1. Scope
This Privacy Policy applies to Simple Modern Software, LLC
("Simple Modern Software," "we," "us," or "our"), our website at
simplemodernsoftware.com, and our apps, including Allodola, Espial, and Provino,
unless a separate product notice says otherwise.
Our products are designed for Apple platforms and may rely on Apple
services such as iCloud, CloudKit, Keychain, Sign in with Apple,
notifications, and App Store distribution. Your use of Apple services
remains subject to Apple's terms and privacy policies.
2. Information We Collect
Information you provide
We may collect information you choose to give us, such as your name,
email address, support messages, feedback, beta enrollment details,
crash descriptions, purchase inquiries, and any files or screenshots
you intentionally send for support.
Information processed by the apps
Our apps may process information on your device to provide features.
For example, Allodola may process mail metadata, message content,
calendar events, tasks, contacts, account labels, trip details, and
preferences when you enable those features. Espial may process device
health and performance data such as CPU, memory, disk, network,
battery, thermal, process, GPU, and remote-device health metrics.
Processing information inside an app does not mean we receive it.
Where features are designed to run locally or through services you
control, the information may stay on your device, in your iCloud
account, in Keychain, or with the third-party provider you connected.
Information from third-party providers
If you connect services such as iCloud, Google, Microsoft, an email
provider, a calendar provider, or another account provider, the app may
request access only to the data needed for the features you enable.
Account tokens or credentials are intended to be stored in secure
platform storage such as Keychain, not on our public website.
Opt-in app diagnostics
Our apps include a diagnostics setting that is off by default. If you
turn it on, the app may send anonymized diagnostic logs and aggregated,
de-identified usage events — such as app version, operating-system
version, device family, broad technical error category, session counts,
and crash counts — to help us detect crashes and reliability problems. These
diagnostics are designed to exclude your name, account credentials, and
the contents of your mail, calendar, files, or messages. You can turn
diagnostics off at any time in the app’s settings.
Support requests and optional diagnostic attachments
When you contact support from an app or this website, we receive the
information you submit, such as your name, email address, subject,
message, app and build version, platform and operating-system version,
locale, and bundle identifier. Allodola can also attach a
text diagnostic log, but only when you separately choose to include it
and explicitly consent to sending diagnostics with that request.
A submitted log may contain technical events and error context. The
service limits attachments to small text-based log formats and attempts
to remove common credentials and tokens before storage, but you should
still review what you send and never include passwords, private keys,
authentication codes, or message content. Support attachments are kept
with the ticket, are available only to authorized support personnel,
and are not added to ongoing app telemetry or used for advertising.
Website and diagnostic information
When you visit our website or contact us, limited technical information
is processed to deliver and secure the service — for example, by our
hosting and email providers, who may briefly process your IP address,
request headers, and timestamps to route and protect traffic. We minimize
this and do not use it to build advertising or cross-site profiles.
Analytics & cookies
Our website analytics are first-party and cookieless by design.
We do not set advertising or tracking cookies, we do not fingerprint your
device, and we do not use third-party analytics or ad networks on this site.
For each page view we store only coarse, non-identifying information:
- the page path and the referring website’s domain (not the full URL);
- your device type and browser and operating-system family
(e.g. “mobile / Safari / iOS”) — never a precise version string;
- your country, derived from a coarse network signal at request time
— we do not store your IP address; and
- a purpose-specific, keyed HMAC generated from the network address and
browser family signal using a server-only secret, used only to count unique
visits. The source network address is not written to our analytics database;
the pseudonym changes every day, is not a cookie, and cannot be joined across
days or other sites.
Under the GDPR, the lawful basis for this processing is our
legitimate interest (Art. 6(1)(f)) in understanding aggregate,
anonymous usage of our site; the privacy-preserving design above keeps the
impact on you minimal. Raw events are retained for about 45 days; after that
only aggregated daily counts are kept.
Your controls. We honor the browser
Do Not Track and Global Privacy Control signals
— if either is enabled, no pageview is sent at all. You can also opt out
at any time using the privacy notice shown on your first visit; your choice is
remembered locally on your device. The only browser storage we use is
strictly necessary — remembering preferences such as your light/dark theme
and your analytics choice — and is never shared.
