Privacy Policy

SimpleGrid

Effective date: 2026-07-20
Last updated: 2026-07-20

Supersedes the version dated 3 March 2026. This version adds the SimpleGrid mobile app, corrects the operating entity, and states our role as a processor of customer data.

SimpleGrid is operated by Valaya AI Technologies Private Limited ("Valaya AI", "we", "us", "our"), a company incorporated in India, registered at 460, 6th Cross, JP Nagar III Phase, Bengaluru South, Bengaluru, Karnataka 560078, India. "SimpleGrid" is our product name, not a separate company. You can reach us at hello@simplegrid.ai.


0. What this policy covers

This one policy covers all three places you meet SimpleGrid:

SurfaceWhat it is
Marketing websitesimplegrid.aiPublic pages, cookie banner, demo booking
Platform — the SimpleGrid web consoleWhere your organisation runs its operations
Mobile app — iOS and Android, bundle ID ai.simplegrid.mobileThe same workspace, on a phone

Where a practice applies to only one surface, it says so. Everything else applies to all three.


1. In plain terms

SimpleGrid is a business product for people at work. You sign in with an account your employer (or whoever runs your SimpleGrid workspace) created for you, and you use it to view and update your organisation's own business records — orders, inventory, ledger entries, approvals, and so on.

Three things are worth stating up front:

We do not sell your data. We do not train shared AI models on your data.


2. Our role: who controls what

This differs by surface, and the distinction decides who you ask to exercise your rights.

Your organisation's workspace data (Platform and mobile app). Your organisation decides what records exist, what personal data goes into them, who gets an account, and how long it is kept.

Practically: if you want your account removed, your details corrected, or a record deleted, the fastest and usually the only correct route is your workspace administrator. We will help, but for most requests we are required to act on your organisation's instruction rather than unilaterally. See section 9.

Where Valaya AI is itself the controller. A small amount of data we handle in our own right: visitors to the marketing website (section 3.1), the app-update check (section 3.11), onboarding correspondence, and any support email you send us directly.


3. What we collect, and why

3.1 Marketing website — cookies and analytics (website only)

The marketing website uses cookies and similar technologies for site functionality, analytics, and measuring how well our marketing works. This section covers the marketing website only. Platform and mobile-app data is governed by the rest of this policy — neither loads any of these tools.

Cookie categories:

Third-party services on the marketing website:

Consent. Analytics cookies do not load until you click Accept on our cookie banner. If you click Decline, or never interact with the banner, no analytics load. You can revoke a previous acceptance at any time by clearing site data in your browser, or by emailing hello@simplegrid.ai.

3.2 Onboarding and account information

When your organisation is set up, we collect business name, contact details and operational structure, plus user account information (names, emails, phone numbers, roles) for the people who get accounts. We also keep your communications with our team.

3.3 Sign-in details

When you sign in, we collect only what is needed to authenticate you:

What you enterWhenWhy
Email address (used as your username)Password sign-in, one-time-code sign-in, password resetTo identify your account
Phone numberOnly if you choose one-time-code sign-in and type a phone number instead of an emailTo send the code by SMS
Password, and any new password you choosePassword sign-in, first-time password setup, password resetTo verify you
One-time codes (email or SMS), password-reset codesCode sign-in and password resetSecond factor / reset credential

These are sent directly to Amazon Cognito, the managed identity service we use, in the AWS Asia Pacific (Mumbai) region — user pool ap-south-1_wPYQ3490r. They are not sent to our own application servers. Your password and one-time codes are never written to your device's storage; they exist only in memory while you are filling in the form.

Mobile app: if you type a phone number, the app decides it is a phone number purely by looking at the characters you typed (and assumes +91 if you omit a country code). It does not ask any server "does this person exist?" before you submit — deliberately, because that kind of check would let strangers test whether an email or number is registered.

We do not collect your name at sign-in. Your display name comes from your organisation's records and is shown back to you.

3.4 Your session (mobile app)

After you sign in, Amazon Cognito issues session tokens. The app stores them in the iOS Keychain / Android Keystore — the operating system's encrypted credential store — not in ordinary app storage. They are stored with a setting that keeps them on that one device: excluded from iCloud and device backups, and not carried over when you migrate to a new phone. Signing out deletes them.

An identity token is attached to every request the app makes to our backend, so the server knows who is asking.

3.5 Your profile and your colleagues' details

The app reads your profile from our backend: user ID, email, name, roles, and which workspace you belong to. This lets you in, decides which screens you can see, and renders the profile card in Settings.

If you are a workspace administrator, the Users screen shows a read-only directory of the other people in your workspace: name, email, username, phone number and roles as held in your organisation's records. Only name, email and roles are displayed on screen. The app cannot create, invite, edit or delete users.

Both are downloads, not uploads — the app receives this information, it does not send it. Neither is written to your device's disk; they live in memory only and are cleared when you sign out.

