Privacy Policy

    Effective date: May 5, 2026

    This policy explains what personal data Simuletic collects when you use our website, dataset studio, and APIs, why we collect it, and the rights you have over it under GDPR and other privacy laws. It applies to account holders, dataset customers, and website visitors. In short: we act as a data controller for your account information and a data processor for content you generate or upload, we never sell your data, and we do not use your uploads to train third-party AI models without your written consent. See section 8 below to exercise your rights, or email contact@simuletic.com.

    1. Introduction

    Simuletic ("we", "us", "our") operates a synthetic data generation platform that helps organizations build computer-vision datasets without exposing real-world personal data. This Privacy Policy explains what information we collect when you use our website, studio, marketplace and APIs (the "Service"), how we use it, and the rights you have over it.

    We act as a data controller for account information and as a data processor for content you generate or upload through the Service.

    2. Data we collect

    • Account information: email address, name, country, account type (individual or corporate) and authentication credentials.
    • Billing metadata: subscription tier, credit balance, invoice history. Payment card details are handled exclusively by Stripe — we never see or store them.
    • Generated content: prompts, generation parameters, synthetic images and YOLO annotations you produce.
    • Reference uploads: images you upload as references for image-to-image generation.
    • Product analytics: page views, feature usage, generation events, error logs. First-party only.
    • Technical data: IP address, browser, device type, timestamps — used for security and abuse prevention.

    3. How we use your data

    • To provide, operate and improve the Service.
    • To process generation jobs and store the resulting datasets in your private workspace.
    • To handle billing, subscriptions and credit accounting.
    • To send transactional emails (account, billing, security).
    • To investigate abuse, fraud and security incidents.
    • To comply with legal obligations.

    We do not sell your data, and we do not use your prompts, reference uploads or generated datasets to train our own or third-party AI models without your explicit, written consent.

    4. Corporate data privacy

    Simuletic is built for corporate use. All user-uploaded reference images and all generated datasets are stored in a private storage bucket with access enforced via row-level security: only the owning user (and, where contractually agreed, their organization administrators) can access their assets. Asset URLs are short-lived signed URLs — they cannot be guessed or shared publicly without your action.

    Reference images uploaded for image-to-image generation are used solely to fulfill the specific job you requested and are never reused for another customer or for model training.

    5. Storage & security

    • Data is encrypted in transit (TLS 1.2+) and at rest.
    • Database access is protected by row-level security policies on every table containing user data.
    • Administrative access is role-based, logged and limited to a small number of authorized engineers.
    • Production infrastructure is hosted in the European Union.
    • We follow the principle of least privilege and review access regularly.

    6. Sub-processors

    We rely on a small set of vetted sub-processors to deliver the Service:

    • Lovable Cloud — managed backend hosting, database and storage (EU region).
    • Stripe — payment processing (PCI-DSS Level 1).
    • Resend — transactional email delivery.
    • Cloudflare — network, DDoS protection and secure tunneling for GPU compute.

    A current list is available on request.

    7. Cookies & analytics

    We use a minimal set of first-party cookies needed for authentication and session continuity, plus first-party product analytics to understand which features are used. We do not use advertising trackers or third-party retargeting pixels.

    8. Your rights (GDPR)

    If you are in the EU/EEA or UK, you have the right to:

    • Access the personal data we hold about you.
    • Have inaccurate data corrected.
    • Request erasure of your data ("right to be forgotten").
    • Export your data in a portable format.
    • Object to or restrict certain processing.
    • Withdraw consent at any time.
    • Lodge a complaint with your local supervisory authority.

    To exercise any of these rights, email contact@simuletic.com. We respond within 30 days.

    9. Data retention

    Account data is retained while your account is active and for up to 30 days after deletion, after which it is purged. Generated datasets and reference uploads remain under your control and are deleted when you delete them or close your account. Anonymized usage statistics may be kept for longer for product analytics.

    10. International transfers

    Where data is transferred outside the EU/EEA (for example to a sub-processor), we rely on Standard Contractual Clauses or equivalent safeguards.

    11. Children

    The Service is not intended for individuals under 16. We do not knowingly collect data from children.

    12. Breach notification

    In the unlikely event of a data breach affecting your personal data, we will notify you and the relevant authorities within the timelines required by applicable law.

    13. Changes to this policy

    We may update this Privacy Policy from time to time. Material changes will be notified by email or in-app notice at least 14 days before they take effect.

    14. Contact

    Questions, requests or concerns? Email contact@simuletic.com.