Software update checks (direct-download Mac apps)
Some of our Mac apps are offered as a direct download from this
website rather than through the App Store. Those direct-download
builds can check our server for new versions so the app can offer
you updates. A check is a single request to simplemodernsoftware.com
containing only the app’s version, the platform it runs on
(e.g. “macos”), and its release channel (e.g.
“stable”). It includes no account, no name or
email, no device identifier, and no cookies — there is
nothing in the request that identifies you or your device.
Checks run automatically about every six hours and when the app
launches, and you can trigger one manually with “Check
Now.” Automatic checking is on by default in
direct-download builds and can be turned off at any time with a
toggle in the app’s Settings; manual checks still work after
you turn it off. This is a separate, disclosed network call and is
independent of the opt-in diagnostics described above, which remain
off by default.
Your IP address is used transiently to serve the request and for
abuse rate-limiting; it is not stored with our update
metrics, and we keep no per-request logs tied to anyone.
From the moment of collection we record only daily aggregate counts
— per day, app, version, platform, and channel — of
checks and downloads, so we can understand version adoption.
When you download an app or an update, the file may be served
directly from our site or delivered via GitHub’s content
delivery network; in that case GitHub, Inc. receives the download
request, subject to its own privacy statement.
3. How We Use Information
We use information for the following business and product purposes:
- Provide, operate, maintain, secure, and improve our apps and website.
- Authenticate users, sync settings, honor preferences, and deliver app features.
- Respond to support requests, bug reports, feedback, and legal requests.
- Analyze reliability, performance, crashes, abuse, fraud, and security risks.
- Develop new features, conduct testing, and improve usability.
- Communicate about product updates, policy changes, beta programs, and purchases.
- Comply with law, enforce our Terms, and protect our rights, users, and business.
4. App-Specific Practices
Allodola
Allodola is designed around personal information such as mail,
calendar, contacts, tasks, and trip context. The product direction is
privacy-first: message bodies and personal content should remain on
device or with the account provider you connected. Cloud sync, where
used, is intended for preferences, account descriptors, rules, settings,
themes, signatures, scheduled-send metadata, and similar metadata, not
raw message bodies or account passwords.
If you allow local-weather access, Allodola requests an approximately
kilometer-level location from the operating system and sends latitude
and longitude to Open-Meteo to retrieve weather and air-quality data;
it does not include your name, email address, or account identifier in
that request. If you do not allow location access, the app may use a
city inferred from your device time zone instead. For trip enrichment,
destination city names or coordinates may also be sent to Open-Meteo
for geocoding and forecasts, and currency codes may be sent to a public
exchange-rate service. These requests are used only to provide the
feature you are viewing and are subject to those providers’ policies.
If Allodola uses on-device intelligence, the goal is to perform
summaries, triage, task suggestions, semantic organization, and day
planning locally where platform support allows. If a future feature
uses a cloud service, the app or documentation will disclose that
before you enable it.
Espial
Espial processes device health metrics to show live stats and insights.
These may include CPU, memory, disk, network, battery, thermal, GPU,
Neural Engine, process, device information, and remote-monitor values.
Local device stats are intended to stay on your device unless you
enable remote monitoring or intentionally share diagnostics.
If you enable remote monitoring, Espial may publish lightweight health
snapshots through Apple services such as iCloud/CloudKit so your own
signed-in devices can view them. You can disable remote monitoring,
remove devices, or block devices where the app provides those controls.
The Mac version of Espial distributed as a direct download from this
website checks for updates as described in
Software update checks above; the iOS and
iPadOS versions from the App Store do not perform these checks.
Provino
Provino is a developer tool that builds your own repositories on your
own Mac and photographs the resulting app to assemble a brand kit.
Repository contents, source code, screenshots, and kits are processed
locally and are never transmitted to us. If you enable iCloud sync in
the app, your Provino configuration (app names, screen lists, brand
settings, page copy) and, optionally, finished kit archives are stored
in your own iCloud account through Apple’s iCloud Drive so your
Macs stay in sync; we cannot read that data.
Provino’s diagnostics setting is off by default and follows the
opt-in policy above: when enabled, it sends the text of run failures
the app itself produced, the app version, macOS version, hardware
model, and country — never repository names, file paths, source
code, screenshots, or personal data. Support requests sent from
Provino’s settings use the same support channel as this website
and include the app version and device model so we can help faster.
