Privacy Policy
Effective Date: November 8, 2025
At Sympl, we believe in simplicity and privacy. We're building a tool to help you sync files and notes across your devices without the clutter. This Privacy Policy explains how we collect, use, and protect your information. It's short because we keep things minimal—no ads, no tracking, no selling your data. By using Sympl (the "Service"), you agree to this policy.
1. Who We Are
Sympl is operated by Sympl LLC, a Colorado Limited Liability Corporation. Contact us at support@sympl.info.
2. Information We Collect
We collect only what's essential for the Service to work:
- Account Information: When you sign in with Google, we receive your email and user ID from Google. This lets us link your devices securely. We don't store passwords or extra profile details.
- Usage Data: File metadata (name, type, size, upload time) and device info (IP address, browser type) to enable sync and debugging. No personal identifiers tied to this.
- Content You Upload: Files, URLs, notes, or keys you send. These are end-to-end encrypted on your device before reaching our servers— we can't read them. Previews (e.g., thumbnails) are generated client-side where possible.
- Analytics: Aggregated, anonymized stats (e.g., number of zaps per day) via Supabase logs. No individual tracking.
We don't collect sensitive data like health info or financial details unless you upload it (and even then, it's encrypted and ephemeral).
3. How We Use Your Information
- Core Functionality: To sync your content across devices in real-time and auto-delete after 5 minutes (or longer if pinned via pro upgrade).
- Security & Support: Detect abuse (e.g., spam uploads) and fix bugs. Emails for account alerts (e.g., "New device signed in?").
- Improvements: Anonymized data helps us refine the app (e.g., "Users love PDF previews").
We never use your data for marketing or share it with third parties beyond what's needed for the Service.
4. How We Share Your Information
- Service Providers: Supabase (hosting/sync) and Google (auth) get minimal access (e.g., encrypted blobs, auth tokens). They comply with GDPR/CCPA and our contracts—no retention beyond our TTL. Stripe (payments) receives billing info for pro subscriptions only.
- Legal Requirements: Only if required by law (e.g., subpoena)—we'll notify you unless prohibited.
- No Sales or Ads: We don't sell data or show targeted ads.
For pro features (e.g., pinning), payments go through Stripe—their policies apply.
5. Data Retention & Deletion
- Ephemeral by Design: Uploaded content auto-deletes after 5 minutes (or on swipe-delete). Metadata follows suit.
- Pins (Pro): Pinned items stay until you delete or pause destruct.
- Account Deletion: Email support@sympl.info to wipe everything—we'll confirm within 30 days.
- Backups: Supabase retains encrypted snapshots for 7 days (disaster recovery only).
6. Your Rights
Under GDPR/CCPA, you can access, correct, or delete your data. Contact us at support@sympl.info. We'll respond in 30 days.
7. Children's Privacy
Sympl is for 13+ (or local age of consent). No knowing collection from kids.
8. Changes to This Policy
We'll notify via email or in-app for material changes. Continued use = agreement.
9. Contact Us
Questions? support@sympl.info. We're a small team—expect human replies.
Also see our Terms of Service