Simplicity Health
Privacy Policy
Simplicity is an adaptive personal training app. This Policy explains how Simplicity Health (“Simplicity,” “we,” “us,” or “our”) handles personal information on simplicityhealth.app and in the app’s optional Google Calendar and Microsoft Outlook calendar integrations.
The short version
- Connecting a calendar is optional and requires your express authorization.
- We use calendar information to find conflicts, adapt your training schedule, and mirror Simplicity workouts to a dedicated provider calendar.
- We do not edit or delete events you created outside Simplicity.
- We do not sell Google Calendar data or use it for advertising.
- You can disconnect a provider, revoke access with that provider, or delete your Simplicity account.
Information we process
Account and connection information
We process your Simplicity account identifier, the calendar provider you connect, a provider-issued account identifier, the permissions you grant, connection and sync status, and OAuth access and refresh tokens. We use the provider identifier only to maintain the correct connection; Google Calendar authorization does not require Simplicity to request your Google email address.
Calendar event information
When you connect Google Calendar or Outlook, we may process event and calendar identifiers, event version, title, location, start and end time, all-day status, free or busy status, and a limited derived context such as travel, unavailable, holiday, birthday, reminder, or ordinary. We also process change-subscription identifiers and sync cursors so that updates can be synchronized efficiently.
Simplicity schedule information
We process workout titles, descriptions, timing, time zone, and internal schedule identifiers when creating, updating, or removing app-managed events from the dedicated Simplicity calendar.
Website information
This website is a static site. It does not use analytics, advertising trackers, contact forms, or browser storage. Our hosting provider may process ordinary request information such as IP address, user agent, requested page, time, and security diagnostics to deliver and protect the site.
How Google Calendar data is used
Simplicity requests the narrow permissions
calendar.events.owned.readonly and
calendar.app.created. The first lets Simplicity read events
from Google calendars you own; the current integration synchronizes your
primary calendar to identify busy periods and scheduling conflicts. The
second lets Simplicity create a secondary calendar named “Simplicity” and
create, change, or delete only the workout events managed by Simplicity on
that calendar.
We use Google Calendar data only to provide and improve the calendar-aware scheduling features you choose to use, keep those features synchronized, prevent duplicate or conflicting workout events, secure the connection, troubleshoot failures, and comply with law. Simplicity does not request permission to change your existing personal events, share your calendars, or change calendar access controls.
Simplicity’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, credit decisions, sale, or training generalized artificial intelligence or machine-learning models.
How we use and disclose information
We use the information described above to:
- connect, authenticate, refresh, and synchronize your calendar;
- show calendar availability and conflicts in Simplicity;
- adapt workout timing and maintain your Simplicity schedule;
- create and maintain app-managed workout events;
- operate, secure, troubleshoot, and improve these user-facing features; and
- respond to support requests and valid legal process.
We use service providers to operate Simplicity. Render hosts the API and background workers that synchronize calendars. Supabase provides the database in which connection records and normalized calendar events are stored. When your separate in-app AI-processing consent is active, calendar event details and derived availability may be included in context sent to Anthropic’s commercial API, or through OpenRouter to Z.AI when you accept the disclosure naming those providers, so Simplicity can provide interactive coaching and automatic Memory and Scheduling updates. Through OpenRouter, TypeSafe’s Jev also receives your current message and up to 20 recent chat messages to choose a coaching model, after you accept the disclosure naming TypeSafe. Coaching messages, training history, program information, and relevant health context may also be included as described in that disclosure. You can revoke permission in Settings to stop future model requests. See the privacy information from Anthropic, OpenRouter, TypeSafe, and Z.AI. These providers process data for us to provide the service; they do not receive it for their own advertising.
We may also disclose information when reasonably necessary to protect the service or users, investigate abuse or a security incident, comply with law or valid legal process, or complete a merger, acquisition, or sale of assets subject to applicable law and the commitments in this Policy. Humans do not read Google user data except with your affirmative request or consent, for security or abuse investigation, when required by law, or when data has been aggregated for lawful internal operations.
Storage, security, and retention
Provider access and refresh tokens are encrypted on the backend using authenticated AES-256-GCM encryption bound to your Simplicity account and provider connection. We use HTTPS for network transmission and limit calendar records to backend service access. No security method is perfect, and we cannot guarantee absolute security.
We keep provider tokens while the connection is active. Disconnecting a provider removes the stored tokens and stops future Calendar access. Synchronized calendar-event records may remain with your Simplicity account after disconnection so that schedule history and system integrity can be maintained. To delete those records, delete your Simplicity account in the app or contact us. We may retain limited security, diagnostic, or legal records for as long as reasonably necessary for those purposes.
Your controls and choices
- Disconnect: use Simplicity’s Calendar settings to disconnect Google Calendar or Outlook.
- Revoke Google access: remove Simplicity from your Google Account’s third-party connections page. Revocation stops future access but does not itself erase data already stored by Simplicity.
- Delete your account: use Settings → Account → Delete Account in the Simplicity app.
- Privacy request: ask to access, correct, or delete your information by emailing us at yisroelrnsn@gmail.com. We may need to verify your identity.
International processing
Simplicity and its service providers may process information in the United States and other countries where they operate. Those locations may have different data-protection laws than your home country.
Changes to this Policy
We may update this Policy as the service, providers, or legal requirements change. We will post the revised Policy here and update the date above. If we materially change how Google user data is used, we will provide notice and request consent when required before using that data for the new purpose.
Contact
For privacy questions or requests, email yisroelrnsn@gmail.com.