Privacy Policy
SimpleGrid
Effective date: 2026-07-20
Last updated: 2026-07-20
Supersedes the version dated 3 March 2026. This version adds the SimpleGrid mobile app, corrects the operating entity, and states our role as a processor of customer data.
SimpleGrid is operated by Valaya AI Technologies Private Limited ("Valaya AI", "we", "us", "our"), a company incorporated in India, registered at 460, 6th Cross, JP Nagar III Phase, Bengaluru South, Bengaluru, Karnataka 560078, India. "SimpleGrid" is our product name, not a separate company. You can reach us at hello@simplegrid.ai.
0. What this policy covers
This one policy covers all three places you meet SimpleGrid:
| Surface | What it is |
|---|---|
Marketing website — simplegrid.ai | Public pages, cookie banner, demo booking |
| Platform — the SimpleGrid web console | Where your organisation runs its operations |
Mobile app — iOS and Android, bundle ID ai.simplegrid.mobile | The same workspace, on a phone |
Where a practice applies to only one surface, it says so. Everything else applies to all three.
1. In plain terms
SimpleGrid is a business product for people at work. You sign in with an account your employer (or whoever runs your SimpleGrid workspace) created for you, and you use it to view and update your organisation's own business records — orders, inventory, ledger entries, approvals, and so on.
Three things are worth stating up front:
- The apps do not track you and carry no advertising. The mobile app contains no advertising SDK, no analytics SDK, no attribution or marketing SDK, and does not read your device's advertising identifier (IDFA / Google Advertising ID). Nothing you do in the Platform or the app is used to build a profile of you or follow you across other apps and websites. Analytics cookies exist on the marketing website only, and only if you accept them — see section 3.1.
- We do not ask for location, contacts, microphone, calendar, motion sensors, or health data. The mobile app has no code that touches any of them.
- Most of the personal data in SimpleGrid belongs to your organisation, not to us. We hold it on their behalf — see section 2.
We do not sell your data. We do not train shared AI models on your data.
2. Our role: who controls what
This differs by surface, and the distinction decides who you ask to exercise your rights.
Your organisation's workspace data (Platform and mobile app). Your organisation decides what records exist, what personal data goes into them, who gets an account, and how long it is kept.
- Your organisation is the data controller (a "Data Fiduciary" under India's Digital Personal Data Protection Act, 2023).
- Valaya AI is the data processor ("Data Processor"), acting on your organisation's documented instructions under our agreement with them.
Practically: if you want your account removed, your details corrected, or a record deleted, the fastest and usually the only correct route is your workspace administrator. We will help, but for most requests we are required to act on your organisation's instruction rather than unilaterally. See section 9.
Where Valaya AI is itself the controller. A small amount of data we handle in our own right: visitors to the marketing website (section 3.1), the app-update check (section 3.11), onboarding correspondence, and any support email you send us directly.
3. What we collect, and why
3.1 Marketing website — cookies and analytics (website only)
The marketing website uses cookies and similar technologies for site functionality, analytics, and measuring how well our marketing works. This section covers the marketing website only. Platform and mobile-app data is governed by the rest of this policy — neither loads any of these tools.
Cookie categories:
- Necessary — site security and core functionality
- Functional — preferences, including your cookie-consent choice
- Analytics — how visitors use the site, so we can improve it
Third-party services on the marketing website:
- PostHog — product analytics
- Google Analytics 4 — aggregate traffic and campaign measurement
- Cal.com — used when you book a demo call
Consent. Analytics cookies do not load until you click Accept on our cookie banner. If you click Decline, or never interact with the banner, no analytics load. You can revoke a previous acceptance at any time by clearing site data in your browser, or by emailing hello@simplegrid.ai.
3.2 Onboarding and account information
When your organisation is set up, we collect business name, contact details and operational structure, plus user account information (names, emails, phone numbers, roles) for the people who get accounts. We also keep your communications with our team.
