Privacy
What we collect, and where it goes.
Written to be read. Last updated August 14, 2026.
What we collect
01
Only what you type into a form: your name, your work email, and, if you choose to give them, a phone number, a company name, and an idle-cash band. Each submission is stored with the time it arrived and which form it came from.
When you enter your name and email to see a report, or ask for a placement session, the submission carries a small snapshot of the report you were looking at (currency, totals, idle amount, annual drag) so our reply can start from your numbers.
Creating an account collects your email address and a password.
When you search for your company in the account-opening flow, the name you type goes through our server to Canada's public business registries, and what comes back is what those registries publish about your corporation. We cache registry answers briefly and don't store your searches. If you give us your website address to draft the business description, our server reads that page once and keeps nothing.
What stays in your browser
02
The balances and burn you enter for the report are saved in your browser's local storage so you don't retype them. They reach us only when you submit a form.
If you enter your email to see a report, it is also kept in a cookie for a week so the signup form can fill it in for you. Only the email, never your balances.
The account application works the same way: your answers save in your browser as you go and reach us only when you press submit. Signing out clears them from the browser.
Signing in sets two cookies, each lasting up to 30 days: st-access and st-refresh carry your session, they can't be read by scripts on the page, and they work only on app.simpletreasury.ai, where the signed-in product lives. No other part of the site can read them, and nothing about your session is stored on this one. Signing out clears both. There are no analytics, no ad trackers, and no third-party scripts.
Where submissions go
03
Simple Treasury is run by Migie Labs Inc. That's who holds the data described on this page.
Each submission is written server-side to our database, hosted with Supabase, and recorded in our server logs so a database outage can't lose it. Database credentials never reach your browser.
Accounts are handled by Supabase's authentication service. Your password goes there when you sign up or sign in, and we never store it ourselves. Asking for a password reset never reveals whether an email has an account.
Submitting an account application stores a record of it with us: your company's registry identity (legal name, numbers, jurisdiction), your email, and the application's status. The record is written under your own account, and the database is set up so you can write your application and nobody can read the table from the browser. The directors and owners you confirm in the flow stay out of that stored record. When account opening runs through a banking provider, the application's company details go to that provider to open the account, and this page will name the provider before that's live for customers.
Phone numbers and consent
04
The phone field is optional. Beside it sits a consent box that is never pre-ticked. We store your answer exactly as you gave it, and we only call or text if you ticked the box. That's your express consent under CASL, and you can withdraw it by telling us.
05
Replies to anything you submit are personal. The only automated emails are for your account: a link to confirm your address when you sign up, if confirmation is needed, and a reset link when you ask for one. Joining the design partner list gets you one email when we open a spot. No sequence, no newsletter.
What we don't do
06
We don't sell your information and we don't pass it to advertisers. It goes nowhere beyond the storage described above.
If you want your details deleted, write to hello@simpletreasury.ai and we’ll delete them. Questions about your data go to the same address.