SimplySync Cloud is operated by Jerico Pulvera under the Simply Finance name. The service is designed so the relay can deliver sealed records without receiving the recovery phrase or encryption keys required to read them.
1. The privacy boundary
Simply Finance encrypts sync content on your device before it reaches the relay. SimplySync Cloud stores and transfers the resulting ciphertext. Assuming your recovery phrase and devices remain secure, the service cannot read the financial content inside those encrypted records.
Encryption does not make every piece of service metadata anonymous. Opaque identifiers, timestamps, sizes, network information, and billing records can still be personal data when they relate to a person. This notice describes those records directly.
2. Data the service processes
Encrypted relay data
We process encrypted event and blob payloads plus delivery metadata such as owner, device, event, stream, and blob identifiers; hashes, timestamps, sequence numbers, byte counts, and storage usage.
Service and billing metadata
We store the random account capability, mappings to relay owner identifiers, Creem checkout, customer, subscription, license, and event identifiers, subscription status and billing dates, checkout-attempt records, and basic usage counters. We do not use these records to build an advertising profile.
Recovery credential
During successful checkout reconciliation, the Worker temporarily receives the Creem license key and immediately derives a keyed cryptographic digest. We store that digest and the Creem license identifier, not the plaintext license key. The key remains a sensitive recovery credential because Creem shows it in the receipt and customer portal.
Checkout cookie and network data
The home page sets one necessary first-party cookie named __Host-simplysync_checkout. It contains a random checkout seed, lasts for up to one hour, is HttpOnly, Secure, and SameSite=Lax, and is used to bind checkout to the browser that started it. We do not use analytics, advertising pixels, local storage, or cross-site tracking.
Cloudflare supplies request and IP metadata that is used transiently for delivery, abuse prevention, and rate limiting. Application code does not intentionally emit request bodies, credentials, or Creem customer fields to its own logs. Cloudflare may create short-lived operational request logs according to the configuration and retention of its platform.
Information received from Creem
Creem collects the buyer name, email, billing and payment details, country, and tax information directly during checkout. Signed webhooks and authenticated checkout responses can expose some customer fields transiently to this Worker. The application ignores and does not store the customer name, email, postal or payment details, or country in D1 or R2. It does not receive or store full card details.
Support communications
If you email support, the support mailbox receives your sender address, message, and any attachments you choose to provide. We use that information to answer the request and handle related service, billing, privacy, or security issues. Do not include your recovery phrase, relay URL, or full license key.
3. How data is used
We process the records above to deliver encrypted changes, authenticate relay requests, enforce storage and identity limits, reconcile subscription entitlement, recover a personal relay page, prevent replay and abuse, investigate service failures, and respond to support or legal requests.
Where data-protection law applies, these uses support performance of the hosted-service agreement, security and service-integrity interests, compliance with legal duties, and consent where the law specifically requires it.
4. Providers and disclosures
- Cloudflare provides DNS, edge delivery, Workers compute, D1 database storage, R2 object storage, rate limiting, and operational security. Its processing is governed by the Cloudflare Privacy Policy.
- Creem is the merchant of record and handles checkout, payment identity, tax, receipts, the customer portal, and approved refunds. See the Creem Privacy Policy and Buyer Terms.
These providers may process data in countries other than your own. We may also disclose limited information when required by law or reasonably necessary to protect customers, the service, or other people. We do not sell personal data.
5. Retention and deletion
Encrypted relay content and pseudonymous service records are currently retained while needed to operate the relay, preserve read access after billing lapses, reconcile billing and recovery, prevent webhook replay, and meet security or legal obligations. Cancellation, expiration, or a refund pauses eligible writes but does not automatically delete the data or recovery mapping. SimplySync Cloud does not currently run an automatic account-purge schedule.
Authenticated client actions may compact superseded event records, but encrypted blobs and billing history can remain. Provider backups, fraud records, and legally required records may also persist for their applicable retention periods.
To request deletion, email support@simplyfinance.app. Include enough non-secret information to locate the purchase, such as the Creem order reference. Never send your recovery phrase, relay URL, or full license key by email. We may need to verify control of the relay or purchase before acting, and will explain any record we must retain.
6. Your choices and rights
You can manage or cancel billing through your personal relay page or Creem My Orders. Depending on where you live, you may also have rights to access, correct, delete, restrict, object to, or receive a copy of personal data, and to complain to a data-protection authority.
For a privacy request, question, or complaint, contact support@simplyfinance.app. The hosted Worker does not maintain an application login or store the checkout email in D1 or R2, although the support mailbox necessarily receives the email you send. We may ask for a safe way to demonstrate control of the relevant purchase or relay.
When this notice changes, the date at the top will be updated. Material changes will be presented on the service where reasonably possible.