Privacy Policy

Effective Date: February 9, 2026 | Last Updated: October 7, 2026 | Version: 3.6

Personal Data Administrator

Business Name: Daniel Siwek

Address: ul. Wiosenna 2/247, 03-749 Warszawa, Poland

Tax ID (NIP): 1132989706

Contact Email: [email protected]

The Administrator is responsible for processing personal data in connection with the use of SyncBooster services and the realization of purposes specified in this Privacy Policy, in accordance with Regulation (EU) 2016/679 (GDPR) and the Polish Act of 10 May 2018 on Personal Data Protection.

I. Definitions

  • Administrator / Operator – Daniel Siwek conducting business activity at ul. Wiosenna 2/247, 03-749 Warszawa, NIP: 1132989706.
  • Service – the SyncBooster platform available at syncbooster.pl and related applications.
  • User – a natural person using the Service.
  • Account – an individual User profile created in the Service.
  • GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data.
  • Personal Data – any information relating to an identified or identifiable natural person.
  • Processing – any operation performed on personal data (collection, recording, storage, modification, disclosure, erasure).
  • Data Processor – a third party processing personal data on behalf of the Administrator.

1. Introduction

This Privacy Policy explains how we collect, use, disclose, and protect your data when using the SyncBooster social media management platform ("Service").

SyncBooster is a comprehensive AI-powered tool that helps businesses and creators manage their social media presence across multiple platforms, including Facebook, Instagram, LinkedIn, and Google Business Profile.

This Policy applies from the moment you start using the Service or create an Account.

2. Legal Basis for Data Processing

We process your personal data based on the following legal grounds under GDPR (Article 6(1)):

Data TypePurposeLegal BasisRetention Period
Account data (email, password, name)Service provisionArt. 6(1)(b) – ContractUntil account deletion + 30 days
Access logs (IP, browser)Security and fraud preventionArt. 6(1)(f) – Legitimate interest12 months
Analytics cookies (GA4, PostHog session recordings)Website analytics and optimizationArt. 6(1)(a) – ConsentMaximum 14 months
Website and panel usage events (PostHog) together with the PostHog identifier stored in a cookie and browser storage, linked in the panel to your Account (identifier, email, first name, last name, company name, country)Analyzing and improving the Service, measuring signup sourcesArt. 6(1)(f) – Legitimate interestUntil account deletion
Entry source (campaign parameters, referring page, landing page) and visitor identifier in the first-party cookies sb_attr and sb_aid, and a homepage experiment assignment label in the first-party cookie sb_expDetermining how you found the Service, linking a website visit to a signup, and comparing homepage variant resultsArt. 6(1)(f) – Legitimate interestsb_attr: 90 days; sb_aid: 12 months; sb_exp: 90 days
OAuth tokens (Facebook, Instagram, Google, LinkedIn, TikTok)Social media publishingArt. 6(1)(b) – ContractUntil platform disconnection
AI-processed contentContent personalization and AI assistantArt. 6(1)(b) – ContractUntil account deletion + 30 days
Published posts and your edits to generated contentBrand memory: matching the style of generated content to your brand (background processing without your involvement, Section 5.3)Art. 6(1)(b) – ContractUntil account deletion + 30 days
Payment dataPayment processing and invoicingArt. 6(1)(b) – Contract; Art. 6(1)(c) – Legal obligation5 years (tax obligation)
Diagnostic data and error logsStability monitoring and bug fixingArt. 6(1)(f) – Legitimate interest90 days
Meta advertising pixelMarketing and conversion trackingArt. 6(1)(a) – ConsentMaximum 180 days
Events sent to Meta from our server (Conversions API): SHA-256 hash of your email address and Account identifier, hashes of phone number, first name, last name, city and country (if present in your profile), IP address and browser dataMeasuring the effectiveness of ads on Meta services (signup, social account connection, post publication, first payment, subscription cancellation)Art. 6(1)(f) – Legitimate interest; Meta advertising identifiers (fbp, fbc) and campaign parameters (UTM, fbclid) are included only after marketing consentUnder the Meta Business Tools Terms
Email address for marketing messagesNewsletter, tips, news and offers from SyncBoosterArt. 6(1)(a) – Consent (Section 4.5)Until consent is withdrawn

YouTube data is subject to the specific rules in Section 3.3a. They take precedence over the general retention periods in this Policy, including for data in logs, chats, caches and backups.

