SimpleTime Privacy Policy

← Home

Last updated: May 26, 2026

Summary

Simple Time is a time-tracking and billing platform built by Simple Intelligence Group, Inc. ("we," "us"). This policy explains what data we collect when you use Simple Time, what we do with it, and what your rights are. We try to keep this short and plain.

Bottom line: We collect what we need to run the product. We never sell your data. We do not use your data, or data from any third-party service you connect (Microsoft, Google, Intuit QuickBooks, Xero, Slack), to train AI models or for advertising.

What we collect

Account data

Your name, work email, and the workspace you belong to. If you sign in with Microsoft Entra ID, Google Workspace, or another SSO provider, we receive the standard OpenID Connect profile (name, email, organization tenant ID). If you sign in with a password, we store a salted hash of your password (we never see the plaintext).

Product data you enter

Time entries, clients, projects, tasks, invoices, expenses, retainers, and any other records you or your team create in Simple Time. This data is stored on your workspace's behalf and is visible only to other members of the same workspace.

Data from third-party services you connect

When a workspace admin connects an outside service, Simple Time stores OAuth tokens for that service and the specific pieces of data the integration was designed to use. We do not request access to anything beyond what's needed.

  • Microsoft 365 (Outlook calendar, sent mail, Teams): event titles, attendees, times, sent-message subject + recipients + snippets. Used only to propose draft time entries that the user reviews.
  • Google Workspace (Calendar, Gmail): calendar event titles + attendees + times; sent-mail subject + recipients + snippet. We read sent mail only (in:sent filter), never inbound mail. Used only to propose draft time entries that the user reviews. See "Google API Limited Use" below for required additional disclosures.
  • QuickBooks Online: the Customer ID matched to each Simple Time Client, and the Invoice ID created in QuickBooks. We do not store Customer names, addresses, balances, or any QuickBooks transaction data.
  • Xero: the Contact ID matched to each Simple Time Client, the Invoice ID created in Xero, and the connected Xero organization's name + ID. We do not store Contact details, bank transactions, payments, or any other Xero data.
  • Slack: the connected workspace's team ID, team name, and a bot access token. Used to deliver notifications and respond to slash commands. Activity-ingest from Slack channels is currently disabled.
  • Stripe: we use Stripe to bill Simple Time subscriptions. Stripe receives the workspace admin's name, email, and payment method on its own pages. We receive a Stripe customer ID and subscription status; we do not see card numbers.

Usage and operational data

IP address (for security logs and abuse prevention), browser type, request paths, error traces, and page-view counts via Microsoft Clarity. Audit-log rows record significant actions (sign-in, invoice push, integration connect/disconnect, role change). Logs do not include OAuth tokens, passwords, or message bodies.

How we use it

  • To provide the product.
  • To communicate with you about your workspace (billing receipts, security alerts, product changes you've opted into).
  • To investigate security incidents and prevent abuse.
  • To comply with legal obligations (subpoenas, tax records, regulatory requests).
  • For AI-drafted features (draft time entries, billable classification, LEDES code suggestions, AI FAQ). AI processing happens on Anthropic Claude models running under Azure AI Foundry's Zero Data Retention contract. Your data is not used to train Anthropic's or Microsoft's models.

How we don't use it

We never:

  • Sell your data, period.
  • Share your data with advertisers.
  • Use your data, or data from any third-party service you connect, to train AI/ML models for ourselves or for third parties.
  • Read your data manually except (a) with your written consent (for example, a support ticket), (b) for security investigations or legal compliance, or (c) where the data is aggregated and no longer identifies any individual.

Sub-processors

The current sub-processor list lives on its own page: /subprocessors. Each entry shows purpose, data category, region, and the date it was added. We notify workspace administrators at least 30 days before adding a new sub-processor; this gives you time to object or terminate before the change takes effect.

Cookies and analytics. Simple Time uses two kinds of browser storage. Strictly-necessary cookies keep you signed in (these are required for the product to work and don't need consent). One optional analytics tool, Microsoft Clarity, loads session-replay telemetry only when you accept the cookie banner. Declining means Clarity never loads, no analytics leaves your browser.

Data retention

We retain your data for as long as your workspace is active.

  • Time entries, clients, projects, invoices, expenses: retained for the life of the workspace, plus seven years after workspace deletion to support tax and audit obligations (you can request earlier deletion subject to legal holds).
  • OAuth tokens for connected services (Microsoft, Google, Intuit, Xero, Slack): deleted immediately when the admin disconnects the integration or when the workspace is deleted. Revoked server-side against the provider's revoke endpoint where available.
  • Activity signals (calendar + email summaries used to draft time entries): retained 90 days by default; workspace admins can shorten or extend this in workspace settings.
  • Application logs: 30 days.
  • Audit log: retained for the life of the workspace, plus seven years after deletion.
  • Backups: seven days, encrypted at rest. Backup copies fall out of retention on a rolling basis after deletion.

