Privacy Policy
Last updated: 22 September 2026
This policy explains what SimpliChat collects, why, and what we do with it. SimpliChat is its own company. The service is used by invited law firms. Those firms are the controllers of their client communications. We process that data to run the service they asked for.
What we collect
- Staff accounts. Email address, display name, language preference, and sign-in events.
- Messages. The text of inbound and outbound messages, timestamps, phone numbers, and any files the firm sends or receives through the service.
- Clio identifiers. Contact id and name, matter id and display number, and ids of notes we write, after the firm authorizes our Clio application.
- Technical logs. Request times, error messages, and enough context to operate the service. We do not put tokens or API keys in those logs.
What we do not collect
We do not sell personal information. We do not use firm or client data for advertising. We do not ask Clio for billing, documents, or the ability to create or delete matters.
Why we use it
- To match a sender to a Clio contact and show staff the right thread.
- To write the daily note the firm asked for.
- To send replies on the firm’s behalf when staff use the inbox.
- To keep the service secure and to fix faults.
Clio
When a firm connects Clio, they grant our application access to Contacts (write), Matters (read), and Users (read). We use that access to look up contacts and matters and to create notes. Tokens are stored for that firm only. The firm can revoke access in Clio at any time. Clio’s own privacy terms also apply to data that lives in Clio.
Who we share with
We share data with the processors needed to run the service: hosting, database, email delivery for login and optional firm digests, and the messaging provider the firm already uses. We share data with Clio when we look up a contact or write a note. We will share data if the law requires it. We do not sell it.
Retention
We keep message history so the inbox and filing can work. Notes written to Clio stay in Clio under the firm’s retention rules. If a firm leaves, we will delete or return operational copies on request, except records we must keep for security or law.
Security
Access to the application requires a firm seat. Clio tokens are stored as secrets. Staff see only their firm’s data. A duplicated note in a client record is worse than a late one; we will not automatically retry a write that may have already landed in Clio.
Children
The service is not directed at children under 13.
Your rights
Staff and firms can ask for a copy of the data we hold about them, ask us to correct it, or ask us to delete operational copies. Client requests about data in Clio should go to the firm. Contact hello@simplichat.co.
Changes
We may update this policy. The date at the top will change. Material changes will be sent to the firm contact we have on file.