Privacy policy

Last updated: 3 October 2026

This page explains who we are, what personal data we hold about you, and exactly what the Simple History plugin does and doesn’t send anywhere. Whether you’re simply curious what the plugin does with your data or you’re vetting us as a supplier, it names every service involved and what each one gets.

Who we are

Simple History is made by Eskapism aktiebolag, a company registered in Sweden. Eskapism is a one-person company, run by Pär Thernström, who has developed and maintained Simple History since 2010.

Eskapism aktiebolag is the data controller for the personal data described on this page.

The short version

  • Everything Simple History logs stays in your WordPress database. We never receive it, and we have no way to read it.
  • The plugin sets no cookies and stores nothing about you in your browser.
  • The plugin sends no usage statistics, analytics or telemetry to us. Paid add-ons check for updates, like any other plugin does, and that’s described in full below.
  • A small number of connections to third parties do exist. They’re listed in full below, and most only happen when you actively ask for them.
  • As a paying customer, we hold your name, email address, license key, and the URL of the site you activated it on. Payment details never reach us.
  • We’re a Swedish company and not subject to the US CLOUD Act. Some of our payment and analytics providers are US-based, and we’ve spelled out exactly which ones below.

What the plugin logs, and where it’s stored

Simple History logs activity on your WordPress site: user logins, post and page edits, plugin and theme changes, settings changes, and more. Depending on the event, a log entry can include usernames, user IDs, email addresses, IP addresses, and browser and device information. Under the GDPR (the EU’s data protection law) this counts as personal data, and you are its controller, the party legally responsible for it.

All of it is stored in your own WordPress database, in two custom tables:

  • {prefix}_simple_history: the main log entries
  • {prefix}_simple_history_contexts: additional context for each entry

This data never leaves your server as part of normal operation. It is not transmitted to us, and we have no access to it. If you delete the plugin’s tables, the data is gone. We hold no copy.

You control how long entries are kept. The default is 30 days (60 days on sites that installed Simple History before version 5.25.0). You can change the retention period with a filter, and Simple History Premium adds a setting to keep entries for any number of days or forever. IP addresses are masked by default: the last part of an IPv4 address, or the second half of an IPv6 address, is removed before it’s stored. Premium has a setting to store full IP addresses instead.

Connections to third parties

Here is every outbound connection the plugin can make, and what triggers it. Nothing here happens silently in the background except the license and update checks.

License activation and plugin updates (paid plugins only)

When you activate a license key, the plugin sends your license key and your site URL to simple-history.com so we can register the activation. Activations are handled by Lemon Squeezy’s licensing system, so the key and site URL are passed on to them.

After that, the plugin checks for updates on WordPress’s normal schedule: roughly twice a day, and whenever you open the Plugins or Updates screen. That check sends your license key and the name of the plugin. Like every update check WordPress makes, including the ones to WordPress.org, the request carries your site’s address in its User-Agent header.

No log data and no information about your users is ever included in either request. With no license key entered, no update checks happen at all. The only other request to us is the plugin details lookup that runs if you click “View details” on an add-on in the Plugins screen.

IP address lookups at ipinfo.io

When an administrator clicks an IP address in the log to see details about it, their browser makes a request to ipinfo.io to fetch information about the address, such as country and organisation. The request is made by the browser, not by your server, and only when someone actively clicks. The IP address being looked up is sent to ipinfo.io as part of that request. With IP masking on, which is the default, that is the masked address. See ipinfo.io’s privacy policy.

Google Static Maps (Premium, and only if you add a key)

If you’ve entered your own Google Maps API key in the Premium settings, the same IP address popup also loads a small static map image from maps.googleapis.com, using the approximate coordinates returned by ipinfo.io. Without an API key, no map is loaded and no request to Google is made.

User avatars from Gravatar

The log shows a small avatar next to each user, using WordPress’s own avatar system. If “Show Avatars” is turned on under Settings → Discussion, the administrator’s browser loads those images from Gravatar, a service run by Automattic, the same way WordPress does on its Users screen. The request includes a hash of the user’s email address. With avatars turned off in the Discussion settings, no request is made. See Automattic’s privacy policy.