3. What Data We Collect

3.1 Personal Data You Provide

  • Account Data: First and last name, email address, password provided during registration
  • Profile Data: Profile picture, bio, and other optional information
  • Communication: Messages sent through contact forms and support channels
  • Team Member Data: Email address of a person invited to the team, provided by the account owner to send an invitation to collaborate on a brand
  • Billing Data: Company name, tax ID, address for invoicing purposes

3.2 Authentication Data

  • Google OAuth: When logging in with Google, we receive your name, email, and profile picture
  • Email Verification: We collect and verify email addresses for account security
  • Session: Tokens and session information for secure access (processed by SuperTokens)

3.3 Social Media Account Data

  • Connected Platforms: Information about accounts (Facebook, Instagram, LinkedIn, Google Business Profile, TikTok)
  • Access Tokens: OAuth tokens and permissions to publish on your behalf
  • Metadata: Profile names, follower counts, and other public data
  • TikTok: Once you connect a TikTok account, we store the access token (and refresh token), the account identifier, the account name and the avatar. We send to TikTok only content that you yourself approve for publishing. You can disconnect the account at any time - we then delete the stored tokens and the account link, and we also revoke the access token on TikTok's side. The TikTok integration is being rolled out gradually, so it may not yet be available to every account.

3.3a YouTube API Services

The YouTube integration in SyncBooster uses YouTube API Services. By using YouTube features, you agree to be bound by the YouTube Terms of Service. Google's processing of data is described in the Google Privacy Policy.

  • Authorization: Before connecting a channel, we require acceptance of the applicable Privacy Policy and Terms of Service, including the YouTube Terms of Service. After your authorization, we receive an access token and refresh token for the youtube.upload and youtube.readonly permissions. We store tokens encrypted. The YouTube connection is separate from Google sign-in and the Google Business Profile connection.
  • Channel and Video Data: We access and store the selected channel's identifier, name and avatar, and data about videos uploaded through SyncBooster: identifiers and URLs, titles, descriptions, privacy settings, made-for-kids and synthetic-content disclosures, upload and processing status, and current view, like and comment counts, including for private videos where authorization permits. We do not retrieve comment text or use the YouTube Analytics API or YouTube Reporting API.
  • Purpose and Legal Basis: Data is used to identify the correct channel, upload an approved video immediately or according to a schedule, and show publication outcomes, status and current statistics. The legal basis is performance of the contract (GDPR Art. 6(1)(b)), within the access you grant. We do not build a historical YouTube statistics database or derive our own engagement scores from these statistics.
  • Uploads and Storage: We send Google/YouTube the video file, title, description, chosen privacy and made-for-kids and synthetic-content disclosures that you approve. To handle uploads, we also store the upload session address, progress and operation outcome. We store data in the Service's databases and file storage, using the infrastructure providers listed in Section 6, only as needed for these features.
  • Sharing: Data is available to you and authorized team members of the relevant brand. Google/YouTube receives data needed for authorization and publication; infrastructure providers process it on our behalf. When you use the AI assistant, necessary operational context may be sent to the AI and monitoring providers listed in Sections 5 and 6. We do not sell YouTube data or use it for advertising profiling. Section 7 describes transfers outside the EEA.
  • In-App Disconnection: You can disconnect the channel in SyncBooster settings. We immediately revoke authorization programmatically with Google, stop access and pending YouTube publications, and remove tokens. We delete related data obtained through your authorization (Authorized Data) as soon as possible and no later than seven calendar days after disconnection. Because the Google client is shared, revocation may require reconnecting Google Business Profile or signing in with Google again; it does not mean deleting unrelated data from those services.
  • Revocation in Google: You can also remove SyncBooster access on the Google account permissions page. We check authorization periodically even when you are not publishing; after revocation on Google's side, we delete related Authorized Data no later than 30 days after the actual revocation.
  • Deletion Requests: You can request deletion of stored YouTube data at [email protected]. We delete it as soon as possible and no later than seven calendar days after the request; the same deadline applies after Account deletion. The general inquiry response period does not extend this deadline.
  • Refresh and Deletion Scope: We refresh or delete stored YouTube API channel and video metadata and current statistics within 30 days of retrieval or the last refresh. These deadlines cover all stored copies of related YouTube data: avatars, identifiers, URLs, statuses, statistics, upload sessions, previews and API-response snapshots in chats, logs, caches and backups. General rules for backups, monitoring and keeping content in another person's brand do not extend these deadlines.
  • Your Own Materials and Videos on YouTube: Disconnection or revocation does not delete videos on YouTube; you manage them in YouTube Studio. Your own drafts and files uploaded to SyncBooster do not become YouTube API data solely because you use them for publication. Disconnection does not automatically delete them; you can request their separate deletion or delete your Account.
  • Legal Obligations: Longer retention of YouTube data is permitted only to the extent and for the time required by a specific binding legal obligation. We segregate such data and do not use it to operate the integration. A general need for backups or defending claims is not such an exception.
  • Contact and Complaints: Send questions, privacy complaints and YouTube data deletion requests to [email protected]; send matters concerning the Terms to [email protected].

