Privacy Policy

Last updated 2026-05-18 · v1.0

← Back to Simplifund

1. About this policy

This policy explains what information Simplifund collects from you, how we use it, who we share it with, and the rights you have over it. It applies whenever you use Simplifund through our website or any of our applications.

2. What we collect

When you create an account, we collect your email address, your name, and a hashed copy of your password (handled by Supabase Auth).

When you use Simplifund, we store the financial data you enter: income records, expenses and deductions, receipts you upload, budgets and goals you set, superannuation details, and any other information you choose to give us.

When you use our AI features (the Atlas chat, the coach, the digest personalisation), we store the text of your conversations with the AI so the assistant can reference earlier context within the session.

We also collect basic usage analytics: pages visited, button clicks, and approximate location (derived from IP, not GPS) so we can understand how Simplifund is being used and where to focus improvements.

3. Where it's stored

Your data is stored in Supabase, in the Singapore (ap-southeast-1) region. Backups are managed by Supabase under their standard policy.

4. Who we share it with

We share specific data with the following service providers, only as needed to run Simplifund:

  • Supabase hosts all your data (database, files, authentication).
  • Anthropic receives the text of your conversations when you use Atlas or any AI feature. Per our commercial agreement with Anthropic, this data is not used to train their models.
  • Stripe handles billing for paid plans. Your card details go directly to Stripe; we never see or store them.
  • Resend sends transactional emails (signup confirmations, notifications). They receive your email address.

We don't sell your data. We don't share it with advertisers. We don't share it with any third party not listed above.

5. Your rights

Under the Australian Privacy Principles, you can:
  • Access the personal information we hold about you.
  • Ask us to correct information that is wrong.
  • Ask us to delete your account and your data.
  • Lodge a complaint about how we handle your data with the Office of the Australian Information Commissioner (oaic.gov.au).

To exercise any of these rights, email hello@simplifund.app.

6. Data retention

We keep your data for as long as your account is active. When you close your account, we delete your data within 30 days. Backups held by Supabase may keep copies for up to 90 days beyond deletion before they roll off the backup retention window.

7. Security

Simplifund uses Supabase row-level security, so each user's data is isolated at the database level. Passwords are hashed by Supabase Auth. All traffic between your browser and Simplifund is encrypted in transit using HTTPS. No system is perfectly secure, but we take reasonable measures consistent with industry practice.

8. Cookies and analytics

Simplifund uses cookies for authentication (so you stay logged in) and session continuity. We do not currently use any third-party analytics tool or advertising tracker. If we introduce analytics in the future, we will update this section and the “Last updated” date.

9. International transfers

Anthropic processes AI conversation text on infrastructure that may be located outside Australia. Where data is transferred internationally, we rely on the vendor's standard contractual terms and security commitments to keep it protected.

10. Children

Simplifund is intended for users 18 and over. We do not knowingly collect personal information from anyone under 18. If you believe a minor has created a Simplifund account, please email hello@simplifund.app and we will close the account.

11. Changes to this policy

We may update this policy as Simplifund evolves. When we do, we will update the “Last updated” date at the top of this page and notify you by email or in-app banner.

12. Contact

Privacy questions, requests, and complaints: email hello@simplifund.app.

This is a plain-English summary written for clarity, not legal advice.