Privacy Policy
Your privacy matters to us
SimplyHere is a mental health companion. We take your privacy extremely seriously because we understand the sensitive nature of what you share. This policy explains what we collect, how we protect it, and your rights.
SimplyHere is designed to meet the data protection requirements of healthcare environments. While we are not a covered entity under HIPAA, we voluntarily implement HIPAA-aligned security controls including field-level encryption, audit logging, access controls, and data retention practices. When SimplyHere is deployed through a healthcare organization, we will enter into a Business Associate Agreement (BAA) as required.
What we collect
Account information: Your email address and full name are protected with field-level encryption. Your password is securely hashed and never stored in plaintext. These are required to create and secure your account.
Health data: Check-ins (including how you're feeling), journal entries, goals, thoughts you work through, PHQ-9 and GAD-7 self-assessment scores, AI chat messages, and safety plan information that you choose to enter. Insights you save from chat are stored as bookmarked entries that surface in your story. This data is yours.
Device information: Device type, app version, and operating system for crash reporting and support. IP addresses are encrypted in audit logs for security purposes. We also store push notification tokens if you enable notifications. We do not collect location data.
AI-derived data: SimplyHere generates observations from your health data, including mood trend summaries, patterns it notices across features, and a private summary of themes across your conversations. These observations are stored encrypted alongside your other data and are used only to personalize your experience. They reflect what you have logged; they are never claims about what works for you.
Subscription data: If you subscribe to the Supporter tier, your subscription is handled by our payment processor (Stripe) or your app store. We receive confirmation of your subscription status but never receive or store your card number or billing address. Payment details are handled entirely by the payment processor.
How we protect your data
Encryption at rest: All sensitive personal data, including journal entries, check-ins, assessment scores, chat messages, thoughts you work through, and safety plans, is protected with field-level encryption before being stored in our database. Stored records are unreadable without the separate encryption keys.
Encryption in transit: All data transmitted between the app and our servers uses TLS 1.2/1.3 encryption.
Password security: Passwords are securely hashed and never stored in plaintext.
Access controls: Your data is returned through your authenticated account and authorized service operations required to provide the features you use. Provider and other sensitive access is permission-gated and audit logged. Organization administrators cannot browse your journal entries, chat messages, check-ins, or other personal content unless you explicitly share information through the provider-consent flow.
Audit logging: Access to your data is logged in line with HIPAA § 164.312(b) requirements. Audit logs record what data was accessed, when, and by which system process. They are retained for 7 years and do not contain your actual health content.
Data retention: Your health data (check-ins, journals, thoughts you work through, assessments, goals, and safety plans) is kept until you choose to delete it. We do not expire your history on a schedule, because your story is yours. Notifications are deleted after 90 days. Audit logs are retained for 7 years per HIPAA requirements and contain no health content. Accounts that are created but never verified are removed after about 48 hours. When you delete your account, all of it is permanently removed after the recovery window described under Your rights.
Infrastructure: SimplyHere is hosted on Google Cloud Run (US region) with Google Cloud SQL (PostgreSQL) as the database. These services provide enterprise-grade physical security and compliance certifications.
AI processing and third parties
AI chat and insights: Your chat messages are processed by OpenAI to generate the companion's responses. OpenAI also runs the safety check that reads each chat message, writes the reflections you read (such as your Monthly Story and the year-end Book), and creates the similarity vectors used to recall relevant moments. Your check-in data, journal entries, and thoughts you work through are also processed by Google's Gemini (through the Google Cloud Vertex AI platform) to notice patterns and surface observations, for you. Data is sent over encrypted TLS connections. Our agreements with both providers prohibit them from using your data to train their models. SimplyHere will not route HIPAA-regulated PHI through an AI provider unless the required BAA covers the workload and is in place before processing begins.
What the AI sees: When you use the chat companion, it receives your recent check-ins, journal snippets, active goals, and a summary of themes from your past conversations. This context helps it respond in a way that is relevant to you. It does not have your full history, only a compressed summary. If you have chosen condition focus areas, the AI receives general behavioral guidelines for those areas but does not reference your conditions by name unless you bring them up first.
