Skip to content

Privacy Policy

Effective date: [DD.MM.YYYY] Last updated: [DD.MM.YYYY]

Synlit (“Synlit”, “we”, “us”) is operated by:

  • Individual entrepreneur (ИП): [Full name]
  • ОГРНИП: [OGRNIP]
  • ИНН: [INN]
  • Registered address: [address]
  • Contact email for privacy matters: [privacy@synlit.app]

We act as the Operator of personal data within the meaning of Russian Federal Law No. 152-FZ “On Personal Data” and, where applicable to users in the EU/EEA, as the data controller within the meaning of the GDPR.

This Policy explains what personal data we process when you use the Synlit website and application at [https://synlit.app] (the “Service”), why, on what legal basis, and what rights you have.

CategoryExamplesSource
Account dataEmail address, username, password (stored only as a cryptographic hash)You, at registration
Service contentTasks, habits, goals, time-tracking entries, mastery progress, shop items and purchases you createYou, while using the Service
Payment dataSubscription/purchase status, transaction identifiers. Card details are entered on and processed by our payment provider — we do not receive or store full card numbers.You / payment provider
Technical dataIP address, browser and device type, session tokens, log records, approximate time zoneAutomatically, when you use the Service
CommunicationsMessages you send us for supportYou

We do not intentionally collect special categories of data (health, biometrics, political views, etc.) or data of children under the age at which consent is valid in their country. Do not submit such data through the Service.

  • To register and authenticate your account.
  • To provide the core Service (tasks, habits, goals, timers, gamification, shop).
  • To process payments and manage your subscription.
  • To send you service and transactional emails (e.g. email verification, password reset, important notices).
  • To provide support and respond to your requests.
  • To ensure security, prevent fraud and abuse, and keep records required by law.
  • To improve the Service using aggregated or de-identified statistics.

Depending on the situation and your location, we rely on:

  • Your consent (152-FZ art. 6(1)(1); GDPR art. 6(1)(a)) — given when you register and accept this Policy and the Consent form.
  • Performance of a contract with you (the Terms of Service / Public Offer) (GDPR art. 6(1)(b)).
  • Compliance with a legal obligation (e.g. accounting and tax record-keeping) (GDPR art. 6(1)(c)).
  • Legitimate interests in securing and improving the Service, where these do not override your rights (GDPR art. 6(1)(f)).

You may withdraw consent at any time (see §9), which will not affect processing carried out before withdrawal.

We apply organisational and technical measures appropriate to the risk, including access controls, encryption of passwords (hashing), encrypted transport (HTTPS), and restricted access to production systems.

Data localisation (Russian users). In accordance with 152-FZ (art. 18, para. 5), the recording, systematisation, accumulation, storage, updating, and retrieval of personal data of citizens of the Russian Federation is carried out using databases located in the territory of the Russian Federation: [hosting provider / data centre in RF].

We do not sell your personal data. We share it only with service providers who process it on our behalf under a data-processing instruction, and only as needed to run the Service:

RecipientPurposeLocation
[Hosting provider]Primary database and application hosting[Russian Federation]
ResendDelivery of transactional/service emailsUnited States
[Payment provider]Processing payments[country]

We may also disclose data where required by law, court order, or a lawful request from a competent authority.

Some processors are located outside the Russian Federation (e.g. Resend, United States). Before transferring personal data across the border, we comply with 152-FZ art. 12 — including notifying Roskomnadzor of the intended cross-border transfer where required — and, for EU/EEA users, we rely on appropriate GDPR safeguards for international transfers.

We keep personal data for as long as your account exists and for as long as necessary for the purposes above. After you delete your account, we delete or anonymise your personal data within [e.g. 30] days, except where a longer retention period is required by law (e.g. accounting/tax records) or to resolve disputes and enforce our agreements.

Depending on your location, you have the right to:

  • access the personal data we hold about you and learn how it is processed;
  • have inaccurate data corrected and incomplete data completed;
  • have your data deleted (“right to be forgotten”) and your account closed;
  • restrict or object to certain processing;
  • withdraw consent at any time;
  • receive your data in a portable format (GDPR);
  • lodge a complaint with a supervisory authority — Roskomnadzor in Russia, or your local data-protection authority in the EU/EEA.

To exercise any of these, email us at [privacy@synlit.app]. We respond within the timeframes required by applicable law. Many actions (edit profile, delete account) are also available directly in the app.

We use strictly necessary cookies and local storage to keep you signed in and to operate the Service. If we later add analytics or non-essential cookies, we will request your consent where required.

We may update this Policy. The current version is always published at [https://synlit.app/legal/privacy-policy] with an updated “Effective date”. Material changes will be communicated through the Service or by email.

Questions or requests about your personal data: [privacy@synlit.app], [Full name (ИП)], [address].