3.4 Content and Posts

  • Post Content: Texts, images, videos, and other media uploaded for publication
  • Scheduled Content: Posts scheduled for future publication
  • Drafts: Saved drafts and content templates
  • Files: Images, videos, and documents uploaded to the platform (stored in Google Cloud Storage)
  • Posts Retrieved from Connected Profiles: The content and metadata of posts published on your profiles, including those created outside the Service, retrieved through platform APIs (publication calendar and brand memory, Section 5.3)

3.5 Usage Data and Analytics

  • Logs: IP addresses, device information, browser type, access time
  • Usage Patterns: Platform interactions, features used, time spent
  • Performance: Performance metrics and error logs (processed by Sentry)
  • API Usage: Interactions with connected platforms
  • Entry Source: Campaign parameters from the page address (utm_source, utm_medium, utm_campaign, utm_term, utm_content, gclid, fbclid, ttclid, msclkid), the referring page and the landing page – stored on your first visit in the first-party cookie sb_attr, together with a random visitor identifier in the sb_aid cookie (Section 11.1)

3.6 Data Processed by Artificial Intelligence

  • AI Assistant Conversations: Chat content and queries directed to the AI assistant
  • Contextual Data: Information about your business, communication style, and target audience provided during the initial interview
  • Website Analysis: Data from your public website used to understand your brand
  • Generated Content: Posts and content generated by AI based on your data
  • AI graphics generation: Feature available on all plans (billed in tokens). Text prompts, generation settings, and optional visual materials you provide may be processed, including via third-party providers' models (incl. OpenAI and Google) also routed through an AI gateway, under the same principles as in Section 5

3a. Google User Data

One SyncBooster Google OAuth application covers three separate features. We request only the scopes needed for each of them, and only when you choose to use the feature. Below you will find what Google data we access and why.

  • Sign in with Google (openid, email, profile): we access your name, email address and profile photo. We use them only to create your account, log you in and show your identity in the app.
  • Google Business Profile (business.manage): we access the business locations you manage and their posts. We use them to let you choose a location, publish posts to it and read post and location statistics shown in SyncBooster.
  • YouTube (youtube.upload, youtube.readonly): we access the name and avatar of the selected channel, we upload videos that you approve in SyncBooster, and we read the status and statistics of those videos. Details are in Section 3.3a.
  • Storage: Google data is stored in our infrastructure, protected as described in Section 9. OAuth tokens are stored encrypted.
  • No selling and no ads: we do not sell Google user data, we do not use it for advertising, including retargeting or interest-based ads, and we do not transfer it to data brokers or advertising platforms.
  • No human reading: our staff do not read Google user data, except when needed for security purposes, to comply with the law, or when you ask us for support and give consent to a specific review.
  • Revocation: you can disconnect each Google feature in SyncBooster settings, or remove SyncBooster access in your Google Account at https://myaccount.google.com/permissions.
  • Deletion: after disconnection or on your request sent to [email protected] we delete the stored Google data within the deadlines in Sections 3.3a and 8. Deleting your Account also deletes it.

