LEGAL

Sineco Privacy Policy

Last Updated: 17 July 2026

Your privacy matters to Sineco. This Privacy Policy explains how we process your personal data when you use the Sineco mobile app, our Apple Health and Garmin integrations, and our website and support channels. A separate cookie notice describes any non-essential cookies or tracking technologies used on sineco.ai.

"Personal data" means information relating to an identified or identifiable person. Because Sineco adapts your music using your heart rate, some of the data we process is data concerning your health. Health data receives special protection under UK law, and we only process it with your explicit consent, which you can withdraw at any time.

Sineco Ltd is established in the United Kingdom, and this Privacy Policy is based on the UK General Data Protection Regulation and the Data Protection Act 2018, as amended including by the Data (Use and Access) Act 2025. The legal grounds we rely on for each processing activity are set out below.

Categories of Personal Data Processed by Sineco

Personal data that is processed when you create a Sineco account:

When you create an account, we ask for your name, your email address, a means of signing in and confirmation that you are 18 or over. We also hold your subscription status so the app knows what you have access to.

Purposes and legal grounds

(a) We process your sign-in details so you can access your account securely. The legal ground is performance of our contract with you, together with our legitimate interest in protecting the security of your account.

(b) We process your age confirmation to keep the service restricted to adults. The legal ground is our legitimate interest in enforcing our age restriction.

(c) We process your email address to send you important information about your account and the service, such as material changes to this Privacy Policy. The legal ground is our legitimate interest in keeping you informed about the service you use.

(d) If you opt in, we process your email address and marketing preference to send you optional marketing messages. The legal ground is your consent or, where lawful, the soft opt-in under the Privacy and Electronic Communications Regulations. You can unsubscribe at any time, and we keep a minimal suppression record so your opt-out is honoured. Health data and inferences drawn from it are never used for marketing.

Personal data that is processed when you give Sineco access to your heart rate:

Before Sineco reads any heart-rate data, you are shown a separate consent step that asks for a specific, affirmative choice, and we record when and how you gave it. This Privacy Policy is information about our processing; it is not itself your consent.

If you connect Apple Health, Sineco requests read access only, and only to heart rate, which is the only measurement the current version of the app uses. If you pair a Garmin device, Sineco receives heart rate from it directly over Bluetooth during your sessions, and your paired device identifier is stored on your phone so the app can reconnect. A wearable's ability to provide other measurements does not give Sineco permission to collect them.

Purposes and legal grounds

We process your heart rate, and the physiological inferences we draw from it, to adapt your music to your body in real time and across sessions. The legal ground is your explicit consent under Article 6(1)(a) and Article 9(2)(a) UK GDPR. You can withdraw consent at any time: revoke Sineco's access in the iOS Health app or unpair your Garmin device, email development@sineco.ai, or delete your account in the app. If you withdraw, Sineco stops reading and inferring from heart-rate data, and you can keep using the non-adaptive parts of the app where available. Withdrawal does not affect the lawfulness of past processing, and we may keep a limited consent record where necessary to demonstrate compliance.

Personal data that is processed during an adaptive music session:

When you start a session, you choose settings such as your activity, the type of place you are in and a genre. The app then plays music and adapts it as your heart rate changes. During the session we record the tracks played and your interactions with them, such as skip, pause, resume and like, and changes in your intensity tier. When the session ends we record its duration and whether tracks were skipped. The section "How Your Heart-Rate Data Flows" below describes exactly which heart-rate values leave your phone.

The "location" in your session settings is a label you choose yourself, such as where you are working out. Sineco does not access or collect your device's location.

Purposes and legal grounds

(a) We process your session settings, intensity tier and interaction events to run the adaptive experience and carry your musical preferences across sessions. Where a record involves your heart rate or inferences drawn from it, including tier-change events, the legal ground is your explicit consent, as described above.

(b) We process your listening behaviour, such as tracks played, skips and likes, to personalise the experience, for example avoiding recently played tracks. The legal ground is performance of our contract with you.

Personal data that is processed when you purchase a subscription:

Subscriptions are purchased through the Apple App Store. Apple collects your payment information under its own terms; Sineco does not see or store your payment card details. We receive confirmation of your subscription status so we can provide what you have paid for.

Purpose and legal ground

We process your subscription status to deliver the service you purchased. The legal ground is performance of our contract with you.

Personal data that is processed when you contact Sineco:

When you contact our support channels we process your name, contact details, the content of your messages and information about the issue you raise. Please do not include medical details that are not needed for your request.

Purpose and legal ground

We process this information to answer your questions and resolve your issue. The legal ground is our legitimate interest in providing quality support to our users. If your request necessarily contains health information, we process it only to handle that request.

