SyncPlayer App Family Privacy Policy
This privacy policy applies to the entire SyncPlayer application family, including: HRSyncPlayer (heart rate pace control), CadenceSyncPlayer (cadence pace control), and BodySyncPlayer (combo edition).
1. Data Controller and Contact
The controller of locally entrusted data is Glaucus TC Sp. z o.o., with its registered office at ul. 1 Sierpnia 53/76, 02-134 Warsaw, Poland (NIP: 5223294403). All requests related to privacy protection (GDPR) and technical support for the application family should be sent to the support e-mail address: syncplayer@glaucus.pl (corporate contact: biuro@glaucus.pl).
2. Zero-Backend Architecture and No Telemetry
All variants of the Application (HRSyncPlayer, CadenceSyncPlayer, BodySyncPlayer) have been designed based on a strict, shared "Zero-Backend" security model.
We do not use our own database servers. No telemetry parameters (heart rate, cadence), workout history, GPS coordinates, or authentication tokens leave your device towards our systems.
Data exchange takes place in a direct model (Client-to-Service P2P) exclusively between your smartphone and certified provider interfaces: Spotify AB, Strava Inc., OpenStreetMap, and Google Play Billing API.
The implementation of any tracking and reporting tools has been blocked in the software code, including Google Firebase Analytics, Crashlytics, Sentry, or Facebook SDK. We do not profile your behavior, and application crashes do not send memory dumps to third parties.
3. Cryptographic Security
All critical session data, including long-term OAuth access tokens, are hardware-encrypted on the device using the Flutter SecureStorage library and a certified Android Keystore (Trusted Execution Environment). Generated workout files and activity history are saved in an isolated App Sandbox environment, preventing other applications installed on the system from reading this data.
4. Scope of External Permissions (OAuth Scopes) – Spotify API
The integration of the player layer with the Spotify ecosystem takes place after you consent to access the following API resources:
- user-read-private: Recognizing account status (Premium/Free) for appropriate adjustment of the graphical interface.
- user-read-email: Securing profile identity and verifying session correctness.
- playlist-read-private and playlist-read-collaborative: Enabling the application to read your playlists for the pace matching algorithm (BPM/HR).
- user-library-read: Reading songs saved by you (Favorites).
- user-read-playback-state and user-modify-playback-state: Necessary for smooth remote playback control (Start, Pause, Next track) in synchronization with physical movement and playback delegation to other hardware devices in the Spotify Connect standard.
- user-read-currently-playing: Downloading title, artist, and cover art to the display in the application.
- app-remote-control and streaming: Formal requirements of the Spotify environment for local audio stream authorization.
5. Scope of External Permissions (OAuth Scopes) – Strava API
Enabling voluntary integration of workout logs with the Strava platform requires authorization:
- activity:write: Permission for the application to export locally processed workout files (coordinates, cadence, heart rate) directly to the target service.
- read: One-way verification of the sports profile paired with the application.
6. Control and System Permission Rules (Android Permissions)
The GPS module does not track user location in the background 24/7. Coordinate retrieval is initiated solely by manually pressing the workout start button.
- Location (ACCESS_FINE_LOCATION, ACCESS_COARSE_LOCATION, ACCESS_BACKGROUND_LOCATION): Read for current calculation of pace, distance, and plotting route vectors on the map – even after the screen is turned off.
- Background processes (FOREGROUND_SERVICE, FOREGROUND_SERVICE_LOCATION, FOREGROUND_SERVICE_MEDIA_PLAYBACK, WAKE_LOCK): Guarantee the uninterrupted recording of workout data against aggressive battery optimization processes in Android. An active process is accompanied by an unconditional system notification "SyncPlayer - GPS Active".
- External devices (BLUETOOTH_SCAN, BLUETOOTH_CONNECT): Scanning over-the-air and reading metrics from external HR heart rate monitors (HRSyncPlayer/BodySyncPlayer) and bike sensors. The
neverForLocationflag blocks any attempt to use this module for spatial position mapping. - Activity and Storage (ACTIVITY_RECOGNITION, READ_MEDIA_AUDIO, READ_EXTERNAL_STORAGE, POST_NOTIFICATIONS): Handling the built-in hardware pedometer, authorizing access to private MP3 file libraries, and displaying the system audio remote control.