Privacy policy

Effective 10 October 2026

This policy explains what information the Simaya app, its service and this website use, why, who receives it and what you can ask of us.

Who we are

Simaya is provided by Esperanes LTD, company number 517155115, 144 Menachem Begin Road, Tel Aviv, Israel ("we"). We are responsible for the information described here. Contact us at hello@simaya.app.

The short version

  • Signing in is optional. You can buy and use an eSIM without an account. With one, your orders, credit and settings follow you to another iPhone.
  • You pay with your Apple Account through the App Store, and we never see your card or bank details.
  • Our eSIM supplier receives our order number and the plan, never your name or contact details.
  • No advertising, no tracking across other companies' apps or websites, no analytics tools, and we don't sell your information.

What we collect and why

A random device code

The first time the app needs our server, it creates a random code and keeps it in your iPhone's Keychain. The app sends it with each request to our server, which stores only a one way hash of it. It lets us show your orders and deliver your eSIM to you and nobody else. It is not your name, your phone number, your Apple Account or an identifier assigned by Apple. iOS may keep it in the Keychain after you delete the app.

If you sign in

You can sign in with Apple, with Google, or with a code we send to your email address. If you do, we keep:

  • your email address and name, as you or the sign in service share them. With Sign in with Apple you can hide your email address, and we then receive an Apple relay address instead;
  • an identifier from Apple or Google that links the sign in to your account. We never receive your password;
  • your signed in sessions, with the time and the iPhone model (such as "iPhone 16 Pro"), so you can see and end them;
  • the orders of the iPhones you link to your account, with encrypted codes that restore their eSIMs on another iPhone;
  • your trip start dates and notification choices, so they follow you to another iPhone;
  • your credit, your referral code and the referrals described below;
  • a security log of sign ins, linked devices, exports and deletion.

We use this to run your account, keep it secure and give you your orders and credit on each iPhone. A code sent by email is valid for 10 minutes and is deleted within a day after it expires.

Credit and referrals

If you have an account, we keep a record of the credit you earn, hold, use, get back or lose, with the amount, the order it relates to and the dates, and the amount you have spent, which we use to calculate credit. When someone uses your referral code, we record that link between the two accounts. We use these records to run the program and to prevent abuse, such as one person claiming the same reward with several accounts or devices. The person who invited you sees only how many friends joined with their code, not your name, email address or orders.

When you share your code, you choose the app and the people you send it to. We don't access your contacts.

When you check a price and buy

  • Quotes. When you open the checkout for a plan, our server records the plan, its price, any promotional code or credit applied, the App Store country of your Apple Account and the time, under your device code and, if you are signed in, your account.
  • Orders. The plan and destination, the price, the order reference (starting with EL), the order's status and its dates (paid, delivered, refunded).
  • From Apple. After you pay, Apple gives the app a signed record of the purchase, and our server verifies it. We keep the transaction identifiers, the product, the App Store country, the price and currency, the purchase date, whether it was a real or a test purchase, and any refund or cancellation Apple later reports to us. A random purchase token links that payment to your order.
  • Apple does not give us your card details or billing address.

Your eSIM

To create your eSIM, we order it from our eSIM supplier and send only our order number and the plan, never your name or contact details. The supplier returns identifiers for the eSIM, which we keep with your order. When you open My eSIMs, our server asks the supplier for the eSIM's current status, the data used and the end date, and passes them to the app. Our server keeps the supplier's latest report of the data used, with the time it was reported, so the app can still show it when the supplier can't report. The app keeps the latest copy on your iPhone so you can see it offline. Installation details are fetched only when you tap Install and are handed to Apple's installation; the app does not save them.

While you use the eSIM, the mobile networks in your destination and our supplier process connection data, such as the network used and the data consumed, as any mobile operator does and under their own obligations. We don't receive your location from them.

When you contact us

If you write to us by email or with the contact form in the app, we receive your email address, your name if you include it and what you write. The form sends your message through our server to our support inbox, with your email address so we can reply; our server doesn't keep a copy, and we don't email you automatically. A message about an order also includes the order's support reference and status. Unless you turn off "Include app and iPhone details", the form also sends the app version, your iPhone model and iOS version and the app's language; an email you start from the app's Help center includes the same details, which you can delete before sending. We use this to answer you and keep a record of the conversation. Please never send activation codes, QR codes or payment details.

