Privacy
What we collect, why we have it, who else sees it, and how to make us delete it.
Last updated 27 August 2026.
Who we are
admin made simple is a trading name of admin made simple Pty Ltd, a private company (Pty) Ltd registered in South Africa with registration number 2022/835591/07.
Our registered address, and the address at which legal documents may be served, is 10 Remhoogte Road, Somerset West, 7130, South Africa.
You can reach us on +27 76 439 8222, or at michael@adminmadesimple.co.za — we answer email within two working days.
We are not registered for VAT, so no VAT is charged on anything we sell and none of our prices contain a VAT component.
The short version
We collect the least we can get away with. We do not sell anything about you to anyone, we do not run advertising, and we do not build a profile of you across other websites.
There is no tracking on this site at all — no analytics script, no advertising pixel, no third-party tag of any kind. Nobody is watching you use it.
Everything below is a plain description of what the software actually does. If something here is unclear, write to michael@adminmadesimple.co.za and we will explain it in as much detail as you want.
What we collect
Only what the product needs to work:
- Your email address and display name, when you make an account. If you start without one, we hold an anonymous identifier and nothing else.
- A phone number, if you sign in with one or give us one so the product can message you.
- The descriptions you write or speak when you ask us to build something, and the conversations you have with the assistant, so you can come back to them.
- Any spreadsheet you upload, and the rows inside it. Any document or photo you ask us to read, though not the file itself — see below.
- Anything an app you use saves: the records it writes, and any photo, video or file it stores.
- Data from a service you explicitly connect, such as Health Connect, Strava or Google Drive — only after you approve it, and only the categories shown on the connection screen.
- Bank details, if you set your organisation up to be paid through the platform. The account number goes straight to our payment provider, who verify it; we keep the bank's name and the last four digits so you can tell which account it is.
- A record of what you used and when, so we can bill accurately and so you can see where your usage went.
Voice notes and your microphone
The app can record you describing what you want, so you do not have to type it.
The microphone is only ever switched on while you are holding or have tapped the record button, and the app shows a running timer the whole time it is listening. Nothing is recorded in the background, and nothing is recorded when the app is not open.
While you talk, short pieces of the recording are sent to a speech-to-text service and come back as words in the box, so you can see and edit them as you go. We do not keep the audio: it is not saved to your device, not written to our database, and not retained after the request finishes. We do not use it to train anything.
You never have to use it. Typing does exactly the same job, and declining the microphone permission leaves the rest of the app working normally.
When an organisation holds your information here
Schools, body corporates and businesses use this platform to run their own affairs, and what they put in is mostly about the people they serve. If a school holds your child's marks here, or a managing agent holds your levy account, that information is theirs and not ours.
The law splits those two roles and the split decides who you deal with. They are the responsible party: they decided to collect it, they choose who in their organisation may see it, and they answer to you for it. We are the operator: we hold it for them and act only on their instructions. So a request to see, correct or delete what is held about you goes to them, not to us — ask the school, the agent or the business directly, and we will act on whatever they tell us. Write to us as well if you cannot get anywhere; we will not decide it for them, but we will not ignore you either.
What we guarantee for our part: it is never used for anything but running that organisation's own workspace, it is never sold or handed to anybody, and it never reaches another organisation on this platform. That last one is not a policy, it is how the software is built — one rule in one place decides every read, and an organisation is the boundary it draws.
If they give you a sign-in of your own — a portal, where you see your own account rather than everybody's — we hold your email address and the one detail that says which rows are yours, and the filtering happens on our server before anything reaches your phone. You see your own and nobody else's, and no other client of theirs can see yours.
Exam entries
If you enter for an examination through a school using this platform, we hold what the examination board requires: the candidate's full name, date of birth, identity or passport number, contact details, the subjects entered, and — where given — a parent's contact details.
