Simansana

Privacy policy

Last updated 1 September 2026

Simansana is a platform for what people create, the relationships they belong to, and the things they hold together. Nearly all of that is somebody's personal life, so this page says plainly what we hold, why, and what happens to it. The platform is in Beta and grows in phases, so parts of this page describe things not everyone can reach yet — what we hold about you is only ever what the parts you use have collected. If anything is unclear, write to us at info@simansana.com.

Who we are

Simansana is a product of Goom Coom Ltd, a company registered in England and Wales (company number 09661684) with its registered office at 7c Hanham Hall, Whittucks Road, Hanham, Bristol, BS15 3FR. Goom Coom Ltd is the data controller for everything described on this page, and is registered with the Information Commissioner's Office under registration number ZC209454.

What we hold

  • Your account — the identifiers you sign in with (an email address, a telephone or WhatsApp number, and your username), your password (stored only as a cryptographic hash — we cannot read it), your second factor — a passkey for each device you add one on, a secret shared with your authenticator app, which we hold encrypted, or the channel you would rather have a code sent to — and your signed-in sessions, kept server-side while they last.
  • Your profile — the name you give, your date of birth, a username, a photograph if you add one, and anything you write about yourself.
  • What you put here — the files and folders in your vault, the albums you gather and the photos in them (including the date a camera recorded, where a photo carries one), your posts, your conversations and anything attached to them, and which messages you have read. The names you give things count too: a folder's name can say as much as what is in it.
  • Who you are connected to — invitations you send and receive, the people you connect with, the circles you belong to, and the occasions you organise or are invited to.
  • Your family trees — the people you place in a tree, how you say they are related, and the dates you record for them. Most of the people in a tree are not members here, and some have died; the section below is about them.
  • Your register — the assets and liabilities you record, any worth you state, the instructions you attach, where you say your will is held, and the dated packs you prepare — each of which is filed as a document into your own vault.
  • Care homes — if a care home is part of your life here: which home you are part of and in what role (resident, or on its staff), and the helper grants a resident makes and ends. Where a member of staff enters something at a resident's telling, the record carries who entered it.
  • Your handover — who you have named as an executor or as the person to carry on something you keep, what you have set down about who should receive what, and whether the people you named have agreed. If a death is reported to us, we hold the report, anything sent to us as evidence of it — a death certificate, for instance — and what was decided.
  • Your journey — a record over time of moments: what you have taken part in here, what a family tree records about you, and what you add to it yourself. It is meant to outlast you, because that is what passing something on means.
  • Payments — if you take out a membership, we hold what you paid and when, whether it succeeded, and a reference that identifies you to our payment processor. We never see or hold your card details; those are given straight to Stripe.
  • Messages you send to our WhatsApp number — if you write to us on WhatsApp we keep the message, the name your WhatsApp profile shares, and delivery records for what we send you.
  • A record of account activity — significant actions (signing in, sharing, changes to your account) are kept in an audit trail so that questions like "who shared this, and when?" can be answered honestly. Each entry records the IP address and browser it came from, because an honest answer to "was that me?" needs them. IP addresses are also read to slow repeated sign-in attempts, and once, when an account is created, to note the country it arrived from — some parts of the platform are offered country by country, and this is how yours is known (IP Geolocation by DB-IP).
  • What you send us and what we show you — feedback you write to us, and the notifications the platform has shown you.

Everything you upload is yours — a file in your vault, a photo in an album, something attached to a post or a message, a picture of yourself. We store it and serve it to the people and audiences you chose, and we do not read, mine or analyse any of it for any purpose of our own. The one exception is a safety one and it is done entirely by machine: uploads are scanned for malware before they can be served, and nothing about that scan is read by a person or used for anything else.

If you close your account we keep a small record of the closure itself for a while — that an account existed, the name and username it held, and when it closed. It is there so we can answer questions about what happened; the rest goes, though a removed account's username is kept so it can never come to mean somebody else. "How long we keep it" sets out the timings.

Information other people give us about you

Some of what we hold about you may not have come from you, and you may not have an account here at all. This is the honest position, because it is the part of the platform people are least likely to expect.

Somebody who uses Simansana may:

  • place you in a family tree, recording your name, your date of birth, your date of death if you have died, and how you are related to somebody else — including whether that relation is by birth, adoption, fostering, marriage or step;
  • name you as somebody an occasion is being held for, or put you on a guest list;
  • name you as an executor, or as the person they would like to carry on something they keep;
  • enter an email address or a telephone number for you so that an invitation can reach you;
  • where they run or staff a care home, enter your name and a contact detail to invite you — as a resident, or onto its staff;
  • record a business they want to reach about an occasion, with its contact details.