Technical information

Our server and this website run on Cloudflare. Requests reach them with your IP address and basic technical details, such as the time and the address requested. Cloudflare uses them to deliver requests and protect the service. Our server uses your IP address for a short time to limit repeated requests and does not store it in our database. Our server's request logs are kept for up to 7 days to fix problems. We don't use them to identify you. This website sets no cookies and runs no analytics or advertising scripts.

What stays on your iPhone

Destination searches, recently viewed destinations, the labels you give your eSIM lines, the reminders iOS schedules and the latest copy of your eSIM's status stay on your iPhone. Trip start dates and reminder choices also stay on your iPhone, unless you sign in, in which case they are kept in your account as well. The app reads your iPhone's region setting to show a warning, without storing or sending it. Deleting the app removes what it stored on your iPhone, apart from what iOS keeps in the Keychain.

Why we use information

  • To sell you a plan, deliver the eSIM, show it in the app and help you install and use it.
  • To run your account, if you have one, and the credit and referral program.
  • To verify payments with Apple, prevent duplicate charges, fraud and misuse, and handle cancellations and refunds.
  • To answer your messages.
  • To keep accounting and tax records and meet our legal obligations.
  • To keep the service secure and working.

We don't use your information for advertising or profiling, and we make no automated decisions about you that have legal or similarly significant effects.

Do you have to give us information?

No law requires you to. Signing in is optional. Without the device code and the order information, we cannot sell or deliver an eSIM; you can still browse plans and read the guides.

Who receives information

  • Apple, which handles the payment, refunds, the App Store and Sign in with Apple. Apple's own privacy policy covers your Apple Account.
  • Google, which confirms your identity if you sign in with Google, and hosts our email inbox.
  • Cloudflare, which hosts our server, our database and this website, delivers the sign in codes we email and the messages you send with the app's contact form, and forwards the email you send to our address.
  • eSIM Access, our eSIM supplier in Hong Kong, which receives our order number and the plan in order to create and run your eSIM, and nothing that identifies you.
  • The mobile networks in your destination, which carry your data connection.
  • Our accountant, lawyers and authorities, when the law requires it or to protect our rights.

We don't sell or rent your information.

Information outside Israel

Our providers process information outside Israel, including in the European Union (our database is stored in Cloudflare's Eastern Europe region) and the United States. We use them under their data protection terms and the safeguards that Israeli law requires for transfers abroad.

How long we keep it

  • Orders, quotes, payment records and credit records: up to 7 years after the end of the tax year in which they were created, as accounting and tax law require, and then we delete them.
  • The latest report of an eSIM's data use: until the eSIM's access in the app ends, a year after purchase.
  • Your account: until you delete it. See below for what happens then.
  • Signed in sessions: they end after 180 days without use.
  • Support messages and emails: 24 months after the conversation ends.
  • Server logs: up to 7 days.
  • Information on your iPhone: until you delete it or the app.

Deleting your account

If you're signed in, open Profile, Account details in the app, where you can download your account data or delete the account. When you delete it, we immediately remove your name, settings, referral code, sessions, linked iPhones and restore codes, and your credit is forfeited. We keep your email address and sign in identifiers for 30 days, to protect against misuse of the deletion, and then delete them. Order, payment and credit records stay for the accounting period above, used only for that purpose.

Deleting the app does not delete your account. It does not cancel an eSIM either; to remove an eSIM from your iPhone, use the iPhone's Settings.

Refund requests through Apple

When you ask Apple for a refund, Apple may ask us for information about the purchase, such as whether the eSIM was delivered or installed. We don't send this information today. If we start, we will ask for your consent in the app first, and you will be able to withdraw it.

Your rights

You can ask to see the information we hold about you and ask us to correct or delete it. Write to hello@simaya.app. If you don't have an account, we may ask for details that show an order is yours, such as the order reference shown in the app, the purchase date and the amount. We answer within 30 days. Some records must be kept for accounting even after a deletion request; we then keep them only for that purpose. You can also complain to the Privacy Protection Authority in Israel.

Security

The app talks to our server only over encrypted connections. We store your device code and session tokens only as hashes and encrypt restore codes, limit access to our systems to the people who run the service, and never handle your payment details. No system is perfectly secure; if a serious incident affects your information, we will act and notify as the law requires.

Children

Simaya is meant for people aged 18 or over. Younger travellers may use it with the consent of a parent or guardian. We don't knowingly collect more information about a child than an order needs.

Changes to this policy

When we change this policy, we publish the new version here with a new effective date. If a change matters, we will also say so in the app.

Contact

Esperanes LTD, 144 Menachem Begin Road, Tel Aviv, Israel. Email hello@simaya.app.