We wrote this to be understandable. Where a section has a fine-print obligation, we say so plainly; where you have a choice, we tell you how to make it.
Who we are and what this covers
CommSync is a unified messaging inbox operated by Haven Media Solutions LLC (“CommSync,” “we,” “us,” or “our”). This Privacy Policy explains what information we collect when you use our websites, applications, and APIs (together, the “Service”), how we use and share it, and the choices and rights you have.
CommSync is a business tool. When you connect a phone number or mailbox, you use it to send and receive messages with your own contacts. For that data, you act as the controller of your contacts’ information and we act as your processor — we handle it to provide the Service to you and on your instructions. For your own account information, we are the controller. This policy should be read together with our Terms of Service and our Security overview.
We collect what we need to run a messaging inbox and bill for it. We do not sell your data, we do not use your messages for advertising, and our AI features are routed only to providers that do not retain or train on your content. We measure how the product is used — never what you write in it.
Information we collect
We collect the following categories of information:
- Account & profile
- Your name, email address, and a securely hashed password. If you join or create a workspace, your role and team membership.
- Channels you connect
- Phone numbers (via Twilio, JustCall, or Skyetel) and email accounts. For mailboxes, we store the mail-server settings and credentials you provide; credentials and provider secrets are encrypted with AES-256-GCM before they are written to our database.
- Message content
- The SMS and email messages you send and receive through the Service, including subjects, bodies, headers, timestamps, delivery status, and any file attachments.
- Contacts
- The people you communicate with — names, phone numbers, email addresses, and any notes or labels you add — and the links you create between a person and their phone and email identities.
- Billing
- Your subscription tier, seat count, and billing status. Card payments are processed by Stripe; we receive identifiers and status from Stripe but never store full card numbers on our systems.
- Usage & device
- Log data such as IP address, browser type, the routes and features you use, and timestamps. We use this for security, debugging, rate-limiting, and improving the Service. What it never includes is the content of your messages — see Analytics and telemetry below for exactly where that line sits.
- Marketing attribution
- If you reach us from a campaign, advertisement, or referral link, we record the campaign parameters carried in the URL (UTM tags) and the referring page, so we can tell which of our marketing is worth continuing.
You can choose not to provide some information, but parts of the Service may not work without it — for example, we cannot sync a mailbox without its credentials.
Your messages, contacts, and files
The heart of CommSync is the content that flows through it. We treat that content as confidential and handle it only to operate the Service for you:
- We transmit on your behalf. When you send a message, we relay it through the relevant carrier or your email provider. When you receive one, we sync it into your inbox.
- The Service reads your messages to do its job. Threading, search, filing, and the optional AI features all work by processing message content. Messages are stored with encryption at rest provided by our database and storage platforms, with access controls on top; they are not end-to-end encrypted, and we say so plainly in our Security overview.
- We do not sell it. We never sell or rent your messages, contacts, or attachments, and we do not share them with third parties for their own marketing.
- We do not use it to train models. Message content is not used to build advertising profiles or to train machine-learning models — ours or our AI providers’ (see the AI section below).
- You are responsible for your recipients. You are responsible for having a lawful basis and any required consent to message the people you contact, and for the content you send (see our Terms of Service).
Workspaces: who can see what
CommSync workspaces share conversations by design — that is what makes a team inbox useful — but sharing follows explicit rules rather than defaults you have to discover:
- Conversations follow channel access. Threads, messages, and attachments on a connected channel are stored once per workspace and are visible to workspace members who have access to that channel. Owners and admins have access to all of the workspace’s channels; other members see only the channels they have been explicitly granted.
- Your view state stays yours. Read status, archive, snooze, labels, drafts, private conversation notes, and your Ask chat history are personal to you — teammates on the same thread do not see them.
- Contacts are personal until shared. Your contact book is yours. A contact becomes visible to teammates only when you explicitly share it or include it in a team view.
How we use information
We use the information we collect to:
- Provide, maintain, and secure the Service and sync your channels;
- Authenticate you and protect accounts against abuse and fraud;
- Power features you use — unified threading, search, labels, shared contacts, teams, webhooks and API access, and optional AI assistance;
- Process payments, manage subscriptions, and meter usage against your plan;
- Provide support and respond to your requests;
- Diagnose problems, monitor performance, and improve reliability and features;
- Understand which features earn their keep and which of our marketing works, so we build and promote the right things;
- Comply with law and enforce our agreements, including detecting and preventing prohibited uses.
Where the law requires a legal basis to process personal data, we rely on performance of our contract with you, our legitimate interests in operating and securing the Service, your consent (where asked for), and compliance with legal obligations.
Analytics and telemetry
We measure how the product is used so we can improve it, and we watch for errors so we can fix them. That work runs through PostHog, a product-analytics platform that acts as our processor and stores the data in the United States. The line we hold is a simple one: analytics sees that you used a feature, never what you wrote in it.
