Privacy Policy

Last updated: 1 October 2026

This policy explains what data the Synclaps Chrome extension and website ("Synclaps", "we", "us") collect, why, where it is stored and what control you have over it. Synclaps is operated by Artem Galyeyev, a sole proprietor based in Maia, Portugal, who is the data controller. Contact: support@synclaps.app.

In short: your mailbox sign-in, access tokens and the content of your emails stay in your browser and never reach our servers. Our server only checks your license. We don't use analytics, we don't sell data and we don't use your data to train AI models.

1. What Synclaps accesses in your mailbox

When you connect a mailbox, you sign in through your provider's official sign-in window and grant Synclaps these permissions:

Using these permissions, the extension can read: (a) the most recent emails in your inbox — subject, sender and the short text preview your provider generates for the inbox list — kept in a local cache so the panel opens instantly; (b) search results across your entire mailbox (not just the inbox), using the same subject/sender/preview fields, when you search from the Synclaps panel; and (c) the full text of an email you actually select to insert into an AI chat, fetched from your provider only at that moment and not cached afterwards. Attachments — their contents, not just their names — are never fetched or read. Synclaps cannot send, delete, move or modify any email.

2. Where your email data is stored

The email fields listed above are fetched directly from your mail provider by the extension in your browser. The recent-emails cache is stored only in your browser's local extension storage on your computer; the full text of an email is never cached — it is fetched, inserted, and discarded from memory. None of this is ever sent to our servers.

The access tokens that let the extension read your mailbox are obtained by the extension directly from Google or Microsoft and are stored only in your browser's local extension storage. For Gmail, Synclaps keeps only a short-lived access token (about one hour) and renews it in your browser while you are signed in to Google; no Google refresh token is ever issued to or stored by Synclaps. For Outlook, the refresh token issued by Microsoft is stored only in your browser. No mailbox token ever reaches our servers.

When you select one or more emails in the Synclaps panel on ChatGPT, Claude, Gemini, Perplexity, DeepSeek or Mistral, their full text (subject, sender, recipients, date and body) is inserted into that chat's input field. This happens only when you click "Insert." Once you send the prompt, the text is processed by that AI service under its own privacy policy. Synclaps itself does not send anything to OpenAI, Anthropic, Google, Perplexity, DeepSeek, Mistral AI or any other AI provider.

3. Data stored on our servers

DataWhyWhere
Only if you buy Pro — license information: license key, subscription status, your email address, the customer/subscription IDs from our payment provider, and a random ID for each browser where you activate the key (to enforce the 3-device limit). The free plan stores nothing on our servers. To check that your subscription is active and to help you recover a lost license key. Supabase database, hosted in the EU (Frankfurt).

That is the only personal data on our servers. Neither Gmail nor Outlook sign-in passes through our server.

Note for early testers: versions released before 1 October 2026 stored a Google refresh token on our server to keep Gmail signed in. That design was retired and all such tokens were deleted from our database on 1 October 2026.

4. Payments

Our order process is conducted by our online reseller Paddle.com, which is the Merchant of Record for all orders. Paddle collects and processes your payment details, billing address and tax information under its own privacy policy. We never see your full card details. Paddle shares with us your email address, the status of your subscription and the related IDs.

5. What we don't do

6. Google API Services — Limited Use

Synclaps' use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Data obtained from Google is used only to provide the user-facing features described above.

7. Service providers

Some of these providers may process data outside the European Economic Area. Where they do, they rely on appropriate safeguards such as an adequacy decision or the EU Standard Contractual Clauses.

8. How long we keep data

9. Your control and your rights

Under the GDPR you have the right to access, correct, delete, restrict or port your personal data and to object to its processing. We process data to provide the service you asked for (performance of a contract) and to keep it secure (legitimate interest). To exercise your rights, email support@synclaps.app. You can also complain to the Portuguese data protection authority, CNPD (cnpd.pt), or your local authority.

10. Children

Synclaps is not intended for anyone under 16, and we don't knowingly collect their data.

11. Changes

If we change this policy, we'll update the date at the top of this page. If a change materially affects how your data is handled, we'll also let subscribers know by email.