1. Introduction
Simuletic ("we", "us", "our") operates a synthetic data generation platform that helps organizations build computer-vision datasets without exposing real-world personal data. This Privacy Policy explains what information we collect when you use our website, studio, marketplace and APIs (the "Service"), how we use it, and the rights you have over it.
We act as a data controller for account information and as a data processor for content you generate or upload through the Service.
2. Data we collect
- Account information: email address, name, country, account type (individual or corporate) and authentication credentials.
- Billing metadata: subscription tier, credit balance, invoice history. Payment card details are handled exclusively by Stripe — we never see or store them.
- Generated content: prompts, generation parameters, synthetic images and YOLO annotations you produce.
- Reference uploads: images you upload as references for image-to-image generation.
- Product analytics: page views, feature usage, generation events, error logs. First-party only.
- Technical data: IP address, browser, device type, timestamps — used for security and abuse prevention.
3. How we use your data
- To provide, operate and improve the Service.
- To process generation jobs and store the resulting datasets in your private workspace.
- To handle billing, subscriptions and credit accounting.
- To send transactional emails (account, billing, security).
- To investigate abuse, fraud and security incidents.
- To comply with legal obligations.
We do not sell your data, and we do not use your prompts, reference uploads or generated datasets to train our own or third-party AI models without your explicit, written consent.
4. Corporate data privacy
Simuletic is built for corporate use. All user-uploaded reference images and all generated datasets are stored in a private storage bucket with access enforced via row-level security: only the owning user (and, where contractually agreed, their organization administrators) can access their assets. Asset URLs are short-lived signed URLs — they cannot be guessed or shared publicly without your action.
Reference images uploaded for image-to-image generation are used solely to fulfill the specific job you requested and are never reused for another customer or for model training.
5. Storage & security
- Data is encrypted in transit (TLS 1.2+) and at rest.
- Database access is protected by row-level security policies on every table containing user data.
- Administrative access is role-based, logged and limited to a small number of authorized engineers.
- Production infrastructure is hosted in the European Union.
- We follow the principle of least privilege and review access regularly.
6. Sub-processors
We rely on a small set of vetted sub-processors to deliver the Service:
- Lovable Cloud — managed backend hosting, database and storage (EU region).
- Stripe — payment processing (PCI-DSS Level 1).
- Resend — transactional email delivery.
- Cloudflare — network, DDoS protection and secure tunneling for GPU compute.
A current list is available on request.
7. Cookies & analytics
We use a minimal set of first-party cookies needed for authentication and session continuity, plus first-party product analytics to understand which features are used. We do not use advertising trackers or third-party retargeting pixels.
8. Your rights (GDPR)
If you are in the EU/EEA or UK, you have the right to:
- Access the personal data we hold about you.
- Have inaccurate data corrected.
- Request erasure of your data ("right to be forgotten").
- Export your data in a portable format.
- Object to or restrict certain processing.
- Withdraw consent at any time.
- Lodge a complaint with your local supervisory authority.
To exercise any of these rights, email contact@simuletic.com. We respond within 30 days.
9. Data retention
Account data is retained while your account is active and for up to 30 days after deletion, after which it is purged. Generated datasets and reference uploads remain under your control and are deleted when you delete them or close your account. Anonymized usage statistics may be kept for longer for product analytics.
10. International transfers
Where data is transferred outside the EU/EEA (for example to a sub-processor), we rely on Standard Contractual Clauses or equivalent safeguards.
11. Children
The Service is not intended for individuals under 16. We do not knowingly collect data from children.
12. Breach notification
In the unlikely event of a data breach affecting your personal data, we will notify you and the relevant authorities within the timelines required by applicable law.
13. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be notified by email or in-app notice at least 14 days before they take effect.
14. Contact
Questions, requests or concerns? Email contact@simuletic.com.