The centre also asks for documents, and we store what you upload: a birth certificate or ID, a photo for the identity card, the signed exam agreement, and proof of payment where the centre takes it outside the platform. If the candidate has an access arrangement — extra time, or a separate room — the centre must hold a psychologist's or doctor's report to support it. That is health information, which the law treats as more sensitive than the rest, and it is held for that one purpose: the examination board will not grant the arrangement without it.
Once the board confirms the entries we hold what it sends back — the candidate number, the confirmed subjects, the timetable that follows from them — and, at the end, the results. Results are imported before they may be released, so there is a period where the centre can see a grade and the candidate cannot; that is the board's rule, not ours.
This information belongs to the examination centre, not to us. We store it on their behalf so they can submit entries and contact you. Only staff at that centre can see it. No other school, and no other part of this platform, has any access to it.
The fee is the centre's money and never ours. The payment runs through our payment provider so that it settles straight into the centre's own bank account — we process it and never hold it, and we never see or store card details.
If the candidate is under 18, a parent or guardian should complete the entry. Ask the centre to correct or delete anything held about you — they control it, and we act on their instruction.
Accounts you connect
If you connect an account of your own — Google Drive, for example — we use a service called Nango to handle the sign-in. Nango holds the access token on your behalf; we never see your password and never store a credential for your account.
Connecting is personal by default. Only you can see the files it brings in and build on them. Letting colleagues use them is a separate switch you have to move yourself.
We copy in spreadsheet-shaped files so your apps can use them. Nothing else is read — documents, photos and anything that is not a table are skipped.
Disconnect and it is gone immediately. The connection is removed and every file we copied in is deleted straight away, along with anything built on it. There is no grace period and no archived copy.
Health and fitness data
You can bring in your own health data two ways, and both start with you. In the Android app, connecting Health Connect reads steps, distance, heart rate, sleep, calories and workouts from your phone — the phone shows you exactly what is asked for, and agreeing there is your consent. Connecting Strava brings in your activities.
Health information is special personal information under South African law, so to be plain about what we hold: the readings you bring in are stored as rows in the app you chose, marked as yours. Only you can see rows brought in from Strava — sharing them is not allowed by Strava's rules, and we do not offer it. Health Connect rows follow the app they landed in.
If you ask questions in an app that holds your health rows, a sample of those rows goes to the AI provider, the same way any other records do. Strava rows are the exception: they are never sent to the AI at all, whoever asks.
Stop whenever you like. Disconnecting Health Connect stops new readings (the phone's own permission is yours to revoke in its settings); disconnecting Strava removes what it brought in. Rows already inside an app are that app's data and are deleted with it.
Photos, files and anything an app saves
An app built here can save records and can store files — a photo of a delivery, a signed form, a short video. The records go in our database; the files go into storage run by Google Firebase, in the same account as everything else.
A stored file gets a link with an unguessable code in it. That means the link works for anybody you send it to, exactly like a shared photo link anywhere else — so treat it as you would any link to something private. Nobody can find the file by guessing, and deleting the app deletes every file it stored, immediately.
Rows an app saves are stamped with who saved them and when, because "who did what" is usually the question a business is asking. In an app you use inside your own workspace, that stamp is your email address.
Documents you ask us to read
You can hand us a PDF or a photo of a page — an invoice, a delivery note, a form somebody filled in by hand — and ask for the numbers off it. The file is sent to the AI to be read, and this is the one thing the country choice does not move: only the American provider can accept a file at all, so if you have chosen the other one, reading a document is simply not available to you.
We do not keep the file. What is stored is its name and the rows the AI proposed, and those rows sit in a review list until a person ticks the ones that are right. Nothing goes into your data because a machine suggested it.
Playing or joining from a link
Some apps can be opened by a link, with no account — a team playing a game, for instance. Tapping the link creates an anonymous identity for that phone, and we hold that plus whatever name you type for yourself or your team.
Everything you save in an app like that is visible to the other people in it, which is usually the point: a scoreboard is no use if it only shows you. It also belongs to the organisation that opened the link, and they can delete it. Do not put anything in one you would not put on a noticeboard.
