Privacy Policy
Last updated: 27 July 2026
simpl.day is built privacy-first and on-device. Your personal content stays on your phone by default. Nothing about your life is sent to us, sold, or shared with advertisers — ever. This page explains exactly what data exists, where it lives, and the few optional features that can send a bounded amount of data off your device only when you turn them on.
1. The short version
- On-device by default. Notes, tasks, goals, people, moods, photos, voice notes, locations and activity history are stored in app-private storage on your device and in a backup file on your device. They are not uploaded anywhere by default.
- No account needed to use the app.
- No ads, no advertising trackers, no sale of personal data.
- Optional online features are opt-in and clearly labeled (AI Companion, shared accountability, cloud backup, anonymous usage stats). The AI Companion never goes online until you explicitly choose an online mode, and you can switch it off any time.
2. Data stored on your device
The core app keeps everything you create locally: lists, tasks, goals and progress, notes and thoughts, people/contacts you add, mood and reflection entries, photos you capture in-app, voice notes and their transcripts, and — if you enable location/activity features — location and physical-activity history used to provide context. This data is held in app-private storage and in a backup file in your device's Documents folder so you can restore it after a reinstall. Uninstalling the app removes the app-private data; the backup file remains on your device until you delete it.
Be aware of what that backup file is: it is written automatically as you edit, it is plaintext, and because it lives in the shared Documents folder it is readable by any app on your device that you have granted storage access. Your chat transcripts with the Companion, its conversation memory, and the app's self-model are deliberately excluded from this file by default; an optional switch (Settings → Your data & safety) can include them if you prefer a complete offline backup over keeping them out of the plaintext file. Most other content is in it — including people records (names, emails, phone numbers, birthdays, cities, private notes, allergies), notes, tasks, goals, logs and photos.
3. Encryption on your device
Chat transcripts, the Companion's conversation memory, the self-model and related memory stores are encrypted at rest with a key held only in your device's hardware keystore. The rest of the app's local data is app-private (sandboxed by Android) but not separately encrypted. Encryption at rest is best-effort: in the rare case that the device keystore is unavailable, the app falls back to unencrypted app-private storage rather than failing to start.
4. AI Companion (optional)
On a fresh install the Companion runs in Rules-only mode: deterministic, on-device, no network calls. The first time you send it a message, the app holds that message and asks you — once — how the Companion should answer:
- simpl.day AI (hosted) — your Companion messages are
sent to a simpl.day-operated server function (hosted on Supabase), which
forwards them to Anthropic's API
(
api.anthropic.com, modelclaude-haiku-4-5) using a key that exists only on the server. The server stores no prompt or response content — it keeps only a per-install daily request count for fair-use and abuse control. - Quick answers only — stays Rules-only; nothing leaves your phone.
Nothing is transmitted until you choose, and you can change the engine at any time in Settings → Companion engine. You may instead pick a bring-your-own-key provider (Anthropic, OpenAI or Google Gemini); your key is stored in your device's secure storage and requests go directly to that provider under its own privacy policy. The first time any online mode is about to be used, the app shows you exactly what leaves the device before sending.
When an online mode is active:
- Data snapshot (on by default, one switch to turn off). So the Companion can be useful about your life, a bounded snapshot of your data may be included with a request: your routine and life constants, item counts, recent task titles, up to 5 note previews (200 characters each), 7 days of mood entries including their free-text notes, 14 recent wellbeing/body log entries, up to 5 recent people interactions with names, goal titles, accountability partner names, aggregate location counts (never coordinates), reflections, and assessment result labels. You can turn the snapshot off at any time in Settings, per app, and the Companion still works.
- Follow-up fetches. To answer a specific question the Companion may make up to four additional requests in a turn to fetch the specific data you asked about; those requests carry that fetched data.
- Install identifier. Each hosted request carries a random, one-way install identifier so we can enforce the daily fair-use limit. It is not your account, your email, or a device advertising ID, and it is reset when you delete your data in the app.
- An audit log you can read. Every online AI call appends a metadata-only row on your device — provider, model, byte and token counts, a one-way digest, and any error code — never the content of your prompts or the responses. The log never leaves your phone and is viewable in Settings. If you flag a Companion reply as problematic, that report is also stored only on your device; it is not transmitted to us.
