Syncore

Principera LLC · Syncore

Privacy policy

Syncore is designed as a local-first development orchestrator. This policy explains what stays on your device, what may leave it when you choose a remote service, and what Principera receives through this website and support channels.

Effective
August 9, 2026
Operator
Principera LLC
Privacy contact
support@principera.com

1. Scope

This policy covers the Syncore Windows desktop application, the usesyncore.com website, private-beta applications, support requests, and AI-output reports operated by Principera LLC (“Principera,” “we,” or “us”). It does not replace the privacy terms of an AI provider, GitHub, development tool, package registry, or other independent service you choose to use.

Local-first does not mean offline-only. Syncore keeps its orchestration state on your Windows device, but a task can transmit selected context when you deliberately enable and consent to a remote provider.

2. Information processed locally

Depending on the features you use, Syncore may process and store the following in its managed application-data directory:

  • task, goal, prompt, model-output, progress, decision, and verification history;
  • workspace paths, selected source text, diffs, commands, test output, and repository metadata;
  • application settings and versioned provider-consent records;
  • provider credentials and OAuth tokens you configure; and
  • bounded diagnostic logs containing operational events and redacted error details.

In the packaged Windows app, managed provider credentials are protected for the current Windows user with Windows Data Protection API (DPAPI). Diagnostic logs rotate at approximately 5 MiB and retain one predecessor. History and preferences remain until you delete them. Credentials remain until logout, revocation, or local-data deletion.

3. Remote AI providers and integrations

Syncore supports user-selected services that may include OpenAI, Anthropic, Google Gemini, and other configured providers. Before the packaged app sends task context to a supported remote AI provider, Syncore requires versioned consent for that provider. You can withdraw consent separately for each provider in Settings → Privacy & Responsible AI.

A remote request may contain your request, Syncore instructions, relevant workspace files or snippets, diffs, command and test output, and prior model context needed to continue the task. Provider credentials authenticate the request and are not intentionally placed in prompt text. The selected provider processes the transmitted information under your account and its own terms and privacy practices. Principera does not control the provider’s independent retention after transmission.

If you configure GitHub, Syncore may exchange repository, issue, pull-request, and account information needed for the action you request. Commands or development tools you authorize inside a workspace may have their own network behavior. Review those tools and services before enabling them.

4. Information Principera receives

Website measurement

We record aggregate page-view and beta-form events to understand whether the site works. The first-party event service does not intentionally store cookies, advertising identifiers, IP addresses, or persistent visitor identifiers. Nginx and infrastructure providers may process transient network information needed to deliver and secure the site.

Private-beta applications

When you apply, we receive your name, work email, company, role, team size, and the use case you choose to describe.

Support and AI-output reports

When you contact support or submit an AI-output report, we receive the information you enter. An AI-output report may include a category, description, optional output excerpt, Syncore version, optional provider and task reference, contact preference, and optional contact email. Do not include credentials, private keys, health or financial information, or personal information unrelated to the issue.

Syncore does not include an advertising SDK and does not currently send an automatic Principera-operated product analytics feed from the desktop application.

5. How we use and disclose information

Principera uses information it receives to operate and secure Syncore; review beta access; answer support requests; investigate, classify, and act on AI-output concerns; improve product behavior and documentation; comply with law; and protect users, Principera, and others.

We do not sell personal information or use it for behavioral advertising. We may disclose information to infrastructure and service providers acting for us, when you direct or consent to a disclosure, to comply with a valid legal obligation, or to protect rights and safety. Remote AI providers and integrations you select act under their own terms when information is transmitted to them.

6. Retention and security

AI-output reports are retained for up to 24 months, unless a shorter period is appropriate or a longer period is required for an active safety, security, legal, or abuse matter. The report service automatically removes reports older than this period during database maintenance. Beta applications are retained while the beta is active and for a reasonable follow-up period. Aggregate event records are retained as operational history until they are no longer useful.

The public report service uses HTTPS, request-size limits, rate limiting, bounded fields, and a server-side database. Reports have no public read endpoint. Production database access is limited to the dedicated service account and authorized operators using the server’s administrative shell. No security measure can eliminate every risk, so submit only the information needed to investigate your concern.

7. Your choices and controls

  • Inspect managed local-data categories, relative paths, sizes, and retention information in Syncore.
  • Grant or withdraw remote-AI consent separately for each provider.
  • Export a secret-free privacy and consent manifest.
  • Log out of configured credentials.
  • Schedule deletion of Syncore-managed history, logs, preferences, consent records, and credentials by using the in-app deletion confirmation and restarting Syncore.
  • Request access, correction, or deletion of information submitted directly to Principera by emailing support@principera.com from the address associated with the request.

Local-data deletion is confined to Syncore’s managed application-data directory. It does not delete your repositories or information retained independently by a remote provider. Contact that provider for provider-held information.

8. Children, updates, and contact

Syncore is a professional development tool and is not directed to children. We will update this policy when product data practices materially change and will revise the effective date above. Material changes may also be communicated in the product or release notes.

Questions and applicable privacy requests can be sent to support@principera.com. Please do not send credentials or unrelated sensitive information.