Skip to content
Simple Genius
Process About Insights Pricing Free Competitor Report Free Consultation
Home Process About Insights Pricing Free Competitor Report Free Consultation

Legal

Privacy Policy

Effective date: October 8, 2026

Simple Genius LLC ("Simple Genius," "we," "us," or "our") provides the Simple Genius Business Brain platform, including the web application at app.simplegenius.com, our public website at www.simplegenius.com, and the related services, integrations, and human Execution Partner support we deliver with the platform (together, the "Service").

This Privacy Policy explains what information we collect, how we use it, who can see it, how long we keep it, and the choices you have. It applies to visitors to our website, individuals who create or use accounts on the Service, individuals who participate in AI-guided interviews conducted through the Service, and individuals whose information appears in the business records our customers bring into the Service.

If you use the Service on behalf of a business, that business (the "Customer") controls the business content it provides to us, and we process that content on the Customer's behalf to deliver the Service. Where this Policy refers to "you," it means the individual reading it, whether you are an account user, an interview participant, or a website visitor.

1. Information we collect

1.1 Information you provide directly

Account and profile information. Name, business email address, phone number, job title, company name, and role or permission level within the Customer's account. Login credentials are created and managed by our identity provider, Auth0; we do not store your password.

Billing information. Billing contact, billing address, and plan selection. Payment card details are collected and processed by our payment processor, Stripe, and are not stored on our systems.

Business content. Documents, spreadsheets, presentations, notes, and other files the Customer uploads; text the Customer enters into intake fields; answers provided in guided intake; and instructions, questions, and messages entered into Workstreams and other conversational features.

Interview transcripts. When the Customer uses the interview feature, participants speak with an AI interviewer in a live voice session. Speech is converted to text in real time and a written transcript is stored as business content. Audio is processed only for the purpose of transcription and is not recorded or retained. Participants are informed that the session is transcribed before it begins.

Voice dictation. If you use voice input in Workstreams, audio is streamed to our transcription provider and converted to text. The audio is not stored.

Communications with us. Emails, support requests, website contact-form submissions, and feedback you send us.

1.2 Information collected from connected services

With the Customer's authorization, the Service can connect to third-party services the Customer already uses, such as cloud storage, calendars, meeting-recording tools, accounting, CRM, messaging, project-management, and analytics tools. The current list of available connections is shown on the Integrations page of the Service. When a connection is authorized, we collect the records that the enabled connection reads from that service, which vary by service and may include file and folder names and metadata, calendar events, customer and contact records, invoices and financial summaries, messages, tickets, tasks, meeting transcripts, and usage metrics. The Service sends these records to our AI provider (Section 3) to extract business facts that are shown to you in your Business Intelligence. Connections are read-only; the Service does not create, modify, or send anything in a connected service.

Meeting-recording tools (for example, Fireflies). When you connect a meeting-recording tool, we collect meeting transcripts, transcript sentences and highlights, meeting summaries and analytics, channel and contact records, and the names and email addresses of meeting participants. Meeting transcripts may contain statements by people outside the Customer's organization; the Customer is responsible for any notice or consent those participants require (see the Terms of Service, Section 3.3).

Google Drive and Google Calendar. When you connect Google Drive, we collect file and folder names, file types, sizes, modification dates, links, shared-drive names, and the sharing permissions of files visible to the authorizing user, which include the names and email addresses of people those files are shared with. We do not read the contents of your files. When you connect Google Calendar, we collect event titles, descriptions, locations, dates and times, recurrence, and status for the primary calendar, for the period one month before and one month after each sync. We do not collect attendee lists. Connections are authorized through Google's OAuth consent screen, and tokens are held by our integration provider, Nango (Section 4.3).

We request only the Google permission scopes required for the enabled feature. You can review and revoke Simple Genius's access at any time in your Google Account security settings or by disconnecting the integration inside the Service. Section 7 describes what happens to previously collected data when you disconnect.

