Contents
1.Data we process
To operate the platform we process: your account details (name, email, organization) via our authentication provider; Salesforce metadata and org configuration you choose to connect and scan; project, ticket, and audit records you create; files you upload or generate; and operational logs.
We do not sell your data, and we do not use your Salesforce metadata to train shared or third-party models.
2.AI: your key, or AI included
On the Free plan, and on any plan where your workspace uses its own key, AI requests are made with your own provider key and billed to your own provider account, so your prompts and org context do not appear in our AI provider logs. The requests themselves are made by our servers, which is where your org context is assembled. Keys are stored encrypted and can be rotated or revoked at any time from Settings.
On a paid plan that uses included AI, requests are made with SyncOnAI's own accounts with Anthropic or OpenAI instead, and we record how much each request used so we can operate the plan. Neither provider trains on API traffic.
Some deployments are configured with a shared platform AI key instead, for evaluation or managed use. Where that is the case, prompts are billed to our provider account rather than yours. It is off by default and your workspace settings show which key is in use.
3.Tenant isolation
Each customer workspace is isolated by the database itself, not only by the application. Connected org credentials and keys are encrypted with a data key held per workspace, and each data key is protected by a key in Google Cloud KMS. Files are kept in private storage and are only served to members of the workspace they belong to.
4.Data retention and deletion
You can disconnect a Salesforce org at any time, which revokes its tokens and removes its cached metadata. Chat history is not removed by disconnecting an org: it stays in your workspace until you delete it. You can request deletion of your workspace and associated data by contacting us. Backups are retained for a limited window for disaster recovery.
5.Subprocessors
Every company that processes your data is named at /subprocessors, with what each one handles and where it is. That page is the current list; you do not need to ask us for it.
6.Contact
For privacy questions or data requests, contact us at hello@synconai360.com.
Questions about this document? Contact hello@synconai360.com.