Zimpley
Privacy Policy
This Privacy Policy explains how Zimpley collects, uses, stores, and protects information when you use our website, web app, Mac app, cloud services, and integrations.
Effective date: July 27, 2026
Who we are
Zimpley is developed and operated by ARTOSX LTD. ARTOSX LTD is registered in England and Wales under company number 16951018. Zimpley provides project management, finance, document, vault, agenda, and collaboration software for individuals and teams.
Contact: uk@artosx.com
Optional website analytics and cookies
Zimpley loads Google Tag Manager and the Google Analytics 4 tag with analytics, advertising, and personalization storage denied by default. In this cookieless mode, Google Analytics receives basic page-view and Mac download events together with limited consent and device signals, but it does not read or write analytics cookies. If you allow analytics cookies, Google Analytics can produce more accurate session and returning-visitor reports for zimpley.com and app.zimpley.com. Advertising storage, advertising user data, advertising personalization, and Google signals remain disabled.
Analytics may process page URLs, referrers, browser and device information, approximate region, and an analytics cookie identifier. Zimpley does not send names, email addresses, workspace content, finance records, documents, vault content, or precise location through these analytics events. Advertising signals and ad personalization are disabled in the Zimpley analytics configuration.
Your analytics choice is stored in a first-party cookie shared across Zimpley’s website and web app. You can change that choice at any time.
Information we collect
Depending on how you use Zimpley, we may collect the following categories of information:
- Account information, such as your name, email address, authentication provider, and account status.
- Workspace content you choose to create or upload, such as projects, tasks, notes, documents, finance records, vault records, reminders, and settings.
- Team and Enterprise information, such as company membership, project access, roles, permissions, and invited email addresses.
- Billing-related information, such as plan status, checkout references, and subscription status. Card details are processed by Stripe and are not stored by Zimpley.
- Technical information, such as device type, browser, IP address, request logs, security events, and error diagnostics needed to operate and protect the service.
AI clients, MCP, and agent data
Zimpley can connect your workspace to AI clients that support the Model Context Protocol (MCP), including clients such as ChatGPT, Codex, Claude, and Grok. You authorize the connection through Zimpley and choose the tools and workspace or project scope that the client may use.
When you enable an MCP connection, Zimpley may process:
- the AI client name and its registered OAuth redirect addresses;
- the tools, workspace, projects, and access level you approve;
- short-lived access tokens, grant status, revocation, and security events;
- tool inputs, outputs, approvals, agent runs, and audit history needed to complete and verify your request.
Zimpley does not send the passwords, API keys, refresh tokens, or other provider credentials stored in your Zimpley connections to an MCP client. The client receives only a scoped Zimpley access token. Information returned by a tool, and information you provide to the AI client, may also be processed under that AI provider's own terms and privacy policy. You should select only the tools and projects needed for your intended use.
Actions that create, send, publish, issue, or otherwise change data remain subject to the Zimpley approval controls shown for that connection. You can revoke an MCP connection from Zimpley to stop future access.
Google Calendar data
If you connect Google Calendar, Zimpley requests read-only access to Google Calendar events using thehttps://www.googleapis.com/auth/calendar.events.readonly scope.
Zimpley uses Google Calendar event data only to:
- show your calendar events inside your private Zimpley agenda;
- let you select events and create Zimpley tasks or reminders from them;
- help you connect calendar context with your own projects and daily planning.
Zimpley does not create, update, delete, or share Google Calendar events. Zimpley does not use Google user data for advertising, profiling, or training AI models. Zimpley's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
X account and public content data
If you connect an X account, Zimpley uses OAuth so you authorize access on X and never provide your X password or developer credentials to Zimpley. Depending on the permissions you select, Zimpley may process your X account ID, handle, display name, profile image, granted scopes, encrypted access and refresh tokens, and connection status.
Zimpley uses this access only to provide features you request, including:
- showing the connected X identity and connection health;
- retrieving limited public trends and public Posts for user-selected briefings and drafting context;
- creating private, AI-assisted Post or thread drafts with source and model attribution;
- sending opt-in briefings or approval requests through your selected Zimpley or Telegram destination;
- publishing the exact Post or thread you review and expressly approve to the selected X account.
