SyncPlayer Ecosystem
HRSyncPlayer | CadenceSyncPlayer | BodySyncPlayer

SyncPlayer App Family Privacy Policy

This privacy policy applies to the entire SyncPlayer application family, including: HRSyncPlayer (heart rate pace control), CadenceSyncPlayer (cadence pace control), and BodySyncPlayer (combo edition).

1. Data Controller and Contact

The controller of locally entrusted data is Glaucus TC Sp. z o.o., with its registered office at ul. 1 Sierpnia 53/76, 02-134 Warsaw, Poland (NIP: 5223294403). All requests related to privacy protection (GDPR) and technical support for the application family should be sent to the support e-mail address: syncplayer@glaucus.pl (corporate contact: biuro@glaucus.pl).

2. Zero-Backend Architecture and No Telemetry

All variants of the Application (HRSyncPlayer, CadenceSyncPlayer, BodySyncPlayer) have been designed based on a strict, shared "Zero-Backend" security model.

We do not use our own database servers. No telemetry parameters (heart rate, cadence), workout history, GPS coordinates, or authentication tokens leave your device towards our systems.

Data exchange takes place in a direct model (Client-to-Service P2P) exclusively between your smartphone and certified provider interfaces: Spotify AB, Strava Inc., OpenStreetMap, and Google Play Billing API.

The implementation of any tracking and reporting tools has been blocked in the software code, including Google Firebase Analytics, Crashlytics, Sentry, or Facebook SDK. We do not profile your behavior, and application crashes do not send memory dumps to third parties.

3. Cryptographic Security

All critical session data, including long-term OAuth access tokens, are hardware-encrypted on the device using the Flutter SecureStorage library and a certified Android Keystore (Trusted Execution Environment). Generated workout files and activity history are saved in an isolated App Sandbox environment, preventing other applications installed on the system from reading this data.

4. Scope of External Permissions (OAuth Scopes) – Spotify API

The integration of the player layer with the Spotify ecosystem takes place after you consent to access the following API resources:

5. Scope of External Permissions (OAuth Scopes) – Strava API

Enabling voluntary integration of workout logs with the Strava platform requires authorization:

6. Control and System Permission Rules (Android Permissions)

The GPS module does not track user location in the background 24/7. Coordinate retrieval is initiated solely by manually pressing the workout start button.