Privacy Policy
How we handle your data — in plain language. Last updated May 27, 2026.
This Privacy Policy describes how AscendSync Code ("we," "us," "our") collects, uses, and protects your information when you use our AI productivity application. We've written this in plain English so you actually know what we do with your data.
1. Who we are
AscendSync Code is operated by Ascend HR Corp. The application is currently restricted to authorized users with @ascendhrcorp.com or @rollisfontenot.com email addresses.
2. Information we collect
From your identity provider (Replit Auth / OIDC)
- Email address
- Display name and profile picture (if provided)
- A unique account identifier
You provide directly when using the app
- Conversation messages and prompts
- Files you upload (images, documents, audio, video)
- Personal Context Layer entries — optional background information you save to make AI responses more relevant
- Project, folder, and conversation names
Collected automatically
- Standard server logs (timestamp, request path, status code, user agent) for security, abuse prevention, and debugging — retained 90 days
- One authentication session cookie (
connect.sid), HTTP-only and Secure
We do NOT collect
- Payment information (we don't process payments)
- Browsing activity outside this app
- Third-party advertising cookies, tracking pixels, or analytics SDKs
- Biometric data
3. How we use your information
- To authenticate your account
- To deliver AI responses by transmitting your selected prompt and context to the AI provider you choose for that conversation
- To store and recall your conversations, files, and settings
- To diagnose errors, prevent abuse, and improve reliability
We do not sell, rent, or share your data with advertisers. We do not use your conversations to train any model.
4. AI providers and your data
When you send a message, the prompt — together with any selected context (uploaded file text, personal context if enabled, prior conversation history) — is transmitted to the AI provider you select for that conversation. The full list of providers is on our Trust & Security page.
OpenAI, Anthropic, and Google have publicly stated that data submitted via their paid API endpoints is not used to train their models. We have not enrolled in any opt-in training program with any provider.
5. Data retention
| Data | Retention |
|---|---|
| Uploaded files (private object storage) | Deleted by file type: audio within 24 hours; documents and images within 30 days; video is never stored — transcribed and immediately discarded |
| Conversations and messages | Retained until you delete them or your account |
| Personal Context Layer | Retained until you edit or delete it |
| Authentication sessions | Expire after 7 days of inactivity |
| Server logs | 90 days |
6. Your rights
We aim to honor the user-rights principles set out in the EU General Data Protection Regulation (GDPR) — access, rectification, erasure, portability, restriction, and objection — for every user regardless of location. We do not claim full legal GDPR compliance; we apply its principles as a baseline. You can, at any time:
- Access all of your data — it's all visible in the app
- Rectify it by editing in-product (conversations, projects, personal context)
- Erase individual conversations, projects, and files in-product
- Request full account deletion by emailing [email protected]
- Request a full data export (portability) in machine-readable format from the same address
- Object to or restrict processing by contacting the same address — or simply stop using the app
We respond to deletion and export requests within 30 days. Self-service versions of these tools are on our roadmap.
7. Cookies
We use exactly one functional cookie: connect.sid for authentication. It is HTTP-only, Secure, and SameSite=Lax. No tracking, advertising, or analytics cookies are used.
8. Children
This app is not directed to children under 13 and we do not knowingly collect data from them.
9. Security
Details of our security controls — encryption, access controls, vulnerability management, incident response, subprocessors — are on our Trust & Security page.
10. International transfers
Our infrastructure and AI provider APIs are primarily hosted in the United States. By using the app from outside the US, you consent to the transfer of your information to the US.
11. Changes to this policy
We will update the "Last updated" date and notify users in-product when we make material changes.
12. Contact
- Privacy: [email protected]
- Security: [email protected]