Personal data that is processed to keep Sineco working and secure:

We process technical information such as device and app version, IP address, connection events, crash reports and diagnostics, security logs, and records of the consents you have given.

Purposes and legal grounds

(a) We process technical, diagnostic and security data to identify and fix errors and to protect the service against fraud and abuse. The legal ground is our legitimate interest in providing a reliable and secure service. Health data is touched for this purpose only if it is essential to investigate a specific incident.

(b) We keep records of your consents, withdrawals and complaints so we can demonstrate that our processing was lawful. The legal ground is compliance with our legal obligations and our legitimate interest in handling legal claims.

How Your Heart-Rate Data Flows

Because heart rate is the most sensitive data we touch, here is exactly what happens to it.

On your phone, heart rate from your Apple Watch or Garmin device streams into the app and is smoothed and analysed in your phone's memory to work out your current intensity tier and show your live heart rate on screen. This stream is held in memory for the active session only, is discarded when no longer needed, is not saved to your device and is not uploaded to our servers.

When a session starts, the app sends our server a single snapshot of your heart rate and resting heart rate so we can compute your starting intensity tier. This is the main moment a heart-rate value reaches our servers. During a session, when your intensity tier changes, the event we log can include the heart-rate value that triggered the change. When a session ends, the app sends only the duration and whether tracks were skipped, with no heart-rate data.

The only things stored on your phone are your paired Garmin device identifier, your last session preferences and a list of recently played tracks. No heart-rate data is kept on your device.

We will not describe data as anonymous unless it truly cannot be linked back to you. Data that is merely pseudonymised or de-identified remains personal data and is treated as such.

Data Not Collected at Launch

The current version of Sineco does not collect heart-rate variability, cadence, sleep, recovery scores, temperature, oxygen saturation, precise location, routes, weight or any other wearable measurement. If a future version introduces any of these, we will update this Privacy Policy and the consent flow before access begins, and we will request only the minimum needed for the new feature.

Categories of Recipients of Personal Data

We never sell your personal data. We never share your health data with advertisers, coaches, clinicians, employers, performance organisations, music labels, artists, rights holders or brand partners, and we never provide it to data brokers. Data received from Apple Health is additionally never used for use-based data mining and is not stored in iCloud by Sineco.

Service providers

We use Amazon Web Services, London region, to host our backend, storage and backups. We also use service providers that help us operate sign-in, subscriptions, support, email and app diagnostics. These providers process personal data on our behalf, only on our instructions and under contracts that impose security and confidentiality obligations. Subscriptions purchased through the App Store are processed by Apple under Apple's own terms.

Integration providers

Garmin and Apple handle your data under their own privacy policies when you use their devices and services and direct the connection to Sineco.

Other disclosures

We may disclose personal data where we have your consent to do so; where the law requires it, such as under a valid court order; where necessary and proportionate to establish, exercise or defend legal rights or to address serious security threats; or, under confidentiality safeguards, in connection with a financing, reorganisation, merger or sale of our business, in which case any new controller must continue to protect your data and provide any required notice.

Advertising, Marketing and Analytics

Sineco does not use your heart-rate data, physiological inferences, music adaptations or any Apple Health or Garmin data for advertising or marketing of any kind.

If a future version of Sineco introduces advertising or sponsored content, health data and health-derived profiles will remain excluded from selecting, measuring or personalising it, and we will provide any additional notice and choices required before such a change.

We may use minimal technical analytics to understand reliability and feature use, subject to any consent the law requires for storage or tracking on your device. Health data is excluded from analytics.

International Transfers of Personal Data

Our servers are located in the AWS London region, in the United Kingdom. If we appoint a service provider that processes any personal data outside the UK, we will assess the transfer and rely on safeguards approved under UK law, such as adequacy regulations or the UK International Data Transfer Agreement or Addendum, together with any supplementary measures needed. You can contact development@sineco.ai for information about the safeguard used for a particular transfer.

Automated Decision-Making, Including Profiling

Sineco uses automated processing to run the adaptive experience. The inputs are your live heart rate on your phone, the snapshot taken at session start and your session history. From these, Sineco estimates your intensity tier, may translate it into a musical-intent signal, and chooses how the music should adapt.

The output of this processing changes your music and nothing else. We do not make decisions based on automated processing that produce legal effects or similarly significant effects on you; Sineco does not decide employment, insurance, credit, education, eligibility or access to essential services.

Sineco staff do not routinely view your health data. Access is limited to what is needed for support you request, or for security and legal reasons.

AI Model Training

We do not use your personal data, including your health data, to train, fine-tune, test or evaluate AI models. The live inference needed to run the adaptive feature is not model training, and your data is used only to deliver your live service as described in this Privacy Policy.

