Syncnema
Privacy Policy
Last updated 29 August 2026
This policy explains what personal data Syncnema uses, why we use it, who receives it, how long we keep it, and the rights you have.
1. Who is responsible
The controller responsible for Syncnema is Nils Henning, trading as Syncnema.
Postal address: Syncnema – Nils Henning, c/o Online-Impressum #10026, Europaring 90, 53757 Sankt Augustin, Germany.
Email: info@syncnema.com. You can also find our provider details in the imprint.
2. What data we use and why
Account and access — We use your email address, display name, username, login credentials, and verification, recovery, session and sign-in data to create, secure and provide your account, including service emails. The legal basis is Article 6(1)(b) GDPR.
Optional social sign-in — If you choose Google, Apple or Discord, the provider tells us your provider account identifier, email address, whether it is verified, and display name. Apple may supply a private relay email address. We use these details to create or link your account and authenticate you. We do not import contacts, messages or viewing history. Provider access and refresh tokens are encrypted; we do not retain profile pictures. Email and password sign-in remains available.
Discovery and social features — We use your discovery settings, swipes, ratings, friendships and interactions to suggest films and series, show your history, create matches and provide the social features you choose. An accepted friend's Watch choices and ratings may also influence your suggestions. This affects entertainment suggestions only. The legal basis is Article 6(1)(b) GDPR.
Push notifications — If you switch them on, we use your browser's push-subscription information to deliver the notifications you request. The legal basis is your consent under Article 6(1)(a) GDPR and § 25(1) TDDDG. You can switch Push off in Settings at any time.
Contact, feedback and legal requests — If you contact us or send feedback, we use your contact details, message and relevant context to reply and provide support. The legal basis is Article 6(1)(b) GDPR for service requests, Article 6(1)(c) GDPR where we must meet a legal duty, and otherwise Article 6(1)(f) GDPR; the interest pursued is responding to messages and using voluntary feedback to improve the service.
Security, service measurement and install reminders — We use request, device, IP address and security-event information to protect accounts, prevent abuse and diagnose faults. We also create overall usage statistics from service data and keep install-reminder status so we can understand whether core features work and avoid repeating install prompts. The legal basis is Article 6(1)(f) GDPR. The interests pursued are account and service security, identifying faults in core features, and presenting the optional install feature in a limited way.
Optional analytics — With your consent, we measure visits, how people find Syncnema, sign-ups and use of the main features so we can understand and improve the service. This is first-party analytics and is not sent to a separate analytics provider. The legal basis is Article 6(1)(a) GDPR and § 25(1) TDDDG. You can change your choice at any time under Privacy choices.
3. Who receives data and international transfers
Accepted friends can see your ratings as part of a combined friend score. People who share a match with you can also see your display name and individual rating in that match. This access ends when the friendship ends or your account is restricted or deleted.
netcup GmbH hosts Syncnema's application, databases, logs and backups for us on a server in the European Union.
Cloudflare, Inc. delivers and protects the site for us and processes connection and request data, including IP addresses. It may process this data outside the EEA, including in the United States, under the EU–US Data Privacy Framework or the European Commission's Standard Contractual Clauses.
OVH GmbH (OVHcloud) in Germany hosts our email mailbox for us in the European Union and processes email addresses, messages and correspondence sent to or from it.
Lettermint B.V. in the Netherlands delivers our outgoing account and service emails for us. It processes the recipient's email address and name, the message and delivery information. Its core email infrastructure is in the European Union; delivery sends the message to the email provider chosen by the recipient, which may be outside the EEA.
When you choose social sign-in, Google, Apple or Discord receives the sign-in request and processes it under its own privacy notice. These are independent identity providers, not our hosting or email processors. Their processing may take place outside the EEA. See Google's privacy notice, Apple's privacy notice, and Discord's privacy notice. Better Auth is software running on our servers; it does not receive your account data as a hosted authentication service.
4. How long we keep data
We keep your account, settings, discovery and social data, feedback, consent records and install-reminder status while your account exists. Deleting your account removes this data from the live service.
Sessions can remain valid for up to 30 days after your last activity. Reusable invite links expire after 31 days and single-use links after seven days; used, expired and invalidated invite records are deleted. Notification and Push-delivery records are kept for up to 90 days.
Security records are kept for up to 90 days and web-server logs for up to 14 days. If you delete your account, direct links to you are removed from security records that must remain for the rest of their retention period.
Verification and recovery codes expire after 15 minutes. Lettermint keeps sent-email content and delivery information for up to 28 days. Messages captured by a development mailbox are removed after seven days.
Privacy and support correspondence is normally kept for three years after the final response, unless it is needed longer for a legal duty or claim.
Backups are kept for up to 30 days and used only for disaster recovery. Account deletions are applied again if a backup is restored.
Optional Analytics data linked to your account is kept until you withdraw consent or delete your account; browser-linked records are deleted after no more than 400 days. Withdrawing consent stops future Analytics and deletes data still linked to you. Anonymous totals may be kept as service history.
5. Cookies and storage on your device
Syncnema uses a first-party session cookie to keep your account secure and signed in. It normally lasts for the browser session, or for up to 30 days after your last activity if you select ‘Keep me signed in.’
The app keeps your current deck on your device for up to 24 hours and unsent offline actions for up to 30 days so they can be delivered when you reconnect.
Syncnema uses a first-party privacy-choice cookie for up to one year to remember whether you accepted or refused Analytics. If you dismiss an in-app notice, your browser remembers that choice until the notice changes or you clear the site's data. This storage is used only to provide the choices and functions you requested.
If you allow Analytics, Syncnema uses a first-party attribution cookie for up to 30 days to remember how you reached the site and a first-party browser token for up to one year to count consenting browsers. No separate analytics provider receives this information. Analytics is off until you consent. You can withdraw consent under Privacy choices; this clears the Analytics cookies and deletes linked Analytics data as described in section 4.
If you enable Push, your browser stores a push subscription for that device. Turning Push off removes it from Syncnema.
6. Your rights
Depending on the circumstances, you have the right to access your personal data, correct it, delete it, restrict its use and receive data you provided in a portable format. You can withdraw consent for Push or Analytics at any time without affecting earlier lawful processing.
Right to object — Where we rely on legitimate interests, you may object for reasons relating to your particular situation. We will stop the processing unless we can demonstrate compelling overriding grounds or need it for legal claims.
You can export your data, update your details and settings, or delete your account in Settings. For any other request, email info@syncnema.com. We normally answer within one month and will explain if the law permits more time or a request cannot be fulfilled.
You have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your habitual residence, place of work, or the place of the alleged infringement (Article 77 GDPR).
7. Required data, age and changes
An email address, password and display name are needed to create and use an account. Without them, we cannot provide a signed-in account. Friends, ratings, Push, feedback and Analytics are optional. If you add and accept friends, ratings you choose to give are shared with those friends as described above. Refusing Analytics does not limit the service.
Syncnema is for people aged 16 and over. Sign-up asks you to confirm that you meet this age requirement.
When this policy changes, we update the date at the top and show an in-app notice where appropriate.
This document is provided for the Syncnema product experience and is not a substitute for tailored legal advice.