Last updated: 7 August 2026
This page explains who we are, what personal data we hold about you, and exactly what the Simple History plugin does and doesn’t send anywhere. We’ve tried to be specific rather than vague — if you’re reviewing us as a supplier, everything you need should be on this page.
Who we are
Simple History is made by Eskapism aktiebolag, a company registered in Sweden. Eskapism is a one-person company, run by Pär Thernström, who has developed and maintained Simple History since 2010.
Eskapism aktiebolag is the data controller for the personal data described on this page.
- Organisation number: 559352-7855
- VAT number: SE559352785501
- D-U-N-S number: 351175734
- General questions: contact@simple-history.com
- Support for paid plugins: support@simple-history.com
- Security issues: security@simple-history.com
The short version
- Everything Simple History logs stays in your WordPress database. We never receive it, and we have no way to read it.
- The plugin sets no cookies and stores nothing about you in your browser.
- The plugin sends no usage statistics, analytics or telemetry to us. There is no “phone home”.
- A small number of connections to third parties do exist — they’re listed in full below, and most only happen when you actively ask for them.
- As a paying customer, we hold your name, email address, license key and the URL of the site you activated it on. Payment details never reach us.
- We’re a Swedish company and not subject to the US CLOUD Act. Some of our payment and analytics providers are US-based, and we’ve spelled out exactly which ones below.
What the plugin logs, and where it’s stored
Simple History logs activity on your WordPress site: user logins, post and page edits, plugin and theme changes, settings changes, and more. Depending on the event, a log entry can include usernames, user IDs, email addresses, IP addresses, and browser and device information. Under the GDPR this counts as personal data, and you are the controller of it.
All of it is stored in your own WordPress database, in two custom tables:
{prefix}_simple_history— the main log entries{prefix}_simple_history_contexts— additional context for each entry
This data never leaves your server as part of normal operation. It is not transmitted to us, and we have no access to it. If you delete the plugin’s tables, the data is gone — we hold no copy.
You control how long entries are kept. The default is 30 days, and you can change the retention period to any number of days, or disable automatic deletion entirely. IP addresses can be anonymised, which replaces the last part of the address before it’s stored.
Connections to third parties
Here is every outbound connection the plugin can make, and what triggers it. Nothing here happens silently in the background except the license and update checks.
License activation and plugin updates (paid plugins only)
When you activate a license key, the plugin sends your license key and your site URL to simple-history.com so we can register the activation. When checking for updates, it sends your license key and the plugin slug. No log data and no information about your users is ever included.
IP address lookups at ipinfo.io
When an administrator clicks an IP address in the log to see details about it, that administrator’s browser makes a request to ipinfo.io to fetch information about the address, such as country and organisation. The request is made by the browser, not by your server, and only when someone actively clicks. The IP address being looked up is sent to ipinfo.io as part of that request. See ipinfo.io’s privacy policy.
Google Static Maps (Premium, and only if you add a key)
If you’ve entered your own Google Maps API key in the Premium settings, the same IP address popup also loads a small static map image from maps.googleapis.com, using the approximate coordinates returned by ipinfo.io. Without an API key, no map is loaded and no request to Google is made.
GitHub, for plugins installed from GitHub
When logging details about a plugin that was installed directly from a GitHub repository, the plugin fetches that repository’s readme from the public GitHub API to show a useful description. Only the repository owner and name are sent. No personal data is involved.
Destinations you configure yourself (Premium)
Premium can forward events and send alerts to services such as Slack, Discord, Telegram, Datadog, Splunk, generic webhooks, and email. These send log data to third parties by design — but only to the destinations you set up yourself, and only once you’ve configured them. Nothing is forwarded anywhere by default, and none of it passes through us. If you use these features, the receiving service’s own privacy policy applies to the data you send it.
Weekly email reports are sent by your own WordPress installation using its normal mail configuration. The report content does not pass through our servers.
What the plugin does not do
- It sets no cookies.
- It stores no data in your browser’s local storage.
- It loads no Google Fonts or other external fonts.
- It sends us no usage statistics, analytics or telemetry of any kind.
Data we hold about you as a customer
If you buy Simple History Premium or another paid add-on, we hold:
- Your name and email address, and your purchase and subscription details, so we can provide the license and support it.
- Your license key and the URL of each site you activate it on, so license activations can be counted and updates delivered.
- Any emails you send us, kept in our mailbox so we can follow up on support conversations.
The legal basis for this is the performance of our contract with you, and our legitimate interest in providing support and preventing license abuse.