SyncBooster's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Read the policy here: https://developers.google.com/terms/api-services-user-data-policy.

4. How We Use Data

4.1 Service Delivery

  • Account Management: Creating and maintaining user accounts
  • Authentication: Identity verification and secure session management
  • Social Media Management: Publishing content to connected accounts
  • Content Storage: Secure storage of posts, media, and drafts
  • Platform Integrations: Connecting and managing social media accounts
  • AI Content Generation: Creating personalized social media content using artificial intelligence

4.1a Subscription plans, tokens, and feature scope

Current prices, AI token limits, number of brands (separate knowledge bases), and channel descriptions are published at https://syncbooster.pl/cennik and in the application panel and may be updated from time to time. As of the last update of this policy, offerings include Start (129 PLN gross per month), Business (249 PLN), Business Pro (449 PLN), and Agency (individual pricing); selected AI operations are billed in tokens (including a free welcome token allowance - part granted unconditionally on signup and part after giving marketing consent - per the current pricing page). Within one brand, channels may include Facebook, Instagram, LinkedIn, and Google Business Profile.

  • AI graphics panel: A feature available on all plans; usage is charged in tokens according to the terms and pricing in force at the time of use.

4.2 Payments and Invoicing

  • Transaction Processing: Processing payments for subscriptions and services
  • Invoice Generation: Issuing VAT invoices through iFirma
  • Tax Compliance: Storing data required by tax law

4.3 Communication and Support

  • Notifications: Sending information about account and services, including changes to prices, plans and terms of the Service. Such messages are not marketing and do not require marketing consent
  • Support: Responding to inquiries and providing technical assistance
  • Security Alerts: Informing about threats and incidents

4.4 Platform Improvement

  • Analytics: Understanding how the platform is used (Google Analytics, PostHog)
  • Error Monitoring: Identifying and resolving technical issues (Sentry)
  • AI Monitoring: Tracking AI model quality and performance (Langfuse)
  • Optimization: Improving speed and reliability

4.5 Marketing

  • Meta Pixel: Conversion tracking and building advertising audiences (consent-only)
  • Meta Conversions API: Independently of the pixel, our server sends Meta information about signup, social account connection, post publication, first payment and subscription cancellation, together with SHA-256 hashes of your email address and Account identifier, hashes of phone number, first name, last name, city and country (if present in your profile), and your IP address and browser data. Meta advertising identifiers (fbp, fbc) are included only when Meta cookies are present in the browser, i.e. after marketing consent; campaign parameters (UTM, fbclid) are likewise included only with marketing consent. You can object by writing to [email protected]
  • Google Tag Manager: Managing analytics and marketing tags (consent-only)
  • Marketing emails (newsletter, tips, news, offers): We send them only after consent given by a separate, explicit action: the "Yes, I want 100 tokens!" button in the welcome wizard, the "Enable marketing consent" button in panel settings, the consent box when purchasing without an account, or the consent box when subscribing to the newsletter on syncbooster.pl. Consent to marketing cookies in the cookie banner is not consent to marketing emails. You can withdraw consent using the unsubscribe link in every such message or by writing to [email protected]

5. AI Processing and Personalization

SyncBooster uses artificial intelligence to personalize content and improve user experience. This section explains how AI processes your data in compliance with GDPR and the EU AI Act (Regulation 2024/1689).

5.1 AI Service Providers Processing Your Data

The data shared with each AI provider depends on the feature. The table lists the purpose and data separately for each provider:

ProviderLocationProcessing PurposeData Types
OpenAI, Inc. (image generation models)USAImage generation and editing in SyncBooster StudioText prompts for graphics, including brand context used to refine them, and images you provide for editing or as references
Perplexity AI, Inc.USAWeb search and research for AI agentsSearch queries, conversation context
Vercel Inc. (AI Gateway)USAAI Gateway – routing communication to AI providersAI queries and responses in transit
AlphaAI Technologies Inc. (Tavily)USARetrieving public pages you identify and public social profiles linked from those pagesPublic page and linked-profile URLs, not chat queries or post text as input
Google LLC (Gemini models)USAImage analysis, content generation, and other AI features powered by Google models, including via Vercel AI GatewayChat content, prompts, images, and brand context you provide

