1. Introduction
Three Four Sàrl ("we," "our," or "us") operates DuoSync, a relationship enhancement application. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.
We are committed to protecting your privacy and ensuring transparency about our data practices. This policy complies with the EU General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), and other applicable privacy laws.
2. Information We Collect
2.1 Information You Provide
- Account Information: Email address, display name, and profile preferences
- Conversation Data: Your responses to conversation prompts and saved favorites
- Partner Information: Partner's email address for account linking (with their consent)
- Communication: Messages you send to our support team
- Payment Information: Processed by Stripe, Apple, or Google - we don't store payment details
2.2 Information We Collect Automatically
- Usage Data: How you interact with the app, features used, session duration
- Device Information: Device type, operating system, app version, unique device identifiers
- Log Information: IP address, access times, error logs (anonymized)
- Analytics Data: App performance metrics and crash reports (anonymized)
2.3 Information We Don't Collect
- We don't access or read your conversation content
- We don't collect sensitive personal data beyond what's necessary
- We don't use tracking cookies on our website
- We don't sell your personal information to third parties
3. How We Use Your Information
3.1 Service Provision
- Provide and maintain the DuoSync application
- Enable conversation synchronization between partners
- Process your subscription and payments
- Provide customer support and respond to inquiries
3.2 Service Improvement
- Analyze usage patterns to improve app functionality
- Develop new features and conversation themes
- Monitor app performance and fix technical issues
- Conduct research on relationship communication (anonymized data only)
3.3 Communication
- Send important service updates and notifications
- Provide customer support
- Send promotional communications (with your consent)
4. Data Security and Encryption
4.1 Encryption
All conversation data is encrypted both in transit and at rest using industry-standard AES-256 encryption. Your conversations are encrypted before leaving your device and remain encrypted in our databases.
4.2 Access Controls
We implement strict access controls and employ security measures including:
- Multi-factor authentication for all team members
- Regular security audits and penetration testing
- Secure development practices and code reviews
- Limited access to personal data on a need-to-know basis
4.3 Data Centers
Our data is stored in secure, SOC 2 Type II certified data centers with physical and network security measures.
5. Data Sharing and Disclosure
5.1 We Don't Sell Your Data
We never sell, rent, or trade your personal information to third parties for marketing purposes.
5.2 Limited Sharing
We may share your information only in these limited circumstances:
- Service Providers: Trusted third parties who help us operate the service (hosting, analytics, payment processing) under strict confidentiality agreements
- Legal Requirements: When required by law, regulation, or court order
- Safety: To protect our users' safety or prevent harm
- Business Transfer: In the event of a merger or acquisition (with notice to users)
5.3 Partner Data
Conversation data is shared only between linked partners within the app. We don't share your conversations with anyone else.
6. Your Privacy Rights
6.1 GDPR Rights (EU Users)
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate personal data
- Erasure: Request deletion of your personal data
- Portability: Export your data in a machine-readable format
- Restriction: Limit how we process your data
- Objection: Object to processing based on legitimate interests
- Withdraw Consent: Withdraw consent for data processing
6.2 CCPA Rights (California Users)
- Know: Know what personal information we collect and how it's used
- Delete: Request deletion of your personal information
- Opt-Out: Opt-out of the sale of personal information (we don't sell data)
- Non-Discrimination: Equal service regardless of privacy choices
6.3 Exercising Your Rights
To exercise these rights, contact us at contact@duosync.app. We'll respond within 30 days for GDPR requests and 45 days for CCPA requests.
7. Data Retention
7.1 Account Data
We retain your account data as long as your account is active and for up to 90 days after deletion to allow for account recovery.
7.2 Conversation Data
Your conversation data is retained as long as your account is active. You can delete specific conversations at any time, and we'll permanently delete them within 30 days.
7.3 Analytics Data
Anonymized analytics data may be retained for up to 26 months for service improvement purposes.
8. International Data Transfers
Your data may be transferred to and processed in countries other than your country of residence. We ensure adequate protection through:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions where applicable
- Certification schemes and codes of conduct
9. Children's Privacy
DuoSync is not intended for children under 16. We don't knowingly collect personal information from children under 16. Users between 16-18 require parental consent. If we become aware that we have collected personal information from a child under 16, we will take steps to delete that information.
10. Cookies and Tracking
10.1 Our Website
Our website uses minimal, essential cookies only for functionality. We don't use tracking cookies or third-party advertising cookies.
10.2 Mobile App
Our mobile app doesn't use cookies but may use device identifiers for analytics and crash reporting (anonymized).
11. Third-Party Services
We use trusted third-party services to provide our service:
- Stripe: Payment processing (see Stripe's privacy policy)
- Apple App Store & Google Play: App distribution and in-app purchases
- Analytics Services: Anonymized usage analytics (Firebase Analytics)
- Cloud Storage: Encrypted data storage (AWS)
12. Privacy by Design
We implement privacy by design principles:
- Data minimization - we collect only what's necessary
- Purpose limitation - data is used only for stated purposes
- Storage limitation - data is kept only as long as needed
- Transparency - clear communication about our practices
- User control - you control your data and privacy settings
13. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in our practices or legal requirements. We'll notify users of significant changes through:
- In-app notifications
- Email notifications
- Website announcements
Continued use of the service after changes constitutes acceptance of the updated policy.
14. Contact Us
For privacy-related questions, data requests, or concerns:
- Email: contact@duosync.app
- Subject Line: "Privacy Inquiry"
- Address: Three Four Sàrl, Rue Saint-Germain 36, c/o Julien Cheseaux, 1030 Bussigny, Switzerland
- Support Hours: Monday-Friday 09:00-17:00 CET
15. Data Protection Officer
For GDPR-related inquiries, you can contact our Data Protection Officer at the email address above with the subject line "DPO Inquiry".
📞 Quick Contact for Privacy Rights
To exercise your privacy rights or for urgent privacy concerns, email us at contact@duosync.app with "Privacy Rights" in the subject line. We'll respond promptly.