until you close the tab. A retention period is the disclosure a reader actually needs, and v1.9 did not contain one for this category. That is what this version adds. For the same reason, no new category of personal information arises under Section 15.3, and that Section is unchanged by the conversation disclosure.

This version also closes a second, unrelated disclosure gap: the tracking applied to the email we send. SynC's email is delivered by a third-party processor which rewrites every link in a message so that a click is recorded before you are redirected, and which can also record that a message was opened. Neither the processor nor the tracking was disclosed in any previous version of this Policy. That is a category of automatically collected information, a processor receiving your personal data, and a transfer to the United States, and the link rewriting is directly visible to any reader who hovers over a link in our email and sees an unfamiliar awstrack.me address. It is now disclosed in Sections 1.2, 3, 4.1, 5.1, 7.1, 8.1, 10.1, 12.3, and 15.3.

  • Section 1.1 extended. A new passage states what a stored conversation contains: your messages, the assistant's replies, and a plain-language record of the actions it took and the outcome of any change you approved. It states that a machine payload produced by an action is reduced to identifying information before the conversation is stored, that the provider and model serving each exchange are recorded, and that a conversation carries the context it was started in and may be restored automatically when you reopen the assistant in that context — with the Services showing you that this has happened.
  • Section 2.1 extended. Storing conversations, and restoring a recent one, are added to the service-delivery purposes.
  • Section 2.2 extended. Two AI-feature purposes are added: continuing a stored conversation, which requires transmitting it to a provider again, and generating a short title for it by a separate small inference request. A bullet is added to the no-training block stating that your messages to the assistant are User Content and the no-training commitment applies to them, and that storing a conversation does not create a training use.
  • Section 3 extended. A contract-performance entry covers storing, restoring, and re-transmitting a conversation, because those are what the feature you are using consists of. A legitimate-interests entry covers generating titles and enforcing the storage limits in Section 5.1.
  • Section 4.1A extended. States that continuing a stored conversation retransmits it — in the reduced form described in Section 1.1 — because the provider holds no memory between requests, that title generation is a separate request over the same content, and that reading a stored conversation transmits nothing, because displaying history is a database read.
  • New Section 4.2A (Conversations with the AI Assistant Are Private to You). States that the Services provide no means for anyone else to view your conversations — no sharing control, no team or company visibility, no view for a project owner or another participant, and no administrative view in the product — and that conversation content never enters a published document, a revision record, or an export of project content. It states expressly that this describes what the Services do and is not a claim that the stored records are beyond our reach: our personnel may access them where necessary to operate, secure or repair the Services, to answer your own request under Section 8, or under Section 4.7. Section 4.2 is conformed with one sentence directing the reader here.
  • Section 4.2A also states the permission-drift position, and states it in the honest direction. Your own past conversations are retained as your record, and that retention does not depend on your still having access to the material they discuss — so a conversation survives the removal of a share link, a change of role, or the deletion of the content. This version deliberately does not claim that a stored conversation contains no project content, because that claim would be false: reduction removes raw payloads, not the assistant's prose, and prose written about a specification restates parts of it. What is offered instead is bounded retention, invisibility to other users, and immediate deletion on demand.
  • Section 5.1 extended. A new "AI Assistant Conversations" block states the retention rule: 180 days measured from last activity, not from creation, restarted by each message, with automatic deletion at the end. It states that no expiry warning is given and that no action exists whose only effect is to exempt a conversation from the period; that your own deletion is immediate and single-stage, with no trash and no recovery; and that limits exist on the number of stored conversations and the length of one, enforced by deleting the conversation you have gone longest without using. The block states expressly that this period is separate from and independent of the account-deletion periods above — conversations survive the account-restoration period so that a restored account recovers them, and are deleted when the account is permanently deleted, whether or not their 180 days have run.
  • Section 5.2 extended. A deletion-request entry states that conversations are deleted with a permanently deleted account, are not exempt from a deletion request, and are deliberately not deleted at the moment you ask to close the account — with the reason, and with a pointer to the immediate self-service deletion that does not require waiting.
  • Section 8.1 extended. A new block records what you can do with your conversations: list and revisit, rename an automatically generated title, copy one out as readable text (the way to keep one past the retention period), delete one immediately, and receive them as part of an access request. It states that these controls remain available if your account's access to the AI assistant ends — you keep read, copy and delete, and lose only the ability to start or continue a conversation.

The email-tracking disclosure described above is made in the following places.