Beta and prototype data
Some products may be in development, prototype, beta, TestFlight, or
preview status. Any additional beta diagnostics will be described in
the app before collection and will use the same consent controls stated
above. We minimize personal information and do not collect the content
of private accounts unless you intentionally provide it for support.
5. How We Share Information
We do not sell your personal information. We also do not share your
personal information for cross-context behavioral advertising as those
terms are commonly used under U.S. state privacy laws.
We may share information in limited circumstances:
- With service providers that host, secure, analyze, support, or operate our website, email, app diagnostics, payments, or customer support.
- With platform providers such as Apple when you use App Store, iCloud, CloudKit, Keychain, notifications, Sign in with Apple, or related services.
- With account providers you choose to connect, such as email, calendar, contacts, or cloud providers.
- When required by law, legal process, government request, or to protect rights, safety, security, and integrity.
- In connection with a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar business transaction, subject to appropriate safeguards where required.
- With your consent or at your direction.
We require service providers that handle personal information for us
to protect it consistently with this policy and applicable law, and to
use it only to provide their contracted services to us.
6. Your Choices and Rights
You can use platform controls to manage permissions for mail, contacts,
calendars, notifications, iCloud, local network, background activity,
and analytics. You can also disconnect accounts, delete app data,
disable sync, turn off remote monitoring, or uninstall an app.
Depending on where you live, you may have rights to request access,
correction, deletion, portability, restriction, objection, withdrawal
of consent, or appeal of certain privacy decisions. You may also have
the right to opt out of sale, sharing, or targeted advertising. We do
not currently sell personal information or share it for cross-context
behavioral advertising.
To make a privacy request, contact us using the information below. We
may need to verify your identity and may retain certain information as
required or permitted by law, including for security, legal compliance,
dispute resolution, and legitimate business records.
7. Retention
We keep personal information only as long as reasonably necessary for
the purposes described in this policy, unless a longer period is
required or permitted by law. App data stored locally, in Keychain, in
iCloud, or with a connected provider may remain under your control until
you delete it through the app, device settings, provider settings, or
account controls.
Software update-check and download metrics are aggregate-only from
the moment of collection — daily counts per app, version,
platform, and channel, never per-user or per-device records —
and are retained for up to 24 months so we can understand version
adoption.
Raw opt-in app telemetry is ordinarily deleted after 45 days. Resolved
or closed support requests, including optional diagnostic attachments,
are ordinarily retained for up to 730 days after the ticket’s last
activity and then deleted, unless we need to keep particular records
longer for security, fraud prevention, dispute resolution, or legal
compliance. You may request earlier deletion using the contact details
below, subject to those limited exceptions.
For support forms, we store the version of the contact-consent notice and
the time it was accepted with the ticket; that record is deleted with the
ticket. A de-identified engineering issue may be retained after its support
ticket is deleted so we can track product reliability. In that case, we
detach it from the conversation, replace the customer-written subject with
a generic issue identifier, and remove its public listing. Requester contact
fields, messages, attachments, and ticket audit entries remain part of the
support ticket and are deleted with it; coarse product/version data and
de-identified engineering status or resolution information may remain.
8. Security
We use reasonable administrative, technical, and organizational measures
designed to protect information. No method of transmission or storage
is perfectly secure, and we cannot guarantee absolute security. You are
responsible for keeping your devices, Apple ID, account credentials,
and recovery methods secure.
9. Children
Our apps and website are not directed to children under 13, and we do
not knowingly collect personal information from children under 13. If
you believe a child has provided personal information to us, contact us
and we will take appropriate steps.
10. International Users
We are based in the United States. If you use our services from outside
the United States, your information may be processed in the United
States or other countries where we or our service providers operate.
These countries may have privacy laws different from those in your
location.
11. Changes to This Policy
We may update this Privacy Policy from time to time. The "Last updated"
date indicates the latest revision. If changes are material, we will
provide notice as required by law, such as by updating this page,
notifying you in-app, or using another reasonable method.
12. Contact
For privacy questions or requests, contact Simple Modern Software, LLC
at privacy@simplemodernsoftware.com.
You may also use our support request form and
select “Privacy.”
Please include enough detail for us to understand and respond to your
request. Do not send passwords, OAuth tokens, private keys, or sensitive
account credentials by email.