Zimpley may store short-lived trend snapshots and limited public Post evidence, draft content, resulting Post IDs and URLs, delivery status, approval decisions, and security or audit records. Zimpley does not request X Direct Messages, use X Content for off-X advertising profiles, resell X data, or train foundation or frontier AI models on X Content. Data obtained with one person's X token is not exposed to another person.
You can disconnect X in Zimpley to stop future use of the stored connection. You can also revoke Zimpley from your X account settings. Public X Content that is deleted, restricted, or otherwise no longer available must be removed or updated in accordance with X requirements.
Instagram account data and deletion
If you connect an Instagram professional account, Zimpley uses Instagram's official OAuth flow. You authorize access on Instagram and never provide your Instagram password to Zimpley. Zimpley may process the connected professional account ID, username, display name, profile picture URL, granted permissions, encrypted access token, connection health, and the IDs and URLs of content you expressly approve for publishing.
Zimpley requests basic professional-account access to identify the account and content-publishing access only when you enable publishing features. It does not request access to Instagram ads, personal consumer accounts, private messages, contacts, or passwords. Zimpley uses connected Instagram data only to show the selected account, map it to your projects, prepare approval-first publishing actions, publish approved images, Reels, Stories, or carousels, and record delivery and security history.
You can disconnect Instagram in Zimpley at any time to revoke Zimpley-held credentials and stop future publishing. You can also remove Zimpley from your Instagram account settings. To request deletion of Instagram-derived identifiers, connection records, and publishing metadata that remain in Zimpley, email uk@artosx.com from your Zimpley account email. We may verify your identity before completing the request and may retain limited security, audit, or legal records where required by law.
How we use information
We use information to:
- provide, maintain, and improve Zimpley;
- authenticate users and protect accounts;
- sync user-selected content across devices when cloud sync is enabled;
- process subscriptions, invoices, and account administration;
- send service messages such as verification, security, billing, invite, or account emails;
- debug errors, prevent abuse, and keep the service secure;
- comply with legal, regulatory, tax, and accounting obligations.
How we share information
We do not sell your personal information. We share information only when needed to operate Zimpley, comply with the law, protect the service, or provide features you request.
- Service providers may process information for hosting, authentication, email delivery, logging, analytics, payment processing, and infrastructure operations.
- Stripe processes payment information according to Stripe's own terms and privacy policy.
- X processes account authorization, public content requests, and user-approved publishing according to X's own terms and privacy policy.
- Instagram processes professional-account authorization and user-approved publishing according to Meta's and Instagram's own terms and privacy policies.
- Telegram processes messages you choose to receive or send through a connected Telegram destination according to Telegram's own terms and privacy policy.
- Team or Enterprise workspace content may be visible to users who have been granted access by the workspace or project owner.
- We may disclose information if required by law or to protect Zimpley, users, or the public from fraud, abuse, or security threats.
Storage, security, and retention
Zimpley uses technical and organizational measures designed to protect user information. No online service can guarantee absolute security, but we work to limit access, protect credentials, and monitor abuse.
We keep information for as long as needed to provide the service, meet legal obligations, resolve disputes, enforce agreements, maintain backups, and protect security. You can request account or data assistance by contacting us.
Your choices and rights
You can update account information, disconnect integrations, remove content, or stop using cloud sync where those controls are available. You may contact us to request access, correction, deletion, or portability of personal information, subject to applicable law and security checks.
You can revoke Google access at any time from your Google Account permissions page. After revocation, Zimpley will no longer be able to refresh Google Calendar data.
You can disconnect X from Zimpley and revoke Zimpley from your X account settings. A pending Post approval can be rejected or allowed to expire without publishing.
You can disconnect Instagram from Zimpley and remove Zimpley from your Instagram account settings. Pending Instagram publishing approvals can be rejected or allowed to expire without publishing.
International processing
Zimpley may process information in countries other than your own. Where required, we rely on appropriate safeguards for international transfers.
Changes to this policy
We may update this Privacy Policy as Zimpley changes. If changes are material, we will take reasonable steps to notify users through the website, app, or account email.
Contact
Questions about this Privacy Policy can be sent to uk@artosx.com. Product and integration support is available at support@zimpley.com.