If we ever propose to use personal data for model development, we will first confirm that our wearable-provider agreements permit it, update our data protection impact assessment and this Privacy Policy, and ask for a separate, optional and explicit opt-in for any health data. Declining will never affect your use of the core service.

Retention and Deletion of Personal Data

We keep personal data only for as long as it is needed for the purposes described in this Privacy Policy, subject to any legal requirement to retain a limited record for longer. Our retention periods are:

  • The continuous heart-rate stream and its rolling average exist in your phone's memory for the active session only and are never stored or uploaded.
  • Session-start heart-rate snapshots, tier-change heart-rate values and session records are kept for 12 months from the session or until account deletion, whichever is earlier, and are then deleted or irreversibly de-identified.
  • The Garmin device identifier, recent preferences and excluded track IDs on your phone remain until replaced, cleared, the app is removed or your account is deleted.
  • Account data is kept while your account is active, then deleted from active systems within 30 days of a deletion request, except limited legal or suppression records.
  • Consent and withdrawal records are kept for six years after withdrawal or account closure, restricted to compliance evidence and never reused for product purposes.
  • Support requests are kept for 24 months after closure, unless a live dispute or legal claim requires longer.
  • Technical and security logs are kept for 12 months, unless an incident requires preservation.
  • Backups are overwritten within 90 days of deletion from active systems, and deletion is re-applied if a backup is ever restored.
  • Marketing opt-out suppression records are kept only as long as needed to honour the opt-out, holding the minimum identifier and preference.

You can delete your account in the app at any time, which starts deletion on the schedule above. Revoking Apple Health access or unpairing your Garmin device stops new data flowing to Sineco but does not by itself delete data already on our servers; deleting your account, or a separate erasure request, does.

Security

We protect your data with technical and organisational measures appropriate to health data. The continuous heart-rate stream is processed locally in your phone's memory and never uploaded; data sent between the app and our backend is encrypted in transit; our hosting is in AWS's London data centres; and access is limited to people and providers who need it for an authorised purpose.

No system is perfectly secure. We review risks as the service develops, and if a breach occurs that puts your rights at risk, we will investigate and make the notifications the law requires, including to the Information Commissioner's Office and, where required, to you.

Age Restriction

Sineco is available only to people aged 18 or over. The service is not intended or designed for children, and a person under 18 must not create or use a Sineco account.

We may use a proportionate age check during registration. If we reasonably believe an account belongs to someone under 18, we may suspend it, stop the related processing and delete the associated data unless a lawful reason requires limited retention.

Sineco Is Not a Medical Service

Sineco is not a medical device and does not provide medical advice, diagnosis, treatment or emergency monitoring. Heart-rate readings, inferences, music adaptations and recommendations may be incomplete or inaccurate and must not replace professional medical judgment. Do not use Sineco to identify or respond to a medical emergency; contact emergency services if you believe you need urgent help.

Privacy Policy Updates

We may update this Privacy Policy as the app, our integrations or the law change, including before any new data type, integration, sharing arrangement, advertising practice or model-training use is introduced. You can see when it was last revised from the "Last Updated" date at the top. If a change materially affects how we use health data or rely on consent, we will give you prominent notice in the app and, where the law requires it, ask for fresh consent before the new processing begins.

Data Controller and Contact

Your personal data is controlled by Sineco Ltd, company number 16350853, registered at 21 Rowbotham Street, Hyde, England, SK14 5RP. Our privacy contact can be reached by email at development@sineco.ai, and our website is https://sineco.ai.

Manage Your Data and Your Rights

You can manage your data directly: revoke Apple Health access or unpair your Garmin device in the relevant settings, withdraw your health-data consent by email, and delete your account in the app at any time.

Under UK data-protection law, and depending on the circumstances and applicable exemptions, you have the right to receive a copy of your personal data and information about its use; to have inaccurate or incomplete data corrected; to have your data deleted; to restrict how it is used; to receive data you provided in a structured, commonly used and machine-readable format and, where technically feasible, have it transmitted to another controller; to object to processing based on legitimate interests or to direct marketing; and to withdraw consent at any time.

To exercise any of these rights, use the in-app controls or email development@sineco.ai. We may request information reasonably necessary to verify your identity and protect your account. We normally respond within one month, subject to lawful extensions for complex or numerous requests.

Complaints

You can send a data-protection complaint electronically to development@sineco.ai with enough detail for us to understand your concern. We will acknowledge it within 30 days and respond without undue delay after investigating.

You can also complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint or on 0303 123 1113. You do not need to complete Sineco's complaint process before contacting the ICO.