S Syntora

Privacy Policy

Syntora records heart rate, sleep, blood oxygen and the routes you run. This document sets out exactly what we collect, where it goes, and how to get it back or have it erased.

Last updated8 September 2026
Effective8 September 2026
Applies toSyntora for Android & iOS
Version1.0.10
Draft — not yet ready for Google Play. Every HIGHLIGHTED FIELD below must be replaced with real details before this URL is submitted to Play Console. Google rejects policies containing placeholders.

01 Who we are

Syntora (“Syntora”, “the app”, “we”, “us”, “our”) is a fitness, activity and wellness tracking application developed and published by Mohan Dhass, an individual developer based in India.

For the purposes of India's Digital Personal Data Protection Act, 2023 (“DPDP Act”) we are the Data Fiduciary for your personal data. For the purposes of the EU and UK General Data Protection Regulation (“GDPR”) we are the Data Controller.

Syntora handles health information and location data, which are sensitive by nature. This policy explains what we collect, why, who it goes to, and what control you have over it.

02 The short version

  • Syntora collects what you enter, what your phone measures, and what your connected smartwatch reads. That includes health data — heart rate, blood oxygen, blood pressure, sleep, stress — and precise GPS location during outdoor runs.
  • We use it to run the features you asked for: tracking workouts, mapping runs, logging meals and water, syncing your watch, and connecting you with friends.
  • We do not sell your personal data. We do not share it with advertisers or data brokers, and we do not use it for advertising or ad profiling.
  • Your data is stored on infrastructure run by Supabase, Google Firebase and Vercel on our behalf.
  • You can request access, correction, export or deletion at any time by emailing SUPPORT EMAIL.
  • Syntora is not intended for anyone under 18.

03 Information we collect

3.1  Account and identity

Data Why we need it
Email address To create your account, sign you in, and contact you about it
Display name and handle To identify you in the app and to friends
Google account identifier and basic profile To authenticate you if you use Google Sign-In, without a separate password
Authentication and session tokens To keep you signed in securely
Account creation date, last sign-in time Security, fraud prevention and account support

You can sign in either with Google Sign-In or with a one-time code sent to your email. If you use Google Sign-In, Google shares your email address, name and profile identifier with us. We never receive your Google password.

3.2  Profile and body measurements Sensitive

  • Height and weight
  • Body fat percentage and muscle percentage
  • Fitness goal, training level, and self-selected tags
  • Short biography and a self-declared location, such as a city name you type in
  • Daily calorie-burn goal and daily hydration goal

3.3  Health and wellness measurements Special category

When you connect a compatible wearable (such as a QWatch band) over Bluetooth, or when your phone's sensors record activity, we collect and store:

Measurement Unit Source
Heart rate bpm Wearable
Heart rate variability ms Wearable
Blood oxygen saturation % SpO₂ Wearable
Blood pressure mmHg systolic / diastolic Wearable
Stress level index Wearable
Sleep duration and stages deep / light / awake segments Wearable
Steps count Wearable or phone pedometer
Distance km Wearable, pedometer or GPS
Calories burned kcal Derived from activity

Each reading is stored with its timestamp, unit, source device and the session it belongs to.

3.4  Precise location Sensitive

When you start an outdoor run or cardio session, Syntora collects precise GPS location in order to map and measure that activity. We record your starting coordinates, your destination if you set one, the route you follow as a series of coordinate points, and the distance, pace, elapsed time and calories for that route.

Limits on location collection

  • Location is collected only while an outdoor session is actively running in the foreground.
  • Syntora does not request or use background location, and does not track you when a session is not running.
  • Workouts, meals, hydration, watch sync and treadmill mode all work without granting location permission at all.

3.5  Activity and workouts

  • Workouts you perform, create or edit — exercises, sets, repetitions and duration
  • Workout plans you follow and your completion history
  • Cardio and running sessions: duration, distance, average pace, steps and calories
  • Treadmill sessions: the speed and incline values you enter
  • Scheduled sessions and reminders, and whether a session was completed, cancelled, abandoned or missed

3.6  Nutrition and hydration Sensitive

  • Meals you log: meal name, food name, meal type and time of day
  • Calories and macronutrients — protein, carbohydrates, fat
  • Water intake entries and your daily hydration totals

3.7  Connected wearable

  • The device's Bluetooth identifier, name and model
  • Battery level, connection status, and last connection and sync timestamps
  • Technical metadata needed to sync readings correctly

Bluetooth scanning in Syntora is declared to Android as not used for deriving location.

3.8  Social features

  • Friend requests you send and receive, and their status
  • Content you choose to share to the community or workout feed

Anything you post to a shared feed is visible to other users. Please do not post information you would not want others to see.

