Syncnema
Privacy Policy
Last updated 27 August 2026
This policy explains what personal data Syncnema uses, why we use it, who receives it, how long we keep it, and the rights you have.
1. Who is responsible
The controller responsible for Syncnema is Nils Henning, trading as Syncnema.
Postal address: Syncnema – Nils Henning, c/o Online-Impressum #10026, Europaring 90, 53757 Sankt Augustin, Germany.
Email: info@syncnema.com. You can also find our provider details in the imprint.
2. What data we use and why
Account and login data — We use your email address, its verification status, display name, username, password hash, short-lived one-time code records, session information and sign-in records to create, secure and provide your account. We send service emails when you verify your address or request a password reset. The legal basis is Article 6(1)(b) GDPR.
Discovery, rating sharing and social features — We use your discovery settings, swipes and ratings to personalise the films and series we suggest and to show your history. An accepted friend's Watch choice and rating may also help us suggest something relevant. Accepted friends see one aggregate friend score on a title's media detail page; if you share a match for that title, its match detail can show your individual rating. Pending requests, strangers and former friends cannot access either view. We use friendships, friend requests, invite links, matches, recommendations, reactions and shared streaks to provide the social features you choose. This personalisation is profiling under the GDPR and affects entertainment suggestions only; it does not make decisions that produce legal or similarly significant effects. The legal basis is Article 6(1)(b) GDPR.
Push notifications — If you switch them on, we use the push endpoint and encryption keys supplied by your browser to deliver the notifications you requested. The legal basis is your consent under Article 6(1)(a) GDPR and § 25(1) TDDDG. You can switch Push off in Settings at any time.
Messages and feedback — If you contact us or send feedback, we use your contact details, message and relevant context to reply, provide support and improve the service. The legal basis is Article 6(1)(b) GDPR where this is needed to handle your service request, and otherwise Article 6(1)(f) GDPR. Our legitimate interest is maintaining and improving a reliable service.
Security and operation — We use limited request, device, IP address and security-event information to protect accounts, prevent abuse and diagnose faults. The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are security, abuse prevention and reliable operation. Article 6(1)(c) GDPR also applies where processing is needed to meet a legal duty, such as answering a valid data-protection request.
Aggregate service measurement — We calculate overall figures from existing account, matching and social-feature records to monitor whether the service is working, understand whether its core features are being used and find potential product problems. We also count landing-page impressions directly as part of the page response. That counter stores only the calendar day and total: it does not receive a cookie, account, IP address, device information or other visitor identifier. The results are available only to the operator and are not used to make decisions about individual members. The legal basis for processing personal service records is Article 6(1)(f) GDPR. Our legitimate interest is operating and improving a reliable service. You may object as explained in section 6.
Optional analytics — If you allow Analytics in Privacy choices, Syncnema measures visits using broad page, audience and acquisition categories, and measures account milestones such as signup source, onboarding, swiping, accepted friendship, first Match and return activity. Invite Copy and Share actions may also contribute to referral totals. A random first-party browser token lets Syncnema count distinct consenting browsers in a selected period and by broad page or acquisition category. The database receives only a one-way digest of that token, not the cookie value. This is a browser count, not a count of unique people. Raw URLs and referrers, IP addresses, device information, advertising identifiers and fingerprints are not stored in Analytics. Page views remain daily aggregate totals; the separate browser-presence rows contain only the digest, day and the same broad categories. Account measurements use one compact milestone record and daily totals for swipes, ratings, Matches views and deliberate notification-inbox views rather than a raw page-view or gesture history. When you are signed in, your account choice is used across browsers and an outdated choice cannot silently restart account measurement. The legal basis is your consent under Article 6(1)(a) GDPR and § 25(1) TDDDG. You can change this choice at any time.
Syncnema has no advertising, does not sell personal data and does not embed a third-party analytics script or send optional Analytics to a separate analytics provider.
Install reminders — We use your existing swipe total and remember the highest of three install reminders sent to your account and the highest one actually shown. These two progress markers prevent duplicate reminders while still recovering one that did not reach your screen. This does not affect your recommendations or access to Syncnema. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is explaining the install option without repeatedly interrupting members. You may object as explained in section 6.
3. Who receives data and international transfers
Accepted friends receive your rating only as part of an aggregate friend score on media details. Friends who share a match with you can also receive your display name and individual rating inside that match. This access ends when the friendship ends or the account is restricted or deleted.
netcup GmbH hosts Syncnema's application, databases, logs and backups on our server in the European Union.
Cloudflare, Inc. delivers and protects the site. It receives connection and request information, including IP addresses and content passing through its network. Cloudflare may process this information outside the EEA, including in the United States. Its US transfers rely on the EU–US Data Privacy Framework and, where needed, the European Commission's Standard Contractual Clauses. Cloudflare describes these safeguards in its Data Processing Addendum.
Proton AG in Switzerland provides our privacy and support mailbox. If you email us, Proton processes your address, message and our correspondence. The European Commission recognises Switzerland as providing adequate data protection.