We hold it to run the platform for the person who entered it — so an invitation can be delivered, a tree can be drawn, an occasion can be organised. We do not use it to advertise to you, we do not sell it, and we do not build a profile of you from it. If you never take up an invitation, what was entered stays with the person who entered it, as their record, not as an account we have opened for you.

You have the same rights over it as anybody else, whether or not you are a member: you can ask what is held about you, ask for it to be corrected, ask for it to be removed, and object to it being held at all. Write to info@simansana.com and we will respond within a month. Where a record concerns someone who has died, write to us in the same way and we will treat it with the same care, alongside the wishes of the people it belongs to.

What we use it for

One thing: providing Simansana. Identifiers let you sign in and let the people who invited you find you; what you put here exists to be kept safe and shown only to the people and audiences you choose; messages we send — sign-in codes, invitations, notices — go to the contact details you verified; and a membership, if you take one, is billed. We do not sell personal data, we do not share it for advertising, and we do not profile you.

Who processes it for us

These providers handle data on our instructions, and only what their job requires:

  • Amazon Web Services — hosting, database and file storage, and the automatic messages the platform sends by email. Our infrastructure runs in London (eu-west-2), and uploads are scanned for malware by an Amazon service as they arrive.
  • Stripe — payments. Stripe receives your email address and a reference identifying your account, and it is Stripe, not us, that takes and holds your card details. Also subject to Stripe's own privacy policy.
  • Google — two separate things, and both are worth saying. The typefaces this site is set in are served by Google, so your IP address and browser reach Google whenever a page here loads, including this one. Separately, our own email is hosted on Google Workspace, so anything you write to info@simansana.com — including a request about your own data, and anything you attach to it — sits in a Google mailbox, as does any reply a person here writes back to you. The platform's automatic messages do not go through Google; they are sent by Amazon. Also subject to Google's privacy policy.
  • Meta (WhatsApp) — carries the WhatsApp messages we exchange with you. WhatsApp messages are also subject to WhatsApp's own privacy policy.
  • Sentry — error monitoring, so we learn about faults; reports are technical and not built from your content.
  • Anthropic — provides the AI assistance we use to operate and support the platform. It handles only what the task in hand requires — it does not handle the content you put here — and on terms that exclude its use for training Anthropic's models. Also subject to Anthropic's privacy policy.

Alerts about whether the service is up reach the people who run it through a channel Amazon operates, and a small amount of that monitoring sits on servers in the United States. It is about the platform's health — response times, error counts — and carries nothing about you.

How long we keep it

For as long as your account is open, because holding things over time is the point of the platform. When you close your account there is a 180-day window in which you can change your mind; after it, your content and profile are removed. The small closure record described above is kept for six years — the period within which a legal question about an account can still arrive — and entries in the audit trail are kept for one year from the action they record. An invitation stands — visible to whoever sent it, with the address it was sent to — until they withdraw it or it is answered, and withdrawing removes it at once; the one-time sign-in ticket it minted is destroyed 90 days after it can no longer be used. The raw notifications our payment provider sends us are kept for one year; the payment records themselves are accounting records, kept for the six years the law requires. If you write to us on WhatsApp, the raw record of what WhatsApp delivered — separate from the conversation itself — is kept for 90 days and then destroyed.

Deleting your data

You can close your account yourself, from your account settings, at any time. Closure ends access immediately and starts the removal described above. If you cannot sign in, write to info@simansana.com from a contact address on your account and we will do it for you.

Your rights

Under UK data protection law you can ask for a copy of the personal data we hold about you, ask us to correct it, ask us to delete it, and object to how it is handled. Write to info@simansana.com — which reaches a mailbox hosted by Google, as described above — or by post to Goom Coom Ltd at the registered office above, and we will respond within a month. If you are not satisfied, you can complain to the Information Commissioner's Office at ico.org.uk.

Cookies

Only the ones the site needs to work, and none of them follows you anywhere: the cookies that sign you in (including, only if you tick "remember me", one that lasts a week), one that remembers whether you chose the light or dark appearance so the page does not flash the wrong one while it loads, and the administrative console's own equivalents.

There are no advertising or analytics cookies here, ours or anyone else's, and there is no analytics service on this site at all.

Changes

The platform is in Beta and changes often, and this policy changes with it. The current version of this page is always the one that applies, and the date at the top is the date of the last change. Where a change matters we will do our best to tell you directly, but we cannot promise notice of every change before it takes effect.