3.3 Sign-in details
When you sign in, we collect only what is needed to authenticate you:
| What you enter | When | Why |
|---|---|---|
| Email address (used as your username) | Password sign-in, one-time-code sign-in, password reset | To identify your account |
| Phone number | Only if you choose one-time-code sign-in and type a phone number instead of an email | To send the code by SMS |
| Password, and any new password you choose | Password sign-in, first-time password setup, password reset | To verify you |
| One-time codes (email or SMS), password-reset codes | Code sign-in and password reset | Second factor / reset credential |
These are sent directly to Amazon Cognito, the managed identity service we use, in the AWS Asia Pacific (Mumbai) region — user pool ap-south-1_wPYQ3490r. They are not sent to our own application servers. Your password and one-time codes are never written to your device's storage; they exist only in memory while you are filling in the form.
Mobile app: if you type a phone number, the app decides it is a phone number purely by looking at the characters you typed (and assumes +91 if you omit a country code). It does not ask any server "does this person exist?" before you submit — deliberately, because that kind of check would let strangers test whether an email or number is registered.
We do not collect your name at sign-in. Your display name comes from your organisation's records and is shown back to you.
3.4 Your session (mobile app)
After you sign in, Amazon Cognito issues session tokens. The app stores them in the iOS Keychain / Android Keystore — the operating system's encrypted credential store — not in ordinary app storage. They are stored with a setting that keeps them on that one device: excluded from iCloud and device backups, and not carried over when you migrate to a new phone. Signing out deletes them.
An identity token is attached to every request the app makes to our backend, so the server knows who is asking.
3.5 Your profile and your colleagues' details
The app reads your profile from our backend: user ID, email, name, roles, and which workspace you belong to. This lets you in, decides which screens you can see, and renders the profile card in Settings.
If you are a workspace administrator, the Users screen shows a read-only directory of the other people in your workspace: name, email, username, phone number and roles as held in your organisation's records. Only name, email and roles are displayed on screen. The app cannot create, invite, edit or delete users.
Both are downloads, not uploads — the app receives this information, it does not send it. Neither is written to your device's disk; they live in memory only and are cleared when you sign out.
3.6 Business and operational records
Everything you enter into a record — order details, quantities, notes, dates, links to other records, line items — is stored in your organisation's SimpleGrid workspace. This includes financial transaction records, inventory data, workflows, employee and vendor information recorded in the Platform, and approval histories and audit trails. It also includes your workflow configurations, approval rules and policies.
If your organisation's forms include personal data (a customer's name, a supplier contact, a driver's phone number), that personal data goes into the record too. What those fields are is entirely your organisation's configuration, not ours.
Unsent drafts (mobile app): if you start filling in a "create record" form and leave, the app saves the partly filled form on your device so you can come back to it. These drafts stay on your device — they are not uploaded — and are deleted when you sign out, so they cannot appear for the next person who signs in on a shared phone.
3.7 Uploaded files
You can upload files — Excel sheets, PDFs, invoices, purchase orders, scanned records — to attach to or populate your records. Contents may be processed by third-party AI providers to extract structured data; see section 3.9 and section 6.
3.8 Photos and camera (mobile app)
If a form has an image field, you can attach a photo from your library or take a new one. The app asks for camera or photo-library permission at the moment you tap, not at launch, and only for still images — never video, never audio.
Before anything is uploaded, the image is re-encoded on your device: resized to a maximum edge of 2000 pixels and recompressed. A useful side effect is that the original file's embedded metadata, including any GPS coordinates, is dropped — the uploaded file is a freshly generated image.
The image bytes are then uploaded directly to Amazon S3 using a short-lived, expiring upload link issued by our backend. The file contents never pass through our application servers. Only the storage key, original filename, size and file type are saved against the record. When the image is displayed later, the app fetches a fresh time-limited link (valid one hour); attachments are never on a public URL.