Sharing an app with other people
If you share an app you made, what travels is the app itself — the thing you built — and never the information inside it. An app that reads your organisation's data cannot be shared at all; the software refuses, because those records mean nothing outside your organisation and would be the one thing worth stealing.
Being named is a separate decision from sharing. You are asked once, at the moment of publishing, what to call yourself; leave it blank and the app is published anonymously. Whatever you type there is public, so use the name you would put on a poster.
Somebody who copies your app can offer their improvements back to you. Neither of you learns who the other is: they see nothing about you, you see a list of changes and no name, and there is no way to reply beyond accepting or declining.
If you sell an app, we record the purchase — who bought it, when, and the payment reference — because both of you may need to prove it later. The money settles to your own bank account through our payment provider; we take our share at the moment of sale and never hold the rest.
Which country the AI runs in
The AI that builds your apps and answers your questions runs on servers in another country, and you choose which. America is the default. Where a second country is offered, the option appears when you sign in and again beside the box you type in, and you can change it whenever you like.
What is sent depends on what you are doing. When you type anything into the assistant — asking it to build something, or simply asking it a question — it receives what you type and the names of your data sources and apps, not the information inside them. The names are sent so that a question phrased in your own words can be recognised as a question about your records. For a spreadsheet you uploaded, the name we hold includes its column headings, so those are sent too. If you attach a file to the conversation, the first rows of it are sent as well — up to 40 of them — because looking at the file is what you attached it for. A picture you paste or attach — a screenshot of something you want built or changed, a photo — is sent whole, because looking at it is what it was pasted for. Nothing else in your workspace sends its rows while you are simply talking.
The assistant also answers ordinary questions — the news, a price, how something works — and looks them up on the web when the answer depends on something current. When it does, the words of that question go to a search engine through the AI provider. Nothing from your own data, apps or records goes with it.
When you ask a question about your records, a sample of those records is sent, because that is what the answer is drawn from — at most 200 rows from each of up to four sources. If your app saves its own records, those can include the email address of whoever saved each one, since questions are often about who did what.
Your choice moves both of those. Whichever country you pick, the same rules apply: nothing is sent from another organisation, the provider is not permitted to use your data for its own purposes, and we do not send your password or card details anywhere.
Voice notes are handled by a separate provider and are not affected by this choice. Recordings are never kept.
If you work inside an organisation, its administrator can switch a country off for everybody in it. When that happens your own preference is kept, and used again if it is ever switched back on.
Who else sees your data
We use a small number of specialist providers. Each one sees only the part it needs to do its job, and none of them are permitted to use your data for their own purposes:
- Google Firebase — accounts, sign-in and the database everything is stored in.
- Nango — handles signing in to accounts you connect, and holds that access token on your behalf.
- Anthropic (United States) — the AI that turns your description into a working app. It receives your description and a sample of the data the app needs. This is the default.
- An AI provider in China — used INSTEAD of the above, and only if you choose it. It then receives exactly what Anthropic would have. See "Which country the AI runs in".
- Anthropic again, if the organisation you deal with has switched on asking questions in their client portal. When you ask one, the rows you can already see are sent so it can answer. Only your own rows are sent — never another client's.
- A speech-to-text provider — receives a voice recording, returns words, keeps nothing.
- Paystack and PayFast — payments. They handle card details directly; we never see or store a card number. Where an organisation sells through an app it built here, Paystack settles that money to the organisation's own bank account — we process the sale but never hold their money.
- Resend and Meta (WhatsApp) — only if you use the messaging features to send something. Email is handled by Resend on servers in Ireland, so a message we send for you leaves South Africa on its way.
- Messages you send TO an organisation on this platform — a WhatsApp reply, or an email to their receiving address — are stored for that organisation to read and act on. Replies to messages marked "notifications only" are not stored; you are told so at the time.
- Garmin — only if you connect it, and only in the direction of reading your own data.
- Brave Search — if an app you use looks something up on the web. It receives the words of that search and nothing else about you.
