Privacy & Data
Sovereignty.
We value technical integrity and client confidentiality. This Privacy Policy details how we collect, protect, and handle your data and source code across all software engineering sprints and advisory engagements.
Data Protection &
Compliance Framework.
Last Updated: August 2026 // Production Policy
1. Information We Collect
We only collect data strictly necessary to scope, engineer, and deploy software services, manage technical communication, and comply with contractual obligations.
Client Inbound & Intake Details
When you initiate a discovery audit, project request, or contact our engineering team, we collect your name, business email, organization name, technical specifications, and project budget parameters.
Technical Telemetry & Analytics
We collect non-identifiable technical metadata such as browser version, edge network latency, operating system, and anonymous Core Web Vitals performance benchmarks to optimize delivery speeds.
Proprietary Codebases & Credentials
Any repository access, API keys, or database credentials shared for development purposes are stored exclusively in encrypted environment vaults and purged upon project handoff.
2. How We Use Your Information
Your data is used solely to deliver software engineering sprints, provide architectural reviews, and maintain direct client communication.
Service Delivery & Scoping
We use your technical inputs to formulate fixed-milestone sprint scopes, design entity relationship diagrams (ERDs), and engineer production web and mobile software.
Communication & Technical Updates
We send sprint progress reports, staging preview URLs, code review briefings, and billing statements directly to your authorized technical contacts.
Zero Public Model Training
We do not sell, rent, or monetize your proprietary business data or source code. We never use client codebases or confidential data to train public foundation AI models.
3. Data Protection & Security Architecture
We employ defense-in-depth security standards to protect your technical assets, databases, and communication channels.
Encryption Protocols
All web traffic and intake forms are encrypted using 256-bit TLS (Transport Layer Security) in transit and AES-256 encryption at rest.
Access Control & Mutual NDAs
Access to client infrastructure and sensitive documentation is restricted to senior engineering architects assigned to your sprint, backed by mutual Non-Disclosure Agreements (NDAs).
Credential Sanitization
We enforce strict environment variable separation (e.g., Vercel Secrets, AWS KMS, Doppler) to prevent accidental credential leakage in version control.
4. Third-Party Infrastructure Providers
We only share data with vetted cloud infrastructure and development vendors essential for hosting, deployment, and communication.
Cloud Hosting & Edge CDNs
We utilize industry-standard cloud providers including Vercel, Amazon Web Services (AWS), Supabase, and Cloudflare to host staging environments and route API telemetry.
Analytics & Monitoring
We may use privacy-first telemetry tools (such as Sentry, PostHog, or Datadog) to track uptime reliability and error logs without storing personally identifiable information.
Legal Disclosures
We only disclose information if required by applicable law, regulatory enforcement, or a binding court order.
5. Your Rights & Data Sovereignty
You retain full ownership of your data and intellectual property with total rights to access, modify, or permanently purge your records.
Access & Rectification
You may request a copy of all personal and project data we hold regarding your account or update any inaccuracies at any time.
Complete Data Erasure (Right to be Forgotten)
Upon milestone completion and final handoff, you can request the permanent deletion of all intake records, staging databases, and temporary environment credentials.
Full IP Ownership
All custom source code, design systems, database schemas, and documentation produced during our engagement belong 100% to you upon milestone settlement.
6. Policy Updates & Contact
We periodically review this policy to reflect new security standards, legal compliance guidelines, and technical infrastructure updates.
Policy Evolution
Any material changes to our privacy practices will be updated directly on this page with an updated revision date.
Direct Security & Privacy Contact
For privacy questions, data deletion requests, or NDA inquiries, contact our security team directly at privacy@sycora.dev.