Privacy Policy
Version 2026-10-06
1. Who we are
StateSync is provided by DECOMPLEXITY (Pty) Ltd (“we”, “us”). We are responsible for the personal information described here under South Africa's Protection of Personal Information Act (POPIA). This policy covers the StateSync desktop app, statesync.net and the account service behind them. Privacy questions and requests: support@statesync.net.
2. What stays on your computer
StateSync runs on your computer. Your source code, file contents, file names, paths, project names, prompts, chats, model replies, commands, search terms, tool output and voice recordings stay there and are never sent to us. Voice dictation runs entirely on your computer.
When you run a session, your prompts and project context go directly from your computer to the coding provider you chose (for example Anthropic or OpenAI), not through our servers. Keys you add for Pi are kept in your operating system's secure store. Keys for OpenCode and Droid are saved in those tools' own settings files on your computer, where those tools read them. Sign-ins to Claude Code, Codex and other agents stay in the files those tools created. None of these are sent to us. To show your provider usage and plan, the app reads your provider's sign-in and session files on your computer and may ask the provider directly using that sign-in; it keeps numbers and model names, not content. StateSync does not change what your coding provider does with your data. Its own terms and privacy policy apply exactly as they do when you use it directly, including any use of your prompts and code to train its models.
If you need help with a problem, you can choose to save an encrypted diagnostics file and send it to us yourself. It can include recent provider and model events and where StateSync keeps its files, which may include your computer user name. The app never sends it on its own.
3. Your account
To provide and improve the service, we collect and keep the following information about your account.
Account details. We keep your name, email address and profile picture from your sign-in (Google, GitHub or a one-time email code; there are no passwords), and the account id of any sign-in you connect. We do not keep Google's or GitHub's access tokens. We keep your country and home language, which we suggest from the country Cloudflare reports for your IP address and you confirm at setup; the country also sets the currency prices are shown in. We also keep which versions of our terms and this policy you accepted, your optional onboarding answers and your product-email choice.
Sign-ins and security. For each browser session, we keep when it started, was last used and expires, your browser type and the IP address it signed in from, so you can spot a session that is not yours. We keep a record of sign-ins, sign-outs, connected sign-ins, authorized devices, subscription changes and deletion requests, which stores a scrambled (hashed) form of the IP address rather than the address itself. To stop repeated and malicious sign-in attempts, the sign-in system we run on Cloudflare keeps your IP address for about a day.
You need to give us your email address and allow the usage figures in section 4 to have an account and a subscription. Onboarding answers, product emails and support messages are optional.
Your devices. Each device you authorize gets a random id created by the app and a label such as “StateSync on Windows · a1b2”. We keep these with the platform, app version and when it last checked in. To keep free trials to one per person, we also keep a scrambled code derived from your computer's system id, which cannot be turned back into that id and is used for nothing else. We do not collect your device's name. When you sign a computer out, it is removed from your account.
Your subscription. We keep your plan, trial and billing dates, subscription status, how much of your allowance you have used, and the reference numbers our payment provider uses for you.
What you send us. We keep the support tickets you send, the optional comment you can leave when you open the billing portal or cancel, and the optional reason you can give when you delete your account. Please keep code, secrets and other people's personal information out of your communication with us.
Invitations. If early access was arranged for your email address before you signed up, we hold that against the address until it is used or removed.
4. What the app sends for billing and fault tracking
While you are signed in, the app sends us numbers about the sessions it runs, about once a day and every few minutes while you work. They are counts, sizes, timings and codes from a fixed list, never content:
- For billing: sessions, turns and their length; how often each StateSync tool ran and how much tool output it trimmed; per model, the provider, model name, token counts and the cost the provider reports; the programming languages worked in; and dictation counts and timings. This is how we work out how much StateSync saved you and count your usage.
- About each project: rough size, language mix and how often it was used. A project appears only as a coded reference made on your computer, never its name or location.
