SimplySync Cloud is operated by Jerico Pulvera. The relay can deliver sealed records without receiving the keys required to read them. The optional application database is a separate data plane and is intentionally readable.
1. The privacy boundary
Simply Finance encrypts sync content on your device before it reaches the relay. SimplySync Cloud stores and transfers the resulting ciphertext. Assuming your recovery phrase and devices remain secure, the service cannot read the financial content inside those encrypted records.
If you enable the optional hosted database, Cloudflare and the database Worker can process its schema, queries, and rows in readable form, and the operator's Cloudflare account has provider-level administrative access needed to provision and delete it. The database starts empty and is not a decrypted replica of the relay or your device. Its physical separation from other subscribers does not turn the data you place in it into end-to-end encrypted content.
Encryption does not make every piece of service metadata anonymous. Opaque identifiers, timestamps, sizes, network information, and billing records can still be personal data when they relate to a person. This notice describes those records directly.
2. Data the service processes
Encrypted relay data
We process encrypted event and blob payloads plus delivery metadata such as owner, device, event, stream, and blob identifiers; hashes, timestamps, sequence numbers, byte counts, and storage usage.
Optional readable application database
If you create it, we process the SQL statements and parameters you submit, the schema and readable rows stored in your isolated D1, query results returned to you, and operational measurements such as rows read or written, database size, request rate, and execution metadata. The control plane stores opaque D1, Worker, and route identifiers but does not copy your application rows into the shared relay database.
Service and billing metadata
We store the random account capability, mappings to relay owner identifiers, Creem checkout, customer, subscription, license, and event identifiers, selected plan and billing quantity, storage allowances and usage, subscription status and billing dates, checkout-attempt records, recovery-window dates, and basic usage counters. Database control-plane counters retain one current UTC-day setup and credential-rotation row per account rather than a daily history. We do not use these records to build an advertising profile.
Recovery credential
During successful checkout reconciliation, the Worker temporarily receives the Creem license key and immediately derives a keyed cryptographic digest. We store that digest and the Creem license identifier, not the plaintext license key. The key remains a sensitive recovery credential because Creem shows it in the receipt and customer portal.
A database bearer token is generated with high-entropy random bytes and shown once. The shared control plane stores keyed and unkeyed cryptographic verifiers, token scope and lifecycle metadata, but not the bearer itself. The isolated Worker receives only the verifier list needed to authenticate that database.
Checkout cookie and network data
The home page sets one necessary first-party cookie named __Host-simplysync_checkout. It contains a random checkout seed, lasts for up to one hour, is HttpOnly, Secure, and SameSite=Lax, and is used to bind checkout to the browser that started it. Cloudflare Web Analytics collects privacy-first page-view and performance metrics without cookies or local storage only on the public home, Terms, and Privacy pages. Capability, checkout, recovery, billing, and database-console pages exclude that browser script and use a no-referrer policy. We do not use advertising pixels or cross-site tracking.
Cloudflare supplies request and IP metadata that is used transiently for delivery, abuse prevention, and rate limiting. Application code does not intentionally emit request bodies, credentials, or Creem customer fields to its own logs. Cloudflare may create short-lived operational request logs according to the configuration and retention of its platform.
Information received from Creem
Creem collects the buyer name, email, billing and payment details, country, and tax information directly during checkout. Signed webhooks and authenticated checkout responses can expose some customer fields transiently to this Worker. The billing control plane ignores and does not copy the customer name, email, postal or payment details, or country into its shared D1 or R2. It does not receive or store full card details. This does not prevent you from deliberately writing similar information to your separate optional application database.
Support communications
If you email support, the support mailbox receives your sender address, message, and any attachments you choose to provide. We use that information to answer the request and handle related service, billing, privacy, or security issues. Do not include your recovery phrase, relay URL, full license key, database bearer token, or readable database export.
3. How data is used
We process the records above to deliver encrypted changes, execute authenticated database queries you request, maintain physical tenant separation, enforce storage, identity, query and abuse limits, reconcile subscription entitlement, recover a personal relay page, rotate credentials, investigate service failures, and respond to support or legal requests.
Where data-protection law applies, these uses support performance of the hosted-service agreement, security and service-integrity interests, compliance with legal duties, and consent where the law specifically requires it.
4. Providers and disclosures
- Cloudflare provides DNS, edge delivery, privacy-first Web Analytics on the three public pages described above, Workers compute, Workflows for timed deletion, D1 database storage, R2 object storage, rate limiting, and operational security. Its processing is governed by the Cloudflare Privacy Policy.
- Creem is the merchant of record and handles checkout, payment identity, tax, receipts, the customer portal, and approved refunds. See the Creem Privacy Policy and Buyer Terms.
These providers may process data in countries other than your own. We may also disclose limited information when required by law or reasonably necessary to protect customers, the service, or other people. We do not sell personal data.
5. Retention and deletion
While paid access is active, encrypted relay content is retained to operate the service. When paid access ends, new writes pause and existing encrypted content remains readable through a 30-day recovery window. At its deadline, access is fenced and a bounded Cloudflare Workflow begins deleting encrypted events and blobs, relay owners and their account mappings, and usage records.
An optional application database becomes read-only when paid access ends and follows the same recovery deadline. The deletion Workflow removes its route, isolated Worker, D1 rows and schema, and credential records after that window. A later reactivation creates a new empty database and cannot restore either data plane after deletion.
Pseudonymous billing events, checkout and subscription identifiers, recovery-key digests, fraud-prevention records, provider backups, and legally required records may remain for their operational or legal retention periods. They are kept separately from deleted relay and application-database content.
To request deletion, email support@simplysync.org. Include enough non-secret information to locate the purchase, such as the Creem order reference. Never send your recovery phrase, relay URL, full license key, or database bearer token by email. We may need to verify control of the relay or purchase before acting, and will explain any record we must retain.
6. Your choices and rights
You can manage or cancel billing through your personal relay page or Creem My Orders. Depending on where you live, you may also have rights to access, correct, delete, restrict, object to, or receive a copy of personal data, and to complain to a data-protection authority.
For a privacy request, question, or complaint, contact support@simplysync.org. The hosted Worker does not maintain an application login or store the checkout email in D1 or R2, although the support mailbox necessarily receives the email you send. We may ask for a safe way to demonstrate control of the relevant purchase or relay.
When this notice changes, the date at the top will be updated. Material changes will be presented on the service where reasonably possible.