SynKitab holds what it needs to sync your documents between your own devices, and nothing else. It has no advertising, no analytics and no third party it sells anything to.
Your email address, and — if you sign in with Google — the name and profile
picture on that Google account. Google sends us nothing else: the app asks for
the email and profile scopes and no others. It cannot
see your Gmail, your Drive or your contacts.
Only for documents you have explicitly added to the cloud: the file itself, its title and page count, and how far through it you have read. Each account's data is isolated at the database level, so one account cannot read another's even by asking directly.
Your files are stored, not end-to-end encrypted. Whoever administers this deployment holds the keys to the database and the file storage, so they are technically able to open a synced document, a note or a highlight. That is true of every service that stores files for you and does anything with them; it is stated here because the alternative is letting you assume otherwise.
Two things narrow it. The API service itself never holds the master key: every request it makes carries your sign-in token and is bound by the same per-account isolation you are, so even a fully compromised server cannot read other people's libraries. And a document you never add to the cloud is not there to be read at all.
Stop syncing a document and it leaves the cloud once no device is using it. Delete your account and everything belonging to it goes with it, including the stored files — see deleting your account.