Isolated by institution
Queries and downloads check the user’s membership and institution before returning data.
This summary describes how SyncSenseDesk handles data in a local installation. Institution administrators are responsible for defining their organization’s use, retention and access policies.
Summary version: July 2026Queries and downloads check the user’s membership and institution before returning data.
Passwords and PINs are hashed; smart-access tokens are only stored as hashes and can be revoked.
Note context is sent to an AI provider only when AI is configured and actively used.
The app stores account profiles, institution memberships, courses, materials, assignment submissions, results, attendance, schedules, reminders and AI conversations needed to provide the platform.
Access depends on institution, role and course participation. Students see only authorized personal records; lecturers manage their courses; administrators manage members and institution settings.
Files are stored in a protected upload location, not as public assets. Every download passes through session and course-permission checks.
QR and NFC carry an opaque access link, not a password. A PIN is still required. Credentials can be regenerated to revoke old links, and repeated failed PIN attempts trigger a temporary lockout.
When an administrator configures Hugging Face and a user requests AI help, relevant note context may be sent to the provider to create a response. Without a token, AI is safely disabled.
Because the platform runs locally, the institution controls its database, file volume, backups and retention periods. Correction or deletion requests should be directed to the institution administrator.
Before real-world use, establish an organizational privacy policy, retention periods, backup routine, network controls and user notices that meet local legal requirements.