5. Shared accountability (optional, end-to-end encrypted)
If you connect an account and invite a partner, accountability messages sync through our backend (Supabase). This is end-to-end encrypted: the server stores only ciphertext, your identity public keys, and the membership links of who is in a circle with whom. We cannot read your accountability content. Your recovery key stays on your device and is never sent to the server. To use this feature you sign in with your email (used only to authenticate and to route invitations).
Some metadata is necessarily visible to the server: when you invite someone by email, that email address is stored in plaintext until the invite is accepted or expires (it is then erased); the server also holds display names, device/push notification registrations, and an access log of which account fetched which shared object and when.
6. Encrypted cloud backup (optional)
If you turn on cloud backup, your backup file is encrypted on your device and uploaded as ciphertext. The server holds only the encrypted blob and small metadata (sizes, timestamps). We cannot read it. Deleting your account deletes it.
7. Usage statistics (optional, default OFF)
If you turn on usage statistics, the app sends product-usage events — screen views and taps from a fixed allowlist, never free text and never your content — tagged with the same random, one-way install identifier described above. These are individual events, not aggregates, and they are off unless you enable them. A local, on-device log of every send attempt is viewable in Settings so you can audit exactly what was sent.
8. Things you volunteer
If you join the waitlist or use the chat on our website, we receive what you choose to submit (for example an email address or your message), used only to follow up with you and improve the product.
The feature-request board is public. Posts, comments, the display name attached to them, and any screenshot you upload are visible to anyone on the internet, including people without the app, and are stored unencrypted. Posts cannot be edited after posting, though you can delete your own. Content can be reported, and reported content is automatically hidden pending review.
9. Permissions and why
- Location (including background) — optional place/context features and auto-tagging; off unless enabled.
- Camera — taking photos for notes, people and tracked items.
- Microphone — voice notes and on-device transcription.
- Physical activity — activity-context features.
- Contacts — importing a person into the app, only when you start an import yourself; no background contact reads.
- Storage / All files access — reading and writing your on-device backup file so your data survives reinstalls.
- Usage access — optional per-app phone-usage coaching; usage data stays on the device.
- Display over other apps — optional wellbeing overlays (for example the sleep and unlock prompts).
- VPN — the optional on-device site blocker. It filters DNS lookups locally; no traffic leaves your device through it, there is no remote server, and nothing is logged.
- Device admin (force-lock only) — optional screen-lock step in wellbeing features; the app can lock the screen and nothing else.
- Notifications & exact alarms — reminders and alarms you schedule.
Every permission backs a specific feature and can be revoked in your device settings.
10. Crisis support
Crisis/self-harm phrase matching happens entirely on your device and returns hotline information locally. On a crisis interaction no AI model is called and nothing is sent off the device — not even an audit-log row is written for that turn. Ordinary turns before and after are handled normally under whichever engine you chose.
11. Children
simpl.day is not directed to children under 13 (or under 16 in regions where that is the threshold) and we do not knowingly collect their data. The shared/social features (accountability, invitations, the public feature board) additionally require you to confirm you are 16 or older.
12. Deleting your data
You can clear data inside the app, and uninstalling removes app-private data (delete the backup file to remove it too). If you signed in, you can delete your account from Settings inside the app — this removes your sign-in identity, your connections and keys, your encrypted cloud backup, your push registrations and your feature-board posts, while leaving everything on your phone untouched. Full details, and what to do if you can no longer sign in, are on Delete your account.
13. Sub-processors
When you use an online feature, these providers process data on our behalf: Supabase (backend hosting for the hosted Companion function, accountability sync, cloud backup, and the feature board) and Anthropic (the hosted Companion's AI model — see Anthropic's privacy policy). If you use a bring-your-own-key AI mode, your requests go directly to the provider you chose (Anthropic, OpenAI or Google) and no simpl.day server is involved. Separately, if you play the optional songs on the Meditate screen, the audio streams from the Internet Archive (archive.org), which — like any website — sees your IP address; the request carries no account or identifier, and our on-device log records only the host name, never which song.
14. Contact
Questions or requests: clintonfernandes4u@gmail.com.
simpl.day · simpl.day