Privacy Policy

Effective Date: February 28, 2026 Last Updated: July 29, 2026

This Privacy Policy describes how AwakApp Inc. ("Company," "we," "our," or "us"), a California corporation, collects, uses, discloses, and protects personal information from users of SIMY (the "Service"). By using the Service, you consent to the data practices described herein.

1. Eligibility and Age Restrictions

The Service is intended solely for users 18 years of age or older. We do not knowingly collect information from individuals under 18. If we discover such data, it will be deleted promptly. Age eligibility is determined by self-certification; users bear sole responsibility for misrepresentation.

2. Information We Collect

2.1 Information You Provide

  • Account Data: Name, email, authentication credentials, and payment information (processed by third-party providers).
  • User Content: Text, code, documents, and files you input or create.
  • Voice and Audio Data: Voice recordings, audio messages, and the resulting transcriptions. We collect metadata such as duration and timestamps.

2.2 Information Collected Automatically

  • Technical Data: IP address, device type, operating system, and approximate geographic location.
  • Usage Data: Features used, pages viewed, and actions taken within the Service.
  • Cookies: We use cookies to improve user experience and analyze Service performance.

2.3 Information from Third Parties

If you connect third-party services (Slack, GitHub, Zoom, Google Workspace, etc.), we receive data as authorized by those platforms' respective permission settings.

Google API Data and Limited Use

This section applies when you choose to connect a Google account. It covers raw Google user data and any aggregated, anonymized, or derived data created from it. SIMY requests Google access only through an in-product connection flow that explains the requested data and purpose before Google's consent screen appears.

Data We Access

  • Google account identity: Name, email address, and account identifier, used to associate the connection with the correct SIMY account.
  • Gmail: Message and thread content, attachments, headers, labels, and mailbox metadata for searches, summaries, and user-requested workflows.
  • Google Drive: File and folder names, metadata, permissions, and file content for user-requested search, reference, creation, and copy workflows.
  • Google Calendar: Calendar lists, event details, and free/busy availability for scheduling context and follow-up workflows.
  • Google Analytics and Search Console: Account, property, and site metadata plus aggregated performance reports, including dimensions and metrics selected by the user. This is a separate, optional, read-only connection.
  • Derived data: Summaries, editable drafts, workflow results, reports, and other artifacts created only from data needed for the user-selected feature.

How We Use Google Data

We use Google user data only to provide or improve user-facing features that the user selects in SIMY, such as finding relevant messages or files, preparing an editable Gmail draft, organizing a mailbox after review, adding scheduling context, or producing an analytics report.

  • Gmail actions are limited to creating or updating drafts and changing read, archive, or label state only when the user requests or approves the action. SIMY does not send email.
  • SIMY creates or copies a Drive file only when the user requests or approves that action.
  • Google Calendar, Google Analytics, and Search Console access is read-only through these connections.

Sharing, Transfers, and Human Access

We do not sell Google user data or share it with advertisers, data brokers, information resellers, or lenders. We transfer only the data necessary to contracted service providers, such as cloud infrastructure and AI processing providers, that act as processors to deliver the user-selected feature. Those providers may not use raw or derived Google Workspace data to train their general or shared models. We do not permit humans to read Google user data except with the user's explicit consent for support, when necessary to investigate abuse or a security incident, when required by law, or when the data has been aggregated and anonymized for permitted internal operations.

Storage, Retention, and Deletion

  • OAuth access and refresh tokens are stored in access-controlled production systems and retained while the connection is active so SIMY can perform user-requested workflows.
  • Google data and derived results are retained in a workspace only when needed to provide the selected feature or when the user saves a run, draft, report, or artifact. SIMY does not create a separate corpus of Google user data.
  • Users can disconnect Google in SIMY, revoke SIMY access from their Google Account, and delete saved workspace data. Disconnecting or revoking stops future access but does not automatically delete artifacts the user previously chose to save.
  • To request full account deletion, contact . Account data, including retained Google user data, is generally deleted within 90 days unless retention is required by law. Encrypted backups may persist for a limited period under our standard backup cycle.

Data Protection

Google user data is protected in transit using encrypted HTTPS connections and at rest in access-controlled production systems. Access is limited to application components and authorized personnel that need it to provide the Service. OAuth tokens are treated as secrets and are not intentionally included in application logs or user-visible output.