5.2 AI Content Personalization

  • Learning Process: AI analyzes your business information, communication style, and target audience through an initial interview
  • Website Analysis: AI examines your public website to understand your brand voice and business context
  • Content Generation: Based on collected data, AI creates personalized social media posts matching your style
  • Continuous Improvement: Based on your published posts and your edits, we match the style of subsequent content to your brand (brand memory, Section 5.3)

5.3 Brand Memory (Background Processing)

Independently of your current instructions in chat, SyncBooster analyzes posts published on your connected profiles and the edits you make to generated content, and uses them to update the description of your brand's communication style stored in your brand. The purpose is to match subsequently generated content to your brand.

  • Data scope: The content of your published posts, your edits to generated content, and brand information previously stored in the Service
  • How it works: Processing runs automatically in the background, without your involvement, using models from the providers listed in Section 5.1. Its output consists of conclusions about your brand's style and preferences, stored in your brand
  • Legal basis: Contract performance (Art. 6(1)(b) GDPR). Matching content to your brand's style is a feature of the Service described in the Terms of Service (Sections 2.1 and 2.2)
  • No decisions about you: The analysis concerns your brand's communication style and is not used to evaluate your personal characteristics or to make decisions about you
  • Retention: Conclusions are stored together with brand data until account deletion + 30 days

5.4 Legal Basis and Transparency

  • Legal Basis: AI processing is necessary for contract performance (Art. 6(1)(b) GDPR)
  • No Automated Decisions: AI does not make decisions that significantly affect your rights – it only assists in content creation
  • Human Control: You maintain full control over all AI-generated content and can modify or reject any suggestions
  • Data Sources: AI uses data you provide directly, data from your website analysis, and social media API data
  • No training by model providers: Content and prompts sent to AI model providers are not used to train their models. Providers process them to generate a response under their service terms.
  • Reading web pages: Tavily receives public addresses of pages you identify or public social profiles linked from those pages. It retrieves their content, which may include published posts. We send addresses as input, not chat content or post text. Its terms govern this tool.

5.5 AI Monitoring and Quality (Langfuse)

To ensure quality and monitor AI service performance, we use Langfuse GmbH (Germany/EU). Langfuse records metadata from AI interactions (response times, model type, token counts) as well as the content of AI prompts and responses, which allows us to diagnose errors and assess service quality. The data is stored in the Langfuse project on EU servers. We keep AI conversation traces in the Langfuse project without automatic deletion. At your request ([email protected]) we delete the traces linked to your account.

5.6 AI label decision record

For each post or Story variant, we record whether you turned on the AI label before publication and the publication result. The record includes the user, brand, platform, and time of the action. This helps us account for publications and handle complaints (legitimate interest, Art. 6(1)(f) GDPR). We keep the record until account deletion. If a publication remains in another person's brand after a team member deletes their account, we remove the information that identifies that member from the record.

6. Data recipients and processors

We use the providers below to deliver the Service. Not every recipient acts as a processor: social media platforms and payment providers may act as independent controllers. When a provider processes data on our behalf, its data processing terms may be part of its service agreement or may require separate acceptance or signature.

