Privacy Policy & Terms of Use
Last updated: July 21, 2026
Your data belongs to you. Syncrix is built around the principle that we act as a secure bridge between your cloud accounts. We access file contents only to carry out the transfers you request — we never analyze, index, mine, or permanently store them. This page also sets out the terms and disclaimers that govern your use of the service.
Encrypted at Rest
OAuth access tokens are encrypted with AES-256-GCM before being stored in our database.
Content Not Retained
We access file contents only to perform the transfer you request. Syncrix does not analyze, index, mine, or permanently store your files.
Secure Infrastructure
All traffic is protected by TLS 1.2+. Our API enforces HSTS, CSP, and strict security headers.
1. Who We Are
Syncrix ("we", "our", "us") is a cloud-to-cloud file synchronization service operated at syncrix.cloud. If you have questions about this policy, contact us at support@syncrix.cloud.
2. What Data We Collect
Account information: name, email address, and a bcrypt-hashed password (we never store your password in plain text).
OAuth credentials: access tokens and refresh tokens issued by third-party cloud providers (Google Drive, OneDrive, Dropbox, etc.). These are encrypted with AES-256-GCM before being written to our database.
Sync configuration: source/destination provider pairs, folder paths, schedule settings, and filter rules you create.
Billing information: your subscription plan, payment status, and transaction records. Card numbers are never stored by us — all payment processing is handled by Stripe and PayPal.
Usage logs: sync job logs (file counts, byte totals, error messages) stored for troubleshooting. Log entries do not contain file content.
3. How We Use Your Data
- Authenticate you and manage your account session.
- Execute sync jobs between cloud accounts on your behalf, using only the OAuth scopes you grant.
- Send transactional emails: account verification, subscription confirmations, expiry reminders, and payment receipts.
- Enforce plan limits (storage quotas, number of sync rules, schedule frequency).
- Investigate errors and improve service reliability.
We do not sell, rent, or share your personal information with third parties for marketing purposes.
4. Token Encryption & Security
Syncrix applies defense-in-depth to protect your OAuth credentials:
- AES-256-GCM encryption: every access token and refresh token is encrypted with a unique random IV before being persisted. The encryption key is derived from a secret stored outside the database.
- HTTPS everywhere: all communication between your browser and our servers, and between our servers and cloud provider APIs, is protected by TLS 1.2 or higher.
- HTTP security headers: we enforce
Strict-Transport-Security(HSTS with preload),Content-Security-Policy,X-Frame-Options: SAMEORIGIN, andX-Content-Type-Options: nosniff. - Password hashing: user passwords are hashed with bcrypt (cost factor 12) and are never recoverable by our team.
- Minimal scopes: we request the least-privileged OAuth scope each provider offers. For Google Drive we use
drive.file, which limits us to the files and folders you explicitly select (see section 5).
No method of transmission or storage is 100% secure. While we work hard to protect your information, we cannot guarantee absolute security.
5. Google Drive Access (drive.file & Google Picker)
Syncrix uses Google's drive.file scope together with the Google Picker API so that users explicitly choose which files or folders Syncrix may access — the most privacy-preserving option Google offers.
Syncrix uses the Google Picker API to allow users to explicitly select the files and folders they want to access. Syncrix cannot browse or access files outside of the items selected by the user through Google's own file picker interface.
Syncrix only accesses files that the user explicitly selects through Google Picker or creates using Syncrix. The application cannot access the rest of the user's Google Drive.
- You stay in control. Access is limited to the specific files and folders you choose, plus files Syncrix creates for you. You can remove any selected item at any time from the File Browser, which instantly revokes our access to it.
- No "read everything" permission. We deliberately do notrequest the broad Google Drive scope that would let an app read your entire Drive. If you ever see Syncrix asking for that, it isn't us.
- File contents are not retained. During a sync, files stream directly between your clouds through our server and are not written to disk or permanently stored (see section 12 below).
Google user data is accessed only while performing the operation explicitly requested by the user.
Google user data is never used for advertising, user profiling, analytics unrelated to Syncrix, or for developing, improving, or training generalized artificial intelligence (AI) or machine learning (ML) models.
Syncrix never sells, shares, or discloses Google user data to any third party. User data is transmitted only to the cloud storage provider explicitly selected by the user to complete the requested synchronization, or when required by applicable law.
Syncrix's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
6. Third-Party Services
Syncrix integrates with third-party cloud storage providers (Google, Microsoft, Dropbox, Box, pCloud) to perform sync operations. By connecting an account you agree to that provider's terms and privacy policy. We act as a data processor on your behalf for these connections.
Stripe and PayPal process payments. We share only the minimum information required (email, plan name) to create a billing record. We never transmit card details through our servers.
