Privacy Policy

What personal data SimpliGen collects, why, who processes it, and the rights you have over it.

Last updated 1 August 2026

1. Who is responsible for your data

The data controller is SimpliGen, a trade name of Raynold Franklin van Heyningen, based in Rotterdam, Netherlands, registered with the Netherlands Chamber of Commerce under KvK 94598924. Our registered postal address is held by the Chamber of Commerce and is available on request.

For anything about your personal data, including a request to exercise the rights in section 7, email hello@simpligen.io. We are a small business and we answer these ourselves.

2. The short version

We collect as little as we can get away with. Local generation is genuinely local: your prompts and the images and video you make never reach us. We hold your email address so your licence works, a machine fingerprint so licences cannot be shared without limit, and records of cloud generations you paid for. We do not sell personal data and we do not use your content to train models.

3. What we collect and why

  • Email address. Needed to issue and recover your licence and to contact you about your purchase. Legal basis: performance of our contract with you.
  • Licence key and activation records, including a machine fingerprint and the IP address seen at activation. Used to enforce the two-machine activation limit and to detect key sharing. Legal basis: performance of the contract and our legitimate interest in preventing licence abuse.
  • Purchase records, including what you bought, when, and the amount. Legal basis: performance of the contract and our legal obligation to keep business records.
  • Cloud generation records, including which preset was used, the cost in credits, timings and status. Used to bill correctly, refund failures and diagnose problems. Legal basis: performance of the contract.
  • Prompts, reference files and generated output, but only when you choose to run a generation in the cloud. Legal basis: performance of the contract. These are deleted on a rolling 24 hour cycle.
  • Error and crash reports, which may include a stack trace, application version, operating system and GPU details. Used to fix bugs. Legal basis: legitimate interest in a working product.
  • Anonymous performance telemetry from local generations, keyed to a random install identifier rather than to you. Used to understand which hardware struggles with which models.
  • Website analytics, and advertising measurement on campaign landing pages. Legal basis: your consent, which we ask for before any of it loads and which you can withdraw at any time.

4. What we do not collect

We never see your card details. Payment is handled entirely by our payment providers. We receive confirmation that a payment succeeded, the amount, and the email you used.

We do not receive your prompts or your generated images and video when you generate locally on your own computer, which is how most SimpliGen usage works. There is no mechanism in the application that transmits them.

5. Who else processes your data

We use a small number of service providers. Each processes data on our instructions only.

  • Vercel: website and API hosting.
  • Neon: the Postgres database holding accounts, licences and job records.
  • Cloudflare R2: temporary storage of cloud generation outputs.
  • Modal: the GPU infrastructure that runs cloud generations.
  • Resend: transactional email, such as login links.
  • Sentry: error and crash reporting.
  • Google Analytics: website traffic measurement. Loaded only if you accept analytics cookies.
  • Meta, TikTok and Google Ads: advertising measurement on campaign landing pages. Loaded only if you accept marketing cookies.
  • Gumroad: payment processing for licences, as merchant of record for those purchases.
  • Stripe: payment processing for cloud credits, which we sell ourselves. Stripe also calculates the VAT on those purchases.

6. Transfers outside the EEA

Some of the providers above are established in the United States. Where personal data is transferred outside the European Economic Area, the transfer is covered by the European Commission's Standard Contractual Clauses or by an adequacy decision.

7. How long we keep things

  • Cloud generation outputs: deleted automatically on a rolling 24 hour cycle.
  • Account, licence and activation records: for as long as your licence is active, then up to two years, so we can help if you reinstall or lose a key.
  • Purchase and financial records: seven years, which is the retention period Dutch tax law requires.
  • Error reports: up to 90 days.

8. Your rights

Under the GDPR you have the right to access the personal data we hold about you, to have it corrected, to have it erased, to restrict or object to how we use it, and to receive it in a portable format. Where we rely on consent, you can withdraw it at any time.

To exercise any of these, email hello@simpligen.io. We will respond within one month.

Erasure has one limit worth knowing: we cannot delete records we are legally required to keep, in particular the financial records covered by the seven year tax retention period.

If you think we have handled your data badly, please tell us first so we can put it right. You also have the right to complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens, at autoriteitpersoonsgegevens.nl, or to the authority in your own country.

9. Cookies and analytics

Nothing that tracks you loads on this website until you agree to it. When you first visit you are asked to choose, and until you do, no analytics or advertising script is loaded at all. Rejecting is one click and is offered as prominently as accepting.

You can change your mind at any time using the Cookie settings link in the footer of any page. Withdrawing is as easy as consenting, and takes effect immediately.

We use Google Analytics to understand how many people visit and which pages they read. On campaign landing pages we may also use advertising pixels from Meta, TikTok or Google Ads to measure which ads brought visitors here. Both categories are off unless you turn them on. We do not sell personal data and we do not use these tools to build profiles of individuals.

The desktop application does not use cookies.

CookieCategoryPurposeExpires
sg_consentStrictly necessaryRemembers the cookie choice you made here, so you are not asked again on every page.6 months
_ga, _ga_<id>AnalyticsGoogle Analytics. Distinguishes one visitor from another so visit counts are not wildly wrong. Set only if you accept analytics.2 years
_fbpMarketingMeta advertising pixel on campaign landing pages, used to measure which ads led to a purchase. Set only if you accept marketing.3 months
_ttpMarketingTikTok advertising pixel on campaign landing pages, same purpose. Set only if you accept marketing.13 months
_gcl_auMarketingGoogle Ads conversion measurement on campaign landing pages. Set only if you accept marketing.3 months

10. How we record your cookie choice

When you choose, we store a record of what you chose, when, and which version of this policy you were shown. That record is kept so we can demonstrate that consent was given, which the GDPR requires of us. It is not linked to your account and contains no IP address. If we materially change what the categories cover, the stored choice is retired and you are asked again rather than us relying on an answer to a different question.

11. Children

SimpliGen is not for anyone under 18. We do not knowingly collect personal data from children. If you believe a minor has bought a licence, contact us and we will cancel it and delete the data.

12. Changes

If we change this policy materially we will update the date at the top and, where the change affects how we use data you have already given us, tell you by email.