Privacy Policy
Effective date: October 7, 2026
ContentsPrivacy Policy
Desync AI, Inc. (Desync, we, us) explains here how it handles personal information across its websites (including desync.ai and catholic-os.desync.ai), the Desync app (including Lead Gen and CRM), Catholic OS, Observatory, datasets, API and MCP services, research, consulting, and related support (Services). Contact us at [email protected] or Desync AI, Inc., 2412 18th Avenue North, #B, Nashville, TN 37208.
1. Information we handle
#Account and business information includes details you provide when registering, purchasing, contacting us, or requesting support, such as your name, organization, contact information, account details, and correspondence. Payment processing is provided through Stripe; transaction and billing information is used to administer purchases and refunds.
Publicly sourced information is information collected independently from publicly accessible sources. Depending on the source and product, records may include published names, professional roles, organizational affiliations, contact details, professional profile links, education history, current employer and position, city-level location, professional credentials and identifiers for healthcare providers, text from published documents such as parish bulletins, source references, AI-generated summaries, and information about organizations.
Customer Content means information an organization or its authorized users provide through uploads, connected systems such as HubSpot, prompts, instructions, or customer-specific projects. It also includes customer-specific results derived from that information. Customer Content is separate from Desync's independently collected datasets.
Service and analytics information concerns how people access and use the Services. We use PostHog for product analytics. PostHog records the pages you view, including the page address, the referring page and any campaign parameters in the link. It also records when you leave a page and your clicks and other interactions with page elements, including the element and its visible text. In the Observatory, it may also record the text of searches you run. When you are signed in to our software, these events may be linked to your account identifier, email address, plan and subscription status and, in some products, to your workspace and its name. PostHog may receive your IP address and use it to estimate your general location. On desync.ai, PostHog sets a first-party cookie that holds identifiers for your browser and session and is set to expire after 365 days, and it keeps related values in your browser's local and session storage. The desync.ai website does not currently respond to browser Do Not Track signals.
PostHog may also record your visits to desync.ai and to our software as session recordings: how the page looks and changes as you scroll, move the pointer, click and type, together with messages your browser logs. Text you type into form fields is masked, so it is not recorded. We keep recordings for 30 days and use them to find and fix problems and to understand how people use the Services.
When you send a form on desync.ai, we store your answers together with the address of the page you sent it from, your browser's user agent and, when available, your country. We use your IP address to limit repeated submissions. Those form pages also load a bot-check service in your browser to screen out automated submissions. The service receives your IP address and information about your browser when it runs, and we send it your IP address again when we verify a submission. Forms in the Observatory store your IP address with your submission and may also store your browser's user agent.
2. Public records and sensitive information
#Our independent datasets use publicly accessible sources. We record source-supported facts, and some records also include AI-generated summaries, which are not verified sources. We do not infer an individual's personal religious beliefs from employment, education, organizational connections, or other associations. A published religious role may itself reveal religious affiliation; a connection to a Catholic organization does not by itself establish a person's beliefs.
We do not intentionally collect information about children or individual health information for our datasets. The Services are intended for adult professional users. Customers must not upload children's information or individual health information. If you believe excluded information has been included, contact [email protected] so we can investigate and take appropriate action.
3. How we use information
#We use information to provide the Services customers request; operate accounts and integrations; produce research, search results and customer deliverables; process payments and refunds; respond to inquiries and to support and privacy requests; send updates you ask to receive, including by text message or messaging app when you give us a phone number for that purpose; understand product use; protect the Services; and meet legal obligations.
When we handle Customer Content on behalf of an organization, we do so to provide its requested services under the applicable agreement and instructions. When Customer Content includes personal information, we process it as the organization's service provider, only to provide the Services and as the organization instructs. We do not sell or share it, or use, keep, or disclose it for any other purpose or outside our business relationship with the organization. We do not combine it with our datasets or with personal information from other sources, except as applicable law permits a service provider to do. The organization determines its purposes for that content. Desync separately determines how it handles its independent datasets, account administration, and its own business records.