Google API Services User Data Policy. Simple Genius's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We use Google user data only to provide and improve user-facing features of the Service that are visible to the user who authorized the connection, including extracting business facts that appear in the Customer's Business Intelligence.
  • We do not transfer Google user data to third parties except as necessary to provide or improve those features (for example, to our hosting, AI inference, and integration providers listed in Section 4.3), to comply with applicable law, or as part of a merger, acquisition, or asset sale with prior notice to you.
  • We do not use Google user data to serve advertisements.
  • We do not allow humans to read Google user data unless (a) you have given explicit consent for specific data, (b) it is necessary for security purposes such as investigating abuse, (c) it is necessary to comply with applicable law, or (d) the data has been aggregated and anonymized for internal operations.
  • We do not use Google Workspace data to develop, improve, or train generalized artificial intelligence or machine learning models.

1.3 Information generated by the Service

As the Service operates, it creates records derived from the information above, including Business Intelligence field values, Business Findings, Strategic Insights, Adopted Initiatives, Workstream conversation histories, Business Updates, competitor research summaries, Board decisions, and the version history of each of these. We treat these derived records as Customer business content.

1.4 Information collected automatically

When you use the website or the Service we collect technical information such as IP address, browser and device type, operating system, pages and features used, timestamps, referring pages, and error and performance data. We collect this through server logs, cookies, and the error-monitoring tool described in Section 5. Our error-monitoring tool, Sentry, also records a masked replay of a sample of user sessions (and of sessions in which an error occurs) so that we can reproduce problems; text you type and content you view are masked in these replays. We also record AI usage metrics for each account and user, including the feature used, the model used, and the number of input and output tokens consumed, for the purposes of billing and cost management.

1.5 Information from public sources

The Competition Hub feature gathers publicly available information about competitors the Customer identifies, such as website content, pricing pages, public marketing materials, public social-media profiles and posts, job listings, advertising creatives, and search-engine ranking and domain-registration data. This may include the names and public professional information of individuals associated with those businesses. We obtain this information through the public-data providers listed in Section 4.3.

2. How we use information

We use information for the following purposes:

To provide the Service. Building and maintaining the Customer's Business Brain; pre-populating Business Intelligence fields; generating Business Findings, Strategic Insights, and Workstream responses; running competitor research; conducting and transcribing interviews; and maintaining the history of findings, decisions, and updates.

To deliver Execution Partner support. Allowing the Execution Partner working with a Customer to review that account's business content so they can prepare for sessions and help the Customer plan and monitor execution. Execution Partner sessions take place outside the platform.

To operate accounts and billing. Authentication, seat and plan management, invoicing, payment processing, and enforcement of plan limits such as seats, competitors, and Competition Hub searches.

To communicate with you. Service notices, security alerts, support responses, onboarding guidance, and, where permitted, information about Simple Genius products and events. You can opt out of marketing communications at any time.

To secure and improve the Service. Monitoring for abuse and fraud, diagnosing errors, understanding how features are used, and improving product quality and performance.

To comply with law. Meeting legal, regulatory, tax, and accounting obligations and responding to lawful requests.

3. Artificial intelligence processing

The Service uses large language models and related AI services to analyze business content and generate output. When you use an AI-powered feature, the relevant business content (for example, uploaded documents, interview transcripts, Business Intelligence records, records from connected services, and your Workstream messages) is transmitted over an encrypted connection to our AI inference provider to produce the requested output.

AI processing is performed on Amazon Web Services through Amazon Bedrock, using models from Anthropic, Amazon, Mistral, and Cohere hosted within AWS. Under the AWS service terms, Customer content submitted to Bedrock is not used to train models and is not retained by AWS or the model vendors.

Some features perform web research. When you use them, the Service builds search queries from your Business Intelligence or your Workstream message and sends those queries to our search and web-data providers listed in Section 4.3. Your documents and transcripts are not sent to these providers.

We do not use Customer business content, interview transcripts, or connected-service data to train general-purpose AI models, and we do not sell or license this content to third parties.

AI-generated output is derived from the information available to the Service at the time of generation and may be incomplete, inaccurate, or out of date. Output is provided to support, not replace, the Customer's own judgment.

We log AI usage (feature, model, tokens, user, account, and time) for billing and cost management. These logs do not include the content of prompts or outputs.