- About your computer: its random id, app version, operating system, general hardware details such as the type of processor, time zone, which StateSync features are on, and the plan level (not the identity) of any coding provider account signed in there.
- For detailed fault tracking: the same kinds of numbers for each session, turn and StateSync tool call, with its time and whether it failed, so we can find and fix problems.
If part of StateSync fails in the background, the app also sends us minimal diagnostics: what failed, which provider, your app version and operating system, and the system's short error message with anything that could identify you removed. We keep these for about three months.
There is no setting to turn this off, because most of it is what we use to work out how much StateSync saved you. We work to count your usage accurately, and where there is doubt we lean towards charging you less, not more. Signing out or uninstalling stops it. If you do not want detailed fault tracking, email support@statesync.net and we will switch it off for your account; billing is not affected.
5. How we use information, and our legal bases
We use personal information only to:
- run and secure your account, license the app to your computers and count your usage (contract);
- take payment and manage your subscription through our payment provider (contract; legal obligations for tax and accounting records);
- find and fix faults and improve StateSync (legitimate interests);
- protect the service with rate limits, abuse checks, the sign-in record and security emails (legitimate interests; legal obligations);
- answer support and privacy requests (contract; legitimate interests);
- send product updates, only if you opt in (consent, which you can withdraw at any time);
- keep records the law requires and deal with legal claims (legal obligation; legitimate interests).
We do not sell personal information, share it for advertising, use it to train models, or run ads.
The owners and maintainers of StateSync can see and manage individual accounts, onboarding answers, support tickets and usage records, and can check who an account belongs to. We need this to support you, to enforce our terms (for example, to identify an account that goes beyond its plan's limits and cancel its subscription), and to meet our legal obligations.
6. Who we share it with
- Cloudflare hosts our website, account service and database, sends our account emails, keeps short-term request logs, and runs a bot check on some sign-in pages (we send it the check result and your IP address).
- Our payment provider (currently Polar), our merchant of record, receives your email, name, StateSync account id, chosen plan and the IP address of your checkout, and tells us your subscription status. It is responsible for the payment information it holds, under its own privacy policy.
- Google and GitHub, when you sign in with them, under their own policies.
- Our email provider, which holds our support mailbox.
- Professional advisers, regulators, courts and law enforcement where the law requires it or to protect our rights, and a buyer of the business, on the same terms as this policy.
When the app checks for updates or you download it, our servers count this by app version, operating system and country, not by person. Optional parts of the app, such as voice and routing models, helper tools and agent installers, download from public sites such as Hugging Face, GitHub and the npm registry, which may see your IP address.
7. International transfers
We operate from South Africa, and our providers process data in other countries, including the United States and in Europe. Where the law requires a safeguard for such a transfer, we rely on one, such as the data protection terms in our agreements with those providers. These countries may not have data protection laws as strong as South Africa's, so we rely on those written agreements and on the transfer being needed to provide the service to you.
8. How long we keep it
We keep personal information only as long as we need it for the purposes in this policy.
- Account, billing and legal records: as long as necessary for those purposes. When you delete your account, we erase it and its data 30 days after your request, apart from a minimal record that you were a customer and the references needed to show your subscription ended and to deal with claims. Our encrypted backups are kept for up to 12 months; if we ever restore an older backup, accounts deleted since it was made are erased again.
- Detailed usage and fault-tracking data: typically summarised or deleted within a few months.
- The devices listed on your account page: until you sign one out or delete your account.
- Support emails: as long as needed to deal with the matter, keep our records, and maintain and improve the service.
Our providers, such as our payment provider and Cloudflare, keep the information they hold, including backups kept for business continuity, under their own policies, which we do not control. Our payment provider keeps billing, tax and fraud records as the law requires.
The app also keeps its own figures on your computer and removes them over time.
9. Cookies and browser storage
We use only what the website needs to work, plus two small preferences. We do not use advertising cookies.
- A sign-in cookie that keeps you signed in for 30 days, extended while you use the site.
