Legal
App Privacy Policy
Last updated: May 2026 · Applies to all Simple-Fi app users
This policy explains how Simple-Fi collects, uses and protects your personal data when you use the app. We've written it in plain language so you can actually understand it.
1. Who controls your data
Simple-Fi is a personal finance tool built for freelancers. The data controller under the General Data Protection Regulation (GDPR) is the operator of the Simple-Fi application. For privacy inquiries, contact us at: privacy@simple-fi.org
2. What data we collect
We collect only the data you actively enter into the app:
• Financial data: transaction amounts, dates, categories and descriptions
• Invoice details: amounts, due dates and invoice numbers
• Client information: names, and optionally, email addresses and phone numbers
• Project and goal names and values
• Bank account names and balances
• App preferences: currency, language and display settings (stored locally in your browser)
• Authentication data: your email address and name, provided via the login system
We do not collect data passively, track your device, or access anything outside the app.
3. How we use your data
Your data is used exclusively to power your personal financial dashboard. We never:
• Sell your data to third parties
• Share data with advertisers
• Use data for profiling or targeted advertising
• Use data for any purpose other than delivering Simple-Fi to you
All Forecast and Tax calculations are estimates based on your own data. They are for planning purposes only and do not constitute professional financial or tax advice.
4. Legal basis for processing
We process your data on the following legal bases:
• Contract performance — to provide you with the Simple-Fi service you signed up for
• Legitimate interests — to keep the service secure, improve performance, and prevent misuse
• Consent — for optional features such as email notifications, which you can withdraw at any time
5. Data retention
Your data is kept for as long as your account remains active. If you delete your account (via Settings → Delete Account), all your data — transactions, invoices, clients, projects, goals, categories and bank accounts — is permanently deleted within 30 days. Deletion initiated from within the app is immediate and irreversible.
6. Where your data is stored
Data is stored on Base44's secure cloud infrastructure. Base44 is SOC 2 Type II and ISO 27001 certified and maintains GDPR compliance. Data may be stored outside the European Union, but appropriate legal safeguards (Standard Contractual Clauses) are in place to ensure your data is protected to European standards wherever it is held.
7. Cookies and local storage
Simple-Fi does not use tracking cookies or third-party analytics trackers.
We use browser local storage (not cookies) only to remember your in-app preferences: dark mode, language, currency and privacy consent. This data never leaves your device and is never transmitted to any server.
8. Third-party integrations
If you connect third-party financial services (such as Wise, PayPal or Revolut), you provide an API token that is stored encrypted and used solely to import your transaction data. We do not share this token or your imported data with any other party.
9. Google Calendar & Google Drive data
Connecting Google Calendar and Google Drive is entirely optional. You connect your own Google account through Google's official OAuth consent screen, and you can disconnect at any time. Simple-Fi's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
What we access and why:
• Google Calendar (calendar.events) — We read your calendar events only to display them alongside your work sessions and deadlines inside the Calendar page, and we create events only when you explicitly log a work session. We never read or modify events for any other purpose.
• Google Drive (drive.file) — We use the per-file Drive scope, which only grants access to files and folders that Simple-Fi itself creates or that you explicitly open with the app. We create a "Simple.fi" folder to organise your project files and store the documents you upload. We cannot see, read or access any other files in your Google Drive.
How this data is handled:
• Access happens through your own OAuth tokens, managed securely by our infrastructure provider (Base44). We only request the minimum scopes needed for these features.
• We do not sell your Google data, use it for advertising, or transfer it to third parties, except as needed to provide these features to you.
• We do not use your Google data to train any generalised artificial intelligence or machine learning models.
• When you disconnect Google, or delete your account, our access is revoked and we stop using your Google data.
You can review or revoke Simple-Fi's access to your Google account at any time at: https://myaccount.google.com/permissions
10. Your rights under GDPR
As a user in the European Economic Area (or worldwide), you have the following rights:
• Right of access — Request a copy of the data we hold about you (available via Settings → Download your data)
• Right to rectification — Correct or update your data at any time within the app
• Right to erasure — Permanently delete all your data via Settings → Delete Account
• Right to restriction — Request that we limit how we process your data
• Right to data portability — Download your data in JSON format from Settings
• Right to object — Object to any processing of your personal data
• Right to withdraw consent — Delete your account at any time to withdraw consent
• Right to lodge a complaint — File a complaint with your local supervisory authority (e.g., CNPD in Portugal, ICO in the UK)
To exercise any of these rights: privacy@simple-fi.org
11. Data minimisation
We collect only what is necessary for the app to function. Client contact fields (email, phone) are entirely optional. Transaction notes are optional. We never require government identification, payment card details, or sensitive personal data of any kind.
12. Security
Your data is stored on certified, encrypted infrastructure. Access is protected by your account credentials. We recommend using a strong, unique password and logging out on shared devices. The app includes an automatic session timeout after 30 minutes of inactivity.
13. Changes to this policy
We will notify you of any material changes to this policy by updating this page and, where appropriate, sending you an email notification. Your continued use of Simple-Fi after changes constitutes acceptance of the updated policy.
14. Contact
For privacy questions, data access requests or concerns:
privacy@simple-fi.org
Simple-Fi is committed to protecting your privacy. This policy reflects our practices as of the date above.