HomeTermsPrivacy RefundsSecuritySupport Start your free trial
Legal

Privacy Policy

Last updated 19 August 2026

01

The short version

Simpl runs on your device and stores your invoices, clients, expenses, rates and bank data in your own browser’s storage, encrypted with a key derived from your password. If you turn on backup, we keep a copy of that encrypted file so a cleared browser or a lost laptop does not cost you your records. It is encrypted before it leaves your device and we never receive the key, so there is nothing in it for us to read, sell or hand over.

The only personal information we hold about you is your name and email address, given at sign-up so we can send you your licence and product updates.

02

What we collect

  • Your name and email address, when you sign up or buy a licence.
  • Your licence status and expiry date, so we can support you and issue renewals.
  • Which link brought you to Simpl, if you arrived through one: a campaign label such as “linkedin”, or a customer’s referral code. We keep it with your sign-up and your purchase so we can tell which channels work and thank the person who recommended us. It says nothing else about you.
  • Anything you choose to write to us: support emails, or the in-app feedback form.
03

What we can never read

Some of the following never reaches us at all. The rest reaches us only as ciphertext we hold no key for. Either way we have no technical means to read any of it:

  • Your invoices, quotes, credit notes, clients, expenses, projects, rates or tracked time. If you turn on backup we store these, encrypted, exactly as they were sealed on your device. We cannot open that file.
  • Your bank statements or anything you reconcile. These sit inside the same encrypted vault, under the same key we do not have.
  • Your master password. It never leaves your device and is never transmitted.
  • Your 12-word recovery phrase. It is generated on your device and never transmitted.
  • Your encrypted backups.
04

What actually leaves your device

So that you can audit the claim rather than trust it, this is the complete list of network requests the application makes:

  • Loading the application itself from our host, and a periodic check for a new version.
  • An anonymous exchange-rate lookup to open.er-api.com, containing no personal or financial data, when you use a currency other than your base currency.
  • Your name and email at sign-up, and your licence key when you activate it.
  • Your encrypted backup, if you turn backup on. This is the only thing containing your financial records that ever leaves your device, and it is ciphertext: it is sealed on your machine with a key derived from your master password, which we never receive. We store the file, its size, when it was made, and how many records it holds so that we can show you what you are about to restore. We cannot open it.
  • A six-digit code sent to your email address when you set up backup on a new device, so we can confirm the address is yours.
  • A one-off notice, sent once when you first open Simpl at its new address, confirming that your move across is complete. It contains the same name and email, and nothing else.
  • A one-off notice when you activate a licence, so we know it reached your device and can help if it didn’t. It contains the email address the licence was issued to, its plan and expiry date — nothing about what you use Simpl for.
  • Anything you deliberately submit through the in-app feedback form.
  • A brief STUN request when you pair two devices, so they can locate each other across networks.
Important

Your licence key travels in the URL fragment, which browsers do not send to web servers. It is verified on your device against a public key built into the app. Activating a licence does not tell us that you did.

05

Device-to-device sync

When you pair two of your own devices, they exchange data over a direct encrypted connection. Your records go straight from one device to the other; they do not pass through our servers, and we keep no copy. The pairing codes are generated on your devices and exchanged by you.

Important

Pairing uses a public STUN server (stun.l.google.com, run by Google) so that the devices can find each other across different networks. That server sees the public IP address of both devices at the moment you pair. It is not a relay: none of your records pass through it, and it receives no financial data. On the same local network, pairing works without contacting it at all.

06

Payments

We never see or store your card details. Payments are processed by Paddle.com Market Limited, which acts as Merchant of Record for the sale. They collect your billing information, calculate and remit the applicable sales tax or VAT, and issue your receipt. For that transaction Paddle is a separate data controller and their privacy policy applies alongside ours.

07

Who else processes data on our behalf

  • Paddle: payment processing, billing and receipts.
  • Zoho Mail: sending your licence key, receipts and product update emails.
  • GitHub Pages: hosting of the application. Their servers record IP addresses in standard access logs.
  • Cloudflare: hosting of this website. Standard access logs apply.
  • Loops: sending your licence key, the backup verification code, and trial and product emails. Holds your name and email address only.
  • Google Analytics: counts visits to this website and clicks on its buttons, only if you agree when asked. If you decline, or ignore the question, it is never loaded and no request is made to Google. It never runs in the application itself, so it never sees anything about your invoices, clients or figures.
  • open.er-api.com: receives an anonymous currency-rate request, and unavoidably your IP address. No personal or financial data is sent.
  • Google: a public STUN server, contacted only when you pair two devices, which sees both devices’ IP addresses. Your data never passes through it.
  • Formspree: delivery of in-app feedback, sign-up details and contact form messages.
08

Cookies and local storage

The application uses your browser’s local storage and IndexedDB to hold your encrypted vault and your preferences. This is how the software works offline; it is not tracking, and none of it is transmitted. The application sets no cookies and loads no analytics of any kind.

This website asks, once, whether it may count your visit with Google Analytics. If you agree it sets Google’s analytics cookies and we can see visit counts, which pages were read and which buttons were clicked. If you decline, the analytics script is never loaded and nothing is sent to Google. Your choice is remembered in this browser’s local storage, and you can change it by clearing site data for simpl.money. The only other thing this website stores without asking is the label of the link you arrived through, in session storage for the length of your visit, so it can be passed on when you start a trial or buy.

We use no advertising or cross-site tracking cookies anywhere.

09

Your rights

You can ask us what we hold about you, correct it, or ask us to delete it. Because the only personal data we hold is your name, email and licence record, deletion means removing you from the licence register and the mailing list. It does not affect your data, which is on your device and stays there.

You can unsubscribe from product updates at any time using the link in any email. If you are in the EU or UK you also have the right to complain to your local data protection authority; if you are in South Africa, to the Information Regulator.

10

Retention

We keep your name, email and licence record for as long as your licence is active and for a reasonable period afterwards so that you can renew or ask for support. Records required for tax and accounting are kept for as long as the law requires.

Encrypted backups are kept while your licence is active and for six months after it lapses, so that you can come back and restore. After that they are deleted. You can delete your backup yourself at any time from Settings, and you should keep your own copy of anything you are legally required to retain: your tax records are your responsibility, not ours, and we are not your archive of record.

11

Security

Your vault is encrypted at rest with AES-256-GCM. The key is derived from your password using PBKDF2-SHA256 with 600,000 iterations, and is separately wrapped for your recovery phrase so that either can open your vault. The application locks itself when you step away. We do not hold either key. Backups are the same encrypted blob, with the same two wrappers, so your recovery phrase opens a backup exactly as it opens your vault. The full technical detail is on the security page.

12

Children

Simpl is a business tool and is not intended for children. We do not knowingly collect personal information from anyone under 18.

13

Changes to this policy

If we change this policy we will update the date at the top of this page, and we will email you if the change is material.

14

Contact

Simpl is operated by Lee Benjamin Rael, trading as Creative Seed, a sole proprietorship based at 10 Royland Crescent, Hout Bay, Cape Town, South Africa, 7806. Questions, requests or complaints: lee@creativeseed.co.za.