Security

We host on Microsoft Azure. All customer data is encrypted at rest (AES-256, Azure Storage Service Encryption) and in transit (TLS 1.2 minimum with HSTS). OAuth tokens are encrypted at the application layer using a per-tenant data-encryption key wrapped by an Azure Key Vault master key.

Sign-in supports Microsoft Entra ID, Google Workspace, and password-with-hash (bcrypt). Multi-factor authentication is enforced through your identity provider; workspaces using SSO inherit their organization's MFA policy.

Production infrastructure is private-network-only (no public IP on the database or the Key Vault). Production access is restricted to a short list of named engineers under just-in-time elevation with audit logging.

Suspected vulnerabilities should be reported to security@simpleintelligence.io or via our security.txt. We will acknowledge receipt within two business days and provide an initial response within five.

Breach notification. If we confirm a security incident affecting your data, we will notify your workspace's owner within 72 hours of confirmation, in line with GDPR Article 33. The notice will describe what was affected, what we know about cause and scope, and the remediation steps in progress.

Your rights

You can:

  • Access your data by signing in. Workspace admins can export tenant-wide data via the Reports + Settings surfaces.
  • Correct inaccurate data by editing it inside the product, or by contacting us if it sits outside an editable surface.
  • Delete your data by deleting your workspace (workspace admins) or by requesting account deletion from us in writing.
  • Export your data in machine-readable formats (CSV for most tables; JSON on request).
  • Opt out of product analytics, AI-drafted features, and marketing emails independently.
  • Disconnect any connected third-party service (Microsoft, Google, Intuit, Xero, Slack) from /settings/integrations at any time.

EU and UK residents have the additional rights granted under the GDPR and UK GDPR. California residents have rights granted under the CCPA/CPRA. To exercise any right, email privacy@simpleintelligence.io. We respond within 30 days.

Google API Limited Use

Simple Time's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Simple Time uses the gmail.readonly scope to read sent messages (using the in:sent filter) for the purpose of proposing draft time-tracking entries to the user. Simple Time uses the calendar.readonly scope to read primary-calendar events for the same purpose.

Simple Time does NOT:

  • Use Google user data for advertising.
  • Sell Google user data.
  • Transfer Google user data to third parties EXCEPT (a) Microsoft Azure (our infrastructure provider, US data centers, DPA in place); and (b) Anthropic via Azure AI Foundry (classification model receives only a one-sentence summary, never raw message body, never recipient list).
  • Use Google user data to develop, improve, or train generalized AI/ML models. Anthropic processes the summary string under Azure AI Foundry's Zero Data Retention contract; data is not retained by Anthropic and is not used for model training.
  • Allow humans at Simple Intelligence Group to read Google user data EXCEPT (a) with the user's explicit consent (for example, a support ticket), (b) for security investigations or to comply with applicable law, or (c) where the data has been aggregated and is used for internal operations.

Users can disconnect Google at any time from /settings/integrations. Disconnection deletes stored Google access tokens immediately and revokes them server-side against https://oauth2.googleapis.com/revoke. Historical activity signals derived from Google data are retained per the workspace's data-retention setting (default 90 days).

QuickBooks Online and Xero data use

When a workspace admin connects QuickBooks Online or Xero, Simple Time pushes invoices created in Simple Time to the connected accounting system as drafts. The connection grants:

  • Read access to existing Customers (QBO) or Contacts (Xero) so we can match Simple Time Clients to the correct accounting record.
  • Write access to create new Customers/Contacts when no match exists.
  • Write access to create Invoices in DRAFT state. We never set invoice status to "sent" or "paid" inside the accounting system; your bookkeeper reviews and sends from QuickBooks or Xero directly.

We do not request scopes for bank transactions, payments, journals, payroll, attachments, settings, reports, or any other data not strictly required for invoice push. Connections can be revoked from /settings/integrations at any time; stored tokens are deleted immediately on disconnect.

Children

Simple Time is a business product not directed at children under 16. We do not knowingly collect personal data from children. If you become aware that a child has provided us with personal data, contact us and we'll delete it.

International transfers

Simple Time hosts in the United States. If you access the product from outside the United States, your data will be transferred to and processed in the United States. We rely on the EU-US Data Privacy Framework and Standard Contractual Clauses where applicable.

Changes to this policy

If we make material changes we'll update the "Last updated" date at the top and notify workspace admins by email at least 30 days before changes take effect. Continued use of the product after the effective date constitutes acceptance.

Contact

Questions or requests: email privacy@simpleintelligence.io. Product support: simpletime@simpleintelligence.io.

Simple Intelligence Group, Inc.

Mailing address available on request.

See also: Terms of Service · Sub-processors · Security · Help