3.6 Business and operational records

Everything you enter into a record — order details, quantities, notes, dates, links to other records, line items — is stored in your organisation's SimpleGrid workspace. This includes financial transaction records, inventory data, workflows, employee and vendor information recorded in the Platform, and approval histories and audit trails. It also includes your workflow configurations, approval rules and policies.

If your organisation's forms include personal data (a customer's name, a supplier contact, a driver's phone number), that personal data goes into the record too. What those fields are is entirely your organisation's configuration, not ours.

Unsent drafts (mobile app): if you start filling in a "create record" form and leave, the app saves the partly filled form on your device so you can come back to it. These drafts stay on your device — they are not uploaded — and are deleted when you sign out, so they cannot appear for the next person who signs in on a shared phone.

3.7 Uploaded files

You can upload files — Excel sheets, PDFs, invoices, purchase orders, scanned records — to attach to or populate your records. Contents may be processed by third-party AI providers to extract structured data; see section 3.9 and section 6.

3.8 Photos and camera (mobile app)

If a form has an image field, you can attach a photo from your library or take a new one. The app asks for camera or photo-library permission at the moment you tap, not at launch, and only for still images — never video, never audio.

Before anything is uploaded, the image is re-encoded on your device: resized to a maximum edge of 2000 pixels and recompressed. A useful side effect is that the original file's embedded metadata, including any GPS coordinates, is dropped — the uploaded file is a freshly generated image.

The image bytes are then uploaded directly to Amazon S3 using a short-lived, expiring upload link issued by our backend. The file contents never pass through our application servers. Only the storage key, original filename, size and file type are saved against the record. When the image is displayed later, the app fetches a fresh time-limited link (valid one hour); attachments are never on a public URL.

The app has read-only access to your photo library. It cannot save anything to your camera roll or delete anything from it.

3.9 Smart Fill — documents you scan (mobile app)

Smart Fill lets you pick a PDF or image of a real document — an invoice, a delivery note — so the assistant can read it and pre-fill a form for you. When you do this:

If a document is too sensitive to be processed this way, don't use Smart Fill for it — type the fields in instead.

3.10 Hank, the in-app assistant (mobile app)

When you chat with Hank, the messages you type — and the workspace data Hank looks up to answer you — are sent to our backend and forwarded to Anthropic's Claude. The whole conversation so far is resent with each message, because the assistant does not hold your conversation between turns.

Your conversation is also saved on your device so it is still there when you reopen the app. It is stored in the app's private storage in unencrypted form (the device's own disk encryption still applies), under a single conversation slot rather than one per account. It is deleted when you sign out.

Please treat Hank the way you would treat any tool that sends text off your device: don't paste credentials or anything your organisation would not want processed by an external AI provider.

3.11 Technical information

Collected automatically across the Platform and website: device and browser information (IP address, browser type, operating system), usage data (features used, time spent, actions taken), and log data (access times, error logs, API requests).

Sent by the mobile app to our backend with every request: your session token, the app's version number (so the server can tell you to update if your version is no longer supported), and — only for platform-level administrator accounts impersonating a workspace — the active workspace ID. No device identifier, installation identifier, advertising identifier or location is added to any request. As with any internet request, our servers and their CDN necessarily see your IP address.

Sent by the mobile app to Expo on every launch: the app uses Expo's EAS Update service to deliver JavaScript updates without a full store release. On each cold start it contacts u.expo.dev and sends:

This is used only to work out whether a newer app bundle should be sent to you.

3.12 App preferences (mobile app)

Your Light / Dark / System appearance choice is stored on your device only and is never transmitted.

3.13 Crash reporting — not enabled in this release (mobile app)

The app includes crash-reporting code (Sentry), but it is switched off in the current release: no reporting endpoint is configured, so no crash, error or performance data leaves your device.

If we enable it in a future release, we will update this policy first. It is already configured so that, when enabled, it would not attach IP addresses, cookies or request bodies, and it does not set a user identity — reports would not be linked to your account.


4. What the mobile app does not collect

We verified each of these by auditing the app's source code and build configuration:

Permissions the app actually asks for: camera and photo library. That is the complete list of user-facing permission prompts tied to app features.


5. How we use information


6. Who your data is shared with

We share data only with service providers ("sub-processors") who process it on our behalf under contract, and only for the purposes above.

