Legal · Privacy

Privacy Policy

What we collect, why we collect it, and the control you keep over it — written to be read, not just filed.

Last updated July 28, 2026Haven Media Solutions LLCReading time ~2 min

We wrote this to be understandable. Where a section has a fine-print obligation, we say so plainly; where you have a choice, we tell you how to make it.

01

Who we are and what this covers

CommSync is a unified messaging inbox operated by Haven Media Solutions LLC (“CommSync,” “we,” “us,” or “our”). This Privacy Policy explains what information we collect when you use our websites, applications, and APIs (together, the “Service”), how we use and share it, and the choices and rights you have.

CommSync is a business tool. When you connect a phone number or mailbox, you use it to send and receive messages with your own contacts. For that data, you act as the controller of your contacts’ information and we act as your processor — we handle it to provide the Service to you and on your instructions. For your own account information, we are the controller. This policy should be read together with our Terms of Service and our Security overview.

In plain terms

We collect what we need to run a messaging inbox and bill for it. We do not sell your data, we do not use your messages for advertising, and our AI features are routed only to providers that do not retain or train on your content. We measure how the product is used — never what you write in it.

02

Information we collect

We collect the following categories of information:

Account & profile
Your name, email address, and a securely hashed password. If you join or create a workspace, your role and team membership.
Channels you connect
Phone numbers (via Twilio, JustCall, or Skyetel) and email accounts. For mailboxes, we store the mail-server settings and credentials you provide; credentials and provider secrets are encrypted with AES-256-GCM before they are written to our database.
Message content
The SMS and email messages you send and receive through the Service, including subjects, bodies, headers, timestamps, delivery status, and any file attachments.
Contacts
The people you communicate with — names, phone numbers, email addresses, and any notes or labels you add — and the links you create between a person and their phone and email identities.
Billing
Your subscription tier, seat count, and billing status. Card payments are processed by Stripe; we receive identifiers and status from Stripe but never store full card numbers on our systems.
Usage & device
Log data such as IP address, browser type, the routes and features you use, and timestamps. We use this for security, debugging, rate-limiting, and improving the Service. What it never includes is the content of your messages — see Analytics and telemetry below for exactly where that line sits.
Marketing attribution
If you reach us from a campaign, advertisement, or referral link, we record the campaign parameters carried in the URL (UTM tags) and the referring page, so we can tell which of our marketing is worth continuing.

You can choose not to provide some information, but parts of the Service may not work without it — for example, we cannot sync a mailbox without its credentials.

03

Your messages, contacts, and files

The heart of CommSync is the content that flows through it. We treat that content as confidential and handle it only to operate the Service for you:

  • We transmit on your behalf. When you send a message, we relay it through the relevant carrier or your email provider. When you receive one, we sync it into your inbox.
  • The Service reads your messages to do its job. Threading, search, filing, and the optional AI features all work by processing message content. Messages are stored with encryption at rest provided by our database and storage platforms, with access controls on top; they are not end-to-end encrypted, and we say so plainly in our Security overview.
  • We do not sell it. We never sell or rent your messages, contacts, or attachments, and we do not share them with third parties for their own marketing.
  • We do not use it to train models. Message content is not used to build advertising profiles or to train machine-learning models — ours or our AI providers’ (see the AI section below).
  • You are responsible for your recipients. You are responsible for having a lawful basis and any required consent to message the people you contact, and for the content you send (see our Terms of Service).
04

Workspaces: who can see what

CommSync workspaces share conversations by design — that is what makes a team inbox useful — but sharing follows explicit rules rather than defaults you have to discover:

  • Conversations follow channel access. Threads, messages, and attachments on a connected channel are stored once per workspace and are visible to workspace members who have access to that channel. Owners and admins have access to all of the workspace’s channels; other members see only the channels they have been explicitly granted.
  • Your view state stays yours. Read status, archive, snooze, labels, drafts, private conversation notes, and your Ask chat history are personal to you — teammates on the same thread do not see them.
  • Contacts are personal until shared. Your contact book is yours. A contact becomes visible to teammates only when you explicitly share it or include it in a team view.
05