GitHub-hosted plugins

When logging details about a plugin that was installed directly from a GitHub repository, the plugin fetches that repository’s readme from the public GitHub API to show a useful description. Only the repository owner and name are sent. No personal data is involved.

Destinations you configure yourself

Premium can forward events and send alerts to services such as Slack, Discord, Telegram, Datadog, Splunk, remote syslog servers, external databases, generic webhooks, and email. These features send log data to third parties by design, but only to the destinations you set up yourself, and only once you’ve configured them. Nothing is forwarded anywhere by default, and none of it passes through us. If you use these features, the receiving service’s own privacy policy applies to the data you send it.

Simple History also makes the log available through the WordPress Abilities API, so AI assistants and other tools you connect to your site can read it. Nothing is sent anywhere unless you connect such a tool and give it access, and the data goes to that tool, not to us.

Weekly email reports are sent by your own WordPress installation using its normal mail configuration. The report content does not pass through our servers.

What the plugin does not do

  • It sets no cookies.
  • It stores no data in your browser’s local storage.
  • It loads no Google Fonts or other external fonts.
  • It sends us no usage statistics, analytics or telemetry of any kind.

Data we hold about you as a customer

If you buy Simple History Premium or another paid add-on, we hold:

  • Your name and email address, and your purchase and subscription details, so we can provide the license and support it.
  • Your license key and the URL of each site you activate it on, so license activations can be counted and updates delivered.
  • Any emails you send us, kept in our mailbox so we can follow up on support conversations.
  • We don’t run a newsletter and we don’t send marketing email. The only messages you get from us are transactional: license details, receipts and renewal notices, and replies to questions you’ve asked.

The legal basis for this is the performance of our contract with you, and our legitimate interest in providing support and preventing license abuse.

Payments

Payments are handled by Lemon Squeezy, who act as the merchant of record for all our sales. They process the payment, handle VAT and tax, and issue your invoice. Card details and other payment information go to Lemon Squeezy and never reach us. We see your name, email and what you bought. Lemon Squeezy also runs our license system, so they hold your license key and the URL of each site you activate it on. See Lemon Squeezy’s privacy policy.

The simple-history.com website

This website uses Google Analytics to understand which pages people find useful. This sets cookies in your browser and collects standard web analytics data such as pages viewed, approximate location and referring site. See Google’s privacy policy.

The cookies it sets are first-party ones named _ga and _ga_<id>, used to tell repeat visits apart. You can block them through your browser’s cookie settings, with any tracker-blocking extension, or with Google’s own opt-out add-on. The site works the same with these cookies blocked.

Some pages show profile pictures from Gravatar, so your browser loads those images from Automattic’s servers.

The website is hosted by Oderland, in Sweden. Server logs are kept by the host as part of normal operation.

How long we keep data

  • Purchase and license records are kept for as long as your license is active, and afterwards for as long as Swedish bookkeeping law requires us to keep accounting records.
  • Support emails are kept for as long as they’re useful for supporting you, and deleted when they aren’t.
  • Log data inside the plugin is entirely under your control. See the retention setting described above.

Who else can see your data

We don’t sell personal data, and we don’t share it for advertising. The only third parties who process customer data on our behalf are the ones named above: Lemon Squeezy for payments, billing and license activations, Google Analytics for website statistics, and Oderland, a Swedish company that provides both our web hosting and our email. Visitors to this website also load Gravatar images from Automattic, as described above.

Do you need a data processing agreement from us?

Almost certainly not. This question comes up in most supplier reviews, so here’s why.

A data processing agreement under Article 28 of the GDPR governs the relationship between a controller and a processor: someone who handles personal data on your behalf and under your instructions. We never do that. The activity your site logs stays in your own database and is never transmitted to us, so there is no data of yours for us to process on your behalf in the first place.

For the account details we hold about you (your name, email address and license information), we are the controller in our own right rather than your processor. That relationship is governed by this privacy policy, not by a processing agreement.