- YouTube — if an app follows a channel or reads what was said in a video. It receives the channel or video, not anything of yours.
- A website an app names — an app can ask our servers to read a public page for you. The request comes from us, not from your browser, and carries nothing of yours with it.
- Vercel — the hosting this website and its servers run on. Like any host, it keeps short-lived request logs, which include the network address a request came from.
- A domain registrar — only if you buy a web address. We register it, so OUR contact details are the public record for it and not yours.
Where your data lives
Our database, our file storage and our servers are hosted outside South Africa — the database and storage with Google Firebase, the servers with Vercel — and the providers listed above process data in various countries. This means your information crosses borders.
POPIA allows this where the receiving party is bound by comparable protection. Each provider above is contractually committed to that standard, and we do not use a provider that will not commit to it.
The one you get to decide is the AI, because it is the one that reads what you write. That choice is yours and is described above.
How we keep it safe
Four things are built in rather than promised:
- One rule, in one place, decides who may read anything. There is no second copy of it to drift out of step, and an organisation is a wall the software cannot see across.
- An app built here runs sealed off in your browser: it has no sign-in token, no way to reach the internet on its own, and no way to read anything except what it asked for and you are allowed to see.
- Nothing in the browser can write to our database directly. Every change goes through our servers, which check who is asking, every time.
- Passwords and account keys are never stored where the product can read them, and never on any record the browser is sent.
Cookies, and what is kept in your browser
There is no cookie banner here because there is nothing to ask you about: we set no advertising cookies and no analytics cookies, and no third party sets one through this site. Signing in with Google happens on Google's own page, under their terms, and then you come back.
Two things are kept in your browser's own storage, and both are for you rather than about you: your sign-in, so you are not asked again every time, and an unpublished draft of an app you are working on, which stays on that device until you publish it.
A web address of an organisation's own is a separate address as far as your browser is concerned, so crossing to one gives you a sign-in there as well. It is carried over by a one-time code in the link, which lasts sixty seconds and works once.
Clearing your browser's storage signs you out and discards any unpublished draft on that device. Nothing else is lost.
How long we keep it
Your account and the things you have built stay until you ask us to delete them. Delete an app and its records and files go with it immediately, along with every earlier version of it — there is no archived copy anywhere.
Usage records are kept for seven years, because tax law requires it of anything that touches an invoice. Records of a payment are kept for the same reason and the same period.
Exam entries and the documents uploaded with them are kept by the examination centre for as long as they need them for certification and appeals — usually several years, because a certificate can be queried long after the exam.
A message waiting to be sent is given a week — or a day, if it is one that asks you something on a schedule — and then dropped, because a reminder about last Tuesday is worse than silence. Notifications are cleared after thirty days.
When something goes wrong we keep a technical note of it — what failed, where, and how often. It carries no rows of anybody's data.
Voice recordings are the exception and are kept for no time at all — see above.
Your rights
Under POPIA you may ask us what we hold about you, ask us to correct it, and ask us to delete it. You can also object to us processing it, and complain to the Information Regulator of South Africa if you think we have got it wrong.
Our information officer is the director of admin made simple Pty Ltd, and the address for any of this is michael@adminmadesimple.co.za or +27 76 439 8222. We will answer within 30 days, and usually within two working days.
If what is held about you was put here by a school, a business or a managing agent, ask them first — see "When an organisation holds your information here". They decide, and we act on their instruction. Tell us anyway if you get nowhere.
The Information Regulator can be reached at inforegulator.org.za, and POPIA complaints go to POPIAComplaints@inforegulator.org.za. You do not have to come to us first, though we would rather you did.
Children
This is a business tool and is not aimed at children. We do not knowingly collect information from anyone under 18. If you believe a child has given us information, tell us and we will remove it.
Changes
When this policy changes, the date at the top moves with it, and the current version is always the one at this address. Check the date when you come back.
Questions about any of this: michael@adminmadesimple.co.za