Executive Privacy Summary & Google User Data Disclosures
- Application Identification: This Privacy Policy applies explicitly to SyntaFlow, also distributed and identified as Syntaflow Desktop (“the application”).
- Google User Data Accessed: Our application accesses only the data you explicitly authorize via Google OAuth: user identity (name, email address, profile picture), Gmail correspondence and draft creation, Google Calendar event details and meeting availability, Google Drive files specifically created or selected through the app, and Google Docs/Sheets for brief draft and budget exports.
- How Google User Data is Used: We use your Google user data exclusively to deliver user-requested workstation features: correlating client email correspondence with active local workspaces, composing review notice drafts upon your command, synchronizing milestone deadlines onto your Google Calendar, and attaching deliverable assets. We do NOT use Google user data for profiling, data enrichment, or advertising.
- Data Sharing & Zero Data Sales: We do NOT sell, rent, trade, or monetize Google user data. We do NOT share, transfer, or disclose Google user data with third-party data brokers, advertising platforms, or information resellers.
- Data Protection & Encryption: All sensitive credentials, including Google OAuth access and refresh tokens, are encrypted at rest using OS-level cryptographic vaults (Windows DPAPI via Electron
safeStorage, Apple Keychain, or Linux Secret Service). All API transit is encrypted via TLS 1.3. - Data Retention & Deletion: Workspace data is stored locally in your physical on-device SQLite database (
%APPDATA%\Syntaflow\storage\syntaflow.db). Gmail and Calendar entries are held only in transient memory during your active session. Disconnecting an integration in Settings → Integrations permanently purges all tokens. Access can also be revoked anytime via Google Security Permissions. - AI / ML Model Training Affirmation: Syntaflow Desktop explicitly affirms that Google Workspace APIs and Google user data are NOT used to develop, improve, or train non-personalized, generalized machine learning (ML) or artificial intelligence (AI) models.
- Google Limited Use Compliance: Syntaflow Desktop’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
1. About this Privacy Policy & Scope
SyntaFlow provides a professional client operating environment designed to maintain continuous context across client onboarding, proposals, project scoping, dual-density task boards, typographic document authoring, client review sign-offs, and delivery gate enforcement. This policy governs both the public Syntaflow website (https://syntaflow.tech) and the Syntaflow Desktop client application (“the application”).
2. Information Syntaflow Collects
We minimize data collection by design. We only collect or process personal data when strictly necessary to provide requested services:
- Website Communication Data: If you submit an inquiry through our Contact page or request preview downloads, we collect your name, email address, and message content to respond to your inquiry.
- Voluntary Account Credentials: If you register an account, we collect your email address and a securely hashed password.
- Connected Integration Metadata: Account identifiers and OAuth tokens required to establish authorized API bridges with third-party providers you choose to connect.
3. Account Information & Authentication
Desktop application user accounts are authenticated locally using industry-standard password hashing (scrypt with randomized salts) and constant-time verification. When using web-based account authentication, sessions are managed via encrypted authentication cookies. We do not store plaintext passwords.
4. Local Application Data & Storage Architecture
The primary source of truth for SyntaFlow workspace data is a physical SQLite database located in your operating system’s local application data directory (%APPDATA%\Syntaflow\storage\syntaflow.db on Windows). Client profiles, blueprints, milestone scopes, task records, document versions, and delivery sign-offs remain strictly on your device. Zero operational records are automatically transmitted to remote cloud databases.
5. Connected Service Data & Integration Architecture
SyntaFlow integrates with third-party productivity platforms—including Google Workspace (Gmail, Google Calendar, Google Drive, Google Docs, Google Sheets), GitHub, Notion, Figma, Slack, and Linear. All third-party connections operate through explicit, user-initiated OAuth authorization or the Model Context Protocol (MCP). Connected data is queried on demand and is not persistently mirrored on external servers.
6. Google User Data: Purpose & Processing Principles
When you connect Google services in Syntaflow Desktop, our application requests access to specific categories of Google user data. We process this data strictly within the boundaries of your local workstation to correlate client communications, schedule delivery review milestones, and attach deliverable files to active projects:
- Principle of Least Privilege: We request only the narrowest possible scopes necessary for specific workstation features.
- Local Contextual Processing: All correlation of email messages and calendar events with client records is performed locally in client memory.
- Zero Commercial Profiling: We do NOT use Google user data for profiling, user advertising, or data enrichment.
