Privacy Policy
Last updated: 2026-08-12
This policy explains what the Synclet Android app
(name.gpm.synclet) does with data. It covers the app only.
The short version: Synclet moves your files between your phone and the servers you tell it to use, and nowhere else. There is no account, no server belonging to us, and no copy of anything kept anywhere you did not configure.
Who is responsible
Gabriele Proietti Mattia is the data controller for the processing described here. Contact: apps@gpm.name.
What leaves your device, and where it goes
Your files — to the remotes you set up yourself, and to nothing else.
A remote is your NAS, your web host, your Nextcloud, your S3 bucket or your cloud storage account. Synclet connects to it directly, with the credentials you entered, over the protocol you chose. There is no intermediary service, no relay and no proxy: Gabriele Proietti Mattia operates no server for this app and could not receive your files even in principle.
Where a remote is a third-party cloud — Google Drive, OneDrive, Dropbox, Box, MEGA, pCloud, an S3 provider — that provider’s own privacy policy governs what happens to the files once they arrive. You are sending them to your own account there.
Nothing else is transmitted. No file names, no folder structure, no list of your remotes, no statistics about what you sync.
What stays on your device
- Credentials. Passwords, SSH private keys and OAuth tokens are stored encrypted, under a key held in the Android Keystore. They are used to connect to your remotes and are never sent anywhere else, never written to a log, and never included in a crash report.
- Your configuration. Remotes, addresses, pairs, schedules and filters.
- Sync state. For two-way jobs, a record of what each side looked like at the end of the last run — path, size, modification time, and where needed a content hash. This is what lets the app tell a new file from a deleted one.
- Run logs. Which files were transferred, skipped, deleted or failed, and why. Logs record paths, never file contents. They stay on the device, are capped in size, and are only shared if you export one yourself — the export screen reminds you that a path list can itself be revealing.
Uninstalling the app removes all of it, as it does for any app’s private storage.
Access to your files
Synclet reads and writes only the folders you grant it, through Android’s Storage Access Framework: you pick a folder, Android grants access to that folder, and the grant is visible and revocable in the system settings.
If you enable the optional All files access permission, the app can reach folders the picker will not offer. It is off by default, the app is fully usable without it, and it changes nothing about where your files go — only which ones the app can be pointed at.
Location permission
Optional, and used for exactly one thing: matching a rule to the name of the Wi-Fi network you are connected to, so that a remote can use its LAN address at home and another address elsewhere.
Android requires location permission to read a Wi-Fi network name; that is the platform’s rule, not a use we have for your position. Synclet never reads your coordinates, never stores them, and the network name never leaves the device. The app’s default way of choosing an address needs no permission at all — it simply tries the addresses and uses the one that answers — so you can decline this and lose nothing but the ability to match a rule by network name.
Tailscale
If you mark a remote as needing Tailscale, Synclet sends a request to the Tailscale app on your phone asking it to connect, using the automation hook Tailscale publishes for this purpose. That request contains no data of yours, goes to no network, and Synclet receives nothing back from Tailscale beyond whether your remote then answers.
Diagnostics
The version distributed on Google Play contains optional crash reporting and usage statistics (Firebase), both switched off unless you turn them on. When enabled, they report crashes and anonymous feature counters — never file names, paths, host names, credentials or the contents of anything you sync.
The version distributed through the F-Droid repository and as a direct APK download contains no such code at all.
What the app never does
- No account, sign-up or email address.
- No advertising, and no sale or sharing of data with anyone.
- No tracking, across this app or any other.
- No uploading of your data to us — there is nowhere to upload it to.
- No reading of your contacts, messages, call history or photos beyond the folders you explicitly pointed the app at.
Legal basis (GDPR)
For readers in the EU/EEA and the UK: Gabriele Proietti Mattia receives no personal data from this app, so there is no processing on that side to which a legal basis under Article 6 would attach. The transfers the app performs are ones you instruct it to make, between your device and services of your own choosing, and each of those services is an independent controller of what it then holds.
Optional diagnostics in the Play build, where you switch them on, rest on your consent, which you may withdraw at any time by switching them off again.
Retention
Gabriele Proietti Mattia holds nothing. On your device, configuration and sync state remain until you delete the job or uninstall the app; logs are capped and rotate. What your remotes retain is up to you and to them.
Your rights
Under the GDPR you may request access to, correction of, or deletion of your personal data. Because Gabriele Proietti Mattia holds no data about you from this app, there is nothing to access, correct or delete on that side; deleting the local data is done by removing a job or uninstalling the app, and deleting what reached a remote is done there. You retain the right to lodge a complaint with a supervisory authority.
Write to apps@gpm.name for any request.
Children
Synclet is not directed at children under 13 and knowingly collects no data from them — or from anyone.
Changes
Material changes will be published on this page with a new date at the top, and significant ones will be noted in the app’s changelog.
Last updated: 2026-08-12