SIMOR

Trust & Security

Last updated: July 25, 2026 · Questions or security reports: security@simor.io

Simor holds work-identity data, so how we handle it matters. This page is the short, factual version for buyers, security reviewers, and anyone deciding whether to connect an account. Everything here is what the product actually does today — not a roadmap.

The three promises

Your score is built from events, not content

The passport keeps typed events and dates — never message text, subjects, or the people you talk to. Content read to answer a question, or to run a workflow you built, is handled differently and we spell out exactly how in the Privacy Policy — “never stored” would be too neat to be true.

You own the connection

Only you can link your own accounts — no employer can link them for you. Unlinking revokes access and deletes that provider's data from your passport.

Every score change is explainable

Each change is recorded with its reason, dimension, and before/after value, visible to you. If something looks wrong, you can contest it and a person reviews it.

Your rights, built into the product

Subprocessors

Simor uses these vendors to operate the service. Each is bound by a data-processing agreement.

VendorPurposeDataRegion
SupabaseDatabase, auth, backend functionsAccount, profile, work dataEU
VercelWeb application hostingRequest metadataGlobal edge
OpenAIAI reasoning and text generationPrompt content (not used for training)US
ElevenLabsVoice conversationVoice audio, transcriptsUS
GoogleGmail / Calendar connector (opt-in)Read at query time; see the Privacy Policy for what is keptUS
NotionNotion connector (opt-in)Read at query time; see the Privacy Policy for what is keptUS
GitHubGitHub connector (opt-in)Public profile and activity metadataUS
ResendTransactional emailEmail address, message contentUS
SentryError monitoringError context and session replay on errorsUS/EU
ExpoMobile push notificationsDevice push token, notification textUS

Transfers outside the EU are covered by Standard Contractual Clauses. We will post material changes to this list here before they take effect.

Security measures

AI governance

Simor is an AI product operating in the work context, so we hold ourselves to explicit limits:

Regulatory position. Simor is assessed as a high-risk AI system under Annex III of the EU AI Act (employment), with obligations applying from 2 December 2027 following Regulation (EU) 2026/1744. We are building to that standard now: risk documentation, human oversight, logging, explanation and contest rights are in the product today.

Incident response

Report a suspected vulnerability or incident to security@simor.io. We acknowledge reports within 1 business day. If a personal-data breach affects you, we notify the relevant supervisory authority within 72 hours of becoming aware and inform affected users without undue delay.

Data residency & retention

Working with us

For a data-processing agreement, security questionnaire, or vendor-review call, contact security@simor.io. See also our Privacy Policy and Terms.