7. Service Provided "As Is" — No Warranty
Syncrix is provided on an "as is" and "as available" basis, without warranties of any kind, whether express or implied, including but not limited to warranties of merchantability, fitness for a particular purpose, non-infringement, accuracy, or uninterrupted or error-free operation.
Syncrix is a file-transfer and synchronization tool — it is not a backup service and is not a substitute for maintaining your own independent backups. Sync and transfer operations depend on third-party provider APIs (Google, Microsoft, Dropbox, Amazon, and others) that may change, throttle, return incomplete results, suspend accounts, lose data, or become unavailable at any time, entirely outside our control. We do not warrant that any sync will be complete, timely, error-free, or that any file will be preserved.
8. Your Responsibilities
By using Syncrix, you acknowledge and agree that:
- You are solely responsible for maintaining your own backups of any important data before running any sync, transfer, migration, or import.
- Mirror and two-way sync modes can delete files. Mirror mode makes a destination match a source, which deletes files at the destination that no longer exist at the source. You choose these modes deliberately and are responsible for reviewing the dry-run preview before running them. We are not liable for files deleted, overwritten, or moved as a result of a configuration you created.
- You are responsible for the accuracy of the sync rules, folders, and destinations you configure, and for ensuring you have the rights to access and transfer the data involved.
- You are responsible for keeping your account credentials secure and for all activity under your account.
- You will not use Syncrix to store, transfer, or distribute unlawful content or content you are not authorized to handle.
9. Limitation of Liability
To the maximum extent permitted by applicable law, Syncrix, its operator, and its affiliates shall not be liable for any indirect, incidental, special, consequential, exemplary, or punitive damages, or for any loss of data, files, profits, revenue, goodwill, or business, arising out of or relating to your use of (or inability to use) the service — including but not limited to data loss, deletion, corruption, or exposure, failed or partial syncs, third-party provider outages or account actions, or unauthorized access — whether based in contract, tort, negligence, strict liability, or any other legal theory, even if we have been advised of the possibility of such damages.
To the maximum extent permitted by law, our total aggregate liability for any and all claims relating to the service shall not exceed the greater of (a) the total fees you paid to Syncrix in the three (3) months immediately preceding the event giving rise to the claim, or (b) USD $50. For users on the free plan, our aggregate liability shall not exceed USD $0. Some jurisdictions do not allow certain limitations, so parts of this section may not apply to you.
10. Indemnification
You agree to indemnify, defend, and hold harmless Syncrix and its operator from and against any claims, liabilities, damages, losses, and expenses (including reasonable legal fees) arising out of or related to your use of the service, your data, your configurations, or your violation of these terms or any applicable law or third-party rights.
11. Service Availability & Changes
We do not guarantee any particular level of uptime or availability. We may modify, suspend, limit, or discontinue any part of the service, and may impose or change plan limits, at any time and without liability to you. We will make reasonable efforts to notify users of significant changes.
12. Data Retention
We retain your account data for as long as your account is active. Sync job logs are retained for 90 days and then automatically deleted. File contents are never retained after a transfer or synchronization operation completes. If you delete your account, we remove your personal information and revoke all stored OAuth tokens within 30 days.
13. Deleting Your Data & Account
You can remove your data from Syncrix at any time, directly in the app:
- Remove selected Google Drive files/folders:in the File Browser, open your Google Drive, use the "⋮" menu on any item and choose Remove from Syncrix. This instantly revokes our access to that item (it stays in your Drive).
- Disconnect a cloud account: go to Cloud Providers and click the trash icon on any provider. This deletes the stored access/refresh tokens for that account.
- Delete your entire account: go to Settings → Delete Account. This permanently deletes your Syncrix account and all associated data — sync rules, job history, connected cloud accounts, and all stored OAuth tokens — and cannot be undone. Files in your cloud providers are not affected.
You can also email support@syncrix.cloud to request deletion. We remove your personal information and revoke all stored OAuth tokens within 30 days of a deletion request.
14. Your Rights
Depending on your location, you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Request deletion of your account and associated data.
- Revoke OAuth access to any connected cloud account at any time from your Providers page.
- Export a copy of your sync configuration data.
To exercise any of these rights, email us at support@syncrix.cloud.
15. Cookies
We use a session cookie to keep you signed in and a privacy-friendly analytics measurement to understand aggregate usage. We do not use third-party advertising cookies.
16. Children's Privacy
Syncrix is not directed at children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
17. Governing Law & Changes to This Policy
This policy and your use of Syncrix are governed by the laws of the operator's jurisdiction, without regard to conflict-of-laws principles. Any disputes shall be resolved in the competent courts of that jurisdiction.
We may update this policy occasionally. When we make material changes, we will notify registered users by email and update the "Last updated" date at the top of this page. Continued use of Syncrix after a policy change constitutes acceptance of the updated terms. If any provision of this document is held unenforceable, the remaining provisions remain in full effect.
18. Contact
Questions or concerns about this policy? We're here to help: