1. Scope and responsibility
This Privacy Policy applies to the Yavisynker website, account service, desktop application, billing features, installer distribution, and device-connection services (together, the “Service”). In this policy, “Yavisynker,” “we,” “us,” and “our” refer to the operator of the Service identified in your account, checkout, receipt, or other service communication.
For account, device, billing, security, and website information, Yavisynker determines why and how that information is processed and acts as the responsible data controller or data user where those terms apply. You remain responsible for the files and other content you choose to synchronize between your devices.
This policy does not govern third-party websites or services that have their own privacy terms, including Stripe-hosted checkout and billing pages.
2. What happens to your synchronized files
Yavisynker does not keep a persistent server copy of active synchronized file content, filenames, or file manifests. Current file manifests and file blocks move directly between authenticated devices over an encrypted WebRTC data channel. The control service helps your devices find and authenticate one another; it is not a cloud drive or a backup destination.
- Your synchronized files remain in the local folders you select on your devices.
- Participating devices receive the filenames, manifests, and content needed to synchronize.
- If every device holding a file is offline or unreachable, synchronization waits.
- Device software keeps local reconciliation information, peer identity pins, and configuration needed to detect changes and resume synchronization.
- Earlier cloud-era releases may have left protected legacy data in inactive storage for controlled migration or deletion. It is not part of the active device-only sync path.
Because your devices hold the primary copy, you should maintain an independent backup of important files. Learn more on How it works.
3. Personal data we process
Account and authentication data
Your display name, email address, password hash, account identifier, role, account status, registration date, and session information. We do not store your password in readable form. The website stores access and refresh tokens in your browser's local storage so you can remain signed in; these are not advertising cookies.
Device and connection data
Device identifiers, device names, platform, public device identity keys, presence and last-seen times, signed connection-setup messages, WebRTC negotiation identifiers, and network candidates such as IP addresses and ports. A connected device may learn the reachable network candidates of another device on the same account, and a STUN provider may observe the public address used for connectivity discovery.
Billing and referral data
Plan, subscription status, billing period, Stripe customer/subscription references, checkout outcome, referral code and relationship, qualification events, credits, and processed billing event identifiers. Payment card and bank details are entered on Stripe-hosted pages and are handled by Stripe rather than stored by Yavisynker.
Security, support, and operational data
Request IP address, user agent, timestamps, authentication and administrative events, rate-limit records, error classifications, installer download authorizations, and communications you send to the operator. Security logs are designed not to contain passwords, session secrets, private device keys, or synchronized file contents.
4. How we collect personal data
We receive information from:
- You, when you register, sign in, choose a plan, contact us, or configure a device.
- Your devices and browser, when they authenticate, report presence, request an installer, or establish a direct connection.
- Other devices on your account, when they address a signed connection message or successful-sync qualification event to your device.
- Stripe, when it reports checkout, subscription, invoice, payment, refund, or billing-portal events.
- A referrer or referred user, when a referral link is used and the stated qualification event occurs.
We do not buy personal-data lists or use third-party advertising profiles.
5. Why we use personal data
We use personal data only where reasonably necessary to:
- create and secure your account, maintain sessions, and authenticate registered devices;
- coordinate presence and short-lived signaling so your devices can attempt a direct connection;
- provide downloads, subscriptions, invoices, plan capacity, trials, and referral rewards;
- operate, troubleshoot, protect, and improve the reliability and security of the Service;
- prevent fraud, abuse, unauthorized access, and violations of our Terms and Conditions;
- respond to support, privacy, billing, legal, or regulatory requests; and
- comply with applicable law and establish, exercise, or defend legal claims.
Depending on where you live, our legal grounds may include performing our contract with you, pursuing legitimate interests in operating and securing the Service, complying with legal obligations, protecting vital interests, or your consent where consent is required. You may withdraw consent for future processing, but withdrawal does not make earlier lawful processing unlawful and does not affect processing needed for another valid legal ground.
7. Storage and retention
We keep personal data only for as long as needed for the purpose described above, including:
- access tokens normally expire after about one hour and refresh sessions after about 30 days, unless rotated or revoked earlier;
- device presence normally expires after about 60 seconds without a heartbeat;
- connection-signaling messages normally expire after about 120 seconds and are deleted after acknowledgement or expiry;
- installer download authorizations normally expire after about 60 seconds;
- account, device, subscription, and referral records are kept while the account is active and afterward where needed for billing, fraud prevention, dispute resolution, legal obligations, or a requested account closure;
- audit, rate-limit, backup, and security records are retained for a proportionate period based on operational, security, and legal need; and
- Stripe keeps payment and transaction information according to its own legal obligations and retention practices.
Removing the desktop application does not automatically delete your service account. Deleting an account does not delete synchronized files from your local device folders; those files remain under your control. Backup copies of service records may remain until their normal backup cycle expires.
8. How we protect information
Yavisynker uses technical and organizational safeguards appropriate to the information and risk. Measures include HTTPS for the control service, adaptive password hashing, rotating sessions, rate limits, account-scoped device access, signed device setup messages, locally pinned device identities, WebRTC DTLS encryption in transit, bounded short-lived signaling, and integrity checks on transferred blocks and rebuilt files.
Private device identity keys and synchronized files remain on your device. The desktop application uses operating-system protection for supported local secrets, but files at rest receive the protection provided by your operating system, disk encryption, account security, and backups. No system is perfectly secure; notify the operator promptly if you believe your account or device has been compromised.
9. Your choices and privacy rights
Subject to applicable law and relevant exceptions, you may ask to:
- access personal data held about you and receive information about its processing;
- correct inaccurate or incomplete information;
- delete information or close your account;
- restrict or object to particular processing;
- receive portable account information where required;
- withdraw consent where processing depends on consent; and
- complain to the privacy or data-protection authority responsible for your location.
You can update some account and billing information through the Service or Stripe billing portal, remove registered devices, sign out to revoke the current session, and clear browser local storage. We may need to verify your identity before completing a privacy request. Certain records may be retained where law permits or requires, including records needed for billing, security, fraud prevention, or legal claims.
Malaysian users can read the official Personal Data Protection Principles. Users in the EEA can review the European Commission's summary of individual rights.
10. Children
The Service is intended for adults and organizations and is not directed to children. You must be old enough to form a binding contract in your location. If you believe a child provided personal data without the authorization required by applicable law, contact the operator so the situation can be reviewed and appropriate action taken.
11. Changes and contact
We may update this policy when the Service, providers, or legal requirements change. Material changes will be communicated through the Service or another reasonable channel before they take effect when required. The effective date at the top identifies the current version.
For a privacy request or question, use the operator contact shown in your Yavisynker account, checkout, receipt, or service communication. Include the email address associated with your account and enough detail to understand the request, but never send your password, refresh token, private device key, or synchronized file contents. If you cannot access your account, use the current operator contact published for yavisynker.yavinesh.com.
This policy should be read with the Terms and Conditions.