We do not add Customer Content, including connected HubSpot records, to our shared datasets, we do not sell it, and we do not make it available to other customers. Access to a customer's information does not authorize us to reuse it as data for other customers.
4. Inference and service providers
#AI-assisted processing of Customer Content uses models from third-party AI model providers. Relevant inputs are processed to provide the requested feature. Some features store your prompts and the resulting outputs with your account, such as assistant conversations.
Our named providers include Neon for database services, Stripe for payments, PostHog for analytics, and Baseten for inference hosting. We may disclose information to providers as necessary for the functions they perform. Our other providers include services for hosting and network security, sign-in, email delivery, error monitoring, bot checks on website forms, retrieving public web pages, and AI models. Providers may also handle information for their own legal or account-administration purposes under their applicable notices.
5. Other disclosures and dataset access
#Customers receive access to the records and deliverables included in their purchases. These records can include publicly sourced information about people. Customers may view and search them, access them through our API and MCP services, and, where their plan or Order allows, download dataset files or use bulk export features. Customers may share the data with their own employees and contractors who are bound by restrictions at least as protective as our Terms of Use, and with others only where their Order expressly allows it. Providing paid access to personal information may qualify as a sale under applicable privacy law, even where the source was publicly accessible. This policy does not make a blanket promise that Desync never sells personal information.
Customer Content is not made available to other customers. We may disclose information when necessary to comply with law, respond to valid legal process, protect rights or security, or complete a corporate transaction subject to appropriate confidentiality and applicable legal requirements.
6. Hosting and retention
#Desync's services and data are hosted in the United States. Hosting location does not by itself establish where all provider support or other processing occurs.
We retain Customer Content while your account remains open, including after you cancel a subscription. Canceling does not close your account or delete Customer Content; to do either, email [email protected]. Following account closure or a verified deletion request, we delete the affected Customer Content from active systems within 30 days, unless retention is required by law. Where a shorter legal deadline applies, we follow it. Requests received while an account remains active may affect the features that require the deleted information.
Backup copies may remain after the affected Customer Content is deleted from active systems.
Necessary billing, tax, security, dispute, and legal records may be retained separately for their required or justified periods. The customer-data 30-day rule does not mean every independently sourced public record expires 30 days after collection.
7. Requests and choices
#Contact [email protected] to request access, correction, deletion, or removal from a Desync dataset. Include enough information to identify the relevant record or account, such as a source or profile link. Do not send passwords or payment credentials. We may request proportionate verification to protect information from unauthorized access.
Depending on applicable law and our processing, you may have additional rights to obtain a portable copy, opt out of sale or certain sharing or targeted advertising, limit certain sensitive-data uses, appeal a decision, or use an authorized agent. We will handle applicable rights within the required periods and will not unlawfully discriminate for exercising them.
If information is controlled by a customer organization, direct your request to that organization; we can help identify the appropriate route and assist the organization under our agreement. Removing a Desync record does not remove the original source or automatically remove copies already held independently by a recipient. We take any additional recipient-notification or deletion steps required by law.
8. Security and policy changes
#No service can guarantee absolute security. Access to customer accounts requires sign-in, and access to our API and MCP services requires credentials that we issue. We will address and communicate security incidents as required by applicable law and customer agreements.
We may update this policy as our Services or practices change. The effective date identifies the current version. Where required, we provide additional notice or obtain consent before a material change applies. Questions: [email protected], Desync AI, Inc., 2412 18th Avenue North, #B, Nashville, TN 37208.
Data Sourcing and Use Policy
#This policy explains how Desync AI, Inc. sources and presents its independent datasets, keeps customer information separate, and sets rules for responsible use. It applies across Desync products, APIs, research, and consulting together with the applicable Order, Terms of Use, and Privacy Policy.
1. Public sources
#Desync independently collects information only from publicly accessible sources. These may include organization websites, published directories, public documents, and public records relevant to the product. Source availability does not eliminate privacy, intellectual-property, access, or other legal restrictions. A Desync license grants only the rights Desync is entitled to provide.
