DRAFT — replace with your finalised policy before public launch. The text below is a starting point, not legal advice.
What we collect
When you create an account we store your email address, a username, a display name, an optional bio, an optional institution, and an optional ORCID iD. When you upload a simulation we store the file you provide and the metadata you choose to attach. When you ask the AI guide a question, the question and its response are sent to our language-model provider (Anthropic) for processing.
What we don't collect
We do not use third-party advertising trackers. We do not sell data. We do not profile users beyond the analytics needed to make the product work (anonymous page views and aggregate event counts).
Cookies and storage
We use first-party cookies to keep you signed in (via Supabase Auth) and local-storage entries for UI preferences (theme, whether you've seen the welcome tour). No third-party tracking cookies.
Who we share data with
Operationally we use: Supabase (database, auth, file storage), Cloudflare R2 (large file storage), Anthropic (LLM inference), and a privacy-friendly analytics provider for aggregate page views. Each receives only the data necessary to perform its role.
Your rights
Under GDPR you have the right to access, correct, and delete your data. Email us at the contact address below to exercise any of these. Deletion of your account removes your profile, uploaded simulations (subject to a 30-day grace period), comments, and AI conversation history.
Contact
Privacy questions: contact form.