WhoWhat they receiveWhyWhere
AWS — CognitoEmail or phone number, password, one-time codes, session tokensAuthentication and session managementAWS Asia Pacific (Mumbai), ap-south-1
AWS — S3, CloudFront, database & computeBusiness records, image attachments, and API traffic (including IP address at the edge)Hosting and delivering SimpleGridPrimary region India (ap-south-1); CloudFront serves from edge locations worldwide
AnthropicAssistant conversation content, the workspace data used to answer, and Smart Fill documentsPowering Hank and Smart FillAnthropic's infrastructure, which may be located outside India
Expo / 650 Industries, Inc.EAS Client ID, platform, runtime version, release channel, update IDs, IP addressDelivering app updatesExpo's infrastructure, which may be located outside India
PostHog, Google Analytics 4, Cal.com (marketing website only)Website usage data, and booking details if you book a demoWebsite analytics and demo schedulingTheir own infrastructure

We may also disclose data where we are legally required to — a valid court order, or a lawful request from a government authority — or where necessary to establish or defend legal claims, or to protect the rights and safety of users. Where we are permitted to, we will tell the affected organisation first. Data may also transfer to a successor entity in a merger or acquisition, with advance notice.

We do not sell personal data, and we do not share it for anyone else's advertising or marketing.

International transfers. Your organisation's core data is stored in India. Where a sub-processor processes data outside India (Anthropic, Expo), we rely on contractual safeguards with that provider. If your organisation requires data-residency guarantees, raise this with us before deployment — some of these features can be restricted at the workspace level.


7. How long data is kept

DataRetained
Session tokens on your deviceUntil you sign out, the token expires, or you uninstall the app
Assistant conversation on your deviceUntil you sign out or uninstall the app
Unsent form drafts on your deviceUntil you submit or discard the form, or sign out
Appearance preferenceUntil you uninstall the app
Your business records and attachments on our serversWhile your organisation's workspace is active. On termination, held 90 days for export and recovery requests, then deleted or anonymised unless law requires otherwise
Your user accountUntil your organisation deactivates or deletes it
Authentication records held by Amazon CognitoFor the life of the account; sign-in event history per AWS's standard retention
Support emails you send to hello@simplegrid.ai24 months from the date the conversation is closed

Signing out of the app clears everything the app stored locally — tokens, conversation, drafts. Uninstalling removes the rest, including the EAS Client ID.


8. How we protect your data

No system is perfectly secure. Use a device passcode, keep the OS and the app updated, and sign out on any shared device. If you believe your account has been compromised, tell your workspace administrator and email hello@simplegrid.ai immediately.

If you believe you have found a security vulnerability in SimpleGrid, please report it to hello@simplegrid.ai rather than disclosing it publicly.


9. Your rights

Depending on where you are, you may have the right to:

If you are in the European Economic Area (GDPR), the United Kingdom (UK GDPR), California (CPRA) or India (DPDP Act 2023), you may have additional rights, including opt-out of certain processing.

How to exercise them. Because your organisation controls the workspace data:

  1. Start with your workspace administrator. They can view, correct, deactivate and remove accounts and records directly, and this is almost always the fastest route.
  2. If you cannot reach them, or the request concerns Valaya AI itself, email hello@simplegrid.ai with your name, your workspace/company name, the email address on your account, and what you want done. We will acknowledge within 3 business days and respond substantively within 30 days, subject to verifying your identity. If you raise your request as a formal grievance under India's IT Rules, the shorter timelines in section 12 apply instead — acknowledgement within 24 hours and resolution within 15 days. For data we hold as a processor, we will pass the request to your organisation and act on their instruction; we will tell you when we have done so.

We will not charge you for a reasonable request, and we will not treat you differently for making one.

Account deletion. Accounts are provisioned by your organisation; there is no public sign-up and no in-app account-deletion flow. To have an account deleted, ask your workspace administrator, or email hello@simplegrid.ai.


10. Children

SimpleGrid is a workplace tool. It is not directed at children and we do not knowingly collect personal data from anyone under 18. Accounts are created by an organisation for its own personnel. If you believe a child's personal data has reached us, email hello@simplegrid.ai and we will delete it.

Note that a customer organisation may enter third parties' details into its own business records; responsibility for the lawfulness of that content rests with the organisation as controller.


11. Changes to this policy

If we change this policy, we will update the "Last updated" date at the top and publish the new version at the link shown on the app's store listings and in the app's Settings screen.

For changes that materially affect you — for example enabling crash reporting, or adding a new sub-processor that receives personal data — we will notify workspace administrators in advance, and where the law requires it we will ask for consent before the change takes effect.


12. Contact us

Valaya AI Technologies Private Limited
460, 6th Cross, JP Nagar III Phase
Bengaluru South, Bengaluru
Karnataka 560078, India
Email: hello@simplegrid.ai

For privacy questions, data requests, or complaints, write to hello@simplegrid.ai with "Privacy" in the subject line.

Grievance Officer (India, per the DPDP Act 2023 and the IT Rules):
Mukund Agarwal
Founder
Email: hello@simplegrid.ai, with "Grievance" in the subject line

We will acknowledge grievances within 24 hours and aim to resolve them within 15 days, as required by the IT Rules 2021.

If you are not satisfied with our response, you may complain to the Data Protection Board of India, or to your local supervisory authority if you are outside India.