Privacy Policy
Last updated 2026-09-19
Miguel Ferreira operates ConfigSync and is the data controller for the personal data described here. This policy explains what we store, why, for how long, and your rights under the GDPR.
1. What we store
- Account: email address, display name, a hashed password (or the id and email your GitHub account provides if you sign in with GitHub), and the username, bio, links and avatar you choose for your profile.
- Your vault: games, presets, categories, settings, notes, revision history, uploaded cover images and the device names, game lists and per-PC choices the companion program sends.
- Sessions and security: session tokens with the IP address and browser user agent they were created from; hashed companion tokens.
- Billing: your Paddle customer and subscription identifiers and plan status. Card details never reach us — Paddle collects them.
- Screenshot importer (Pro, optional): when you upload a screenshot for analysis it is sent to our AI provider once and discarded; we keep only a usage record (model name, token counts, time) for the daily limit.
- Server logs: standard request logs (IP, path, time, status) kept for up to 30 days for security and debugging.
No analytics, no advertising trackers, no third-party cookies.
2. Why (legal bases)
To provide the Service you signed up for (contract): accounts, vault, companion, billing status. To keep the Service secure and to meet tax and accounting duties (legal obligation and legitimate interest): sessions, logs, payment records held by Paddle. To run optional features you turn on (contract, or consent where you upload a screenshot).
3. Who else sees data (processors)
- Hetzner Online GmbH (Germany, EU) — hosting of the application and database.
- Paddle.com Market Ltd — payments, invoices and VAT, as merchant of record. Paddle is an independent controller for the purchase itself; see its privacy policy.
- Anthropic, PBC — analysis of screenshots you upload to the Pro screenshot importer. Images are processed to answer the request and not used to train models under our API agreement.
- GitHub, Inc. — only if you choose “Continue with GitHub”.
- Our email provider — password-reset emails (recipient address and the message only).
We do not sell personal data. Public profiles and presets you explicitly make public are visible to anyone with the link; notes are never shown publicly.
4. Where
Data is stored in the European Union. Paddle and Anthropic may process data outside the EU under the EU Standard Contractual Clauses.
5. How long
Account and vault data: until you delete your account (Settings → Delete account), then removed from the live database immediately and from backups within 30 days. Sessions: until they expire or you sign out. Server logs: 30 days. Billing records: as long as tax law requires (held by Paddle).
6. Your rights
You can access, correct and export your data yourself in the app (Settings and Export). You can delete your account at any time. For anything else — restriction, objection, portability in another format, or a question — email hello@configsync.app; we answer within 30 days. You can also complain to your national data-protection authority (in Portugal, the CNPD).
7. Cookies
We set strictly necessary session cookies (prefix csync) to keep you signed in. Your theme and density preferences live in your browser’s local storage. Nothing else, so no cookie banner is needed.
8. Changes
We will announce material changes in the app before they take effect and update the date at the top of this page.