Last updated July 22, 2026

Privacy Policy

On this page

This policy describes how Tonning (doing business as Synci, "we", "us"), org. no. 930076066, Nordbø 15, 5009 Bergen, Norway, processes your personal data when you use Synci or visit synci.io. We are the data controller for the processing described here.

Synci lets you fetch, transform, and transfer your own banking, brokerage, and crypto data to destinations you choose. That purpose shapes everything in this policy: we hold as little as possible, for as short a time as possible, and we move data only where you direct it.

Questions? Contact us at support@synci.io.

What we collect

Account data. Name, email address, password (hashed) or passkey, two-factor authentication settings, and your account preferences.

Financial data. Account details (such as account numbers and account holder names), balances, and transactions from the financial institutions you connect. We retrieve this through the data providers listed in section 2, only after you approve the connection through the provider's consent flow. We never see or store your bank login credentials, and our access is read-only.

Payment data. If you subscribe, Stripe processes your payment. We store your plan, invoice history, and the last four digits and brand of your card. Full card details never touch our systems.

Support and feedback. Messages you send us and posts you make on our feedback board, along with your name and email.

Technical data. Log data (IP address, browser, device information, timestamps, actions in the service) collected to run and secure the service. Usage analytics as described in section 6.

We do not buy or collect data about you from data brokers or other outside sources. The only third-party data we receive is the financial data you instruct your institutions to share with us.

Where your financial data comes from

We retrieve financial data through licensed and established connectivity providers. Which provider is used depends on your institution:

GoCardless (GoCardless SAS, France) provides regulated account information services for banks in the UK and Europe. GoCardless is a licensed payment institution supervised by the French ACPR. When you connect a bank through GoCardless, they retrieve your account data with your consent and pass it to us. You have data protection rights toward GoCardless directly, including the right to object to their processing. Read their Privacy Policy and their Bank Account Data End User Terms.

Akahu (Akahu Limited, New Zealand) provides the same role for New Zealand banks, under New Zealand's regulatory regime.

SnapTrade (Passiv Inc., Canada) provides connectivity to brokerages and crypto exchanges. When you connect an account through SnapTrade, you also accept SnapTrade's own End User Terms, which govern their handling of your data.

In each case, the provider acts as its own data controller under its own terms and regulatory obligations. We receive the data they retrieve at your instruction and process it as described in this policy.

To provide Synci (Art. 6(1)(b) GDPR, contract): fetching your financial data, running your rules and transfers, delivering data to your destinations, managing your account, and billing.

To meet legal obligations (Art. 6(1)(c)): keeping accounting records as required by Norwegian bookkeeping law.

With your consent (Art. 6(1)(a)): identified product analytics (section 6), optional transaction enrichment (section 4), and any other processing we explicitly ask you about. You can withdraw consent at any time, with effect going forward.

Based on our legitimate interests (Art. 6(1)(f)): anonymous usage measurement (section 6), responding to support requests, securing the service and preventing fraud, sending changelog and product update emails to users (every email has an unsubscribe link, and we stop when you unsubscribe or delete your account), and anonymized, aggregated analysis to improve the service. You have the right to object to processing based on legitimate interests.

We do not use your data for automated decision-making with legal effects, and we never sell personal data.

Transaction enrichment and AI features

Enrichment cleans up transaction data: proper merchant names, logos, and categories. It is strictly opt-in, available on the Pro plan, and can be switched on or off per financial account in your settings at any time.

When enrichment is on, we send the minimum data needed to our enrichment providers: transaction descriptions, amounts, dates, currencies, and counterparty names. Your identity is pseudonymized toward these providers; they receive an internal reference, never your name or email. Note that transaction descriptions and counterparty names can themselves contain personal information, such as the name of a person you paid.

Our enrichment providers process this data on our instructions as data processors:

  • Ntropy, via their EU processing endpoint.
  • Microsoft Azure AI Foundry (OpenAI models), deployed in Sweden. Your data is not used to train models.

AI assistants and destinations you connect

Separately from the features above, you can direct your own data to third parties you choose:

Destinations. You can create transfer links that send selected data to tools like YNAB, Lunch Money, Actual Budget, Google Sheets, Zapier, or your own webhooks.

AI assistants and other clients. You can connect third-party clients, including AI assistants such as Claude, through the Model Context Protocol (MCP) or our API. The data you request through such a client is transmitted to the provider operating it.

In both cases, you decide what is shared, the connection is scoped to the accounts and data you select, and you can revoke it at any time in your settings. Once data reaches a destination or client you connected, it is governed by that provider's own privacy terms, which we do not control. These providers act at your direction, not ours.