What the AI does NOT see: The AI cannot access your password, email address, or any data belonging to other users. If you are part of an organization, the AI cannot access other members' data. AI-generated responses are not reviewed by humans at SimplyHere or at our AI providers.
No selling of data: We do not sell, rent, trade, or share your personal data or health data with advertisers, data brokers, analytics companies, or any third party for marketing purposes. We will never monetize your data. Our revenue comes from subscriptions and from organizations that pay for clinician tools, never from your data.
No ads: SimplyHere does not display advertisements. We do not use third-party analytics that track individual users.
Transactional email: We use Amazon Simple Email Service (SES) to send transactional emails only: verification codes, password resets, and account notifications. SES does not have access to your health data.
Error monitoring: We use Sentry to collect anonymous crash reports (stack traces, device model, OS version) to fix bugs. No personal health information is sent to Sentry. These reports do not contain your health data, journal content, chat messages, or any other personal information.
Your rights
Export your data: You can download all of your data at any time from Settings, in a machine-readable JSON format. Your export covers everything you wrote and everything the app holds about you, including a receipt of derived data such as the similarity vectors used for recall. One exception, consistent with healthcare records practice: if you work with a care provider through SimplyHere, their own session notes are part of their professional records, not your account data, and can be requested directly from your provider. Anything they sent to you, and everything you shared with them, is yours and is included.
Delete your account: You can delete your account and all associated data from Settings. To protect against an accidental or malicious deletion, your account first enters a short grace period (about 7 days), during which you can restore it using a link we email you. After that window it is permanently and irreversibly removed, cascading across all check-ins, journal entries, goals, chat history, thoughts you work through, assessments, safety plans, surveys, and notifications.
Share my progress: You can generate a summary of your journey to share with someone you trust: a care provider, a doctor, or anyone in your corner. This is entirely opt-in and initiated only by you. It is never shared automatically.
Correction: If any of your account information is inaccurate, you can update it directly in Settings. Health data can be edited or deleted individually within the app.
Data portability: Your exported data is provided in standard JSON, readable by any software. We do not lock your data into proprietary formats.
Security controls: You can enable or disable two-factor authentication and manage trusted devices from the Security section in Settings.
GDPR rights (EU/EEA residents): You have the right of access, rectification, erasure, restriction of processing, data portability, and objection. Our legal basis for processing is your consent (provided at registration) and our legitimate interest in providing the service. To exercise these rights, contact support@simplyhere.app or use the in-app export and deletion features.
CCPA rights (California residents): You have the right to know what personal information we collect and how it is used, the right to request deletion, and the right to opt out of the sale of personal information. Since we never sell personal information, the right to opt out is already satisfied. You will not receive discriminatory treatment for exercising your rights. Contact support@simplyhere.app or use the in-app features.
Age requirement
SimplyHere is intended for adults aged 18 and older. We do not knowingly collect personal information from anyone under 18. If you believe someone under 18 has created an account, please contact us at support@simplyhere.app and we will promptly delete the account and all associated data.
Organizational use
When SimplyHere is provided through an organization (referred to as "your group" within the app) such as a university, health system, or employer, the organization may have access to anonymized, aggregate engagement metrics, such as how many users completed check-ins this week. Organizations cannot access any individual user's health data, journal entries, chat messages, thoughts you work through, check-in data, or other personal content.
Your organization may see: the number of active users, feature adoption rates, average engagement frequency, and aggregate satisfaction scores. Your organization cannot see: anything you wrote, anything the AI said to you, your check-in data, your goals, your safety plan, or any content that could identify your specific experience.
Members register with their personal email address and an invite code provided by their institution. The organization never receives individual email addresses or personal data from SimplyHere.
If your organization's agreement with SimplyHere ends, you will be notified at least 30 days in advance, with the opportunity to export your data and optionally convert to a personal account before organizational access is terminated.
Changes to this policy
We may update this privacy policy from time to time to reflect changes in our practices, technology, or legal requirements. If we make material changes, we will notify you through the app or via email at least 30 days before they take effect. Continued use of SimplyHere after changes constitutes acceptance of the updated policy.
Contact us
If you have questions about this privacy policy or how your data is handled, contact us at support@simplyhere.app. We aim to respond within 48 hours.