Privacy Policy
Simor gives you a work identity: an AI agent that answers on your behalf, a trust score built from a record of real work, and tools to be found by the right people. Doing that needs some of your data. This policy explains exactly what we collect, why we are allowed to, and what you can do about it. Our Trust & Security page has the short version plus our subprocessor list.
Who is responsible
Simor is the data controller for the personal data described here. For any privacy question or request, contact privacy@simor.io. We answer data-rights requests within one month.
What we collect
- Account data — email address, name, and password (stored as a salted hash), or your Google / Apple sign-in identity.
- Profile and company data — job title, industry, company details, skills, and anything you add to your profile or “My Data”.
- Conversations with your AI — text chats and voice calls with Simor agents. Voice audio is streamed for real-time transcription and response, and call summaries are stored so your agent remembers.
- Trust signals — dated, objective events from your work (a commitment kept, a question answered, a delivery made) that build your trust score.
- Connected work accounts (only if you connect them) — if you link Gmail, Calendar, Notion, GitHub or another tool, what Simor keeps depends on what you asked it to do. See Connected accounts: what is kept below — it is worth reading, because the honest answer is not "nothing".
- Consent records — what you agreed to, when, and which version of the wording you saw.
- Location (optional) — your city, and only if you opt in, your company’s coordinates for the discovery map. Companies that don’t opt in never appear on the map.
- Device data — basic technical logs (app version, device type, error reports) to keep the service working.
We do not buy behavioural data about you from data brokers, and we do not import data about you from anywhere you have not connected yourself.
Why we are allowed to use it
| What | Why | Legal basis |
|---|---|---|
| Account, profile, workspaces, messaging | To provide the service you signed up for | Performance of a contract (Art 6(1)(b)) |
| Building and showing your trust score | It is the core of the product, and third parties may rely on it | Your explicit consent (Art 6(1)(a) with Art 22(2)(c)) — given separately at sign-up, withdrawable |
| Reading a connected work account | To answer your questions and derive events | Your consent, given per provider when you connect it |
| Security, abuse prevention, service logs | To keep Simor working and safe | Legitimate interests (Art 6(1)(f)) |
| Product emails | To tell you about Simor | Your consent — optional, off by default, unsubscribe anytime |
Where we rely on consent you can withdraw it at any time, and withdrawing is as easy as giving it. Withdrawing does not affect processing that already happened.
Your trust score is an automated decision — and you can challenge it
This section matters most. Because other people may rely on your score when deciding whether to work with you, we treat the scoring itself as automated decision-making under Article 22 GDPR — and we give you the rights that come with it.
- Explanation. Every score change is stored with its reason, its dimension, and the value before and after. You can see all of it in your score history, and your assistant will explain your own score on request.
- Human review. Tap “This looks wrong” on any change. A person at Simor reviews it, and the decision and reviewer are recorded.
- Express your view and object. Your statement is stored with the dispute and is part of the review.
- No emotion, ever. Simor does not infer mood, sentiment, tone, or emotional state — not from your text, not from your voice, not from anything else. This is enforced in our code, not just promised in writing: model output containing an emotional judgement is rejected before it can be stored. We process no biometric data of any kind.
- Work purposes only. The score is for work decisions. We do not license or permit its use for housing, credit, insurance, background checks, or any non-work purpose, and we do not offer bulk lookup. See the Terms.
Connected accounts: what is kept
Earlier versions of this policy said content from a connected account is “never stored”. That is true of the part that feeds your trust score, and it was not true of everything else — so here is the precise answer, path by path.
| When you… | What Simor keeps |
|---|---|
| Just connect the account (the passport / trust-signal path) | No content. Simor reads live, derives typed, dated events and aggregate counts — “a commitment was kept on this date” — and discards the rest. No message text, no subjects, no attachments, and not the identities of the people you correspond with: a thread is checked for whether anyone outside your own mailbox took part, and only that verdict (“external” or “self”), a count, and the thread’s own Gmail id — kept so the same thread is never counted twice — are stored. No address is ever stored. Threads that are only you talking to yourself are discarded entirely. |
| Ask your assistant about your email (“what needs a reply?”) | It reads live to answer you. The answer becomes part of your chat history, so if you asked it to summarise three emails, those summaries are in your history until you delete them. Your history is yours — it is in your data export and it goes when your account does. |
| Build a workflow that triggers on email | Simor stores the sender, subject and preview snippet of each triggering message in that workflow’s run record. A workflow that acts on your email has to know what it is acting on. These are kept with the workflow’s run history; delete the runs or the workflow to remove them. |
Nothing here changes the two rules that matter most: only you can connect your accounts, and events are only ever recorded about you — never about the people you correspond with.
