Privacy Policy

Version 2.0 · Effective 22 July 2026

1. Who we are & what StayInSync does

StayInSync is an AI-powered email digest service. With your consent, we securely connect to your email inbox(es), read incoming messages, filter the ones that match your chosen categories (school, family, finance, travel, etc.), summarise them, and deliver a concise digest to you on WhatsApp. Nothing is posted, sent, replied to, or shared on your behalf.

2. Consent — the basis on which we process your data

We rely on your explicit, informed, specific consent under the Digital Personal Data Protection Act, 2023 (DPDP Act) as the primary legal basis for processing your personal data. You give consent in three distinct places, each optional and independently revocable:

  • At signup — you agree to this Privacy Policy and our Terms.
  • At inbox connection — you separately authorise StayInSync to access email headers (subject line and sender) in that specific inbox for the sole purpose of generating your digest. Email content is never accessed.
  • At WhatsApp verification — you authorise us to deliver your digest to that WhatsApp number.

You can withdraw any of these consents at any time from your dashboard. Withdrawal does not affect the lawfulness of processing done before the withdrawal.

3. Data we collect

  • Account data: your name, email address, WhatsApp number, password hash (never the plaintext password), and preferences.
  • Family & category configuration: optional details you add — child names, school/grade, categories you want tracked, keywords, sender domains.
  • Mailbox access tokens: OAuth access and refresh tokens for the Gmail / Outlook accounts you connect. These tokens are encrypted at rest. We never see, ask for, or store your email password.
  • Email content read on your behalf: to build your digest, our system reads messages from your connected inbox(es) using Google's read-only gmail.readonly scope — sender, subject, timestamps and message text. We never send, delete, label or modify anything. See Section 4 for exactly what we retain.
  • Digest history: the summaries we generate and deliver.
  • Delivery & operational logs: WhatsApp message delivery status, error logs, digest schedule status, IP address, browser/device fingerprint (for security and abuse prevention).
  • Payment metadata: if you subscribe, our payment partner (Razorpay) collects and processes your payment details. We only receive metadata (plan, status, subscription id, invoice) — we never see or store your card, UPI, or bank details.

We do not knowingly collect location data, biometric data, health data, or data of children under 18. If you configure a child's name and grade for digest grouping, that information is treated as your personal preference — we do not create a profile of the child.

4. What we do — and do not — retain from your emails

What Gmail data we access: StayInSync connects to your Gmail inbox using Google OAuth 2.0. We request the gmail.readonly scope — read-only access. It allows reading only: StayInSync can never send, delete, label or modify any message in your mailbox.

We read the sender, subject, timestamp and message text of emails that match the filters you configure. We do not download or store attachments. Access is read-only and used solely to build your digest.

What we do with this data: the sender, subject and message text are used exclusively to identify school-related communications and generate your daily WhatsApp digest summary. This information is processed by our AI engine (Anthropic Claude API) to classify emails into urgency tiers — Urgent, Events and General — and generate a one-line parent-friendly summary for each relevant email. We never sell your data and never use it to train AI models.

What we retain: only the generated digest summary, along with lightweight references (subject line and sender) to the emails that were selected for that digest. This lets you review past digests and lets our system avoid re-summarising the same message.

What we never do:

  • Never read email body content.
  • Never access email attachments.
  • Never store raw email headers beyond the current digest cycle.
  • Never share your email data with third parties for any purpose other than AI summarisation.
  • Never use your email data for advertising or profiling.
  • Never train AI models on your email data.

What we ignore: personal correspondence, chat threads, private messages, one-to-one conversations, and any category you have not enabled are ignored during classification.

5. How we use your data

Your data is used only to operate the Service:

  • Authenticating you and securing your account.
  • Fetching, filtering, classifying, and summarising your emails per the categories you have enabled.
  • Delivering your digest on WhatsApp at the schedule you configure.
  • Sending you critical service notifications (delivery failures, security alerts, billing).
  • Debugging and improving reliability of the Service.
  • Complying with legal obligations.

We do not use your subject line and sender information, digest content, or personal data for advertising, marketing profiling, or resale to third parties.

6. AI processing — what you should know

To generate summaries, only email header data — subject line and sender information — is sent to our large-language-model provider (currently the Anthropic Claude API). Email body content is never accessed and therefore never sent. We take the following safeguards:

  • We send only subject lines and sender information — never email body content or attachments.
  • We use enterprise / API-mode endpoints under a data processing agreement where the provider contractually agrees not to train their models on our data.
  • We do not permit the AI provider to log or retain the prompt beyond the transient window required to return a response.
  • We never send payment credentials, passwords, or one-time codes to the AI provider.