3.9  Device and diagnostic data

  • Device model, operating system and version, and platform
  • App version and build identifiers
  • A Firebase Cloud Messaging registration token, used to deliver push notifications
  • IP address, request metadata and timestamps when the app contacts our servers
  • Diagnostic and error logs, including error messages, stack traces and the request that failed

We use diagnostic data to detect crashes, fix defects, and keep the service reliable and secure.

3.10  Files we read but never upload Stays on device

If you attach media to a custom workout, or pick music for treadmill playback, Syntora reads those files from your device only. The files themselves are not uploaded to our servers — the app saves only a reference to where the file sits on your device, and plays or displays it locally.

3.11  What we do not collect

  • We do not collect your contacts, call logs, SMS messages or camera roll.
  • We do not collect background location.
  • We do not use advertising identifiers, and Syntora contains no third-party advertising SDKs.
  • We do not collect payment card details.

04 Permissions we request

Android asks you to approve each of these. You can decline or revoke any of them under Settings → Apps → Syntora → Permissions, and the app keeps working with the related feature disabled.

Permission Used for If you decline
Location, precise & approximate Mapping and measuring outdoor runs while they are active Outdoor run mapping is unavailable; everything else works
Physical activity Reading your phone's step counter for daily steps Phone step counting is unavailable
Nearby devices & Bluetooth Finding your wearable and syncing its readings Watch pairing and health sync are unavailable
Notifications Session reminders and ongoing-session controls You receive no reminders or push notifications
Files and media Letting you pick workout media or music from your own storage You cannot attach your own media or music
Internet access Syncing your data, signing in and loading maps The app cannot sync or sign in

05 How we use it, and why

Purpose Data used Legal basis (GDPR) Basis (DPDP Act)
Creating and securing your account Account and identity Contract, Art. 6(1)(b) Consent for a lawful purpose
Tracking workouts, steps, runs, meals, hydration Activity, health, nutrition, location Explicit consent, Art. 9(2)(a), for health data; contract for the rest Consent
Syncing and displaying wearable readings Health and device data Explicit consent, Art. 9(2)(a) Consent
Mapping outdoor runs Precise location Consent, Art. 6(1)(a) Consent
Session reminders and notifications Device token, session data Consent, Art. 6(1)(a) Consent
Friend requests and community features Account and social data Contract, Art. 6(1)(b) Consent
Fixing bugs, preventing abuse, keeping the service secure Diagnostic and technical Legitimate interests, Art. 6(1)(f) Legitimate use
Complying with legal obligations As required Legal obligation, Art. 6(1)(c) Legal obligation

Where we rely on consent, you may withdraw it at any time — by revoking the relevant Android permission, disconnecting your wearable, or contacting us. Withdrawing consent does not affect processing that already took place lawfully.

We do not use your data for automated decision-making that produces legal or similarly significant effects, and we do not build advertising profiles.

06 Who we share it with

We do not sell your personal data, and we do not share it with advertisers or data brokers. We share data only with the service providers below, who process it on our instructions in order to run Syntora.

Provider Role Data involved
Supabase, Inc. Authentication and primary database hosting Account, profile, health, activity, nutrition, location and social data
Google LLC — Firebase Cloud Messaging Delivering push notifications Device push token, device and app metadata
Google LLC — Google Sign-In Authenticating you, if you choose it Email, name, Google account identifier
Vercel Inc. Hosting our backend API Data passing through API requests; diagnostic logs
Shorebird Delivering over-the-air app updates App version and update-check metadata; no personal fitness data
OpenStreetMap Foundation Supplying the map tiles shown during runs Tile requests reveal the approximate map area you are viewing
Google Play App distribution Handled under Google's own privacy policy

Each provider is bound by contract to protect your data and to use it only for the purposes we specify.

We may also disclose data where we are legally required to — in response to a valid court order, lawful government request or legal obligation — or where necessary to establish, exercise or defend legal claims, or to protect the rights and safety of our users. If Syntora is ever sold or merged, your data may transfer to the acquirer; we will notify you before that happens and before any different privacy policy takes effect.

07 International transfers

Our service providers operate data centres outside India, including in the European Union and the United States. Your personal data — including health and location data — may therefore be transferred to, stored in and processed in countries outside your own.

  • For transfers out of the EU/UK, we rely on the European Commission's Standard Contractual Clauses — and the UK Addendum where applicable — together with the safeguards our providers maintain.
  • For transfers from India, we transfer only to countries not restricted by the Central Government under Section 16 of the DPDP Act.

You may request a copy of the relevant safeguards by contacting us.

08 Payments

Syntora is free to use at launch. We do not currently charge for the app and we do not process any payments.

