Legal
Privacy Policy
Last updated June 12, 2026
Syncademia builds Sync, an operations platform that clinical education programs license for their students, faculty, and preceptors. This policy explains what we collect, why, and what we will never collect.
The short version
- We process student and faculty data on behalf of your institution and under its direction. Your institution decides who has accounts and what the data is used for.
- We do not collect patient-identifying information, ever. Clinical case logs are de-identified by design.
- We do not sell data, use it for advertising, or use it to train AI models.
- Location is captured only at the moment of clinical check-in. Sync does not track location in the background.
Who this covers
This policy covers the Sync platform (web and mobile) and this website. If you use Sync through your school or program, our contract with that institution governs how we handle its data; where that contract and this policy differ, the contract controls.
What we collect
Account and profile data
Name, institutional email address, role (student, faculty, preceptor, administrator), and program/cohort assignment, typically provided by your institution via its student information system or roster import, and linked to your institutional sign-on account.
Education records
Clinical schedules and rotation assignments, attendance, case logs, evaluations, and credential documents your program requires (such as immunization records, titers, licenses, and certifications). These are education records protected under the Family Educational Rights and Privacy Act (FERPA); Syncademia processes them as a service provider acting at the institution’s direction.
Location at check-in
When you check in at a clinical site, the app records your location at that moment to verify attendance. Location is used only for check-in verification, is visible to your program, and is never collected in the background.
What we deliberately do not collect
Sync stores no patient-identifying information: no patient names, dates of birth, record or account numbers, contact information, photographs, or any other direct patient identifier. Case logging captures de-identified clinical attributes only, and the platform validates this at the point of entry.
Technical data
Standard service logs (IP address, browser/device type, pages requested, timestamps) used for security, debugging, and reliability. Sync uses session cookies required to keep you signed in; we do not use advertising trackers or third-party analytics cookies on the platform.
How we use data
To provide the service to your institution: scheduling, attendance, case tracking, credential management, evaluations, notifications (email and, if you enable them, push notifications), reporting to your program, and support. We also use technical logs to keep the service secure and reliable. That’s the list: there is no advertising use, no sale of data, no training of AI models on your data.
AI features
Some Sync features use AI models. For example, reading a clinical site’s schedule document into structured assignments for human review. These features operate only on scheduling documents and de-identified data; patient identifiers are never sent to any AI model (the platform doesn’t store them in the first place), and your data is not used to train models.
Who we share data with
Your institution and its authorized program staff: it’s their program and their education records. Beyond that, only the service providers (subprocessors) we use to run Sync: Amazon Web Services (hosting, United States) and Cloudflare (DNS and content delivery). We share data with no one else, except where the law requires it. And where permitted, we will notify your institution before responding to legal requests.
Retention and deletion
We retain data for as long as your institution’s contract directs. When a contract ends, the institution’s data is exported on request and then destroyed. Sync’s architecture gives each institution a dedicated database, so deletion is complete and verifiable. Students: requests to access or correct your records go through your program, consistent with FERPA.
Security
Data is encrypted in transit and at rest, isolated per institution, and backed up with point-in-time recovery. See the security page for specifics.
Children
Sync is built for graduate health programs and is not directed at children under 13.
Changes to this policy
When we update this policy we’ll change the date above; for material changes we’ll notify institutional administrators directly.
Contact
Privacy questions: hello@syncademia.com, or write to Syncademia, 950 South Pine Island Road, Suite 150, Plantation, FL 33324.