7. Limited Use Compliance Statement (Google User Data)

The use of raw or derived user data received from Google Workspace APIs, including Gmail, will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

StayInSync accesses Gmail data solely to identify and summarise relevant communications for the authenticated user. Gmail data is:

  • Never used to train AI or ML models.
  • Never transferred to third parties for advertising, data brokerage, or any purpose other than delivering the digest service to the user who granted access.
  • Processed in memory and not stored permanently after summarisation.
  • Never shared with or sold to any third party.

The AI summarisation service (Anthropic Claude API) processes only subject line and sender information and short 25–30 word summaries — never email body content — and operates under Anthropic's enterprise data processing agreement which prohibits training on customer data.

We do not allow humans to read Gmail data unless we have your explicit consent, it is necessary for security purposes (such as investigating abuse), to comply with applicable law, or the data has been aggregated and anonymised.

Gmail access is limited to the gmail.readonly scope — read-only, never send/modify/delete — and can be revoked at any time from your dashboard or from your Google Account permissions.

8. Third-party service providers (Data Fiduciaries & Processors)

We rely on the following processors, each bound by their own privacy commitments and data-processing terms:

  • Google LLC — Gmail API (read-only access, gmail.readonly scope), OAuth authentication.
  • Microsoft Corporation — Outlook / Microsoft Graph API (read-only email access).
  • Meta Platforms, Inc. — WhatsApp Business Cloud API (digest delivery).
  • Supabase, Inc. — managed database, authentication, and storage.
  • Cloudflare, Inc. — hosting, edge compute, CDN, and DDoS protection.
  • Razorpay Software Pvt Ltd — payment processing for paid plans.
  • Google, OpenAI or comparable LLM providers — AI summarisation (see Section 6).
  • Resend / SES or comparable — transactional email delivery (verification, password reset).

Each processor accesses your data strictly to fulfil the sub-processing task described above.

9. Data security

  • All traffic between your device, StayInSync, and our processors is encrypted in transit (TLS 1.2+).
  • OAuth tokens and personal data are encrypted at rest.
  • Access to production systems is restricted to authorised personnel, protected by strong authentication and audit logging.
  • Row-level security policies enforce that one user's data can never be read by another user through the application.
  • We regularly review dependencies for known vulnerabilities and patch promptly.

No system is perfectly secure. If we ever become aware of a personal-data breach affecting you, we will notify you and the Data Protection Board of India as required under Section 8(6) of the DPDP Act.

10. Data retention & deletion

  • Account & preferences: retained while your account is active.
  • OAuth tokens: retained until you disconnect the inbox or delete your account.
  • Digest history & message references: retained for up to 90 days from generation, then automatically purged. You may delete individual digests earlier from your dashboard.
  • Full email bodies: not retained (see Section 4).
  • Operational logs: retained for up to 30 days for troubleshooting and security.
  • Payment records: retained for the period required by applicable tax/accounting law (typically 7 years in India).

On account deletion, all personal data other than what we are legally required to retain (e.g. tax invoices) is deleted within 30 days.

11. Your rights under the DPDP Act

As a Data Principal, you have the right to:

  • Access a summary of the personal data we hold about you.
  • Correct, update, or complete your personal data.
  • Erase your personal data (subject to legal retention requirements).
  • Withdraw a previously given consent at any time.
  • Nominate another individual to exercise these rights on your behalf in the event of death or incapacity.
  • Register a grievance with us and, if unsatisfied, escalate to the Data Protection Board of India.

Most of these actions can be performed directly from your dashboard. For anything you cannot self-serve, email us at support@solutionist.co.in and we will respond within 30 days.

12. Children

StayInSync is intended for use by adults (18+). We do not knowingly create accounts for children. Child names and grades entered by a parent are used solely as labels to group the parent's own digest and are not treated as an independent child profile.

13. International transfers

Our processors (Google, Microsoft, Meta, Supabase, Cloudflare, LLM providers, Razorpay) may process your data on servers located outside India. Where this happens, we rely on their contractual and technical safeguards to ensure your data is protected to a standard comparable to the DPDP Act.

14. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will bump the version number, update the effective date at the top of this page, and prompt you to review and re-accept the policy the next time you sign in. Continued use of the Service after acceptance constitutes agreement to the updated policy.

15. Grievance officer & contact

For any question, concern, or grievance regarding this policy or your personal data, please contact:

Solutionist
Bengaluru, Karnataka, India
Email: support@solutionist.co.in

If you are not satisfied with our response, you may lodge a complaint with the Data Protection Board of India under the DPDP Act, 2023.

16. Governing law

This Privacy Policy is governed by the laws of India. Any dispute arising out of or in connection with it is subject to the exclusive jurisdiction of the competent courts at Bengaluru, Karnataka.