How we use information

We use the information we collect to:

  • Provide, maintain, and secure the Service and sync your channels;
  • Authenticate you and protect accounts against abuse and fraud;
  • Power features you use — unified threading, search, labels, shared contacts, teams, webhooks and API access, and optional AI assistance;
  • Process payments, manage subscriptions, and meter usage against your plan;
  • Provide support and respond to your requests;
  • Diagnose problems, monitor performance, and improve reliability and features;
  • Understand which features earn their keep and which of our marketing works, so we build and promote the right things;
  • Comply with law and enforce our agreements, including detecting and preventing prohibited uses.

Where the law requires a legal basis to process personal data, we rely on performance of our contract with you, our legitimate interests in operating and securing the Service, your consent (where asked for), and compliance with legal obligations.

06

Analytics and telemetry

We measure how the product is used so we can improve it, and we watch for errors so we can fix them. That work runs through PostHog, a product-analytics platform that acts as our processor and stores the data in the United States. The line we hold is a simple one: analytics sees that you used a feature, never what you wrote in it.

  • What we record. Event names and feature usage, the kind of channel or provider involved, your plan tier, timestamps, and — while you are signed in — your own account identifier, name, and email, so we can support you and count you once rather than a dozen times.
  • What we deliberately do not record. Message bodies, subjects, contact names, contact phone numbers and email addresses, and the text of your searches. None of it is sent, so none of it can be stored.
  • Routes, not addresses. Inside the app we record which page you were on — the inbox, a settings tab — and nothing else from the address bar. Invite links, password-reset tokens, and other query parameters are stripped in your browser before the event is sent.
  • Session recording stays on the front door. Session replay and heatmaps run only on our public pages — the marketing site, pricing, contact, these legal pages, and the sign-in screen — and they mask what you type into form fields. They are never enabled on a signed-in surface: not the inbox, not settings, not admin, agents, or onboarding. There is no recording of your workspace for anyone to review, because none is ever made.
  • Campaign attribution. When you arrive from a campaign or referral link, we keep the campaign parameters and referring page so we can tell which of our marketing brought you here.
  • Errors and reliability. When something breaks we collect the error, its stack trace, and the route it happened on — never the content you were working with. Server logs we ship for reliability monitoring are redacted first: message bodies, subjects, addresses, and search text are stripped or dropped before the log leaves our infrastructure.
  • AI telemetry counts, it does not read. For AI features we record which model ran, how long it took, how many tokens it used, and what it cost. Prompts and completions are not sent to our analytics platform.
  • Support sessions are never you. When you grant a member of our support team temporary access to your account, that session is never identified or counted as your account.

PostHog is listed among our subprocessors below. Cookies used for this measurement are described in Cookies and tracking.

07

Optional AI features

CommSync includes optional AI features — automatic labelling, filtering of machine-sent mail out of your primary inbox, a daily digest, clearer titles for forwarded threads, and Ask, an assistant that answers questions about your own inbox. When a feature runs, the relevant message content is sent to the Google Gemini API (or Vertex AI), which runs the model pinned for that feature and returns the result to your inbox.

  • No training on your content. We use only the paid Gemini API tier and Vertex AI, whose data-use terms state that prompts and outputs are not used to train models;
  • You can turn it off. Each AI feature can be switched off individually in settings, and a single switch disables AI entirely — with AI off, no message content is sent to any inference provider and the rest of the product works the same;
  • Outputs are assistive. Suggestions and drafts are applied to your own inbox views; nothing is sent to your contacts unless you (or an automated responder your workspace admins explicitly configured and scoped) send it.
08

How we share information and our subprocessors

We share information only as needed to run the Service, and we do not sell it. We rely on a small set of vetted subprocessors that handle data on our behalf under contractual confidentiality and security obligations:

