Information Syncore keeps on your device
Syncore may store the information needed to plan, carry out, and verify development work, including:
- goals, tasks, prompts, model output, decisions, progress, and verification history;
- workspace paths, selected source text, diffs, commands, test output, and repository metadata;
- application settings and provider-consent records;
- provider credentials and OAuth tokens that you configure; and
- bounded diagnostic logs with operational events and redacted error details.
In the packaged Windows application, Syncore protects managed credentials for the current Windows user with Windows Data Protection API (DPAPI). Diagnostic logs rotate at approximately 5 MiB and retain one predecessor.
Remote AI providers and integrations
Syncore can connect to AI providers such as OpenAI, Anthropic, and Google Gemini. Before the packaged app sends task context to a supported provider, Syncore asks for provider-specific consent. You may withdraw that consent at any time in Settings → Privacy & Responsible AI.
A provider request may contain your instructions, relevant files or excerpts, diffs, command and test output, and prior context needed to continue the task. Credentials authenticate the request and are not intentionally included in prompt text.
The provider processes information under your account and its own terms and privacy practices. The same principle applies to integrations you enable, including GitHub, and to development tools you authorize to run in a workspace.
Information Principera receives
| Website | Aggregate page-view and beta-form events used to check whether the site and application flow work. The first-party event service does not intentionally store cookies, advertising IDs, IP addresses, or persistent visitor IDs. |
|---|---|
| Private beta | Name, the verified email supplied by your selected Google or GitHub identity, company, role, team size, and the use case you choose to describe. |
| Syncore account | Your verified email address, display name, optional company and job title, Google or GitHub account identifier, identity provider, registration and sign-in timestamps, access status, and the administrative history of access decisions. Principera does not retain the provider access token used during sign-in. |
| Support | The message and contact information you send when asking for help. |
| AI-output reports | Report category, description, optional redacted output, Syncore version, optional provider and task reference, contact preference, and optional email address. |
The desktop application does not currently include advertising software or send an automatic Principera-operated product analytics feed.
How Principera uses and shares information
Principera uses information to operate and secure Syncore, review beta applications, provide support, investigate reported AI output, improve the product, comply with law, and protect users and others.
We may share information with service providers working on our behalf; with Google or GitHub when you choose that provider for account sign-in; with a provider or integration you select; when you direct or consent to the disclosure; or when disclosure is reasonably necessary to comply with law or protect rights and safety.
Principera does not sell personal information or use it for behavioral advertising.
Retention and security
AI-output reports are kept for up to 24 months, unless an active safety, security, legal, or abuse matter requires a longer period. The reporting service removes older reports during database maintenance. Beta applications are kept while the beta is active and for a reasonable follow-up period. Account and access-decision records are kept while the account is active and for a reasonable period afterward for security, dispute resolution, and legal compliance. Expired browser, OAuth, device, and desktop sessions are not used to restore access. Local Syncore history and settings remain until you delete them.
The public reporting service uses HTTPS, request-size limits, rate limiting, field validation, and a server-side database. Reports have no public read endpoint. Production database access is restricted to the service account and authorized operators.
Your choices
Syncore provides controls to review managed local-data categories, grant or withdraw provider consent, export a privacy and consent manifest without secrets, log out of configured credentials, and schedule deletion of Syncore-managed local data. On the account page, you can edit your display name, company, and job title or sign out. Signing out ends that browser session but does not delete the account or its access-decision history.
Deleting Syncore-managed data does not delete your repositories or information retained independently by an AI provider or integration. Contact that service directly about information it holds.
To request access to, correction of, or deletion of information submitted directly to Principera, email support@principera.com from the address associated with the submission.
Children and changes to this policy
Syncore is a professional development tool and is not directed to children.
We will update this policy when our data practices materially change. The date at the top of the page identifies the current version.