4. Who can access your information

4.1 Within the Customer's account

All users invited to a Customer account can see that account's business content, including interview transcripts. Customer administrators control who is invited, who holds the administrator role, which integrations are connected, and what content is uploaded or deleted.

4.2 Simple Genius personnel

Access to Customer business content by Simple Genius is limited to:

  • Execution Partners working with the Customer, for the purpose of delivering the included support hours and helping the Customer plan and monitor execution.
  • Simple Genius support staff, through a dedicated administration console protected by two-factor authentication, for the purpose of resolving support requests, re-running processing of uploaded files and connected services, regenerating findings, correcting company records, and investigating security incidents. Support staff may also view the Service as a Customer user in a read-only, time-limited "view as customer" mode; each such session requires a stated reason and is recorded.
  • Engineering and operations personnel, including our contracted development partners, for the purpose of operating, maintaining, and troubleshooting the Service. This access is limited to what the task requires, is subject to audit logging, and is governed by confidentiality obligations.

We do not use interview transcripts or business content from one Customer to train, coach, or demonstrate to other Customers or personnel without that Customer's specific written permission.

4.3 Service providers

We share information with service providers who process it on our behalf and under contract. Our current categories of service providers are:

CategoryProviderInformation processed
Cloud hosting and storageAmazon Web Services (United States regions)All Service data
AI model inferenceAmazon Bedrock (AWS), running models from Anthropic, Amazon, Mistral, and CohereBusiness content submitted to AI features
Speech-to-text and text-to-speechAmazon Transcribe and Amazon Polly (AWS)Interview and dictation audio, processed in real time
Real-time voice transportLiveKitInterview audio in transit
Identity and loginAuth0Name, email address, login credentials, session data
Integration connectionsNangoOAuth tokens for connected services and records synced from them
PaymentsStripeBilling contact and payment details
Error monitoringSentryTechnical error and performance data, masked session replays
Transactional emailSendGridName and email address
Search and public web dataExa, Bright Data, DataForSEOSearch queries derived from Business Intelligence and Workstream messages; competitor names and domains; public web pages retrieved on your behalf

We will update this table when providers change. Service providers are permitted to use information only to perform services for us and are required to protect it.

4.4 Other disclosures

We may disclose information (a) to comply with law, regulation, legal process, or enforceable government request; (b) to enforce our agreements and protect the rights, property, or safety of Simple Genius, our Customers, or others; (c) in connection with a merger, acquisition, financing, or sale of all or part of our business, in which case we will notify affected Customers before their information becomes subject to a different privacy policy; and (d) with your direction or consent.

We do not sell personal information and we do not share personal information for cross-context behavioral advertising.

5. Cookies and analytics

The website and the Service use cookies and similar technologies for authentication, security, and remembering preferences. The Service sets a login session cookie managed by Auth0, a cookie that remembers that you have signed in before, a cookie that preserves interface preferences such as the sidebar state, and, during a support "view as customer" session, a cookie that identifies that session. We use Sentry for error monitoring, including masked session replay as described in Section 1.4. We do not use product-analytics tools or third-party advertising cookies. You can control cookies through your browser settings; disabling essential cookies may prevent the Service from functioning.

6. Data retention

We retain information for as long as needed for the purposes described in this Policy:

Business content and derived records are retained for the life of the Customer's subscription. The Service intentionally preserves history, so prior versions of findings and superseded documents remain in the Customer's record until deleted under Section 7.

Interview transcripts are retained as business content until the Customer deletes the interview or closes the account.

Account and billing records are retained for the life of the account and for seven years thereafter as required for tax and accounting purposes.

Technical logs are retained for up to 90 days. AI usage records are retained for the life of the account.

Database backups are retained for seven days on a rolling basis. Prior versions of uploaded files are retained until the content is deleted under Section 7.

7. Disconnecting, deleting, and closing

The Service offers three distinct actions. They have different effects:

Disconnect an integration. Stops the Service from accessing the connected third-party service going forward and revokes the connection at the provider. The raw records synced from that service are removed at the same time. Business Intelligence and other derived records that were generated from those records remain in the account as business content until edited or deleted.