Cloud database & storage
A managed PostgreSQL database (Google Cloud SQL) for application data and Google Cloud Storage for file attachments. Both encrypt data at rest. The Service itself runs on Google Cloud.
SMS carriers
Twilio, JustCall, and Skyetel deliver and receive text messages for the numbers you connect.
Email delivery
Twilio SendGrid sends our system emails (password resets, invites, notifications, and contact-form replies). Your own outbound email is sent through the mail provider you connect.
Payments
Stripe processes subscriptions and card payments.
AI inference
Google (Gemini API / Vertex AI), only when AI features are enabled, under the no-training terms described above.
Product analytics & telemetry
PostHog (United States) receives the usage events, marketing attribution, error reports, and redacted reliability logs described above, within the limits set out there. It does not receive message content, contact details, or search text.
Monitoring
Better Stack for uptime monitoring, which does not receive message content.

Our job queue (Redis) runs on our own servers — it is not a third-party service.

We may also disclose information:

  • To comply with law — in response to a valid legal request, or to protect the rights, safety, and property of CommSync, our users, or the public;
  • In a business transfer — in connection with a merger, acquisition, financing, or sale of assets, subject to this policy;
  • With your direction — when you connect an integration, issue an API key, register a webhook endpoint, or otherwise instruct us to share data.
09

How long we keep data

We keep information for as long as your account is active and as needed to provide the Service. Specifically:

  • Messages and contacts persist in your inbox until you delete them or close your account;
  • Items you move to Trash are permanently deleted after 30 days by a scheduled sweep, and orphaned attachment files are cleaned up automatically;
  • When you delete your account, we delete your personal data and per-user content, subject to short operational backup windows and any data we must retain to meet legal, tax, or accounting obligations or to resolve disputes;
  • We may retain de-identified or aggregated data that no longer identifies you.
10

How we protect information

We encrypt data in transit with TLS; store application data and attachments on platforms that encrypt at rest (Cloud SQL and Cloud Storage); add our own AES-256-GCM encryption layer for the credentials you entrust to us; store passwords and API keys only as one-way cryptographic hashes; and isolate each workspace’s data behind role-based access controls and explicit channel grants. No method of transmission or storage is perfectly secure, but we work hard to protect your information.

Our Security overview describes these safeguards in detail — including which layer provides each protection and what we deliberately do not claim — and explains how to report a vulnerability.

11

Your choices and rights

You can access and update most of your information directly in the app, and you can delete your account at any time from your account settings, which removes your personal data and per-user content as described above.

Depending on where you live, you may have rights to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to withdraw consent. We honor these rights and do not discriminate against you for exercising them. We do not sell personal information or share it for cross-context behavioral advertising. To make a request, email support@commsync.ai — we may need to verify your identity first.

If you use CommSync through a workspace administered by someone else, please direct rights requests about that workspace’s data to your administrator; we will assist them as their processor.

12

International users and data location

CommSync is operated from the United States, and we and our subprocessors store and process information in the United States and other countries. If you use the Service from outside the United States, you understand that your information will be transferred to and processed in the United States, where data-protection laws may differ from those in your country. Where required, we put appropriate safeguards in place for such transfers.

13

Cookies and tracking

We use a small number of cookies and similar technologies, in two groups. The strictly necessary ones keep you signed in, remember preferences such as light or dark theme, and keep the Service secure. A first-party analytics cookie lets us recognize the same browser across visits, so one person counts as one person rather than a dozen — it carries an identifier, not your messages.

We do not use advertising cookies, we do not embed ad-network trackers, and we do not share cookie data with advertisers. You can control cookies through your browser, though disabling necessary cookies may break sign-in.

14

Children's privacy

CommSync is a business product intended for adults. It is not directed to children, and we do not knowingly collect personal information from anyone under 18. If you believe a child has provided us personal information, contact us and we will delete it.

15

Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the date at the top of this page and, where appropriate, notify you in the app or by email. Your continued use of the Service after an update means you accept the revised policy.

16

How to contact us

Questions about this policy or your data? Email us at support@commsync.ai or write to Haven Media Solutions LLC. We’re happy to help.

Questions?

If anything here is unclear, we’re glad to explain it in plain language. Email support@commsync.ai or use our contact page.