Privacy Policy

How we handle your data — in plain language. Last updated May 27, 2026.

This Privacy Policy describes how AscendSync Code ("we," "us," "our") collects, uses, and protects your information when you use our AI productivity application. We've written this in plain English so you actually know what we do with your data.

1. Who we are

AscendSync Code is operated by Ascend HR Corp. The application is currently restricted to authorized users with @ascendhrcorp.com or @rollisfontenot.com email addresses.

2. Information we collect

From your identity provider (Replit Auth / OIDC)

You provide directly when using the app

Collected automatically

We do NOT collect

3. How we use your information

We do not sell, rent, or share your data with advertisers. We do not use your conversations to train any model.

4. AI providers and your data

When you send a message, the prompt — together with any selected context (uploaded file text, personal context if enabled, prior conversation history) — is transmitted to the AI provider you select for that conversation. The full list of providers is on our Trust & Security page.

OpenAI, Anthropic, and Google have publicly stated that data submitted via their paid API endpoints is not used to train their models. We have not enrolled in any opt-in training program with any provider.

5. Data retention

DataRetention
Uploaded files (private object storage)Deleted by file type: audio within 24 hours; documents and images within 30 days; video is never stored — transcribed and immediately discarded
Conversations and messagesRetained until you delete them or your account
Personal Context LayerRetained until you edit or delete it
Authentication sessionsExpire after 7 days of inactivity
Server logs90 days

6. Your rights

We aim to honor the user-rights principles set out in the EU General Data Protection Regulation (GDPR) — access, rectification, erasure, portability, restriction, and objection — for every user regardless of location. We do not claim full legal GDPR compliance; we apply its principles as a baseline. You can, at any time:

We respond to deletion and export requests within 30 days. Self-service versions of these tools are on our roadmap.

7. Cookies

We use exactly one functional cookie: connect.sid for authentication. It is HTTP-only, Secure, and SameSite=Lax. No tracking, advertising, or analytics cookies are used.

8. Children

This app is not directed to children under 13 and we do not knowingly collect data from them.

9. Security

Details of our security controls — encryption, access controls, vulnerability management, incident response, subprocessors — are on our Trust & Security page.

10. International transfers

Our infrastructure and AI provider APIs are primarily hosted in the United States. By using the app from outside the US, you consent to the transfer of your information to the US.

11. Changes to this policy

We will update the "Last updated" date and notify users in-product when we make material changes.

12. Contact