7. Gmail Data & Requested Scopes
When connecting Gmail, Syntaflow Desktop requests the following specific OAuth scopes:
| Scope | User Benefit / Purpose | Data Storage |
|---|---|---|
https://www.googleapis.com/auth/gmail.readonly |
View email messages and settings. Searches and displays correspondence matching email addresses of clients on active projects so you can review conversations without leaving the project workspace. | Queried dynamically on demand; cached in volatile session memory only. Never written to disk or external servers. |
https://www.googleapis.com/auth/gmail.compose |
Manage drafts and send emails. Composes draft review notices and deliverable transmission emails. Syntaflow creates drafts on your behalf; dispatching live outbound emails requires your explicit confirmation. | Drafts are created directly in your Gmail account. No copies stored remotely. |
8. Google Calendar Data & Requested Scopes
When connecting Google Calendar, Syntaflow Desktop requests the following scopes:
| Scope | User Benefit / Purpose | Data Storage |
|---|---|---|
https://www.googleapis.com/auth/calendar.readonly |
See and download calendars you can access. Inspects meeting availability and surfaces upcoming client review sessions and project deadlines alongside your milestone timeline. | Queried dynamically via the Google Calendar API. Never exported or shared. |
https://www.googleapis.com/auth/calendar.events |
View and edit events on all your calendars. Schedules client review meetings, presentation appointments, and delivery milestones directly onto your Google Calendar upon your command. | Events are written directly to your Google Calendar. |
9. Google Drive Data & Requested Scopes
When connecting Google Drive, Syntaflow Desktop requests narrow, file-level access:
| Scope | User Benefit / Purpose | Scope Boundary |
|---|---|---|
https://www.googleapis.com/auth/drive.file |
See, edit, create, and delete only the specific Google Drive files you use with this app. Used to upload final deliverable packages, export proposals, and open specific project files you choose. | Syntaflow cannot access or view other files in your Google Drive that were not created or selected through the application. |
https://www.googleapis.com/auth/drive.metadata.readonly |
See information about your Google Drive files. Displays file names, file sizes, and revision dates in the document attachment selector so you can link assets to client blueprints. | Read-only metadata inspection for user-selected assets. |
10. Google Docs & Sheets Scopes
For extended document authoring and commercial table workflows, Syntaflow Desktop requests:
https://www.googleapis.com/auth/documents: Used to read client briefs and export completed document drafts to Google Docs.https://www.googleapis.com/auth/spreadsheets: Used to synchronize milestone budgets, commercial hourly logs, and financial runways with Google Sheets spreadsheets.
11. Google Account Identity Scopes
https://www.googleapis.com/auth/userinfo.email: Used solely to display the email address of your connected Google account in application settings and verify token ownership.https://www.googleapis.com/auth/userinfo.profile: Used solely to display your account name and avatar within the local integration status card.
12. How Connected Service Data is Used & Processed
All data accessed from connected services is used exclusively to deliver user-requested workspace features:
- Displaying contextually relevant communications alongside active projects.
- Scheduling milestone deadlines and synchronizing calendar availability.
- Attaching deliverable assets and exporting document versions.
- Allowing you to manage client engagements from a unified operational cockpit.
13. Artificial Intelligence (AI) & Model Processing Transparency
Syntaflow includes contextual intelligence features designed to summarize client threads, assist with project scoping, and generate document drafts. Our AI architecture enforces strict privacy safeguards:
- No Generalized AI Model Training: Syntaflow does NOT use your client records, documents, emails, calendar events, or Google user data to train, retrain, or fine-tune generalized machine learning (ML) or foundational AI models.
- Local-First Model Support: Syntaflow supports executing open-weights models locally on your workstation via Ollama, ensuring prompt context never leaves your physical hardware.
- User-Initiated Execution: AI features operate only when explicitly invoked by you. Integration data is passed to the AI inference engine strictly within the scope of your immediate command.
- Granular Agent Permission Gates: In application settings, you can toggle agent access for each integration and require explicit human confirmation before any external action (such as sending an email) is performed.
14. Local-First Physical Storage & OS-Level Credential Encryption
OAuth access tokens and refresh tokens required to maintain API connections are encrypted at rest using your operating system’s native cryptographic vault:
- On Windows, credentials are encrypted using the Windows Data Protection API (DPAPI) via Electron
safeStorage. - On macOS, credentials are protected by the Apple Keychain.
- On Linux, credentials utilize Secret Service API /
libsecret.
Tokens are never written in plaintext to disk, never checked into code repositories, and never transmitted to Syntaflow servers.
