This policy explains what Infersync Ltd ("Infersync", "we", "us") collects when you use infersync.com and the Infersync application, who else processes it, how long we keep it, and the rights you have over it.
Infersync Ltd is registered in England and Wales, company number 16434490, at 86-90 Paul Street, London, EC2A 4NE, United Kingdom. We are the data controller for the personal data described here. For anything in this policy, contact hello@infersync.com.
What we do not collect
We do not read your source code. The Infersync GitHub App does not request access to repository contents, commits, branches or files, so that data never reaches us and cannot be passed to anyone else, including any AI provider.
What we collect
- Account data. Your name, email address and GitHub account identifier, taken from GitHub when you sign in.
- Workspace data from GitHub. Issue, pull request and project metadata: titles, descriptions, comments, labels, status, assignees, due dates, and organisation membership. This is metadata about work, not the work product itself.
- Records you create in Infersync. Time entries, clock-in and clock-out records, breaks, leave requests, cost and rate settings, tasks created directly in Infersync, and comments you write.
- Assistant prompts. The instructions you give the assistant, and the work item text needed to answer them.
- Usage data. Pages visited, features used, approximate location derived from IP address, browser and device type, and timestamps.
- Technical data. IP address, request logs, and error reports generated when something fails.
If you connect a mailbox, the credentials you supply are stored encrypted and used only for the mail features you enabled.
Why we use it, and our legal basis
- To provide the service (performance of a contract): syncing your GitHub work, tracking time and cost, running the assistant, and producing the reports you ask for.
- To keep it working and secure (legitimate interests): error monitoring, rate limiting, abuse prevention, and understanding which features are used.
- To take payment (performance of a contract), where you are on a paid plan.
- To send service messages (legitimate interests), and marketing email only where you have consented. You can withdraw consent at any time.
- To meet legal obligations, including tax and accounting records.
We do not sell your personal data, and we do not use it to train AI models.
Who else processes it
We use the sub-processors below. Each acts on our instructions and is bound by contract to protect the data it handles.
- Cloudflare. Hosting, database (D1), object storage (R2), rate limiting and bot protection (Turnstile). Handles all service data, at rest and in transit, including request identifiers such as IP address for abuse prevention.
- GitHub. Authentication and the integration itself. Receives account identity, and issue, pull request and project metadata.
- Stripe. Payment processing. Billing and card details are handled by Stripe, not by us.
- Cerebras. Default AI provider for assistant features. Receives the work item text you ask about.
- Anthropic, OpenAI or Google. AI provider, only where a workspace supplies its own key. Receives the work item text you ask about.
- Sentry. Error monitoring. Receives error reports and technical diagnostics.
- PostHog. Product analytics. Receives usage events and identifiers.
- Google Analytics. Website analytics. Receives page views and technical identifiers such as IP address and device information from visits to our marketing site.
- Resend. Transactional email. Receives your email address and the message.
We may also disclose personal data where the law requires it, or in connection with a merger, acquisition or sale of assets, in which case we will tell you before your data becomes subject to a different privacy policy.
International transfers
Your data is processed in the United Kingdom, the European Union and the United States. Where data leaves the UK or EEA, transfers rely on the UK International Data Transfer Addendum or the EU Standard Contractual Clauses, alongside the safeguards our providers operate.
How long we keep it
- Account and workspace data: while your account is active.
- After you close your account or uninstall the GitHub App: deleted within 90 days, unless the law requires us to keep it longer.
- Billing and tax records: seven years, as UK law requires.
- Error and request logs: up to 90 days.
Your rights
Under the UK GDPR and EU GDPR you have the right to access your data, to have it corrected, to have it deleted, to restrict or object to how we use it, and to receive a portable copy. Where we rely on consent, you can withdraw it at any time.
Email hello@infersync.com and we will respond within one month. You can uninstall the Infersync GitHub App at any time from your GitHub settings, which revokes our access immediately.
If you are unhappy with how we have handled your data, you can complain to the UK Information Commissioner's Office at ico.org.uk, or to your local supervisory authority in the EEA.
Security
Traffic is encrypted with TLS 1.2 or above, and data at rest is encrypted by our infrastructure providers. Access is role-based and scoped to a workspace, so one workspace cannot see another's data. Credentials you supply are stored encrypted. No system is perfectly secure, but we monitor for errors and suspicious activity, and aim to acknowledge a reported security issue within one business day. Report issues to hello@infersync.com.
Cookies and analytics
We use cookies that are strictly necessary to sign you in and keep your session, and analytics cookies to understand how the product is used. You can decline analytics on the sign-in screen and we will not load them. Blocking the necessary cookies will stop you signing in.
Children
Infersync is a business product and is not directed at anyone under 16. We do not knowingly collect data from children. If you believe a child has given us personal data, contact us and we will delete it.
Changes
We will update this policy when our practices change, and change the date at the top when we do. Material changes will be notified by email or in the product before they take effect.
Contact
Infersync Ltd, 86-90 Paul Street, London, EC2A 4NE, United Kingdom. hello@infersync.com. See also our Terms of Service and Support page.