  • Section 1.2 extended — email interaction data. A new passage states that our email-delivery service applies tracking to the messages it sends for us: that every link is rewritten to resolve through the tracking domain awstrack.me, which records the click and then redirects you, and that this is why hovering a link in our email shows that address rather than ours; and that where open tracking is enabled on our account, an invisible image in the message records that it was opened. It states what each records — which link or which message, with IP address, date and time, and client information — and that no email interaction record is written to your SynC account or to our application database.
  • Section 4.1 extended — Email Delivery processor (Amazon SES). A processor entry is added in the same shape as the Web Analytics, Product Analytics, and Error Monitoring entries, identifying Amazon Web Services, Inc. and Amazon SES, stating US processing, the purpose, the categories of data received, what is not received, and that the tracking is configured on our email-delivery account rather than built into the Services — which is why Section 8.1 does not offer a switch in the product. The "Transactional email delivery services" bullet now points at that entry.
  • Section 3 extended. A legitimate-interests entry is added for measuring whether the email we send is delivered and acted on.
  • Section 5.1 extended — and states a retention period we do not know. A new "Email Interaction Data" block states that these records are held by the processor and not in our database, and then says plainly that we are not able to state a retention period for them and will not invent one, because the period is set by that processor's configuration and terms rather than by a setting we maintain and we do not currently hold a documented figure. It commits to stating the period here once established. Every other retention rule in Section 5.1 gives a period or a condition; this one gives neither, and says so rather than appearing to.
  • Section 7.1 extended. Amazon Web Services, Inc. is added to the list of processors receiving transferred data, with US-region processing, because email delivery is a transfer to the United States like the three already listed.
  • Section 8.1 extended. A new block states that you may object to email tracking by contacting us and under Section 8.2, and states the limits honestly: there is no per-recipient setting that turns it off and this Policy does not describe one, because one does not exist; if you object we will consider what we can do and tell you the answer, without promising in advance that we can exclude your mail. It also states the two things you can do without us — not following the link, and configuring your email program not to load remote images — and notes that a marketing opt-out does not reach transactional mail.
  • Section 10.1 extended. A note states that email tracking is not a browser cookie, is not covered by the cookie controls in Section 10.2, and is reached by no cookie opt-out, because the mechanisms are carried inside the message and operate in your email program rather than on our site. Section 10 already referred to "web beacons, pixels, and similar tracking technologies" while describing only site cookies; this closes that gap.
  • New Section 12.3. States that the tracking applies to all of our email and not only marketing, that most of the email SynC sends is transactional — verification, invitations, share-link notices, notifications, and required legal notices — and that unsubscribing from marketing under Section 12.2 therefore neither stops that mail nor stops it being tracked.
  • Section 15.3 updated. Email-delivery providers are added to the recipients of Identifiers and of Internet activity disclosed for business purposes. No new category of personal information arises; the recipient set changes.

Notice of these changes. Beginning to retain a category of user content that was not previously retained and stating the period for which it is kept, and disclosing a previously undisclosed category of automatically collected information together with the processor that collects it and the transfer to the United States that it involves, are material changes, and notice is given under Sections 13.1–13.3 by posting this Policy with a new Effective Date, sending email notification to registered users, and displaying a prominent notice in the Services. All other obligations, definitions, and user rights from v1.9 remain in effect.

14. Contact Information

14.1 Data Controller

Synergy In Construction, LLC, a Florida limited liability company, is the data controller responsible for your personal information.

Contact Details: Synergy In Construction, LLC A Florida limited liability company United States Email: privacy@synergyinconstruction.com

14.2 Privacy Inquiries

For questions, concerns, or requests regarding this Privacy Policy or our data practices, contact:

Privacy Team: Email: privacy@synergyinconstruction.com Subject Line: "Privacy Inquiry"

General Support: Email: support@synergyinconstruction.com

14.3 GDPR and Data-Protection Inquiries

SynC has not designated a formal Data Protection Officer, and one is not currently required for our processing activities under applicable law. For GDPR-related or other data-protection inquiries, contact our privacy team: Email: privacy@synergyinconstruction.com Subject Line: "Attention: Data Protection"

14.4 Response Time

We aim to respond to all privacy inquiries within:

  • 5 business days for general inquiries
  • 30 days for data subject rights requests (GDPR)
  • 45 days for CCPA requests

15. Additional Disclosures

15.1 California "Shine the Light" Law

California Civil Code Section 1798.83 permits California residents to request certain information about disclosure of personal information to third parties for direct marketing purposes. We do not share personal information with third parties for their direct marketing purposes.

15.2 Nevada Privacy Rights

Nevada residents may opt out of the sale of certain personal information. We do not sell personal information as defined under Nevada law. If you have questions, contact privacy@synergyinconstruction.com.

15.3 Categories of Personal Information (CCPA)

In the past 12 months, we have collected and disclosed the following categories of personal information for business purposes:

Categories Collected:

  • Identifiers (name, email, IP address)
  • Commercial information (purchase history, subscription data)
  • Internet activity (usage data, browsing history on our Services, search queries, session recordings)
  • Geolocation data (city/region level)
  • Professional information (job title, company)
  • Inferences (preferences, characteristics)
  • Sensitive personal information (account credentials)

Categories Disclosed for Business Purposes:

  • Identifiers (to service providers for hosting, product analytics, email delivery, support)
  • Internet activity (to web-analytics, product-analytics, error-monitoring, and email-delivery providers)

No payment processor is integrated with the Services as of the Effective Date, and no commercial information has been disclosed to one. The reference to payment processors in Section 4.1 identifies a category of service provider we would engage if payment functionality were enabled; it is not a disclosure that one is in use.

Categories NOT Sold or Shared:

  • We do not sell or share personal information for cross-context behavioral advertising

15.4 Data Protection Impact Assessments (DPIA)

Where required by applicable law, we will conduct a Data Protection Impact Assessment before undertaking high-risk processing activities, such as automated decision-making with legal or similarly significant effects. As of the Effective Date, we do not engage in such processing.


Last Updated: August 29, 2026 Version: 1.10

This Privacy Policy was drafted to comply with applicable privacy laws, including GDPR, CCPA/CPRA, and other relevant regulations as of the Effective Date.

For questions or to exercise your privacy rights, please contact privacy@synergyinconstruction.com.