- What we record. Event names and feature usage, the kind of channel or provider involved, your plan tier, timestamps, and — while you are signed in — your own account identifier, name, and email, so we can support you and count you once rather than a dozen times.
- What we deliberately do not record. Message bodies, subjects, contact names, contact phone numbers and email addresses, and the text of your searches. None of it is sent, so none of it can be stored.
- Routes, not addresses. Inside the app we record which page you were on — the inbox, a settings tab — and nothing else from the address bar. Invite links, password-reset tokens, and other query parameters are stripped in your browser before the event is sent.
- Session recording stays on the front door. Session replay and heatmaps run only on our public pages — the marketing site, pricing, contact, these legal pages, and the sign-in screen — and they mask what you type into form fields. They are never enabled on a signed-in surface: not the inbox, not settings, not admin, agents, or onboarding. There is no recording of your workspace for anyone to review, because none is ever made.
- Campaign attribution. When you arrive from a campaign or referral link, we keep the campaign parameters and referring page so we can tell which of our marketing brought you here.
- Errors and reliability. When something breaks we collect the error, its stack trace, and the route it happened on — never the content you were working with. Server logs we ship for reliability monitoring are redacted first: message bodies, subjects, addresses, and search text are stripped or dropped before the log leaves our infrastructure.
- AI telemetry counts, it does not read. For AI features we record which model ran, how long it took, how many tokens it used, and what it cost. Prompts and completions are not sent to our analytics platform.
- Support sessions are never you. When you grant a member of our support team temporary access to your account, that session is never identified or counted as your account.
PostHog is listed among our subprocessors below. Cookies used for this measurement are described in Cookies and tracking.
Optional AI features
CommSync includes optional AI features — automatic labelling, filtering of machine-sent mail out of your primary inbox, a daily digest, clearer titles for forwarded threads, and Ask, an assistant that answers questions about your own inbox. When a feature runs, the relevant message content is sent to the Google Gemini API (or Vertex AI), which runs the model pinned for that feature and returns the result to your inbox.
- No training on your content. We use only the paid Gemini API tier and Vertex AI, whose data-use terms state that prompts and outputs are not used to train models;
- You can turn it off. Each AI feature can be switched off individually in settings, and a single switch disables AI entirely — with AI off, no message content is sent to any inference provider and the rest of the product works the same;
- Outputs are assistive. Suggestions and drafts are applied to your own inbox views; nothing is sent to your contacts unless you (or an automated responder your workspace admins explicitly configured and scoped) send it.
How long we keep data
We keep information for as long as your account is active and as needed to provide the Service. Specifically:
- Messages and contacts persist in your inbox until you delete them or close your account;
- Items you move to Trash are permanently deleted after 30 days by a scheduled sweep, and orphaned attachment files are cleaned up automatically;
- When you delete your account, we delete your personal data and per-user content, subject to short operational backup windows and any data we must retain to meet legal, tax, or accounting obligations or to resolve disputes;
- We may retain de-identified or aggregated data that no longer identifies you.
How we protect information
We encrypt data in transit with TLS; store application data and attachments on platforms that encrypt at rest (Cloud SQL and Cloud Storage); add our own AES-256-GCM encryption layer for the credentials you entrust to us; store passwords and API keys only as one-way cryptographic hashes; and isolate each workspace’s data behind role-based access controls and explicit channel grants. No method of transmission or storage is perfectly secure, but we work hard to protect your information.
Our Security overview describes these safeguards in detail — including which layer provides each protection and what we deliberately do not claim — and explains how to report a vulnerability.
Your choices and rights
You can access and update most of your information directly in the app, and you can delete your account at any time from your account settings, which removes your personal data and per-user content as described above.
Depending on where you live, you may have rights to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to withdraw consent. We honor these rights and do not discriminate against you for exercising them. We do not sell personal information or share it for cross-context behavioral advertising. To make a request, email support@commsync.ai — we may need to verify your identity first.
If you use CommSync through a workspace administered by someone else, please direct rights requests about that workspace’s data to your administrator; we will assist them as their processor.
International users and data location
CommSync is operated from the United States, and we and our subprocessors store and process information in the United States and other countries. If you use the Service from outside the United States, you understand that your information will be transferred to and processed in the United States, where data-protection laws may differ from those in your country. Where required, we put appropriate safeguards in place for such transfers.
Children's privacy
CommSync is a business product intended for adults. It is not directed to children, and we do not knowingly collect personal information from anyone under 18. If you believe a child has provided us personal information, contact us and we will delete it.
Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the date at the top of this page and, where appropriate, notify you in the app or by email. Your continued use of the Service after an update means you accept the revised policy.
How to contact us
Questions about this policy or your data? Email us at support@commsync.ai or write to Haven Media Solutions LLC. We’re happy to help.
If anything here is unclear, we’re glad to explain it in plain language. Email support@commsync.ai or use our contact page.