SIMOR

Privacy Policy

Effective date: July 26, 2026 · Applies to the Simor app (iOS and web) and simor.io · Replaces the version of July 10, 2026

Simor gives you a work identity: an AI agent that answers on your behalf, a trust score built from a record of real work, and tools to be found by the right people. Doing that needs some of your data. This policy explains exactly what we collect, why we are allowed to, and what you can do about it. Our Trust & Security page has the short version plus our subprocessor list.

Who is responsible

Simor is the data controller for the personal data described here. For any privacy question or request, contact privacy@simor.io. We answer data-rights requests within one month.

What we collect

We do not buy behavioural data about you from data brokers, and we do not import data about you from anywhere you have not connected yourself.

Why we are allowed to use it

WhatWhyLegal basis
Account, profile, workspaces, messagingTo provide the service you signed up forPerformance of a contract (Art 6(1)(b))
Building and showing your trust scoreIt is the core of the product, and third parties may rely on itYour explicit consent (Art 6(1)(a) with Art 22(2)(c)) — given separately at sign-up, withdrawable
Reading a connected work accountTo answer your questions and derive eventsYour consent, given per provider when you connect it
Security, abuse prevention, service logsTo keep Simor working and safeLegitimate interests (Art 6(1)(f))
Product emailsTo tell you about SimorYour consent — optional, off by default, unsubscribe anytime

Where we rely on consent you can withdraw it at any time, and withdrawing is as easy as giving it. Withdrawing does not affect processing that already happened.

Your trust score is an automated decision — and you can challenge it

This section matters most. Because other people may rely on your score when deciding whether to work with you, we treat the scoring itself as automated decision-making under Article 22 GDPR — and we give you the rights that come with it.

Connected accounts: what is kept

Earlier versions of this policy said content from a connected account is “never stored”. That is true of the part that feeds your trust score, and it was not true of everything else — so here is the precise answer, path by path.

When you…What Simor keeps
Just connect the account (the passport / trust-signal path)No content. Simor reads live, derives typed, dated events and aggregate counts — “a commitment was kept on this date” — and discards the rest. No message text, no subjects, no attachments, and not the identities of the people you correspond with: a thread is checked for whether anyone outside your own mailbox took part, and only that verdict (“external” or “self”), a count, and the thread’s own Gmail id — kept so the same thread is never counted twice — are stored. No address is ever stored. Threads that are only you talking to yourself are discarded entirely.
Ask your assistant about your email (“what needs a reply?”)It reads live to answer you. The answer becomes part of your chat history, so if you asked it to summarise three emails, those summaries are in your history until you delete them. Your history is yours — it is in your data export and it goes when your account does.
Build a workflow that triggers on emailSimor stores the sender, subject and preview snippet of each triggering message in that workflow’s run record. A workflow that acts on your email has to know what it is acting on. These are kept with the workflow’s run history; delete the runs or the workflow to remove them.

Nothing here changes the two rules that matter most: only you can connect your accounts, and events are only ever recorded about you — never about the people you correspond with.

What we do not do

AI processing

Simor’s text intelligence is powered by OpenAI’s API and its voice conversations by ElevenLabs. Relevant parts of your conversations and profile are sent to them to generate responses, under data-processing agreements that prohibit training on your data. Every Simor agent identifies itself as an AI at the start of a conversation or call.

Who else touches your data

We use a small number of vendors to operate the service, each bound by a data-processing agreement. The current list — who they are, what they do, and what they see — is published on our Trust & Security page, and we post changes there before they take effect.

Where your data lives, and transfers

Primary data is stored in the European Union with Supabase (managed PostgreSQL) and served through Vercel. Data is encrypted in transit (TLS) and at rest. Access is enforced row by row: your data is readable only by you and the teams you join.

Some subprocessors (for example our AI providers) are in the United States. Those transfers are covered by the European Commission’s Standard Contractual Clauses.

Cookies and local storage

On the web, Simor stores what it needs to keep you signed in. That is strictly necessary and cannot be switched off — without it you cannot stay logged in.

Anything beyond that is your choice. We ask on your first visit, with declining exactly as easy as accepting, and nothing optional runs before you decide. Your choice is remembered on your device and you can change it any time in Settings → Cookie choices.

CategoryWhat it doesYour choice
EssentialKeeps you signed in and the app workingAlways on — no consent needed or claimed
AnalyticsTells us which pages people use, so we can improve themOff unless you allow it

We do not use advertising or cross-site tracking cookies.

Public information

Your public card (simor.io/id/…) shows what you choose: name, role, trust score, and an AI-written summary that passes a privacy filter before publishing. You can set your card to private at any time in Settings.

Your rights and controls

If you are in the EU/EEA or UK, these are your GDPR rights; California residents have equivalent CCPA rights, including the right not to be discriminated against for exercising them.

Retention

Security and breaches

Security measures are described on our Trust & Security page. If a personal-data breach affects you, we notify the relevant supervisory authority within 72 hours of becoming aware and inform you without undue delay. Report a suspected issue to security@simor.io.

Children

Simor is a professional tool and is not directed at children under 16. We do not knowingly collect data from children.

Changes

We will post material changes here with a new effective date and announce significant ones in the app. Where a change affects something you consented to, we will ask you again rather than assume — and your consent record keeps the version of the wording you actually saw.

Contact

Questions or privacy requests: privacy@simor.io