🔒
Last Updated: May 2026

Privacy Policy

CircleSync is committed to protecting your privacy. This policy explains exactly what information we collect, how we use it, who we share it with, and your rights regarding your personal data.

Contents
  1. Information We Collect
  2. How We Use Your Information
  3. Third-Party Services
  4. Data Sharing Within the App
  5. Data Security
  6. Your Rights
  7. Data Retention
  8. Account Deletion
  9. International Data Transfers
  10. Children's Privacy
  11. Changes to This Policy
  12. Contact Us
1 Information We Collect

Account Information

When you create an account we collect your email address and display name. If you provide one, we also store your profile photo. If you sign in with Google or Apple, we receive your name and email address from those services. Your phone number, if provided, is stored privately and is never shared with other users or visible in groups.

Content You Create

We store everything you create in CircleSync: group names, shared lists and checklist items, trip plans including titles, destinations, dates, and budgets, trip expenses and expense splits, trip comments, trip documents, and personal lists and personal trips. Content added to a shared group is visible to all members of that group.

Travel Booking Data (Premium Feature)

When you use the email forwarding feature, we collect and process:

  • Your forwarding address — a unique email address assigned to your account, stored privately and not visible to other users
  • Raw email content — subject line, body text, sender address, and metadata to process your booking and for debugging purposes
  • Parsed booking records — structured booking data including booking type, title, travel dates, origin, destination, confirmation number, cost, passenger names, and provider name
  • Email deduplication fingerprints — a SHA-256 hash of each processed email's content to prevent duplicate bookings. The hash cannot reconstruct the original email

Device and Notification Data

We collect your device's FCM (Firebase Cloud Messaging) token to deliver push notifications. This token is stored privately and is not visible to other users or group members. Multiple tokens may be stored if you use the app on more than one device.

Location Data

When matching a forwarded booking to one of your trips, we use the booking's location to look up geographic coordinates via the Google Geocoding API. We cache the results but do not store your real-time device location.

Usage and Activity Data

Group activity (who added, edited, or completed items) is logged and visible to all members of that group. We maintain internal counters for rate limiting to protect the service from abuse.

Weather Data

The weather forecast feature retrieves forecasts for your trip destinations from the OpenWeatherMap API using the destination city name. We do not store your location or weather query history.

2 How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain CircleSync
  • Sync your data in real time across your devices and with your group members
  • Parse forwarded booking emails using AI to extract structured travel data (premium)
  • Match parsed bookings to your existing trips automatically (premium)
  • Send push notifications about group activity, trip reminders, and account events
  • Process and manage your subscription through RevenueCat
  • Enforce usage limits and detect abuse
  • Provide customer support
  • Improve the app

We do not use your content to train AI models. Email content sent for booking extraction is processed by OpenAI's API under a data processing agreement. OpenAI's API usage policies prohibit using API inputs to train their models.

3 Third-Party Services

We use the following third-party services to operate CircleSync. Each has its own privacy policy.

  • Google Firebase — Database, authentication, file storage, push notifications. All app data is stored on Firebase infrastructure.
  • RevenueCat — Subscription management and payment processing. Shares your user ID and purchase history.
  • OpenAI — AI parsing of forwarded booking emails (premium). Shares email subject and body text.
  • Google Geocoding API — Converting booking locations to coordinates for trip matching. Shares place name strings.
  • OpenWeatherMap — Trip weather forecasts. Shares destination city name.
  • SendGrid — Routing forwarded booking emails to our processing pipeline. Shares inbound email content as described above.
  • Apple / Google — Sign in with Apple and Google Sign-In. Shares name and email address.

We never sell your data. CircleSync does not sell, rent, or trade your personal information to third parties for marketing purposes. Ever.

4 Data Sharing Within the App

Group Members

Content you add to a shared group — lists, checklist items, trips, expenses, comments, and documents — is visible to all current members of that group. Group activity logs (who did what and when) are visible to all group members.

Other Users

Your display name and profile photo are visible to other authenticated users of the app (for example, in group member lists). Your email address, phone number, forwarding address, and booking data are never shared with other users.

5 Data Security
  • All data is encrypted in transit using HTTPS/TLS
  • Firebase provides encryption at rest for all stored data
  • Firebase App Check is enabled in production builds to verify that API requests originate from the genuine CircleSync app
  • Your FCM tokens and forwarding address are stored in a private subcollection that other users cannot read
  • Firestore security rules enforce ownership — users can only read and write their own data, and group data is restricted to verified group members
  • Booking data and raw email logs are inaccessible to clients other than the authenticated owner
6 Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access — view your data within the app at any time
  • Correction — update your name, email, and profile photo from Profile settings
  • Deletion — delete your account and associated data from Profile settings (see Section 8)
  • Portability — contact us to request a copy of your data in a portable format
  • Opt-out of notifications — manage notification preferences in the app settings
  • Object to processing — contact us if you object to any specific use of your data

For GDPR or CCPA requests, contact us at support@getcirclesync.com. We will respond within 30 days.

7 Data Retention

Active Accounts

We retain your data for as long as your account is active.

Deleted Accounts

When you delete your account, personal data is removed from active systems immediately. Raw email logs stored for debugging purposes are not automatically purged on account deletion; these are accessible only via administrative tools and contain no attribution to your deleted account after your user record is removed. Google Firebase may retain encrypted infrastructure backups per their own retention policies; we do not control these backups.

Booking Email Logs

Raw inbound email content is stored in a restricted administrative collection for debugging and support purposes. This data is not accessible to end users or group members.

8 Account Deletion

What is permanently deleted

  • Your profile, display name, email address, and phone number
  • Your profile photo
  • Your Firebase Authentication account and all sign-in credentials
  • Your private data (FCM tokens, forwarding address, notification settings)
  • All parsed booking records and travel data extracted from forwarded emails
  • All personal lists and their items
  • All personal trips and their items, expenses, comments, and documents
  • Your RevenueCat subscription identity

Groups you own

If a group has other members, ownership is transferred to the next member and your membership is removed. If you are the sole member, the group and all its content is permanently deleted.

Groups you belong to but don't own

You are removed from the members list. Content you created remains but is anonymised (ownership attributed to "deleted user"). Your individual activity log entries may remain visible to remaining group members due to a technical limitation in group activity rules.

Infrastructure backups

Google Firebase may retain encrypted backups per their own data retention policies. We do not control these backups. See Google's Privacy Policy for details.

Full details including step-by-step instructions and an alternative email method are available on our Account Deletion page.

9 International Data Transfers

Cross-border transfers

CircleSync uses Google Firebase infrastructure, which may process and store your data in data centers outside your country of residence, including the United States. OpenAI processes forwarded email content in the United States. By using CircleSync you consent to these transfers. We rely on standard contractual clauses and data processing agreements with our service providers to protect transferred data.

10 Children's Privacy

Age Requirement

CircleSync is not intended for children under 13 years of age (or under 16 in the European Economic Area). We do not knowingly collect personal information from children. If you believe we have collected information from a child please contact us at support@getcirclesync.com and we will delete it promptly.

11 Changes to This Policy

Updates

We may update this Privacy Policy from time to time. We will notify you of material changes via a notice in the app or by email before the changes take effect. Continued use of CircleSync after the effective date constitutes acceptance of the updated policy. The date at the top of this page reflects when it was last updated.

12 Contact Us

Privacy Questions? Contact us at support@getcirclesync.com. We will respond within 48 hours for general inquiries and within 30 days for formal data rights requests.