If we introduce paid subscriptions in future, they will be billed through Google Play Billing. Google — not Syntora — would process your payment. We would never receive or store your card number, CVV or bank details; only a confirmation of your subscription status. We will update this policy before any paid feature goes live.

09 How long we keep it

Data Retention
Account and profile For as long as your account is active
Health, activity, nutrition and run history For as long as your account is active, so you can see progress over time
Diagnostic and API logs Up to 90 days, then deleted or anonymised
Push notification tokens Until replaced, until the app is uninstalled, or until the token becomes invalid
Data we must keep by law For the period the law requires

When you delete your account we delete or irreversibly anonymise your personal data within 30 days, except where we are legally required to keep it. Backups are purged on our normal rotation, within 90 days.

10 Deleting your account

How to delete your account

In the app. Open Profile, scroll to Delete account, tap Delete my account and confirm. The deletion runs straight away and cannot be undone.

By email. If you can no longer sign in, email mohandhass28@gmail.com from the address registered to your Syntora account, with the subject line “Delete my account”. We will confirm the request, verify your identity, and complete the deletion within 30 days. We will tell you when it is done.

What gets deleted: your account and login credentials, profile and body measurements, all health and wearable readings, all workout, run and route history, all meal and hydration logs, your friend connections and requests, and your push notification tokens.

What may be retained: anonymised or aggregated statistics that can no longer identify you, and any records we are legally obliged to keep.

You can also stop all data collection at any time by revoking permissions in Android settings, disconnecting your wearable, or uninstalling the app — though uninstalling alone does not delete data already held on our servers.

11 Your rights

11.1  If you are in India — DPDP Act, 2023

  • Access a summary of the personal data we process about you and the processing we undertake
  • Correct, complete, update or erase your personal data
  • Nominate another individual to exercise your rights in the event of your death or incapacity
  • Withdraw consent as easily as you gave it
  • Grievance redressal — raise a complaint with us and, if unsatisfied, escalate to the Data Protection Board of India

Grievance Officer

GRIEVANCE OFFICER NAME  ·  mohandhass28@gmail.com

We acknowledge grievances within 7 days and resolve them within 30 days.

11.2  If you are in the EEA or UK — GDPR

  • Access your personal data and receive a copy of it
  • Rectify inaccurate or incomplete data
  • Erase your data — the “right to be forgotten”
  • Restrict processing in certain circumstances
  • Data portability — receive your data in a structured, commonly used, machine-readable format
  • Object to processing based on legitimate interests
  • Withdraw consent at any time, without affecting the lawfulness of prior processing
  • Lodge a complaint with your national supervisory authority — in the UK, the Information Commissioner's Office

11.3  How to exercise them

Email mohandhass28@gmail.com. We respond within 30 days. We may need to verify your identity first, to be sure we are not disclosing your health data to someone else. Exercising your rights is free; we may charge a reasonable fee only for manifestly unfounded or excessive repeat requests.

12 How we protect it

  • All traffic between the app and our servers is encrypted in transit using HTTPS/TLS.
  • Data at rest is encrypted by our infrastructure providers.
  • Access to production data is restricted to authorised personnel behind authentication controls.
  • Database-level access rules scope each user to their own records, so one user cannot read another user's health, workout or location data.
  • Authentication is handled by an established identity provider; we never store your password in plain text.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a personal data breach occurs that is likely to affect you, we will notify you and the relevant authorities as required — including the Data Protection Board of India under the DPDP Act, and within 72 hours to the supervisory authority under the GDPR.

13 Children's privacy

Syntora is not intended for anyone under the age of 18. We do not knowingly collect personal data from children.

Under the DPDP Act, processing a child's data requires verifiable parental consent, and behavioural tracking and targeted advertising directed at children are prohibited. Syntora does neither.

If you believe a child has provided us with personal data, contact mohandhass28@gmail.com and we will delete it promptly.

14 Third-party links

Syntora may link out to third-party services — for example, opening a route in Google Maps. Those services have their own privacy policies, and this policy does not cover them. We encourage you to read the policy of any third-party service you use.

15 Changes to this policy

We may update this Privacy Policy from time to time. When we do, we revise the “Last updated” date at the top.

If we make a material change — collecting a new category of sensitive data, say, or using your data for a new purpose — we will notify you in the app or by email before the change takes effect, and where the law requires it, we will ask for your consent again.

Your continued use of Syntora after a change takes effect means you accept the revised policy.

16 Contact us

Questions, requests or complaints about this policy or your personal data:

Mohan Dhass

Email: mohandhass28@gmail.com

We aim to respond to every enquiry within 7 days, and to resolve requests within 30 days.