Privacy Policy
Effective 3 August 2026
1. Scope
This policy explains what Simplist collects, why, and who else can see it. Simplist is operated by VECTOR VECTOR VECTOR & VECTOR, LLC (State of Delaware, United States). Questions, requests, and complaints go to info@vector.sh.
2. What we collect
Account details. Your email address, whether it has been verified, and a hash of your password — never the password itself. We do not ask for your name, phone number, or a photo.
The content you create. Your models, records, field values, comments, and uploaded files, along with their version history. When you upload an image we extract any text in it so the image is searchable; that extraction runs on our own servers and the image is not sent to a third party.
Technical records. We store the IP address and browser user-agent of each sign-in session so you can review and revoke your own sessions, and we keep an audit trail of security-relevant actions that includes the IP address they came from. We record IP addresses briefly for rate limiting. We log requests — the route, status, timing, your user id, and the browser user-agent and referring page — to understand load and errors.
Error reports. When something breaks we capture the error, where it happened, the page URL, and the account and workspace involved, so it can be fixed.
Billing records. If you subscribe, we store the Stripe customer and subscription identifiers, the subscription's status, the seat count, and when the current period ends. Card details go to Stripe and never reach us.
3. Cookies
We set a session cookie to keep you signed in, and a CSRF cookie to protect forms from cross-site abuse. Both are restricted to this site, and the session cookie cannot be read by JavaScript. The session cookie is issued to visitors who are not signed in as well, because it is what makes a sign-in attempt secure.
If you connect GitHub backups, one short-lived cookie carries that setup across the round trip and is removed immediately afterwards.
We set no advertising or analytics cookies, and we embed no third-party scripts, fonts, or trackers. The site's Content-Security-Policy blocks requests to other hosts outright.
4. How we use it
To run the service: authenticate you, store and return your content, send the email the product depends on, process payment, and enforce plan limits.
To keep it working and safe: diagnose errors, investigate abuse, and apply rate limits.
We do not sell your data, we do not share it with advertisers, and we do not use your content to train machine-learning models.
5. Who else receives data
We use a small number of service providers to operate Simplist. They may process your data only to provide their service to us.
6. How long we keep it
Deleted models, records, fields, and files go to the trash and are recoverable for 30 days, after which they are permanently removed — including the underlying files in storage, unless an earlier version of a record you still have depends on them.
Request logs and error reports are deleted after 30 days. Records of transactional email we sent are deleted after 7 days. Rate-limit records are discarded within the hour. Expired sessions and expired links are cleaned up continuously.
A closed account is recoverable for 30 days. After that we strip everything personal from it — your email address and password are gone, and the audit trail keeps only the actions, with no identifier attached. The workspaces you alone owned are removed at the same time, so nothing of yours outlives that 30-day window.
The security audit trail itself is retained, because its purpose is to reconstruct what happened after the fact — but once an account is closed, nothing in it identifies the person.
Everything else is kept until you delete it or close your account.
7. Your choices
Export. You can download your entire workspace — structure, records, and the original uploaded files — from the app at any time, on any plan.
Correction. You can change your email address and edit or delete any content you have access to, from within the app.
Deletion. You can delete individual records, files, whole workspaces, and your entire account from inside the app. Deleting your account deactivates it straight away and schedules it for permanent removal; sign in before the date we show you and it is restored exactly as it was.
Depending on where you live you may have additional rights over your personal data, including access, correction, deletion, and portability. Write to info@vector.sh and we will action it.
8. Security
Passwords are hashed with Argon2. Session tokens, password-reset links, and API keys are stored only as hashes, so a copy of our database does not reveal them. Traffic is served over HTTPS with strict transport security, and the application sends a restrictive Content-Security-Policy.
No system is perfectly secure. If you believe you have found a vulnerability, please tell us before telling anyone else.
9. Where data is processed
Simplist is hosted in the United States, and our service providers may process data there and elsewhere. If you use the service from another country, you are sending your data to the United States.
10. Children
Simplist is not intended for children under 13, and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will remove it.
11. Changes to this policy
If we change what we collect or who receives it, we will update this page and its effective date, and tell account holders before the change takes effect. Contact us any time at info@vector.sh.
- Railway. Hosts the application and its database.
- Amazon S3. Stores every uploaded file and its generated thumbnail.
- Postmark. Delivers transactional email — verification, password resets, invitations, and notifications.
- Stripe. Processes payments for Pro. Stripe receives your billing details directly; we never see or store your card number.
- OpenStreetMap. Supplies map imagery and place search. Map tiles are fetched by our server rather than your browser, so your IP address is not exposed — but when you search for a place, the text you type is sent to OpenStreetMap's geocoder to look it up.
Only when you turn them on
- GitHub. Only if you connect a repository for backups: we push copies of your workspace, including uploaded files, to the repository you choose.
- Endpoints you configure. Only if you create an outbound webhook: we send the affected record to the URL you supply whenever it changes.
- AI clients you authorize. Only if you connect one: an MCP or API client you have granted access can read and write the workspace data you gave it access to.