The app has read-only access to your photo library. It cannot save anything to your camera roll or delete anything from it.
3.9 Smart Fill — documents you scan (mobile app)
Smart Fill lets you pick a PDF or image of a real document — an invoice, a delivery note — so the assistant can read it and pre-fill a form for you. When you do this:
- the file (up to 10 MB) is sent to our backend, which passes its contents to Anthropic's Claude to extract the field values;
- the file is not stored in our file storage and is not kept on your device;
- whatever is in that document, including any personal data printed on it, is part of what is sent.
If a document is too sensitive to be processed this way, don't use Smart Fill for it — type the fields in instead.
3.10 Hank, the in-app assistant (mobile app)
When you chat with Hank, the messages you type — and the workspace data Hank looks up to answer you — are sent to our backend and forwarded to Anthropic's Claude. The whole conversation so far is resent with each message, because the assistant does not hold your conversation between turns.
Your conversation is also saved on your device so it is still there when you reopen the app. It is stored in the app's private storage in unencrypted form (the device's own disk encryption still applies), under a single conversation slot rather than one per account. It is deleted when you sign out.
Please treat Hank the way you would treat any tool that sends text off your device: don't paste credentials or anything your organisation would not want processed by an external AI provider.
3.11 Technical information
Collected automatically across the Platform and website: device and browser information (IP address, browser type, operating system), usage data (features used, time spent, actions taken), and log data (access times, error logs, API requests).
Sent by the mobile app to our backend with every request: your session token, the app's version number (so the server can tell you to update if your version is no longer supported), and — only for platform-level administrator accounts impersonating a workspace — the active workspace ID. No device identifier, installation identifier, advertising identifier or location is added to any request. As with any internet request, our servers and their CDN necessarily see your IP address.
Sent by the mobile app to Expo on every launch: the app uses Expo's EAS Update service to deliver JavaScript updates without a full store release. On each cold start it contacts u.expo.dev and sends:
- an EAS Client ID — a random identifier generated the first time you open the app and stored on your device. It stays the same until you uninstall the app. It is not an advertising identifier, is not linked to your SimpleGrid account, and is not used for cross-app tracking, but it is a persistent install identifier and we disclose it as such;
- your platform (iOS/Android), the app's runtime fingerprint, release channel, and current/embedded update IDs;
- if a previous update failed to start, the error message and the IDs of the recently failed updates, so the service can roll you back off a broken version;
- your IP address, inherent to making the request.
This is used only to work out whether a newer app bundle should be sent to you.
3.12 App preferences (mobile app)
Your Light / Dark / System appearance choice is stored on your device only and is never transmitted.
3.13 Crash reporting — not enabled in this release (mobile app)
The app includes crash-reporting code (Sentry), but it is switched off in the current release: no reporting endpoint is configured, so no crash, error or performance data leaves your device.
If we enable it in a future release, we will update this policy first. It is already configured so that, when enabled, it would not attach IP addresses, cookies or request bodies, and it does not set a user identity — reports would not be linked to your account.
4. What the mobile app does not collect
We verified each of these by auditing the app's source code and build configuration:
- No location data. No GPS, no coarse location, no location permission. (The word "Location" on the Inventory screen refers to a warehouse location in your own records, not your device's position.)
- No contacts, calendar, or motion/fitness sensors.
- No microphone or audio recording. Microphone access is explicitly disabled in the build.
- No advertising identifiers (IDFA, Google Advertising ID) and no App Tracking Transparency prompt, because there is nothing to track.
- No analytics, product-analytics, attribution or marketing SDKs. None are installed — not Google Analytics/Firebase, Meta, Amplitude, Mixpanel, Segment, PostHog, AppsFlyer, Adjust, Branch, or any similar tool. (PostHog and Google Analytics run on the marketing website only — section 3.1.)
- No push notifications (the app has no push capability in this version).
