Skip to content

Privacy Notice

Version 1.0 · Effective 2026-08-11

This notice describes what iiq-rules-mcp and its licensing service do and do not collect. It is written to match how the software actually behaves; the technical statements here are enforced by the product's own tests. Defined terms follow the EULA.

1. Who we are

iiq-rules-mcp is a product of SIMPLIFYAUTH CONSULTANCY SERVICES (OPC) PRIVATE LIMITED ("SimplifyAuth", "we", "us"), an Indian One Person Company. For any privacy question or request, contact contact@simplifyauth.com. We are the data fiduciary/controller for the limited personal data described below.

2. The core principle: the software collects nothing

iiq-rules-mcp verifies IdentityIQ rules locally, on your machine. Its verification and analysis engine:

  • makes no network calls, sends no telemetry, and performs no update checks (this is enforced by an automated test and is observable at runtime with any network monitor);
  • never transmits your rule content, BeanShell, identityiq.jar, WEB-INF/lib, sailpoint.dtd, object exports, file paths, or anything read from your IdentityIQ installation.

None of your IdentityIQ data or intellectual property ever leaves your machine.

3. What we do collect — and only for licensing

The only component that uses the network is the license client, and only to manage your license. Over an encrypted (TLS) connection to our license server it transmits:

When What is sent
Start a trial your email, salted one-way hashes of device components, the accepted EULA version + local timestamp
Activate a purchased key the license key, salted device hashes, the accepted EULA version + timestamp
Periodic lease renewal (about monthly) the license id, salted device hashes
Deactivate / migrate a device the license id, your email

"Salted one-way hashes of device components" are irreversible fingerprints used solely to enforce the one-user-one-device term and to prevent trial abuse; we do not receive your hostname, serial numbers, or any raw device identifier.

We store, on our license server: your email (to deliver the license and provide support), your license records (type, dates, salted device hash, migration count), your EULA-acceptance record (version, timestamp), and an operations audit log (e.g. "trial started", "license renewed"). Backups of this database are described in §6.

4. Payments

Payments are processed by Razorpay. We do not see or store your card, UPI, or bank details — Razorpay handles them under its own privacy policy. From a completed payment we receive only your email, the amount, and a Razorpay payment identifier, which we use to issue and (on refund) revoke your license.

5. Support and email

If you email us, we keep that correspondence to answer you and improve the product. Transactional emails (trial welcome, license delivery, renewal) are sent through our email provider using the email you supplied.

6. Service providers (sub-processors)

We share the limited data above only with providers that help us run the service, each bound to protect it:

  • Razorpay — payment processing (India).
  • Our email/SMTP provider — transactional email delivery.
  • Google Drive — encrypted off-site backups of the license database.
  • Our hosting provider (VPS) — where the license server and its database run.

We do not sell your personal data, and we do not use it for advertising.

7. The documentation website

docs.simplifyauth.com is a static site. It sets no tracking cookies, embeds no third-party analytics or ad scripts, and self-hosts its fonts, so visiting it does not send your browsing data to third parties. Standard server access logs (IP, timestamp, requested path) may be retained short-term for security and diagnostics.

8. Retention

We keep license and acceptance records for the life of the license plus the period needed for tax, accounting, and legal compliance, after which they are deleted or anonymized. Trial-abuse-guard hashes are retained to enforce the one-trial-per-person/device rule. You may request deletion as described below; we will honor it except where law requires us to retain certain records.

9. Security

The license database runs on an access-controlled host, is transmitted only over TLS, and is backed up (encrypted, off-site). Licenses are cryptographically signed (Ed25519). Device identifiers exist only as salted hashes computed on your machine — never as raw values.

10. Your rights

Subject to applicable law (including India's Digital Personal Data Protection Act, 2023, and, where relevant, the GDPR), you may request to access, correct, or delete your personal data, or withdraw consent. Email contact@simplifyauth.com from the address on your license; we will respond within the period required by law. Deleting your data may end your ability to use a paid license (a signed license cannot be reissued to an unknown account).

11. International transfers

We are based in India and our providers may process data in India, the EU, or the United States. Where required, transfers rely on appropriate safeguards.

12. Children

The product is a professional developer tool and is not directed to children; we do not knowingly collect data from anyone under 18.

13. Changes

We may update this notice; the version and date at the top will change, and material changes will be reflected on this page.

14. Grievances

For privacy grievances, contact the Grievance Officer at contact@simplifyauth.com.


SimplifyAuth is an independent product of SIMPLIFYAUTH CONSULTANCY SERVICES (OPC) PRIVATE LIMITED, not affiliated with SailPoint Technologies. SailPoint and IdentityIQ are trademarks of SailPoint Technologies, Inc., used only to describe compatibility.