EntityLocationProcessing Purpose
OpenAI, Inc.USAAI model provider – image generation and editing
Perplexity AI, Inc.USAAI model for web research by agents, accessed through Vercel AI Gateway
Vercel Inc.USAAI Gateway – routing communication to AI models
AlphaAI Technologies Inc. (Tavily)USARetrieving chosen public web pages for AI agents
Google (Google Ireland Limited for GA4, Google LLC for OAuth; other services depend on the agreement)Ireland (EU) / USA, depending on the serviceGoogle Analytics 4 – analytics as processor, and independent controller for additional data sharing when enabled; Google Tag Manager – tag management; Google OAuth – authentication as independent controller; Gemini models – AI features including via Vercel AI Gateway
PostHog Inc.EU (Frankfurt)Product analytics (events from the website, the panel and our server), session recordings, heatmaps, UX optimization, and email notifications about Service changes through PostHog Messaging
Functional Software Inc. (Sentry)USAError monitoring, application performance tracking, profiling
Langfuse GmbHGermany (EU)AI interaction monitoring and tracing (LLM observability)
Meta Platforms Ireland LtdIreland (EU)Facebook and Instagram API integration (Meta as an independent controller); Meta Pixel and Conversions API – ad conversion measurement, with Meta acting as a processor or joint controller for certain operations (Section 4.5)
LinkedIn Ireland Unlimited CompanyIreland (EU)LinkedIn API integration – post publishing
Google Ireland LimitedIreland (EU)Google Business Profile API integration; Google acts as an independent controller
SuperTokens Inc.USA (self-hosted in EU)Authentication software running on our own infrastructure; the software vendor does not store users' login data
Krajowy Integrator Płatności S.A. (Tpay)Poland (EU)Online payment processing (BLIK, bank transfers, cards); Tpay is an independent controller of payer data
Stripe Payments Europe, LimitedIreland (EU)Online payment processing (cards, international transfers); Stripe acts as a processor or independent controller depending on the operation and may transfer data to Stripe, LLC (USA) – planned payment method, currently inactive; we do not transfer data until launch
PayPal (Europe) S.à r.l. et Cie, S.C.A.Luxembourg (EU)Online payment processing; PayPal acts as an independent controller – planned payment method, currently inactive; we do not transfer data until launch
IFIRMA SAPoland (EU)VAT invoice issuance through an API; IFIRMA processes the customer data on invoices on our behalf
Railway CorporationUSAApplication hosting, databases (PostgreSQL, Redis)
Google Cloud (contracting entity depends on billing address)EU (regional bucket) / USAStorage of user-uploaded media in Google Cloud Storage; also Vertex AI models if a direct connection is used
Aftermarket.pl mail operator (AFTERMARKET.PL LIMITED or Polska Giełda Domen Sp. z o.o., depending on the agreement)Cyprus or Poland (EU), depending on the operatorSMTP services – transactional emails and notifications
Plus Five Five, Inc. (Resend)USASending emails to users and consent-based marketing messages; storing the newsletter subscriber list, including people without an Account

The list above describes data recipients and the purposes of processing linked to their services. We publish the current list in this Policy.

7. International Data Transfers

Because some providers are based outside the EEA, personal data may be transferred to third countries, especially the United States. The transfer mechanism depends on the recipient and the data involved. Relevant mechanisms include:

  • Standard Contractual Clauses (SCC): The clauses approved by the European Commission (Implementing Decision 2021/914) may be a basis for a transfer if they cover the provider and the transfer in question
  • EU-US Data Privacy Framework (DPF): The adequacy decision of July 10, 2023 applies to transfers to US companies with active DPF certification

Countries to which data may be transferred:

CountryEntitiesSafeguards
United StatesOpenAI, Perplexity AI (via AI Gateway), Vercel, Tavily, Google LLC, Sentry, Railway, Resend; Stripe, LLC only after Stripe payments launchSCC or EU-US DPF only where they cover the recipient and transfer in question
Ireland (EU)Meta Platforms Ireland, LinkedIn Ireland, Google Ireland; Stripe Payments Europe, Limited only after payment launchProcessing within EEA
Germany (EU)Langfuse GmbHProcessing within EEA
Poland (EU)Tpay (KIP S.A.), IFIRMA SAProcessing within EEA
Cyprus or Poland (EU)Aftermarket.pl mail operator, depending on the agreementProcessing within EEA
Luxembourg (EU)PayPal (Europe), only after payment launchProcessing within EEA

You have the right to obtain a copy of data transferred outside the EEA and information about the safeguards applied. Requests should be directed to: [email protected].