What we do not do
- We do not sell your personal data, ever.
- We do not show ads or share data with ad networks.
- We do not use your content to train AI models, and our AI providers are contractually barred from doing so.
- We do not read your device contacts, photos, or files unless you explicitly attach them.
- Your private company knowledge (“brain”) is never shown publicly. Public cards show only what you approve.
- We do not build profiles of people who are not Simor members. Events derived from a connected mailbox are about you, the account owner — never about the people you correspond with.
AI processing
Simor’s text intelligence is powered by OpenAI’s API and its voice conversations by ElevenLabs. Relevant parts of your conversations and profile are sent to them to generate responses, under data-processing agreements that prohibit training on your data. Every Simor agent identifies itself as an AI at the start of a conversation or call.
Who else touches your data
We use a small number of vendors to operate the service, each bound by a data-processing agreement. The current list — who they are, what they do, and what they see — is published on our Trust & Security page, and we post changes there before they take effect.
Where your data lives, and transfers
Primary data is stored in the European Union with Supabase (managed PostgreSQL) and served through Vercel. Data is encrypted in transit (TLS) and at rest. Access is enforced row by row: your data is readable only by you and the teams you join.
Some subprocessors (for example our AI providers) are in the United States. Those transfers are covered by the European Commission’s Standard Contractual Clauses.
Cookies and local storage
On the web, Simor stores what it needs to keep you signed in. That is strictly necessary and cannot be switched off — without it you cannot stay logged in.
Anything beyond that is your choice. We ask on your first visit, with declining exactly as easy as accepting, and nothing optional runs before you decide. Your choice is remembered on your device and you can change it any time in Settings → Cookie choices.
| Category | What it does | Your choice |
|---|---|---|
| Essential | Keeps you signed in and the app working | Always on — no consent needed or claimed |
| Analytics | Tells us which pages people use, so we can improve them | Off unless you allow it |
We do not use advertising or cross-site tracking cookies.
Public information
Your public card (simor.io/id/…) shows what you choose: name, role, trust score, and an AI-written summary that passes a privacy filter before publishing. You can set your card to private at any time in Settings.
Your rights and controls
- Access and portability — Settings → Download my data exports everything we hold about you as JSON, instantly. No need to ask.
- Contest a decision — any score change can be disputed from your score history; a person reviews it (see above).
- Correct — edit your profile at any time.
- Withdraw consent — disconnect a provider in Settings, change your cookie choice, or unsubscribe from emails. Withdrawing consent to trust-score processing means closing your account, because the score is what the account is; tell us and we will help.
- Erasure — Settings → Delete account removes your profile, conversations, and personal data. Disconnecting a provider removes that provider’s derived data immediately.
- Restrict or object — email privacy@simor.io.
- Complain — if you are in the EU/EEA you may lodge a complaint with your national data protection authority. We would rather you told us first, but it is your right either way.
If you are in the EU/EEA or UK, these are your GDPR rights; California residents have equivalent CCPA rights, including the right not to be discriminated against for exercising them.
Retention
- Account and profile data: kept while your account is active.
- Trust events and score history: kept while your account is active — they are the record the score is made of, and deleting them piecemeal would make your score unexplainable.
- Consent records: kept while your account is active, and deleted with your account. We do not keep a record of your consent after you are gone.
- Audit and security logs: at least 6 months.
- Connected-account content: not retained — read at query time and discarded.
- After account deletion: personal data is removed immediately; residual backups expire within 30 days.
- One exception, stated plainly: we keep a one-way hash of your email address after deletion. It cannot be turned back into your address and is not used to contact you or to profile you. Its only purpose is to stop a deleted account being recreated to shed a trust record — without it, anyone could reset an unflattering track record by deleting and signing up again, which would make every score on Simor worthless.
Security and breaches
Security measures are described on our Trust & Security page. If a personal-data breach affects you, we notify the relevant supervisory authority within 72 hours of becoming aware and inform you without undue delay. Report a suspected issue to security@simor.io.
Children
Simor is a professional tool and is not directed at children under 16. We do not knowingly collect data from children.
Changes
We will post material changes here with a new effective date and announce significant ones in the app. Where a change affects something you consented to, we will ask you again rather than assume — and your consent record keeps the version of the wording you actually saw.
Contact
Questions or privacy requests: privacy@simor.io