August 1, 2026

Privacy policy

This Privacy Policy explains how Simeon ("Simeon," "we," "us," or "our") collects, uses, discloses, and safeguards your information when you use our website (simeon.so) and our revenue aggregation service (the "Service").

By using Simeon, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the Service.

1. Who We Are

Simeon is a revenue aggregation platform that helps indie hackers, SaaS founders, content creators, and ecommerce sellers consolidate earnings from multiple payment and commerce platforms into a single dashboard.

Data Controller: Mohamed Diaby 'Moshymercy' Contact: heelo@simeon.so Location: France

2. How We Use Your Information

2.1 Information You Provide Directly

Account information: Email address (used for magic link authentication via Resend)

  • Manual entries: Any revenue data you manually input into the dashboard

  • Support communications: Information you share when contacting us for support

2.2 Information We Collect via Connected Providers

When you connect a third-party revenue provider to Simeon, we access and store data via their APIs, including:

  • Stripe: Transaction data, customer/payment metadata

  • Polar: Transaction and payout data (net amounts)

  • Shopify: Order and sales data (via Shopify API)

  • Gumroad: Sales and payout data (via OAuth)

  • Lemon Squeezy: Transaction data (via API token)

  • Paddle: Transaction data (via API, including sandbox/test data where applicable)

  • WooCommerce: Order and sales data (via store API credentials)

  • Patreon: Membership and pledge data (via OAuth)

  • Whop: Sales and membership data (via API)

This data typically includes: transaction amounts, currencies, dates, fees, customer identifiers (where provided by the platform), product/subscription references, and refund/dispute status.

We connect to these providers using API keys, OAuth tokens, or similar credentials that you provide and control. You may revoke this access at any time, either within Simeon or directly through the provider's platform.

2.3 Information Collected Automatically

  • Usage data: Pages visited, features used, actions taken within the dashboard

  • Device and log data: IP address, browser type, operating system, timestamps

  • Cookies and similar technologies: Used for authentication (session management) and, where applicable, basic analytics

2.4 Information We Do Not Collect

We do not integrate with banking services (e.g., Revolut, Wise) and do not access your bank account data. We do not collect payment card numbers directly — payment processing for your Simeon subscription is handled by our billing provider (see Section 4).

3. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain the Service (consolidating your revenue data into a dashboard)

  • Perform currency conversion and fee calculations

  • Generate AI-powered insights about your revenue (via the Anthropic Claude API)

  • Authenticate your account (magic link sign-in)

  • Send transactional emails (new payment, refund, or threshold-exceeded notifications)

  • Generate scheduled reports (e.g., monthly/annual summaries)

  • Monitor, secure, and improve the Service, including rate limiting to prevent abuse

  • Respond to support requests

  • Comply with legal obligations

We do not sell your personal data or your revenue data to third parties.

4. Third-Party Service Providers

We rely on the following categories of subprocessors to operate Simeon. Each processes data only as necessary to provide their respective service to us.

Hosting & infrastructure — Vercel. Application hosting and deployment.

Database — Neon (PostgreSQL). Storage of account and transaction data.

Caching / rate limiting — Upstash (Redis). Rate limiting, temporary caching.

Authentication email — Resend. Sending magic link and notification emails.

Billing — Polar. Subscription billing and payment processing for Simeon plans.

Revenue data sources — Stripe, Polar, Shopify, Gumroad, Lemon Squeezy, Paddle, WooCommerce, Patreon, Whop. Providing your connected transaction data.

Currency conversion — open.er-api.com. Real-time exchange rate data.

AI insights — Anthropic (Claude API). Generating revenue insights from your data.

DDoS protection — Cloudflare. Network security.

Each of these providers has its own privacy policy governing how they handle data on our behalf. We select providers that maintain appropriate technical and organizational security measures.

5. Data Sharing and Disclosure

We do not share your personal or revenue data with third parties except:

  • With the subprocessors listed in Section 4, strictly to operate the Service

  • If required by law, subpoena, or other legal process

  • To protect the rights, property, or safety of Simeon, our users, or others

  • In connection with a merger, acquisition, or sale of assets (you will be notified before your data becomes subject to a different privacy policy)

  • With your explicit consent

6. Data Retention

We retain your account and transaction data for as long as your account is active. If you delete your account:

  • Your personal account information is deleted or anonymized within 24 hours

  • Cached or synced transaction data from connected providers is deleted within 2 weeks

  • We may retain certain data longer where required for legal, tax, or accounting obligations, or to resolve disputes

You can request deletion of your data at any time (see Section 9).

7. Data Security

We implement technical and organizational measures to protect your data, including:

  • Encrypted connections (HTTPS/TLS) for all data in transit

  • Short-lived authentication tokens (magic links expire after 10 minutes)

  • Rate limiting on authentication and data export endpoints

  • Input validation on all API routes

  • Restricted access to production environment variables and credentials

  • Regular dependency vulnerability monitoring (Dependabot)

  • Branch protection on our source code repository

No method of transmission or storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.

8. International Data Transfers

Your data may be processed in countries other than your own, including the United States and the European Union, depending on where our subprocessors operate. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) to ensure your data remains protected in accordance with this policy.

9. Your Rights

Depending on your location (e.g., EU/EEA under GDPR, California under CCPA/CPRA, or other applicable law), you may have the right to:

  • Access the personal data we hold about you

  • Correct inaccurate data

  • Delete your data ("right to be forgotten")

  • Export your data in a portable format (CSV export is available directly in-app)

  • Restrict or object to certain processing

  • Withdraw consent at any time, where processing is based on consent

  • Lodge a complaint with your local data protection authority

To exercise any of these rights, contact us at hello@simeon.sh. We will respond within the timeframe required by applicable law.

10. Your Connected Provider Credentials

When you connect a revenue provider (e.g., Stripe, Shopify, Gumroad), you are responsible for the credentials (API keys, OAuth tokens) you provide. We store these credentials securely and use them solely to fetch your revenue data on your behalf. You can disconnect a provider at any time within Simeon, which will revoke our access going forward.

We recommend using API keys or tokens with the minimum necessary permissions (read-only access) where your provider supports this.

11. Cookies

We use cookies for:

  • Essential/session cookies: To keep you logged in and maintain security (e.g., authentication state)

  • Preference cookies: To remember dashboard settings, where applicable

We do not use third-party advertising cookies. You can control cookies through your browser settings, though disabling essential cookies may prevent you from using the Service.

12. Children's Privacy

Simeon is not directed at individuals under the age of 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us so we can delete it.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email or a notice on the Service prior to the change taking effect. The "Last updated" date at the top of this page reflects the most recent revision.

14. Contact Us

If you have questions about this Privacy Policy or how we handle your data, contact us at:

Email:hello@simeon.sh Website:simeon.sh