- No biometric data. Face ID / fingerprint prompts are disabled; device credential storage relies on the device being unlocked, not on biometric enrolment.
- No health, financial-instrument, or government-ID data collected from your device.
- No data sold, rented, or shared with data brokers, ever. We have no advertising business.
Permissions the app actually asks for: camera and photo library. That is the complete list of user-facing permission prompts tied to app features.
5. How we use information
- Provide, operate and maintain the Platform and the app
- Configure and personalise your workflows and system structure
- Process uploaded documents using AI/ML models
- Enable real-time updates, approvals and status tracking
- Communicate about your account, onboarding and support
- Improve features and capabilities
- Ensure security and prevent fraud
- Comply with legal obligations
6. Who your data is shared with
We share data only with service providers ("sub-processors") who process it on our behalf under contract, and only for the purposes above.
| Who | What they receive | Why | Where |
|---|---|---|---|
| AWS — Cognito | Email or phone number, password, one-time codes, session tokens | Authentication and session management | AWS Asia Pacific (Mumbai), ap-south-1 |
| AWS — S3, CloudFront, database & compute | Business records, image attachments, and API traffic (including IP address at the edge) | Hosting and delivering SimpleGrid | Primary region India (ap-south-1); CloudFront serves from edge locations worldwide |
| Anthropic | Assistant conversation content, the workspace data used to answer, and Smart Fill documents | Powering Hank and Smart Fill | Anthropic's infrastructure, which may be located outside India |
| Expo / 650 Industries, Inc. | EAS Client ID, platform, runtime version, release channel, update IDs, IP address | Delivering app updates | Expo's infrastructure, which may be located outside India |
| PostHog, Google Analytics 4, Cal.com (marketing website only) | Website usage data, and booking details if you book a demo | Website analytics and demo scheduling | Their own infrastructure |
We may also disclose data where we are legally required to — a valid court order, or a lawful request from a government authority — or where necessary to establish or defend legal claims, or to protect the rights and safety of users. Where we are permitted to, we will tell the affected organisation first. Data may also transfer to a successor entity in a merger or acquisition, with advance notice.
We do not sell personal data, and we do not share it for anyone else's advertising or marketing.
International transfers. Your organisation's core data is stored in India. Where a sub-processor processes data outside India (Anthropic, Expo), we rely on contractual safeguards with that provider. If your organisation requires data-residency guarantees, raise this with us before deployment — some of these features can be restricted at the workspace level.
7. How long data is kept
| Data | Retained |
|---|---|
| Session tokens on your device | Until you sign out, the token expires, or you uninstall the app |
| Assistant conversation on your device | Until you sign out or uninstall the app |
| Unsent form drafts on your device | Until you submit or discard the form, or sign out |
| Appearance preference | Until you uninstall the app |
| Your business records and attachments on our servers | While your organisation's workspace is active. On termination, held 90 days for export and recovery requests, then deleted or anonymised unless law requires otherwise |
| Your user account | Until your organisation deactivates or deletes it |
| Authentication records held by Amazon Cognito | For the life of the account; sign-in event history per AWS's standard retention |
| Support emails you send to hello@simplegrid.ai | 24 months from the date the conversation is closed |
Signing out of the app clears everything the app stored locally — tokens, conversation, drafts. Uninstalling removes the rest, including the EAS Client ID.
8. How we protect your data
- Credentials go straight to Amazon Cognito; our application servers never see your password or one-time codes.
- Session tokens are held in the iOS Keychain / Android Keystore, marked so they stay on that device and are excluded from iCloud and device backups. The username embedded in the storage key is encoded rather than written in readable form.
- All traffic is over HTTPS. Data is encrypted in transit (TLS/SSL) and at rest.
- Every API request is authenticated and scoped to your organisation's workspace. Platform-level administrator accounts are blocked from the mobile app entirely and directed to the web console.
- Role-based access controls, regular security assessments, and audit trails for Platform activity.
