Dashboard

Legal

Privacy Policy

Last updated 15 August 2026

What we collect, why, who else sees it, and how to get it back. Your application data belongs to you — we hold it to run your services and for nothing else.

01Who we are

Simplifyd Cloud is a platform for deploying applications, databases and object storage. This policy covers the website at simplifyd.com, the console at console.cloud.simplifyd.com, the edge CLI, the API at api.cloud.simplifyd.com, and the MCP server at mcp.simplifyd.com.

The data controller is Simplifyd Systems (RC 1695886), 1 Marina Road, Lagos Island, Lagos, Nigeria. Questions about this policy go to savvy@simplifyd.com.

Two roles matter here, and we keep them apart. For your account data — your email, your billing history, your usage — we are the controller. For the content of what you deploy — the rows in your database, the objects in your buckets, the requests your users make to your app — we are a processor. That content is yours. We do not read it, mine it, sell it, or train anything on it. We access it only when you ask us to for support, or when we are legally compelled to.

02What we collect

Account data. Your name and email address. If you sign in with Google, we receive your email, name and profile picture from Google — not your Google password. If you turn on two-factor authentication we store a TOTP secret and a set of hashed recovery codes.

Workspace data. Workspace, project, environment and service names, member lists and roles, API tokens (stored hashed), and your service configuration — environment variables, config files, ingress rules, allowlists. Environment variables and secrets are encrypted at rest with a per-project key.

Billing data. Wallet balance, transactions, per-second metering records for CPU, memory, volumes, object storage and network traffic. Card details never touch our servers — they go directly to our payment processors.

Operational telemetry. Deployment logs, build output, CPU and memory metrics sampled roughly once a minute, and network traffic counters. Traffic counters record how many bytes moved, in which direction, and which carrier network the other end was on — that last part is what makes zerodata billing possible. We do not record the contents of that traffic.

Support data. Anything you write into a support ticket, plus the messages exchanged on it.

Website data. Aggregate, cookieless analytics on simplifyd.com via Ahrefs Analytics. No cross-site tracking, no advertising pixels.

03Why we collect it

  • To run the service — authenticate you, schedule your workloads, route your traffic, keep your data stores alive.
  • To bill you — metering is the bill. Without the per-second records we cannot produce an invoice you can check.
  • To keep it up — logs and metrics are how we find out something is broken, usually before you do.
  • To answer you — support tickets, incident notices, low-balance warnings.
  • To stop abuse — detecting fraud, credential stuffing and workloads that endanger the platform.

Our lawful bases, where that framing applies: performance of a contract for everything needed to deliver the service and bill for it; legitimate interest for security, abuse prevention and product analytics; consent for marketing email, which you can withdraw at any time.

04Who we share it with

We do not sell personal data. We share it with a short list of subprocessors, each doing one job:

  • Stripe, Paystack, Flutterwave — payment processing. They receive your payment details directly; we receive a result.
  • SendGrid — transactional email (verification, alerts, receipts).
  • Google — OAuth sign-in, if you choose it.
  • Cloudflare — DNS and certificate issuance for the domains you attach to your services.
  • Anthropic — first-pass triage of support tickets. Ticket text is sent to the Claude API to draft a response. It is not used to train models. If you would rather no ticket of yours be processed this way, say so in the ticket and we will handle it manually.
  • Mobile network operators — MTN, Airtel, Glo, 9mobile and Safaricom receive the aggregate byte counts needed to settle zerodata delivery. They do not receive your account data.

We also disclose data when the law requires it. Where we are permitted to tell you about such a request, we will.

05Where your data lives

Simplifyd runs its own infrastructure in Nigeria. Your workloads, your databases and your buckets stay on that infrastructure — we do not silently move them offshore. The subprocessors listed above (payments, email, OAuth, DNS, support triage) operate outside Nigeria, so the specific data each one needs does cross a border. That is the extent of it.

06How long we keep it

  • Account and workspace data — for as long as your account exists.
  • Deployment logs — retained for a rolling window, then dropped.
  • Metrics — 30 days.
  • Billing and transaction records — kept as long as tax and accounting law requires, which outlives your account.
  • Deleted services — volumes and buckets are destroyed when you delete the service. Deletion is not reversible and we do not keep a shadow copy.
  • Closed accounts — personal data is deleted or anonymised within 90 days, except the billing records above.

07Security

  • Passwords are hashed. API tokens are stored hashed and shown once.
  • Environment variables, service secrets and database passwords are encrypted at rest with a per-project key.
  • Two-factor authentication (TOTP) is available on every account.
  • Data stores are private to your project network by default. Public exposure is something you switch on deliberately.
  • Workspace roles limit what each member can do — a developer-role member cannot reach billing.
  • Deployment logs are filtered for credential patterns before they are returned over the API or to an AI agent. This is a safety net, not a guarantee: an application can print a secret in a shape no filter anticipates.

No system is perfectly secure. If we discover a breach affecting your personal data, we will notify you and the relevant authority without undue delay.

08AI agents and the MCP server

Connecting an AI coding agent through mcp.simplifyd.com gives that agent an OAuth token scoped to the workspaces you picked on the approval screen, and no wider than your own role. Normal tool responses omit variable values, passwords and connection strings; only tools that explicitly say they reveal credentials do.

What the agent does with what it reads is between you and whoever operates that agent — their privacy policy governs the transcript, not ours. Connected applications are listed in your account settings and revoking one takes effect on the next request.

09Your rights

Under the Nigeria Data Protection Act and, where it applies to you, the GDPR, you can ask us to give you a copy of your data, correct it, delete it, restrict how we use it, or object to processing based on legitimate interest. You can export your workspace data yourself at any time through the API or the edge CLI — that is usually faster than asking us.

Email savvy@simplifyd.com and we will respond within 30 days. If you are not satisfied, you can complain to the Nigeria Data Protection Commission, or to your local supervisory authority in the EU/UK.

10Children

Simplifyd is not for people under 18. We do not knowingly collect data from children. If you believe a child has an account, tell us and we will remove it.

11Changes to this policy

We will update this page when what we do changes, and move the "last updated" date. For changes that materially affect your rights we will email account owners at least 30 days before they take effect.

Fast deploys.
#Zerodata access.

Install the CLI, run one command, and your app is live on Simplifyd’s infrastructure — the meter only ticks while it’s running.