One exception: if you send us a support email that happens to contain personal data, such as a debug log or a screenshot of your event log, we hold that for as long as the conversation is useful and then delete it. If your organisation needs that covered by a written agreement, get in touch and we’ll sort something out.

EU jurisdiction and the US CLOUD Act

Eskapism aktiebolag is a Swedish company. We have no US parent company, subsidiary or branch office, and we are not a US communications or cloud service provider. That means we are not subject to the US CLOUD Act or to FISA Section 702, and US authorities can’t compel us to hand over data directly. A US request would have to go through Swedish or EU legal process, and we respond only to lawful requests made under Swedish and EU law.

The activity data Simple History logs never reaches us. It stays in your own database on your own server, so there is nothing for any authority (Swedish, EU, US or otherwise) to obtain from us.

There are places where US companies are involved, and here they are:

  • Lemon Squeezy, our merchant of record, is a US company and is therefore subject to US law, including the CLOUD Act. They hold your name, email address, purchase details, license key and the URLs of the sites you activate it on. Their data processing agreement relies on the EU-approved standard contractual clauses for transfers out of the EU.
  • Google Analytics on this website is operated by Google, a US company. This concerns visitors to simple-history.com, not users of the plugin.
  • ipinfo.io lookups, Google Maps images and Gravatar avatars are requested directly by the administrator’s own browser, not by us and not by your server. We never see them. ipinfo.io and Google Maps requests only happen when someone clicks an IP address in the log, and Gravatar images only load when avatars are turned on in WordPress. All three services are US-based.

Our web hosting and email are both with Oderland, a Swedish provider, so that part of the chain stays inside the EU.

Your log data never reaches a US company through us, because we never hold it. The parts that do involve US companies are billing and license activation, the browser lookups listed above, and any forwarding destinations you choose to set up yourself. If your organisation needs to avoid US processing entirely, email us and we’ll tell you exactly which parts involve US companies.

Your rights

If you’re in the EU or EEA, the GDPR gives you the right to access the personal data we hold about you, to have it corrected or deleted, to receive a copy of it (data portability), to object to how we use it, and to restrict its use. To exercise any of these, email contact@simple-history.com. We’ll reply within one month, as the GDPR requires.

We don’t use your personal data for automated decision-making or profiling.

You also have the right to complain to your national data protection authority. In Sweden that’s Integritetsskyddsmyndigheten (IMY).

Note that for data logged by the plugin on your own site, you are the controller and we can’t help with access or deletion requests. That data is in your database, not ours.

Security

Your log data stays on your own server. We don’t collect it, store it or have any way to access it, so there is no copy of your site’s activity in our systems to protect.

Beyond that:

  • The full source code of the free plugin is public on GitHub and on WordPress.org, so you can audit it yourself.
  • The free plugin is reviewed and distributed by the WordPress.org plugin team.
  • Payment data is handled entirely by Lemon Squeezy, a PCI DSS–compliant merchant of record (the payment card industry’s own security standard).
  • The website and our email are served over encrypted connections (HTTPS/TLS), and both are hosted in Sweden by Oderland.
  • Security issues can be reported directly to security@simple-history.com.

If we ever discover a breach affecting your personal data, we will tell you without undue delay, and report it to the Swedish supervisory authority (IMY) within 72 hours where the GDPR requires it.

Eskapism is a one-person company and holds no ISO 27001, SOC 2 or similar certification. If your organisation needs a supplier questionnaire filled in, email us and we’ll answer it as fully and honestly as we can.

Licensing and terms

Simple History and its paid add-ons are released under the GNU General Public License, version 2 or later. There is no separate end user license agreement to sign. The GPL is the license. What a license covers is explained in our license terms.

Because Lemon Squeezy acts as the merchant of record for our sales, the terms and conditions covering your actual purchase are theirs: see Lemon Squeezy’s Buyer Terms. Our own refund policy gives you 30 days to change your mind, no reason needed.

Changes to this policy

If we change how we handle data, we’ll update this page and change the date at the top. For a more technical walkthrough of how the plugin handles data, see GDPR and privacy: how your data is stored in Simple History.