Skip to content

Legal

Privacy Policy

Last updated 2026-08-31

This covers everything The Simply Initiative runs: the products you sign in to, and the site you are reading now. It says what we collect, why we have it, how long we keep it, and what you can tell us to do about it.

We are an Australian business. This is written to meet the Australian Privacy Act and the Australian Privacy Principles, the General Data Protection Regulation if you are in the EU or the UK, and United States state privacy law.

What we collect

Your account

One account works across everything we build. It holds your name, your email address, whether you have confirmed that address, and a picture if you set one. It also holds the sign-ins that keep you signed in.

You give us all of that. We do not buy it from anyone, and we do not go looking for the rest of it elsewhere.

What you put into a product

Whatever the product is for. If it helps you keep track of something, it holds the things you are keeping track of, and the settings you chose while doing it. None of it is sold, none of it is shared for advertising, and none of it is used to train anyone's model.

Products link your data to your account by an internal reference rather than by your name or email address, so a product generally holds what you put into it and not who you are.

One thing is worth being plain about, because budgeting software invites the assumption. We do not hold your money and we are not connected to your bank. Nothing we build moves a cent, opens an account, or reads your balance. If you use SimplyBudget, what it has is the figures you typed in yourself: what comes in, what goes out, and what you are putting aside. That is still personal, so it is stored in Australia and looked after accordingly, but it is a picture of your finances rather than access to them.

When a product uses AI

Some things a product does are answered by an AI model, and where that happens the product tells you at the time. What you give it goes to one of the providers in our subprocessor list to be answered.

How they handle it from there is governed by their own terms and the agreement we have with them. They are named in that list, so you can read what each of them says for yourself.

When you contact us

The contact and beta-request forms on this site hand what you type to a relay that turns it into an email to us. It is in the subprocessor list. Nothing you type into those forms is stored by any of our applications.

How the site gets used

We count page visits. It stores nothing on your device and cannot tell one visitor from another, so we can see that a page was read and not who read it.

Why we hold it

Your account and the sign-ins attached to it exist so we can let you in and keep you there. Your email address is how we confirm the account is yours, reset a password when you need it, and tell you something about your account you would want to know.

Whatever you have put into a product is there because it is the product. There is no version of it that works without holding the thing it is helping you with.

Payment records exist because we took a payment and because tax law says we have to be able to explain it later. Page counts exist because we would like to know which pages people actually read.

If you are covered by the GDPR: our lawful basis is performance of a contract for everything the product needs to run, legal obligation for the tax and payment records we are required to keep, and legitimate interest for keeping the service secure and knowing which pages get read. We do not rely on consent, because nothing we currently do needs it. If that changes we will ask you properly, for the thing that needs asking about.

How long we keep it

What you have put into a product stays while you are using it, and your sign-ins expire on their own.

We also clear out what we no longer need. That is ordinary housekeeping rather than a schedule you have to keep track of, and it means we may remove data the product has no continuing use for. You can export what you have put in at any time, so keep your own copy of anything you would miss.

Ask us to delete you and we will, apart from the records the law makes us keep.

Payment records we keep for five years from the transaction, because Australian tax law requires records that explain a transaction. That is the one thing a deletion request cannot take with it, and we will say so when you make one.

Who else sees it

The companies in our subprocessor list, and each only for the job it does. All of them are bound to handle it on our instructions and for nothing of their own.

Some of them are overseas. Model providers are the clearest case. Where data goes outside Australia we rely on the contractual protections those providers offer, and we name the companies involved so you can decide what you make of that.

We do not sell your personal information and we do not share it for advertising. There is no advertising in anything we build, no advertising network on any page, and nobody is handed your data to build a picture of you from. That is how the business works rather than a setting you have to go and find.

What you can ask us to do

Email admin@thesimplyinitiative.com.au. We will get back to you within 30 days.

You can ask us what we hold about you, and we will tell you what we have, where it came from and who else has seen it. You can ask for a copy of it, and we will send it in a format you can read and take somewhere else. That stays true even if a paid plan has lapsed, because your data is yours whether or not your subscription is. You can tell us something we hold is wrong and we will correct it. And you can ask us to delete you, in which case we will, and tell you what the law makes us keep and for how long.

We will ask you to confirm the request from the email address on the account before we act on it. It is the one check standing between someone else and everything we hold about you, so we would rather ask.

Every one of those has a written procedure behind it. We do not promise a right we have no way of honouring.

If you are unhappy with how we handled a request, tell us. If you are still unhappy after that, you can take it to the Office of the Australian Information Commissioner, or to the data protection authority where you live if that is in the EU or the UK.

Cookies

Everything our products store on your device, and why none of it asks your permission, is in the Cookie Policy. The short version is that all of it is needed to run the thing you asked for, and none of it follows you anywhere.

Children

Our products are not built for children under 16 and we do not knowingly collect anything about one. If you think a child has an account, tell us and we will remove it.

Keeping it safe

Passwords are hashed, so we never hold the password you typed. Traffic between you and us is encrypted. Card numbers go straight to our payment provider and are never held by us. We use established hosting and database providers and rely on the protections they build in.

No system is perfect and we are not going to pretend otherwise. If something goes wrong in a way that puts you at risk, we will tell you and the regulator, as the law requires.

When this changes

The date at the top moves when the text does, and every version of this document is kept. If a change affects your rights or what we do with your data, we will tell you rather than leave you to notice.

Contact

The Simply Initiative
admin@thesimplyinitiative.com.au