15. Data Stored by Syntaflow Services
Our web infrastructure (hosted on Appwrite Sites with CDN edge routing) does not store your local workspace records. If you submit an inquiry through our contact form, that inquiry information is securely stored only for the purpose of communicating with you and is deleted upon request.
16. Authentication, OAuth Tokens & Session Security
Syntaflow implements the industry-standard OAuth 2.0 with Proof Key for Code Exchange (PKCE) (RFC 8252) flow for native desktop applications. During authentication, a local loopback server is instantiated dynamically on 127.0.0.1 to receive the authorization code. Single-use cryptographic state parameters with short expiration windows are enforced to prevent CSRF and replay attacks.
17. Third-Party Service Providers & Subprocessors
We use a minimal set of reputable infrastructure providers to host our public website and documentation:
- Appwrite Cloud / Fastly: Hosting and content delivery for the static marketing website (https://syntaflow.tech).
- GitHub: Source code repository hosting and release artifact distribution.
None of these providers receive access to your local SQLite databases or integration tokens.
18. Data Sharing & Non-Disclosure (Zero Data Sales, Zero Ad Networks)
We maintain an absolute commitment to user confidentiality:
- We do NOT sell, rent, trade, or monetize your personal data or Google user data.
- We do NOT share user data with data brokers, advertising platforms, or market research firms.
- We do NOT permit third parties to access your connected service records.
- We only disclose information if strictly required by applicable law, court order, or governmental subpoena.
19. Google API Services User Data Policy & Limited Use Compliance
Syntaflow Desktop’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements:
- We only use Google user data to provide or improve user-facing features that are prominent in Syntaflow Desktop’s user interface.
- We do not transfer Google user data to third parties unless necessary to provide or improve user-facing features, comply with applicable law, or as part of a merger, acquisition, or asset sale with user consent.
- We do not use or transfer Google user data for serving advertisements, including retargeting, personalized, or interest-based advertising.
- We do not allow humans to read Google user data unless: (a) we have obtained your affirmative agreement for specific messages; (b) it is necessary for security purposes (such as investigating a bug or abuse); (c) it is required to comply with applicable law; or (d) the data is aggregated and anonymized for internal operations.
- We do not use Google user data to train non-personalized or generalized machine learning (ML) or artificial intelligence (AI) models.
20. Data Retention Criteria & Storage Durations
Because Syntaflow operates on a local-first model:
- Local Workspace Data: Persists on your computer until you delete individual records or uninstall the application.
- Connected Integration Data: Gmail messages and calendar entries are queried on demand and stored in transient memory; they are discarded upon closing the view or session.
- OAuth Tokens: Persist in your OS encrypted credential vault until you click “Disconnect” or revoke the authorization.
- Contact Inquiries: Retained on our secure email servers for up to 90 days to resolve support requests, after which they are permanently purged.
21. Disconnecting Integrations & Revoking OAuth Grants
You maintain complete, immediate control over all connected services:
- Within Syntaflow: Open Settings → Integrations, select any connected service, and click Disconnect. All encrypted tokens and cached session metadata are instantly deleted from your machine.
- Within Google Account: You can revoke Syntaflow’s access at any time by visiting Google Security: Third-party apps with account access and removing Syntaflow. Once revoked, Syntaflow can no longer access your Google data.
22. Data Deletion Rights & Procedures
You have the right to request deletion of any personal data we hold. To delete your local application data, you can delete the Syntaflow data directory from your workstation at any time. To request deletion of any inquiry communications or account records, email privacy@syntaflow.tech with the subject “Data Deletion Request”. We fulfill verified deletion requests within 30 days.
23. Security Practices & Defense-in-Depth
We employ comprehensive technical and architectural security controls:
- Electron Privilege Boundary: The user-facing renderer operates in a sandboxed context with zero direct Node.js or filesystem access. All privileged interactions traverse a typed preload IPC bridge.
- OS Cryptographic Vaults: Secret tokens are protected using DPAPI / Keychain encryption.
- Transport Layer Security: All API requests use TLS 1.3 encryption in transit.
- Automated Test Suites: Security boundaries, preload isolation, and token redactions are verified continuously by automated unit and integration tests.
24. International Processing, Children’s Privacy, Policy Updates & Contact
Children’s Privacy: Syntaflow is professional workstation software not directed to individuals under the age of 16. We do not knowingly collect personal data from children.
Changes to this Policy: We may update this Privacy Policy from time to time to reflect product enhancements or regulatory requirements. Material revisions will be posted on this page with an updated effective date.
Privacy Inquiries & Contact: For any questions, data subject requests, or privacy concerns, please contact our privacy team: