Who this policy covers
This policy explains how CLRT L.L.C-FZ, Meydan Grandstand, 6th Floor, Meydan Road, Nad Al Sheba, Dubai, United Arab Emirates, trading as SyncLine (“SyncLine”, “we”, or “us”) handles personal information when you visit syncline.ai or use app.syncline.ai and its supporting services.
We determine how information is used to manage our customer relationships, accounts, billing, and service security. When you provide personal information within a brand workspace or publishing request, we process that information to carry out your instructions. Your organisation remains responsible for its own use of that information.
CLRT L.L.C-FZ
Meydan Grandstand, 6th Floor, Meydan Road, Nad Al Sheba, Dubai, United Arab Emirates
delete@syncline.ai
Information we process
- Account information: your name, email address, authentication and session records, workspace details, subscription, and billing status. Sign-in codes are sent to your email address; we retain a protected verification record and its expiry to validate the code.
- Brand and content information: website and source links, brand descriptions, audience, writing preferences, examples, approved facts, content restrictions, logos, colours, font files, uploaded images and videos, prompts, generation conversations and revisions, generated content, drafts, timezones, and schedules.
- Social connection information: account, page, channel, and business-location identifiers, display names, profile images, authorisation tokens, permissions, expiry, and connection status. Telegram connections also use channel identifiers, the bot’s posting permissions, and connection messages sent through the SyncLine bot.
- Publishing and analytics information: selected destinations, post identifiers, publication results, errors, and performance metrics made available by the platforms you connect.
- Inbox information: where inbox features are enabled, comments and direct messages from connected Facebook and Instagram accounts, conversation and message identifiers, message text and direction, timestamps, replies, and the reply rules you configure.
- Collaboration information: where team features are enabled, the email address, role and brand access of people you invite, and the names, decisions and comments that team members and client reviewers enter on posts sent for review.
- Billing and AI usage information: Stripe customer, checkout, subscription, and payment references; plan and introductory-offer eligibility; credit grants, reservations, spending, refunds, and expiry; and AI model identifiers, request status, token or image counts, and recorded processing costs.
- Technical and support information: IP addresses, browser and device information, request and security logs, and information you provide when contacting us.
Some information comes directly from you; some comes from the services you authorise or is generated when you use SyncLine. The exact data available depends on the connection, granted permissions, and feature used.
How and why we use it
We use information to create and secure accounts, organise brands, generate requested content, manage connections, publish according to your instructions, show available analytics, manage enabled inbox features and reply rules, manage subscriptions and credits, provide support, and investigate errors or abuse.
Where a legal basis is required, we rely on performing our agreement for core services; legitimate interests for proportionate security, troubleshooting, and service administration; legal obligations for required records; and consent where a feature or law requires it. You may withdraw consent, although the related feature may then stop working.
Content generation and AI providers
When you use enabled generation features, text-planning and writing requests are sent to Google’s Gemini API and image-generation requests to OpenAI’s API. Text requests can include your prompt, brand profile, writing examples and restrictions, supplied facts, relevant generation conversation history, draft text being revised, selected connection names and internal SyncLine identifiers, platform requirements, and suggested publishing times derived from available account performance. Image requests include the image description and relevant brand style. Generated content is saved to your workspace so you can review, edit, schedule, or publish it.
If AI inbox replies are configured and you enable an AI reply rule, Gemini receives the text and direction (incoming or outgoing) of up to ten recent comments or messages from the relevant Facebook or Instagram conversation, along with your brand name, context, voice, audience, writing style, and supplied knowledge. The reply is saved as a draft or sent automatically according to the rule’s settings.
We record generation usage and credit transactions to account for requests, process credit refunds, and understand service costs. Social access tokens and payment-card details are not included in generation prompts. Entering a website or source link does not automatically cause SyncLine to crawl that website.
AI providers process submitted content under their applicable terms and account settings, including security, abuse-prevention, and retention practices. See the Gemini API terms and OpenAI API data controls. Avoid submitting sensitive information unnecessary for your request. Connecting a social account does not authorise AI processing of its data beyond the features described here and the AI tools you choose to connect with an agent token, as described under When information is shared. We will update these disclosures before materially changing how content is shared with AI services.
Payments and generation credits
Stripe handles checkout, recurring charges, payment methods, and the customer billing portal. Payment-card details are entered through Stripe. SyncLine stores the references and billing status needed to manage access, renewals, cancellations, introductory offers, and purchased credits; our application does not store your full payment-card number or card security code.
Stripe sends payment and subscription updates to SyncLine. We use those updates to activate access and grant the relevant credits. Credit and usage records are also used to investigate billing issues, prevent duplicate grants or repeated introductory offers, and return credits for failed generation. See Stripe’s Privacy Policy for its processing practices.
Uploaded and generated media
Images, videos, and other brand assets are stored so SyncLine and the social platforms you choose can retrieve them. Media used by the publishing service is served through public HTTPS URLs. Anyone who has one of those URLs may be able to view or download the asset, including while its associated post is a draft. This media storage is not intended for confidential documents.
Deleting an asset or requesting account deletion does not automatically erase copies already downloaded, cached, or published by a social platform or another recipient. Platform posts must be removed through that platform’s controls where appropriate.
How we protect your data
We use the following technical measures to protect personal information and sensitive account data, including Google and YouTube data accessed through the permissions you grant:
- Encrypted connections: the production website and application use HTTPS to protect data in transit between your browser and SyncLine. Requests to Google and YouTube APIs also use HTTPS.
- Protected connection tokens: connected social-account access and refresh tokens, including Google and YouTube tokens, are encrypted before they are stored in our application database. The server uses these tokens to carry out authorised requests; they are excluded from the connection information returned to the browser.
- Access controls: authenticated requests are checked against the user’s workspace and applicable role and brand permissions. These checks restrict access to connected-account information, content and analytics.
- Account and session safeguards: passwords, where used, are stored as hashes rather than readable text. Session and password-reset tokens are also stored as hashes. Email sign-in codes have protected verification records, expire after ten minutes and can be used only once. Sign-in and verification requests are rate limited to reduce repeated guessing.
- Browser session protection: production session cookies use Secure, HttpOnly and SameSite settings to limit exposure to browser scripts and cross-site requests. The application’s browser-facing API checks that requests to change data come from the same origin.
No service or transmission can be guaranteed completely secure. These protections do not make media URLs private; the access characteristics of uploaded and generated media are explained above.
Storage and retention
We keep information for the purposes described here, considering whether your account is active, whether content is needed for scheduled work or generation history, applicable provider requirements, legal recordkeeping, and the need to resolve disputes or security incidents. Expiry of an AI credit allowance does not itself delete the content generated with it or the related billing records.
Account closure does not necessarily remove every record immediately. Information required for legal, billing, fraud-prevention, or dispute purposes may need to be retained, and backup removal may follow the relevant backup cycle. Platform-specific deletion requirements may impose shorter deadlines; YouTube and Google Business Profile data is deleted as described under Connected social platforms.
Hosting and other providers may process information outside your country. International transfers are subject to the safeguards required by applicable law.
Your choices and deletion requests
You can edit brand information, manage content, and disconnect social accounts through the app. To request a copy of personal information, correction, account closure, or deletion of stored connection data, contact us using the details below. Include your account email and the account, brand, or connection concerned; do not send passwords, tokens, or secret keys.
We may need to verify your identity and authority before acting. Depending on your location, you may also have rights to restrict or object to processing, portability, withdrawal of consent, and to complain to a data protection authority. Applicable exceptions and response deadlines apply.
Removing information from SyncLine does not automatically delete copies already published to a social platform or held by an independent third party. Use that platform’s controls for those copies. Cancelling a subscription, disconnecting an account, and requesting data deletion are separate actions, although disconnecting a YouTube or Google Business Profile connection also deletes its Google data as described above. Account deletion is handled through the contact request process below.
See our data deletion instructions for the request steps.
CLRT L.L.C-FZ
Meydan Grandstand, 6th Floor, Meydan Road, Nad Al Sheba, Dubai, United Arab Emirates
delete@syncline.ai
Age requirements
SyncLine is intended for adults managing brands and social content, and is not directed to children. If you believe a child has provided personal information through the service, contact us so we can investigate and address it.
Updates to this policy
We may update this policy when our service or information practices change. We will update the date above and provide additional notice of material changes where required. New purposes requiring consent will be presented before that processing begins.
Connected social platforms
You choose which accounts to connect and which permissions to grant. SyncLine uses those permissions to provide the features you request. Publishing sends your selected content to the chosen platform, where visibility is governed by your settings and that platform’s policies.
You can disconnect an account in SyncLine’s Connections screen and revoke authorisation in the platform’s own account settings. Disconnecting does not automatically delete previously published posts or, apart from the Google data described below, all historical information held by SyncLine.
YouTube features use YouTube API Services. Google’s handling of information is described in the Google Privacy Policy. You can revoke SyncLine’s access through Google’s third-party access settings.
Disconnecting a YouTube or Google Business Profile connection in SyncLine revokes SyncLine’s Google authorisation, which can also end SyncLine’s access to other connections authorised with the same Google account. Whether you disconnect in SyncLine or revoke access in your Google account, SyncLine deletes the Google data it stored for each affected connection: its tokens, channel or location identifier, name and image, analytics, timing data, post links and identifiers, and shared report copies that include it. For a connection you disconnect in SyncLine this happens immediately; otherwise it happens once SyncLine detects the change, and in any case within 30 days. SyncLine re-verifies each YouTube and Business Profile connection, and each YouTube video it links to, with Google at least every 30 days, and deletes the stored Google data it cannot re-verify. Posts and media you created stay in your workspace until you delete them or ask us to.
Google and YouTube account, channel, business-location, publishing, and analytics data are used for the connection and reporting features you request. They can also be shared through the report links, review links and agent tokens you choose to create, as described under When information is shared. They are not collected to target advertising, build unrelated user profiles, or train general-purpose AI models. Google API data is subject to the Google API Services User Data Policy, including applicable Limited Use requirements.