Cookies and analytics

We built our own consent system. Non-essential cookies and identified tracking are off until you say yes, and you can change your choices at any time, on the website and inside the app. Your preferences are stored on our servers so they follow you across devices.

Analytics runs in two modes:

With your consent, we use PostHog (EU-hosted) for identified product analytics, including session replays. All text in session replays is masked, so the content of your financial data never appears in them. If you withdraw consent, we unlink your identity and stop identified tracking.

Without consent, we collect only anonymous, cookieless usage events that cannot be tied to you. We use this to understand aggregate product usage, based on our legitimate interest. You can object by contacting us.

To measure whether our ad campaigns work, we import aggregate campaign statistics (impressions, clicks, spend) from the ad platforms we advertise on, currently Reddit Ads, into our analytics. This data describes our campaigns, not you, and we do not send any data about you to ad platforms.

Details are in our Cookie Notice.

Who we share data with

We share personal data with service providers that process it on our behalf, under data processing agreements, and only as needed to run Synci:

  • Infrastructure: DigitalOcean (backend and database, EU), Vercel (frontend), Cloudflare (network and security)
  • Enrichment: Ntropy, Microsoft Azure (section 4)
  • Email: Resend (primary), Mailgun (backup), Google Workspace
  • Support and feedback: Featurebase (EU-hosted)
  • Analytics and monitoring: PostHog (EU-hosted), Laravel Nightwatch
  • Accounting: Fiken

Stripe processes payments as an independent controller under its own terms, acting as merchant of record for purchases.

Beyond that, we share data only: with the financial data providers and destinations you connect (sections 2 and 5); if required by law or a competent authority; or as part of a business transfer such as a merger or acquisition, in which case this policy continues to apply to your data.

International transfers

We keep processing inside the EEA wherever possible. Our servers are in the EU, and our enrichment, analytics, and support providers process data in the EU.

Some providers involve transfers outside the EEA: Akahu operates from New Zealand and SnapTrade from Canada, both countries covered by EU adequacy decisions. US-based providers (such as Google, Resend, Mailgun, and Cloudflare) are covered by the EU-US Data Privacy Framework and/or the European Commission's Standard Contractual Clauses. Copies of relevant safeguards are available on request.

How long we keep your data

Financial data has its own strict retention window. Every transaction, balance, and log we fetch is stored only for the length of your retention setting, measured from when we fetch it, then permanently deleted. No soft deletes, no retained copies. You control the window in Settings, from a minimum of 7 days (needed to prevent sync errors and duplicates) up to your plan's maximum. Deletion covers transactions, balances, transfer logs, rule logs, and bank logs. Your connections and accounts remain until you remove them. Data already delivered to a destination you connected is outside our systems and follows that destination's practices.

Everything else:

  • Account data: until you delete your account.
  • Invoices and accounting records: 5 years, as required by Norwegian bookkeeping law.
  • Support conversations: deleted on request or account deletion, and purged after 24 months of inactivity.
  • Public feedback posts (feature requests, comments, votes): anonymized when you delete your account, so the content remains without any link to you; deleted or redacted entirely on request.
  • Security and access logs: up to 12 months, so we can investigate incidents.
  • Consent records: kept as proof of lawful processing.

When you delete your account, we delete your personal data from active systems promptly and from backups in the ordinary backup cycle, keeping only what law requires us to keep and the minimum needed to prevent fraud and abuse, resolve disputes, or enforce our agreements.

How we protect your data

Sensitive fields, including account numbers, balances, and access tokens, are encrypted at the field level on top of full encryption at rest and in transit. We never store bank credentials, and our provider access is read-only. Further details about our technical safeguards are in our Security overview.

No system is perfectly secure, and we cannot guarantee that unauthorized access will never occur. If a breach affects your data and poses a high risk to you, we will inform you and the Norwegian Data Protection Authority as required by law.

Your rights

Under the GDPR (and the UK GDPR if you are in the UK), you have the right to access your data, correct it, delete it, restrict or object to processing, receive a copy in a portable format, and withdraw any consent at any time. Most of this you can do directly in the app; for anything else, email support@synci.io and we will respond within 30 days.

If you believe we process your data unlawfully, you can complain to Datatilsynet (the Norwegian Data Protection Authority, datatilsynet.no) or your local supervisory authority.

Minors

Synci is not for anyone under 18. We do not knowingly process children's data; if you believe we hold any, contact us and we will delete it.

Changes to this policy

We will update this policy when our practices change. The date at the top always reflects the current version, and we will notify you of material changes in the app or by email.

Contact

Tonning (Synci)
Nordbø 15
5009 Bergen, Norway
support@synci.io