Limited Use and AI/ML Restrictions

The use of raw or derived user data received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

  • Raw, aggregated, anonymized, and derived Google user data is used only to provide or improve prominent user-facing features requested by the user.
  • Raw or derived Google Workspace data is not used to develop, improve, or train a general or shared AI/ML model and is not transferred to a third party for that purpose.
  • Google user data is not used for advertising or retargeting, credit or lending decisions, surveillance, unsolicited commercial email, email warming, or as a general-purpose content repository or content delivery network.
  • Google user data is not sold or transferred to advertising platforms, data brokers, information resellers, or other third parties except as necessary to provide the user-selected feature, for security, to comply with law, or as part of a business transfer with the user's explicit prior consent.

3. Recording Consent and Compliance

Crucial Responsibility: By using voice recording features, you represent and warrant that you have obtained all necessary consents from all parties involved in the conversation, as required by applicable laws (including "all-party consent" states like California). The Company is not responsible for illegal recordings made by users.

4. How We Use Your Information (AI Training Policy)

Our use of User Content for AI development depends on your subscription plan:

  • (a) Standard and Pro Plans (Individual): We may use User Content and voice transcriptions to train, fine-tune, and improve our AI models and machine learning algorithms.
  • (b) Enterprise and Business Plans: We DO NOT use your User Content or voice data to train our global AI models. Your data is used exclusively to provide the Service to your organization.
  • (c) Google User Data: Notwithstanding any other provision, information received from Google APIs will NEVER be used for AI model training, in strict adherence to the Google API User Data Policy's Limited Use requirements.
  • (d) Biometric Data: We do NOT use voice data to create biometric voiceprints or for individual authentication.

5. Information Sharing and Disclosure

We do not sell your personal information. We share data only in these cases:

  • Service Providers: Cloud hosting (AWS/GCP), payment processors (Stripe), and analytics tools.
  • Legal Requirements: To comply with lawful requests by public authorities or to protect our legal rights.
  • Business Transfers: In the event of a merger, sale, or bankruptcy.

6. Data Retention

  • General Data: We retain personal data as long as your account is active. Upon account deletion, we generally delete data within 90 days.
  • Exceptions: We may retain data longer if required for legal compliance, dispute resolution, or as part of anonymized/aggregated datasets. Backups may persist for a limited period per our standard cycle.
  • AI Models: For Standard/Pro users, data already incorporated into trained models cannot be retroactively deleted.

7. Your Privacy Rights (GDPR & CCPA)

Depending on your location (e.g., EEA, UK, California), you may have the following rights:

  • Access, Correct, or Delete your personal information.
  • Object to or Restrict certain processing activities.
  • Data Portability to receive your data in a structured format.
  • Opt-Out of AI Training: Standard/Pro users may request to opt-out of future training by emailing .

8. Data Security and Disclaimers

8.1 No Specific Regulatory Compliance

IMPORTANT: You acknowledge that the Company has NOT yet obtained SOC2 Type II, HIPAA, or PCI DSS certifications.

  • You are strictly prohibited from inputting "Highly Sensitive Personal Data" (e.g., health records, credit card numbers, SSNs).
  • While we use industry-standard encryption, we do not guarantee absolute security. You accept all inherent risks of online data transmission.

9. International Data Transfers

Your data may be transferred to and processed in the United States. For users in the EEA/UK, we rely on Standard Contractual Clauses (SCCs) to ensure an adequate level of data protection.

10. Data Breach Notification

In the event of a breach posing a risk to your rights, we will notify you via email or through the Service without undue delay, and within 72 hours where required by law (e.g., GDPR).

11. Contact Information

AwakApp Inc.
Privacy Requests:
General Inquiries:

12. Acknowledgment

BY USING SIMY, YOU ACKNOWLEDGE AND AGREE THAT:

  1. You have read and understood this Privacy Policy.
  2. Enterprise data is NOT used for training; Standard/Pro data IS used.
  3. The Service is NOT yet SOC2 or HIPAA compliant.
  4. You are 100% responsible for obtaining recording consents from others.
  5. You are 18 years of age or older and not in a sanctioned jurisdiction.

IF YOU DO NOT AGREE TO THESE TERMS, DO NOT USE THE SERVICE.