Delete content. Removes the selected document, interview, or record from the Customer's active account so it is no longer shown or used for new AI output. Text extracted from the content and search-index entries generated from it are removed when the account's knowledge base is next rebuilt or when the account is closed. Derived records that were generated using the deleted content (for example, a Business Finding) are not automatically deleted, because they are the Customer's own record; the Customer can edit or delete them separately.

Close the account. Ends the subscription. The Customer may request a copy of its business content by contacting us within 30 days after closure. After that period, we delete the account's business content, transcripts, and derived records from active systems, and from backups on the schedule in Section 6, except for information we are required to retain under Section 6 or by law.

Customer administrators can delete content and disconnect integrations in the Service. Account closure, content export, and deletion requests are handled by contacting us at the address in Section 12.

8. Security

Protecting Customer business content is central to how the Service is built. Our safeguards include:

  • Controlled environment. The application servers, databases, file storage, search indexes, and backups are hosted within Amazon Web Services in United States regions. The service providers listed in Section 4.3 operate their own infrastructure under contract with us. Customer content is not stored on personal devices or in unmanaged third-party tools.
  • Encryption at every stage. Content is encrypted in transit using TLS between your browser and the Service, between the Service and every service provider listed in Section 4.3, and encrypted at rest in databases, file storage, and backups.
  • Tenant isolation. Each Customer's data is logically separated by account. Every request is checked against the user's account membership before any data is returned, and no other Customer's users, queries, or AI features can reach it.
  • Least-privilege access. Access by Simple Genius personnel is role-based and limited to the purposes in Section 4.2. Access to the administration console requires two-factor authentication.
  • Audit logs. Administrative actions, support views of Customer content, "view as customer" sessions, integration connections, and Business Update actions are written to audit records.
  • Protected credentials. Passwords are managed by Auth0 and are never stored on our systems. Integration tokens are held by our integration provider and are not stored in our database. System secrets are stored encrypted.
  • AWS-hosted AI processing. AI features run on Amazon Bedrock within AWS, whose terms prohibit training on Customer content and retention of prompts and outputs.
  • Monitoring and response. Production systems are monitored continuously for errors, anomalies, and unauthorized access, with alerts routed to our engineering team.

No system is completely secure, and we cannot guarantee that unauthorized access, loss, or misuse will never occur. If we become aware of a security incident affecting your information, we will notify affected Customers and, where required, regulators and individuals without undue delay.

9. Your rights and choices

Depending on where you live, you may have the right to request access to the personal information we hold about you, to correct it, to delete it, to receive a copy in a portable format, to object to or restrict certain processing, and to appeal a decision we make on your request. To exercise these rights, contact us using the details in Section 12. We will verify your identity before acting on a request and will respond within the time required by applicable law.

If your information is contained in a Customer's account (for example, you are an employee of a Customer or a participant in a Customer's interview), we may direct your request to that Customer or ask the Customer to confirm it, because the Customer controls that content.

You may opt out of marketing emails using the unsubscribe link in any marketing message. We will continue to send service and security communications required to operate your account.

We do not sell personal information, so there is no sale to opt out of. We do not knowingly process the personal information of anyone under 18; the Service is intended for business use by adults.

10. Where information is processed

Simple Genius is based in the United States and processes information in the United States. If you access the Service from outside the United States, you understand that your information will be transferred to and processed in the United States, where privacy laws may differ from those in your location.

11. Changes to this Policy

We may update this Policy from time to time. When we do, we will change the effective date above and, for material changes, notify Customer administrators by email or through the Service before the change takes effect. Continued use of the Service after the effective date constitutes acceptance of the updated Policy.

12. Contact us

Simple Genius LLC

Greenville, South Carolina, United States

Email: support@simplegenius.com

For privacy requests, please include your name, the email address associated with your account, and a description of your request.

Simple Genius
Explore Process About Insights Pricing
Company Free Consultation Free Competitor Report

© 2026 Simple Genius LLC. All rights reserved.

Privacy Policy Terms of Service Data Protection