The information included depends on the dataset and stated scope. Organization facts, published professional roles, contact information, and source references must be described accurately in the product documentation. We do not intentionally include children's information or individual health information in our independent datasets.
2. Recorded facts and generated analysis
#We record published facts and relationships. We do not infer a person's religious beliefs from a name, employment, education, institutional connection, or other association. A record of affiliation is not a declaration of personal belief. A published clerical or other religious role may itself disclose a religious connection and should be handled accordingly.
Search, matching, summaries, and AI-assisted analysis can introduce errors. Source facts, normalized records, and generated analysis should be distinguished in the product or deliverable. A generated result is not an independently verified source. Verify material conclusions against the cited source where available, and flag missing or conflicting evidence.
3. Provenance and corrections
#Source coverage and verification vary by product. Review the source references and dates provided with the record or deliverable; a missing date is not evidence that a record is current. We do not guarantee that every field is complete, that every source is accurate, or that every record has been recently rechecked.
Report an inaccurate match, outdated record, missing attribution, or inappropriate inclusion to [email protected]. Include the relevant record or source link and the correction you request. We assess the evidence and take the appropriate action, which may include correction or removal.
4. Customer data stays separate
#Customer uploads, connected HubSpot records, private project information, and customer-specific derived results do not enter Desync's shared datasets. We do not sell that information or reuse it as data for other customers. Under the applicable agreement, Desync personnel and our service providers may process it only as needed to provide and support the customer's requested services, keep them secure, and comply with law.
AI-assisted processing of Customer Content uses third-party AI model providers. That processing does not make Customer Content public or part of our independent dataset. Any use for training or fine-tuning must be disclosed and authorized under the applicable agreement.
Disconnecting an integration stops future access to that integration. Previously imported data is handled under the customer's instructions and the Privacy Policy's retention terms. Disconnecting does not by itself delete information already imported; customers who want it deleted can contact [email protected] or close their account.
5. Permitted and prohibited use
#Customers may use data for the lawful research, relationship management, and other internal business purposes permitted by their purchase. A dataset license does not guarantee that a particular outreach campaign, profiling activity, or other use is lawful. Customers must independently meet applicable notice, consent, communication, and opt-out requirements.
Do not use Desync data for stalking, harassment, unlawful discrimination, unlawful surveillance, fraud, or other rights violations. Do not treat an institutional association as proof of personal belief. Do not use Desync data to decide anyone's eligibility for credit, insurance, employment, housing, or any other purpose covered by the Fair Credit Reporting Act. Desync does not provide consumer reports.
Unless your Order expressly permits it, do not resell, sublicense, publicly republish, or distribute a dataset or any substantial part of it, or use a dataset to build or improve a competing dataset or data product. You may share licensed data with your employees and contractors who work for you and are bound by restrictions at least as protective as the Terms of Use. Preserve applicable source references, license restrictions, and removal notices. Access does not authorize bypassing security controls or collecting additional nonpublic information.
6. Removal and retention
#Individuals can contact [email protected] about their own records, including correction, removal, and applicable opt-out rights. We verify requests proportionately and explain the outcome.
A removal from Desync does not alter the original public source or automatically recall every prior recipient's independent copy. We comply with applicable obligations to notify recipients or require action. When we tell customers that a record in licensed data has been corrected or removed, they must update or delete their copies of that record within a reasonable time.
When an account is closed, or when we receive a verified deletion request, we delete the affected Customer Content from our active systems within 30 days, as described in the Privacy Policy and subject to the exceptions it states. Customers remain responsible for the retention and lawful use of copies they control.
7. Questions and changes
#Questions about a dataset, its permitted use, a source, or a person's record can be directed to [email protected] or by mail to Desync AI, Inc., 2412 18th Avenue North, #B, Nashville, TN 37208. We update this policy when practices or requirements change and identify the current version by its effective date. If this policy conflicts with the Terms of Use, the applicable Order, or a signed agreement with Desync, those documents control, and mandatory law controls in every case.