8. Data Retention Period

We retain personal data for specific periods based on the purpose of processing and legal requirements:

  • Account Data: Until account deletion + 30 days (for backup and recovery purposes); YouTube data is subject to the shorter deadlines in Section 3.3a
  • Access Logs (IP, Browser): 12 months (for security and fraud prevention)
  • Analytics Cookies (GA4, PostHog): Maximum 14 months
  • Analytics Events Linked to Your Account (PostHog): Until account deletion
  • Entry Source Cookies: sb_attr – 90 days, sb_aid – 12 months, sb_exp – 90 days
  • OAuth Tokens: Until account disconnection or revocation
  • AI-Generated Content: Until account deletion + 30 days
  • AI conversation traces (Langfuse): no automatic deletion; deleted at your request (Section 5.5). YouTube data stored in these traces is subject to the deadlines in Section 3.3a
  • AI label publication record: Kept until account deletion; in another person's brand, the record remains without information identifying the deleted team member (Section 5.6)
  • Error Logs (Sentry): 90 days
  • Backup Data: Up to 30 days after account deletion, except for YouTube data, which is subject to the deadlines in Section 3.3a
  • Communication Data: 3 years (for customer support and legal compliance)
  • Invoice and Payment Data: 5 years after the end of the fiscal year (obligation under Polish Accounting Act, Art. 74)
  • Marketing Data (Meta Pixel): Maximum 180 days

If you are an invited team member, when your account is deleted, another person's brand you worked in keeps the knowledge base documents, brand settings (profile, voice, and preferences), posts and images, videos, and sounds used in those posts, in reels, or as brand assets, reel projects and editor library items, and your chat messages, without data identifying you as their author; images, videos, and sounds uploaded to its gallery but not used in any of those ways are deleted.

After the retention period expires, we securely delete or anonymize your personal data, except where we are legally required to retain it longer (e.g., tax regulations, statute of limitations for claims).

YouTube data is subject to deletion and only the narrow legal exception in Section 3.3a; anonymization does not replace the required deletion.

9. Data Security

9.1 Technical Safeguards

  • Encryption: Data transmission using HTTPS/TLS protocol
  • Secure Storage: Encrypted databases and cloud infrastructure
  • Access Control: Strict permission and role management
  • Audits: Regular security and vulnerability testing
  • Secure AI Communication: Connections to AI providers are encrypted (TLS) and authenticated with API keys

9.2 Operational Safeguards

  • Training: Data protection practices for the team
  • Incident Response: Procedures for handling data breaches (in accordance with Art. 33-34 GDPR)
  • Backups: Regular data backups
  • Monitoring: Continuous monitoring of threats and unauthorized access (Sentry)

10. Your Rights

10.1 Your GDPR Rights

As a data subject, you have the following rights:

  • Right of Access (Art. 15): Right to obtain information about the processing of your data and to receive a copy
  • Right to Rectification (Art. 16): Right to correct inaccurate or supplement incomplete data
  • Right to Erasure (Art. 17): Right to request deletion of data ("right to be forgotten")
  • Right to Restrict Processing (Art. 18): Right to request restriction of processing in certain circumstances
  • Right to Data Portability (Art. 20): Right to receive your data in a structured, commonly used, machine-readable format
  • Right to Object (Art. 21): Right to object to processing based on legitimate interests
  • Right to Withdraw Consent: Withdraw consent for analytics and marketing cookies and for marketing emails at any time without affecting the lawfulness of processing before withdrawal
  • Right Not to Be Subject to Automated Decision-Making (Art. 22): Right not to be subject to a decision based solely on automated processing, including profiling

10.2 How to Exercise Your Rights

  • Account Settings: Access, correct, or delete data through your account dashboard
  • Email: Send a request to [email protected] with subject "Data Rights Request"
  • Cookie Management: Use our cookie banner or browser settings
  • Response Time: We will respond to your request within 30 days of receipt (Art. 12(3) GDPR)

10.3 Right to Lodge a Complaint

If you believe that the processing of your personal data violates GDPR, you have the right to lodge a complaint with the supervisory authority:

President of the Personal Data Protection Office (UODO)

Address: ul. Stawki 2, 00-193 Warszawa, Poland

Website: www.uodo.gov.pl

Email: [email protected]

Phone: +48 (22) 531 03 00

11. Cookies and Tracking Technologies

We use cookies and similar technologies to operate and improve our Service. This section provides detailed information in compliance with the ePrivacy Directive and GDPR.