Lettermint B.V. in the Netherlands delivers account-verification and password-reset emails. It receives the recipient address and name, the service-email content and delivery information for that purpose. Open and click tracking are disabled for these messages. Lettermint states that this data is processed within the EU/EEA under its Data Processing Agreement.
If you enable Push, the push service selected by your browser receives your device endpoint and the encrypted notification. Depending on the browser provider, this may involve processing outside the EEA under an adequacy decision, the EU–US Data Privacy Framework or Standard Contractual Clauses.
4. How long we keep data
We keep your account, settings, swipes, ratings, friendships, recommendations, reactions, streaks, invites, feedback and install-reminder progress markers while your account exists. Deleting your account removes this active-service data.
Sessions can remain valid for up to 30 days after your last activity. Invite links are reusable for any number of people and expire after 31 days by default. You can switch to single-use links in Settings; this invalidates your current links, and new links then work once and expire after seven days. We delete used, expired and invalidated invite records daily. Notification and Push-delivery records are kept for up to 90 days.
Security records are kept for up to 90 days. If you delete your account, direct links to you are removed from any security record that must remain for the rest of that period. Web-server logs are kept for up to 14 daily rotations.
One-time codes expire after 15 minutes and can be used once. Used and expired challenge records are removed by the daily retention job. Lettermint keeps sent-email content, message metadata and delivery events for up to 28 days. Messages captured by an explicitly enabled development mailbox are visible only to operators on that deployment and are removed after seven days.
Privacy and support correspondence is normally kept for three years after the final response, unless it is needed longer for a legal duty or claim.
Backups are kept for up to 30 days and are used only for disaster recovery. If a backup is restored, account deletions requested after that backup was made are applied again.
Daily landing-impression and consented page/source totals are not linked to a person or browser and may be kept as aggregate operational history. Consenting-browser presence rows are automatically deleted after 400 days; withdrawing Analytics deletes every row reachable from that browser token sooner. If you are signed in, withdrawal also deletes your account-linked growth milestone and daily activity records and stops future optional measurement. We keep the dated grant/withdrawal evidence while your account exists so we can demonstrate your choice; deleting your account removes it. Your browser keeps the privacy-choice and optional random Analytics browser-token cookies for up to one year, and the optional coarse attribution cookie for up to 30 days. The install-reminder progress markers remain with your account until account deletion so dismissed reminders do not restart.
5. Cookies and storage on your device
When you sign in, Syncnema uses a first-party cookie to keep your account secure and signed in. Normally it is a browser-session cookie. If you select ‘Keep me signed in,’ it can remain for up to 30 days after your last activity. Signing out removes it.
The app stores your current deck for up to 24 hours and keeps unsent offline actions for up to 30 days so they can be delivered when you reconnect. Signing out or deleting your account clears the active account's local app data when the device is online and working.
Install-reminder progress is held with your account on Syncnema's server. It does not add a cookie or other browser storage.
Syncnema stores a first-party privacy-choice cookie for up to one year so it can remember whether you allowed or refused Analytics. It contains the policy version, that choice and a server integrity signature, not an account or visitor identifier. This preference cookie is necessary to respect your choice.
If you allow Analytics, Syncnema stores two separate first-party Analytics cookies: an attribution cookie for up to 30 days and a random browser token for up to one year. The attribution cookie contains only a broad source, medium, campaign and landing-page category so a signup can be related to the route that introduced Syncnema; it contains no visitor or account id and no raw URL or referrer. The random token exists only to de-duplicate consenting browsers, is protected by a server signature and is stored in the database only as a one-way digest. Analytics is off before you choose it. Signed-in members can reopen Privacy choices under Your data in Settings, and signed-out visitors can use the Privacy choices link in the landing-page footer. Withdrawing Analytics stops future optional collection, clears both Analytics cookies and deletes browser-keyed and current account-linked growth measurements as described in section 4.
If you dismiss an in-app notice, the browser may remember that notice's version so it stays dismissed. This is used only to carry out your dismissal request.
If you enable Push, your browser stores a push subscription for that device. Turning Push off removes it from Syncnema.
6. Your rights
Depending on the circumstances, you have the right to access your personal data, correct it, delete it, restrict its use, object to processing based on legitimate interests, and receive data you provided in a portable format. You can withdraw consent for Push or Analytics at any time without affecting earlier lawful processing.
You can export your data, update your details and settings, or delete your account in Settings. To ask us to reset your recommendations, or for any other request you cannot complete there, email info@syncnema.com. We normally answer within one month and will explain if the law permits more time or a request cannot be fulfilled.
You have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your habitual residence, place of work, or the place of the alleged infringement (Article 77 GDPR).
7. Required data, age and changes
An email address, password and display name are needed to create and use an account. Without them, we cannot provide a signed-in account. Friends, ratings, Push, feedback and Analytics are optional. If you add and accept friends, ratings you choose to give are shared with those friends as described above. Refusing Analytics does not limit the service.
Syncnema is for people aged 16 and over. Sign-up asks you to confirm that you meet this age requirement.
When this policy changes, we update the date at the top and show an in-app notice where appropriate.
Questions about this policy or your data can be sent to info@syncnema.com.
This document is provided for the Syncnema product experience and is not a substitute for tailored legal advice.