Payments
Payments are handled by Lemon Squeezy, who act as the merchant of record for all our sales. They process the payment, handle VAT and tax, and issue your invoice. Card details and other payment information go to Lemon Squeezy and never reach us — we only see your name, email and what you bought. See Lemon Squeezy’s privacy policy.
The simple-history.com website
This website uses Google Analytics to understand which pages people find useful. This sets cookies in your browser and collects standard web analytics data such as pages viewed, approximate location and referring site. See Google’s privacy policy.
The website is hosted by Oderland, in Sweden. Server logs are kept by the host as part of normal operation.
How long we keep data
- Purchase and license records are kept for as long as your license is active, and afterwards for as long as Swedish bookkeeping law requires us to keep accounting records.
- Support emails are kept for as long as they’re useful for supporting you, and deleted when they aren’t.
- Log data inside the plugin is entirely under your control — see the retention setting described above.
Who else can see your data
We don’t sell personal data, and we don’t share it for advertising. The only third parties who process customer data on our behalf are the ones named above: Lemon Squeezy for payments and billing, Google Analytics for website statistics, and our web host and email provider as part of running the service.
EU jurisdiction and the US CLOUD Act
This is a common concern for European customers, so here it is plainly.
Eskapism aktiebolag is a Swedish company. We have no US parent company, subsidiary or branch office, and we are not a US communications or cloud service provider. That means we are not subject to the US CLOUD Act or to FISA Section 702, and US authorities have no legal route to compel us to hand over data. We respond only to lawful requests made under Swedish and EU law.
More importantly for most people: the activity data that Simple History logs never reaches us in the first place. It stays in your own database on your own server. There is nothing for any authority — Swedish, EU, US or otherwise — to obtain from us, because we simply don’t have it.
We should be equally clear about where US companies are involved, because a couple of them are:
- Lemon Squeezy, our merchant of record, is a US company and is therefore subject to US law, including the CLOUD Act. They hold your name, email address and purchase details. Their data processing agreement relies on the EU-approved standard contractual clauses for transfers out of the EU.
- Google Analytics on this website is operated by Google, a US company. This concerns visitors to simple-history.com, not users of the plugin.
- ipinfo.io lookups and Google Maps images are requested directly by the administrator’s own browser, not by us and not by your server. We never see them, and they only happen when someone clicks an IP address in the log. Both services are US-based.
So: your logged site activity never touches a US company through us, and neither do we. The billing chain is the part that does. If your organisation needs to avoid US processing entirely, get in touch and we’ll talk it through honestly rather than have you find out later.
Your rights
If you’re in the EU or EEA, the GDPR gives you the right to access the personal data we hold about you, to have it corrected or deleted, to receive a copy of it, to object to how we use it, and to restrict its use. To exercise any of these, email contact@simple-history.com and we’ll get back to you.
You also have the right to complain to your national data protection authority. In Sweden that’s Integritetsskyddsmyndigheten (IMY).
Note that for data logged by the plugin on your own site, you are the controller and we can’t help with access or deletion requests — that data is in your database, not ours.
Security
The most important thing about Simple History’s security posture is architectural: your log data stays on your own server. We don’t collect it, store it or have any way to access it, so there is no copy of your site’s activity data in our systems to protect.
Beyond that:
- The full source code of the free plugin is public on GitHub and on WordPress.org, so you can audit it yourself.
- The free plugin is reviewed and distributed by the WordPress.org plugin team.
- Payment data is handled entirely by Lemon Squeezy, a PCI-compliant merchant of record.
- Security issues can be reported directly to security@simple-history.com. We take them seriously and will respond quickly.
We should be straightforward about the limits, too: Eskapism is a one-person company, and we don’t hold ISO 27001, SOC 2 or similar certifications. If your organisation needs a supplier questionnaire filled in, email us and we’ll answer it as fully and honestly as we can.
Licensing and terms
Simple History and its paid add-ons are released under the GNU General Public License, version 2 or later. There is no separate end user license agreement to sign — the GPL is the license.
Because Lemon Squeezy acts as the merchant of record for our sales, the terms and conditions covering your actual purchase are theirs: see Lemon Squeezy’s Buyer Terms. Our own refund policy gives you 30 days to change your mind, no reason needed.
Changes to this policy
If we change how we handle data, we’ll update this page and change the date at the top. For a more technical walkthrough of how the plugin handles data, see GDPR and privacy: how your data is stored in Simple History.