11.1 Types of Cookies We Use

Essential Cookies (No Consent Required)

  • SuperTokens Session Cookies: Required for user authentication and secure login sessions
  • Security Cookies: Protect against fraud and ensure platform security
  • Functional Cookies: Remember your preferences and settings

First-Party Entry Source Cookies (Set on Your First Visit)

  • sb_attr: Campaign parameters, referring page and landing page from your first and last visit; retention: 90 days; read at signup to record how you found the Service
  • sb_exp: Readable label of the homepage experiment group you were assigned to; retention: 90 days; used only to compare page variant results, not for any permission or security decision
  • sb_aid: Random visitor identifier shared by syncbooster.pl and panel.syncbooster.pl; retention: 12 months; links a website visit to a signup in analytics (PostHog)

Analytics Cookies (Consent Required)

  • Google Analytics 4:
    • Purpose: Website traffic analysis and user behavior insights
    • Data: Anonymized IP addresses, page views, session duration
    • Retention: Maximum 14 months
    • Provider: Google LLC (USA) with Standard Contractual Clauses
  • PostHog:
    • Purpose: Product analytics, heatmaps, session recordings, and UX optimization
    • Identifier: from your first visit, PostHog stores a random identifier in a cookie shared by syncbooster.pl and panel.syncbooster.pl and in browser storage, to link page views and events of the same person (legitimate interest, Section 2)
    • Session recordings on syncbooster.pl: only after analytics consent
    • Data: Mouse movements, clicks, scroll behavior, product events, IP address and browser data; in the panel, after you log in, events are linked to your Account (identifier, email, first name, last name, company name, country)
    • Retention: Cookie maximum 14 months; data linked to your Account until account deletion
    • Provider: PostHog Inc. (processed in EU, Frankfurt region)

Marketing Cookies (Consent Required)

  • Meta Pixel (Facebook Pixel):
    • Purpose: Conversion tracking, remarketing, building advertising audiences
    • Data: Website actions, pixel identifiers
    • Before consent: the pixel script is downloaded from Meta servers when you open the website, but runs in revoked-consent mode; the pixel fully operates only after marketing consent
    • Retention: Maximum 180 days
    • Provider: Meta Platforms Ireland Ltd (Ireland/USA)

11.2 Cookie Consent Management

  • Google Consent Mode v2: We implement a compliant consent management mechanism
  • Granular Control: You can accept all, reject non-essential, or customize preferences
  • Easy Withdrawal: Change your preferences anytime through our cookie banner or browser settings
  • No Pre-checked Boxes: All consent is opt-in

11.3 Third-Party Privacy Policies

12. Children's Privacy

The Service is not intended for persons under 16 years of age. We do not knowingly collect personal data from persons under 16. If we discover that we have collected data from a person under that age, we will immediately delete the data and terminate the account.

13. Privacy Policy Changes

The Administrator reserves the right to amend this Privacy Policy in the event of changes in processing practices, technology, or legal requirements. We will notify you of significant changes by:

  • Publishing a new version on this page with an updated date
  • Sending an email notification to registered users
  • Displaying a prominent notice on our website

Continued use of our Service after changes constitutes acceptance of the updated Privacy Policy.

14. Contact Information

If you have questions about this Privacy Policy or wish to exercise your data protection rights, please contact us:

Privacy Inquiries: [email protected]

General Support: [email protected]

Data Rights Requests: [email protected] (subject: "Data Rights Request")

We will respond to your inquiry within 30 days; YouTube data deletion requests are fulfilled within seven calendar days (Section 3.3a). For complaints about data protection, you can also contact the Polish data protection authority (UODO) as described in section 10.3.

15. Consent and Final Provisions

By using SyncBooster, you confirm that you have read and understood this Privacy Policy and agree to our data processing practices as described herein.

Important: Consent for analytics cookies (Google Analytics 4, PostHog session recordings), marketing cookies (Meta Pixel) and marketing emails is voluntary and can be withdrawn at any time without affecting your ability to use the core features of our Service.

This Privacy Policy is governed by Polish law. Matters not regulated herein are subject to the provisions of GDPR, the Polish Act of 10 May 2018 on Personal Data Protection, and the Polish Act of 18 July 2002 on Electronic Services.

If you do not agree with any part of this Privacy Policy, please do not use our Service.

This Privacy Policy is effective as of February 9, 2026. Document version: 3.6 (updated October 7, 2026)

We encourage you to periodically review this policy to check for updates.