This Privacy Policy describes how Syntara ("we", "us", "our") collects, uses, and protects your personal data when you use the Syntara application and service. We are the controller of your personal data in accordance with applicable data-protection laws, including Russian Federal Law No. 152-FZ "On Personal Data".
1. Data We Collect
When you use Syntara, we may collect the following categories of data:
- Account data: phone number, email, username, display name, avatar, profile bio.
- Messages: text and media messages, attachments, metadata (time, delivery status). Secret-chat content is end-to-end encrypted on your device and we have no access to its decrypted form.
- Calls: call metadata (participants, duration, time); the audio/video stream itself is real-time and not retained.
- Contacts: phone numbers and email addresses from your address book — only with your explicit consent. See section 2 for details.
- Device data: device model, operating system, app version, push token.
- Network data: IP address, country of connection, last-seen timestamps.
- Analytics data: aggregated app-usage events (sessions, screens opened, feature interactions), performance and crash diagnostics, app version, device model and OS, and approximate region derived from IP. We do NOT collect advertising identifiers (IDFA / Google Advertising ID), and message content is never sent to analytics. See section 6.
2. Address Book Contacts — What Actually Happens
We dedicate a separate section to your address book because it is the most sensitive data we handle.
When we ask for access: we never access your contacts automatically. Before any data leaves your device, the app shows you a consent screen describing exactly what will be uploaded and why. Without your explicit consent, contacts are never transmitted to our servers.
What is transmitted to our servers:
- phone numbers in normalized international format (E.164);
- email addresses in lower case.
Contact names, photos, notes, addresses and any other address book fields are never transmitted to our servers.
How the data is stored: matches with existing Syntara users are saved as references to their accounts (with no additional information from your address book). Phone numbers that do not yet correspond to a Syntara account are stored as SHA-256 hashes — we use these hashes to notify you when one of your contacts joins Syntara. The original (unhashed) phone numbers and email addresses from your address book are not retained on our servers.
How to withdraw consent and delete the data:
- turn contact synchronization off in Settings → Privacy → Contacts;
- delete all previously uploaded hashes and contact references with a single tap on "Delete Uploaded Contacts". After disabling and deleting, your address book is no longer stored on our servers.
3. How We Use the Data
- Providing and improving messenger features — messaging, calling, file sharing.
- Account verification and protection from unauthorized access.
- Delivering push notifications to your device.
- Detecting and preventing spam, fraud and abuse.
- Technical support and troubleshooting.
- Compliance with applicable laws.
- Product analytics — understanding aggregated app usage and stability to improve the service (via Yandex AppMetrica; see section 6).
We do not sell your data, do not use it for advertising, do not collect advertising identifiers and do not share your data with advertising networks or data brokers. Our analytics are limited to aggregated product and stability metrics.
4. Legal Basis for Processing
Personal data is processed on the following legal bases:
- your consent (at registration and when granting access to the address book);
- performance of the service contract (Syntara Terms of Service);
- compliance with applicable law;
- legitimate interests of the operator in keeping the service secure.
5. Storage and Security
Syntara servers are located in the Russian Federation. Initial recording and storage of personal data of Russian citizens is performed in databases located in Russia, in accordance with laws 149-FZ and 242-FZ.
We apply the following safeguards:
- Encryption in transit (TLS 1.2+).
- End-to-end encryption (E2E) for secret chats (X25519 + ChaCha20-Poly1305).
- Sessions bound to specific devices; rotation of authentication tokens.
- Restricted internal access on a least-privilege basis.
- The ability to revoke access for any device at any time.
6. Sharing With Third Parties
We share a limited amount of data with the following categories of recipients:
- Infrastructure providers: Yandex Cloud — application hosting and Yandex Object Storage for media files (located in Russia). These providers offer data protection equivalent to ours.
- Push services: Apple Push Notification service (APNs) and Google Firebase Cloud Messaging (FCM) for delivering notifications. Only the push token, the notification identifier and (unless you disable previews) a brief title are transmitted. Secret-chat content is sent only in encrypted form and is decrypted on your device.
- Analytics service: Yandex AppMetrica — aggregated product analytics and crash diagnostics that help us understand usage and improve the app. AppMetrica receives usage events, diagnostics and basic device/network information (device model, OS, app version, IP-derived approximate region). It does not receive message content, and advertising-identifier collection (IDFA / Google Advertising ID) is disabled in our integration.
- Government authorities: only when required by a lawful request under applicable law.
No data is shared with advertising networks or data brokers.
7. Retention Periods
- Account data — kept until account deletion + 30 days for backup recovery.
- Messages — kept until you delete them or your self-destruct timer expires.
- Network logs (IP) — no longer than 1 year.
- Deleted account — full data erasure within 90 days of the request.
- Contact hashes — deleted on your request or together with your account.
8. Your Rights
You have the right to:
- Access your personal data.
- Rectify inaccurate or incomplete data.
- Delete your account and the associated data via Settings → Account → Delete Account.
- Restrict processing or withdraw consent (including consent to contact synchronization).
- Receive a copy of your data in a machine-readable format. To exercise these rights, contact privacy@getsyntara.me. We respond within 30 days.
9. Children
Syntara is intended for users aged 12 and above. We do not knowingly collect data from children under 12. If you believe a child under 12 has registered an account, please let us know and we will remove the account.
10. Changes to This Policy
For material changes, we will notify you in-app at least 7 days before the changes take effect. The current version is always available on this page.