Privacy Policy
This policy is maintained by the InSynk team and explains how we handle personal information as the responsible party under the Protection of Personal Information Act 4 of 2013 (POPIA). Last updated 26 July 2026.
1. Information we collect
You give us: your email address, optional full name, password (stored only as a salted hash by our authentication provider), your chosen plan, your selected charity, your daily review time, your honesty oath acceptance and its date, the goals you create with their schedules, and the daily logs you record.
Generated for you: a six-character sync code, your partner link, monthly evaluations, success scores and penalty amounts.
Collected automatically: basic technical data needed to run and secure the app — IP address, device and browser type, timestamps, and security event records such as failed sign-ins. If you sign in with Google, we receive your email, name and profile picture from Google.
We never collect: your fingerprint or face data, your card number (our payment provider handles that directly), your phone contacts, your location, or the contents of your device calendar.
2. Why we use it, and our lawful basis
To create and run your account and authenticate you (performance of our contract with you); to show your goals, calculate scores and process monthly penalties and charity payouts (contract); to let your paired partner approve or reject logs (contract, and your consent given by sharing your sync code); to send service emails such as password resets and billing notices (contract); to keep the Service secure, prevent fraud and abuse, and debug problems (our legitimate interest); and to comply with tax, accounting and legal obligations (legal obligation).
We do not sell your personal information, we do not use it for third-party advertising, and we do not make automated decisions with legal effects about you.
3. Who can see your information
You can see all of your own data. Your paired partner can see your goals, schedules and daily logs, and can approve or reject them; in return you see their name and email. Nobody else can read your data — access is enforced by database-level row security, not merely hidden in the interface. Unpairing removes that access going forward.
Charities receive pooled donation payments and are not told which individual users contributed unless you ask us to tell them.
4. Operators and service providers
We use a small number of processors (operators under POPIA), each bound to process data only on our instructions: our cloud platform for hosting, database, authentication and transactional email; and a payment provider for subscriptions and penalty collection, which receives your name, email and payment details directly and never shares your full card details with us. Some providers process data outside South Africa; where that happens we rely on contractual safeguards requiring a comparable level of protection as required by section 72 of POPIA.
We may also disclose information if required by law, court order or a lawful regulatory request, or to establish or defend legal claims.
5. Biometric unlock and device features
Fingerprint or face unlock uses your device’s own WebAuthn hardware. InSynk never receives, sees or stores biometric data — the device only tells the app whether the check passed, unlocking a session you already signed into. Calendar export creates a standard .ics file that your device passes to your own calendar app; we get no access to your calendar.
6. Cookies and similar technologies
We use strictly necessary storage only: a session token so you stay signed in, and small local-storage entries that remember your biometric-lock preference and whether you have seen today’s motivational quote. We do not use advertising or cross-site tracking cookies. Clearing site data signs you out and resets those preferences.
7. Security
Data is encrypted in transit with TLS and at rest by our cloud provider. Access rules are enforced in the database, money- and approval-related writes are restricted to authenticated server functions, passwords are hashed, and security-relevant events are logged. No system is perfectly secure; if a breach affects your personal information, we will notify you and the Information Regulator as required by section 22 of POPIA.
8. How long we keep it
Account data (profile, goals, logs) is kept while your account is active and deleted when you delete your account, usually within 30 days across backups. Monthly evaluation and payment records are kept for five years to meet South African tax and accounting requirements. Security logs are kept for up to 12 months.
9. Your rights
Under POPIA you may: ask what we hold about you and get a copy; correct or update it; ask us to delete or destroy it; object to processing based on legitimate interest; withdraw consent where consent is the basis; and complain to the Information Regulator of South Africa (enquiries@inforegulator.org.za). Many of these you can do yourself in the app — edit your details, change plan or charity, unpair from a partner, turn biometrics off, or delete your account. For anything else, contact the support address in the app and we will respond within 30 days.
10. Children
InSynk is intended for users 18 and over, and for users 13 and over with verified parental consent. We do not knowingly collect information from children under 13; if we learn that we have, we delete it promptly.
11. Changes and contact
If this policy changes we will update the date above and, for material changes, notify you in the app or by email. Privacy questions, access requests and complaints go to the support address shown in the app.