Design stage: there is no released app yet. This site separates what exists in the repository from what is planned. See status

Capabilities

Security and privacy themes

Security statements here are design intent. The launcher and the customer app have no code to audit, the packaging tool has not been audited, and the site makes no certification claim of any kind.

Questions

Is Simca certified?
No. No PCI, SOC 2, HIPAA, GDPR or EMV compliance is claimed.
Does it collect telemetry?
The README states a no-telemetry principle. It is a design principle, not a measured property of a shipped app.