- A 5-minute cookie that protects a Google or GitHub sign-in from forgery.
- A cookie that remembers which sign-in button you used last (30 days).
- Storage for your current tab: the plan you picked while signing in and the currency prices are shown in.
- Your light or dark theme choice on some pages.
- Cloudflare's bot check may store its own data on sign-in pages.
We also count a short list of website actions, such as a plan being chosen, as daily totals by country. These totals cannot be linked to you. The website uses Cloudflare Web Analytics, which records page views, the page you came from and an approximate location derived from your IP address, without advertising cookies.
10. Payments
Our payment provider runs the checkout, holds your payment details, issues invoices and handles tax. We never see or store your card number, expiry date or security code.
11. Emails we send
We send account and security emails as part of the service: your sign-in code, a welcome message, and notices when a computer is authorized, a sign-in method is removed, a subscription starts, a payment fails, or a deletion is requested or completed. We may change which events trigger these emails, and their timing, content and wording, as the service develops. Our payment provider also emails you receipts and trial reminders. Product updates are a separate choice, off by default, that you can change on your account page.
About sign-in codes. A code is valid for 10 minutes and is for you to enter on the StateSync sign-in page only. Nobody from StateSync will ever ask you to send, forward or read out a code by email, chat or phone. If anyone does, it is not us.
12. Your rights
You can ask what personal information we hold about you and for a copy of it, ask us to correct or delete it, object to how we use it, and withdraw consent where we rely on it. If you ask us to delete or stop using information the service needs, we may no longer be able to provide the service to you. Email support@statesync.net. We reply within the period the law that applies to you requires, may first check that the request comes from you, and do not charge for reasonable requests. Your account page lets you end sessions, remove devices, disconnect a sign-in, change your email choice and delete your account.
South Africa. You have the rights in POPIA, and may complain to the Information Regulator (inforegulator.org.za, enquiries@inforegulator.org.za, 010 023 5200). Requests for records under the Promotion of Access to Information Act go to admin@statesync.net.
Depending on where you live, you may have further rights under local law; we will handle those requests as that law requires.
13. Deleting your account
When you delete your account from the account page, every session and computer is signed out at once. The account and its data are erased 30 days after your request, and you can sign in and cancel the deletion during those 30 days. Copies in our encrypted backups are kept for up to 12 months; if we ever restore an older backup, data from accounts deleted since it was made is removed again. If you have a subscription that could still renew, the account is erased once our payment provider confirms it has ended, and we then ask it to delete its customer record.
After erasure we keep only what proves a subscription was ended and lets us deal with claims: the deletion record and its dates, the reference numbers our payment provider used for you, and the scrambled computer code that shows a trial was used. Our payment provider keeps its own billing, tax and fraud records as the law requires.
When you uninstall the app, it makes one last attempt to send any usage it has not yet sent, whether or not you choose to delete your local data.
14. Security
We protect personal information in proportion to how sensitive it is. Data is encrypted in transit. Sensitive and confidential data we store is encrypted or scrambled (hashed), such as the sign-in credentials of your devices and the IP addresses in the sign-in record, and for everything else we rely on the security of our hosting and payment providers. We limit who can see account data and limit repeated sign-in attempts. If a breach affects your personal information, we will tell you and the regulator as the law requires. How we handle your API keys is on the security page.
15. Children
StateSync is intended for adults and is not directed at anyone under 18 or the age of majority where they live. We do not knowingly collect their information; if we learn an account belongs to someone under that age, we may close it and delete its information.
16. Changes to this policy
We publish each version with its date and ask you to acknowledge a new one the next time you sign in. Before a significant change, such as a new kind of data or a new recipient, applies, we will let you know by email or with a notice on the website or in the app.
17. Contact
Privacy questions and requests: support@statesync.net. Legal notices: admin@statesync.net. Our company details, including our Information Officer, are in our legal information. You may also complain to the Information Regulator (South Africa) or the data protection authority where you live.