- File attachments use short-lived, expiring signed links. There are no public file URLs; view links expire after one hour.
- Your profile and the workspace directory are held in memory only — never written to the device's disk.
- Locally cached content (assistant conversation, form drafts) sits in the app's private, sandboxed storage protected by the device's own encryption, and is wiped on sign-out so it cannot surface for a different account on a shared device.
No system is perfectly secure. Use a device passcode, keep the OS and the app updated, and sign out on any shared device. If you believe your account has been compromised, tell your workspace administrator and email hello@simplegrid.ai immediately.
If you believe you have found a security vulnerability in SimpleGrid, please report it to hello@simplegrid.ai rather than disclosing it publicly.
9. Your rights
Depending on where you are, you may have the right to:
- access the personal data we hold about you and get a summary of how it is processed;
- correct or complete inaccurate data;
- have your data erased where there is no lawful basis to keep it;
- restrict or object to processing, and request data portability;
- withdraw consent where processing rests on consent (you can also revoke camera and photo-library permission at any time in your device's Settings — the app will simply stop offering those features, and you can decline analytics cookies on the marketing website);
- nominate another person to exercise your rights on your behalf if you die or become incapacitated (India, DPDP Act 2023);
- complain to a supervisory authority — in India, the Data Protection Board.
If you are in the European Economic Area (GDPR), the United Kingdom (UK GDPR), California (CPRA) or India (DPDP Act 2023), you may have additional rights, including opt-out of certain processing.
How to exercise them. Because your organisation controls the workspace data:
- Start with your workspace administrator. They can view, correct, deactivate and remove accounts and records directly, and this is almost always the fastest route.
- If you cannot reach them, or the request concerns Valaya AI itself, email hello@simplegrid.ai with your name, your workspace/company name, the email address on your account, and what you want done. We will acknowledge within 3 business days and respond substantively within 30 days, subject to verifying your identity. If you raise your request as a formal grievance under India's IT Rules, the shorter timelines in section 12 apply instead — acknowledgement within 24 hours and resolution within 15 days. For data we hold as a processor, we will pass the request to your organisation and act on their instruction; we will tell you when we have done so.
We will not charge you for a reasonable request, and we will not treat you differently for making one.
Account deletion. Accounts are provisioned by your organisation; there is no public sign-up and no in-app account-deletion flow. To have an account deleted, ask your workspace administrator, or email hello@simplegrid.ai.
10. Children
SimpleGrid is a workplace tool. It is not directed at children and we do not knowingly collect personal data from anyone under 18. Accounts are created by an organisation for its own personnel. If you believe a child's personal data has reached us, email hello@simplegrid.ai and we will delete it.
Note that a customer organisation may enter third parties' details into its own business records; responsibility for the lawfulness of that content rests with the organisation as controller.
11. Changes to this policy
If we change this policy, we will update the "Last updated" date at the top and publish the new version at the link shown on the app's store listings and in the app's Settings screen.
For changes that materially affect you — for example enabling crash reporting, or adding a new sub-processor that receives personal data — we will notify workspace administrators in advance, and where the law requires it we will ask for consent before the change takes effect.
12. Contact us
Valaya AI Technologies Private Limited
460, 6th Cross, JP Nagar III Phase
Bengaluru South, Bengaluru
Karnataka 560078, India
Email: hello@simplegrid.ai
For privacy questions, data requests, or complaints, write to hello@simplegrid.ai with "Privacy" in the subject line.
Grievance Officer (India, per the DPDP Act 2023 and the IT Rules):
Mukund Agarwal
Founder
Email: hello@simplegrid.ai, with "Grievance" in the subject line
We will acknowledge grievances within 24 hours and aim to resolve them within 15 days, as required by the IT Rules 2021.
If you are not satisfied with our response, you may complain to the Data Protection Board of India, or to your local supervisory authority if you are outside India.