Trust & Security
Simor holds work-identity data, so how we handle it matters. This page is the short, factual version for buyers, security reviewers, and anyone deciding whether to connect an account. Everything here is what the product actually does today — not a roadmap.
The three promises
Your score is built from events, not content
The passport keeps typed events and dates — never message text, subjects, or the people you talk to. Content read to answer a question, or to run a workflow you built, is handled differently and we spell out exactly how in the Privacy Policy — “never stored” would be too neat to be true.
You own the connection
Only you can link your own accounts — no employer can link them for you. Unlinking revokes access and deletes that provider's data from your passport.
Every score change is explainable
Each change is recorded with its reason, dimension, and before/after value, visible to you. If something looks wrong, you can contest it and a person reviews it.
Your rights, built into the product
- Access & portability — Settings → Download my data exports everything we hold about you as JSON.
- Contest a decision — any score change can be disputed from your score history; a human at Simor reviews it and the outcome is recorded.
- Explanation — your assistant explains your own score on request, and every change carries a structured reason.
- Consent record — every consent you give or withdraw is logged with a timestamp and shown in your export.
- Erasure — unlink a provider to purge its data, or delete your account from Settings.
Subprocessors
Simor uses these vendors to operate the service. Each is bound by a data-processing agreement.
| Vendor | Purpose | Data | Region |
|---|---|---|---|
| Supabase | Database, auth, backend functions | Account, profile, work data | EU |
| Vercel | Web application hosting | Request metadata | Global edge |
| OpenAI | AI reasoning and text generation | Prompt content (not used for training) | US |
| ElevenLabs | Voice conversation | Voice audio, transcripts | US |
| Gmail / Calendar connector (opt-in) | Read at query time; see the Privacy Policy for what is kept | US | |
| Notion | Notion connector (opt-in) | Read at query time; see the Privacy Policy for what is kept | US |
| GitHub | GitHub connector (opt-in) | Public profile and activity metadata | US |
| Resend | Transactional email | Email address, message content | US |
| Sentry | Error monitoring | Error context and session replay on errors | US/EU |
| Expo | Mobile push notifications | Device push token, notification text | US |
Transfers outside the EU are covered by Standard Contractual Clauses. We will post material changes to this list here before they take effect.
Security measures
- Encryption — TLS in transit; encryption at rest on all stored data.
- Access control — row-level security on every user-facing table; connector tokens live in a deny-all table reachable only by server-side functions, never by a client.
- Least privilege — database functions are explicitly revoked from anonymous and authenticated roles and granted only where required.
- Audit logging — administrative actions are recorded to an append-only audit trail.
- Secure development — every change passes an adversarial security review before it ships, and findings are recorded.
- Secret management — credentials live in the platform secret store; no secrets in source control.
AI governance
Simor is an AI product operating in the work context, so we hold ourselves to explicit limits:
- never No emotion or sentiment inference. Simor never infers mood, tone, or emotional state — from text, from voice, or from anything else. This is enforced in code, not just policy: model output containing an affect judgement is rejected before it can be stored.
- never No biometric processing of any kind.
- never No use outside work. The score is for work decisions. We do not license or permit it for housing, credit, insurance, or any non-work purpose.
- Objective events only. Signals are discrete, dated, verifiable events — not character or personality judgements.
- AI is always disclosed. Every Simor voice or chat agent identifies itself as AI at the start of the interaction.
- Connector evidence is entering the score through a limited pilot, on specific opted-in accounts only — not across all users. For everyone outside that pilot, data from connected tools is shown as activity and carries no score weight.
- How connector evidence is limited when it counts. A thread where every party is you — including dotted, plus-tagged, googlemail, and same-organisation variants of your own address — is self-dealing and is discarded before it becomes a signal at all; you cannot raise your score by emailing yourself. What survives is weighted at a fifth of an ordinary in-Simor action, is capped so it can never exceed 15% of the record you actually earned inside Simor (so a person with no Simor track record gains nothing, however much mail they generate), never counts toward how confident we say we are, and never widens your network. A change in your connected-account evidence writes a line in your score history saying so — and ordinary score drift never gets blamed on a connected account.
Regulatory position. Simor is assessed as a high-risk AI system under Annex III of the EU AI Act (employment), with obligations applying from 2 December 2027 following Regulation (EU) 2026/1744. We are building to that standard now: risk documentation, human oversight, logging, explanation and contest rights are in the product today.
Incident response
Report a suspected vulnerability or incident to security@simor.io. We acknowledge reports within 1 business day. If a personal-data breach affects you, we notify the relevant supervisory authority within 72 hours of becoming aware and inform affected users without undue delay.
Data residency & retention
- Primary data is stored in the European Union.
- Audit and event logs are retained for at least 6 months.
- Deleting your account removes your personal data; unlinking a connector removes that provider's derived data immediately.
Working with us
For a data-processing agreement, security questionnaire, or vendor-review call, contact security@simor.io. See also our Privacy Policy and Terms.