Skip to document
Simply Review
HomeData settings
Pilot draft · Operationally accurate for the current preview. Legal review and verified business contact details are required before launch.

Simply Review · Trust center

Privacy notice

Last updated July 29, 2026

A plain-language record of what Simply Review stores, how its Google connection works, and which launch details still require legal and operational approval.

In this document
Preview and account modesGoogle connectionHow data is usedSharing and saleRetention and deletionSecurityYour choicesBefore launch
RelatedTerms of use

What preview and account modes store

Simply Review’s public preview does not request a Google sign-in, import live reviews, publish replies, create a customer account, or send browser push notifications.

When you answer Business Brain questions or move through Guided Launch, those records are stored in this browser’s local storage. They stay on this browser unless you export or erase them from Settings. The installed app caches only its static offline safety screen and icons—not reviews, drafts, training answers, or approval decisions.

In account mode, Supabase stores the signed-in workspace, Business Brain answers, setup progress, selected Google listing metadata, imported reviews, drafts, approval and publication state, billing status, and safety audit events. Google refresh tokens are encrypted and kept in a server-only database schema.

Stored locallyTraining answers, added facts, setup progress
Account modeWorkspace-scoped records in Supabase
Not activeAdvertising, third-party analytics, push delivery

What the Google connection accesses

Account mode requests the Google Business Profile permission needed to list the profiles you manage, let you choose one location, read that location’s reviews, and submit only replies a permitted person explicitly approves. Simply Review never receives your Google password.

The owner or an administrator can revoke the Google grant from Settings. Simply Review then removes the encrypted refresh credential and marks the connection revoked. Imported reviews remain in the workspace until the account is deleted or the final retention policy requires their earlier removal.

How product data is intended to be used

  • Train the response manager on owner-verified business facts and policies.
  • Prepare review-response drafts and explain which verified sources support them.
  • Route sensitive reviews to the owner and require approval before publishing.
  • Record review, approval, edit, publishing, and safety events for accountability.
  • Deliver alerts the owner has chosen to enable.

Google user data will not be used for advertising, sold to data brokers, or used for an unrelated secondary purpose. Any material change would require an updated disclosure and renewed consent before the new use begins.

Sharing and sale

The public preview does not transmit its browser-local training records to Simply Review. Account mode currently relies on Vercel for application hosting, Supabase for authentication and database services, Stripe for billing, OpenAI for AI drafting, and Google for Business Profile access. The final legally reviewed subprocessor list and contractual details are not complete.

Simply Review is not designed to sell personal information or Google user data.

Retention, export, and deletion

In preview mode, data remains in this browser until you clear browser storage or use the reset control in Settings. You can download the same Simply Review preview records before erasing them.

In account mode, the owner can download a workspace export from Settings. A sole-owner account can be deleted only after any Stripe subscription is no longer active. The deletion flow first revokes Google access, then removes the workspace’s live database records and Supabase login in one protected database transaction.

Exact retention periods and the timetable for data to age out of infrastructure backups are not final. Those details remain launch blockers and must be published here before general registration opens.

Security approach

The product is being designed to minimize permissions, keep connection tokens out of browser code, encrypt sensitive data in transit and at rest, isolate each business workspace, and preserve an audit trail for public actions. Those controls require staging security and tenant-isolation testing before real customer data is accepted.

Your choices

  • Skip setup questions without publishing anything.
  • Download or erase the current browser preview from Settings.
  • Download account-mode workspace records from Settings.
  • Revoke Google access without deleting the account.
  • Delete an eligible sole-owner account after completing the typed confirmation.
  • Decline browser notification permission.
  • Withhold Google authorization or disconnect it later.
  • Review and approve every response before publication.

What must be completed before launch

The verified operator name, postal address, privacy contact, subprocessors, jurisdiction-specific rights, retention schedule, incident process, and effective date still require counsel and operational sign-off. Public registration and live Google access should remain disabled until that review is complete.

This design follows the transparency, minimum-permission, limited-use, and secure handling principles in the Google API Services User Data Policy and the FTC’s privacy and security guidance.