Legal
Privacy policy
What is collected, why it is collected, how long it is kept, who else touches it and what you can ask for. Written to be read in one sitting by the person who has to sign off on it.
What happens to your filesSub-processors
Applies to this website and to the hosted version of the product. A self hosted install collects nothing for anybody but you.
A note on this document. It is a plain language template written by the operator of this site, not by a lawyer, and it has not yet been reviewed for any particular jurisdiction. Before relying on it, the operator must have it reviewed against the law that applies where the business is established and where its customers are. If you are evaluating this product and your counsel needs changes, say so on the contact page and it will be looked at rather than defended.
What is collected and why
Three categories, and nothing outside them.
Account information
Your name, your email address, your company name where you give one, the plan you are on and the dates it runs between. This exists so that you can sign in, so that access can be resolved, and so that an invoice can be matched to a person. It comes from you, at signup or on your profile.
The content you upload
The files you put into a twin, the text pulled out of them, the facts extracted from that text, the graph, the assumption ledger, the scenarios you build, the results of runs and the questions you ask. This is processed only to run the service for you: to build your twin, to run your simulations and to show you the answers. It is not analysed for any other purpose, it is not shared between accounts, and it is never used to train, fine tune or evaluate any model.
Uploaded files may contain personal data if you choose to put it in them, for example the names of employees in an organisation chart or the names of individual contacts in a customer list. You decide what to upload. The product does not need names to work, because it models sizes and relationships, so replacing names with labels costs you very little.
Technical and usage records
Standard web server logs, which include an IP address and are kept by the hosting provider under its own retention. Inside the product, a usage meter recording that a run or a sweep happened, when, by which account and against which twin, plus token counts when an optional language model call is made. An audit line when a source is added or a twin is rebuilt. A hashed version of the IP address on public forms, used to rate limit spam rather than to identify anybody.
None of this is used to build a profile of you, and none of it is sold, rented or shared for advertising.
Legal bases
Why each kind of processing is lawful
Framed in the language of the UK and EU General Data Protection Regulation, because that is the strictest common standard and using it makes the answer clear in most other places as well.
| What is processed | Legal basis | In plain terms |
|---|---|---|
| Account information | Performance of a contract | We cannot give you an account without it. |
| The content you upload | Performance of a contract | Processing it is the service. Where that content contains personal data about other people, you are the controller and this software is your processor, which is what the data processing addendum is for. |
| Billing records | Legal obligation | Tax and accounting law requires invoices to be kept. |
| Usage meters and audit lines | Legitimate interests | Enforcing plan limits, preventing abuse and being able to answer the question of what happened to a twin. |
| Server logs and form rate limiting | Legitimate interests | Keeping the site up and keeping spam out. |
| Product emails about your account | Performance of a contract | Receipts, password resets and notices about the service. |
| Marketing email, if any | Consent | Only if you asked for it, and every message carries an unsubscribe link that works. |
If you are established somewhere that frames this differently, the underlying behaviour is the same: the data is used to run the product for you and for nothing else.
How long it is kept
Content you upload is kept while your account is active. Delete a source and its file, its chunks and the facts extracted from it are deleted together, immediately, with no archive copy. Delete a twin and its sources, chunks, facts, assumptions, scenarios, runs and questions go with it.
If you close your account, or if a subscription lapses and is not restored, the account data and the twins attached to it are deleted after thirty days. That window exists so that an accidental cancellation or a failed card does not destroy your work. Export before it closes if you want to keep anything, because after it the data is gone rather than archived.
Billing records are kept for as long as tax law requires, which is commonly six or seven years depending on jurisdiction. These are invoices and amounts, not the content of your twins.
Server logs follow the hosting provider's own retention, typically a few weeks. Form submissions from the contact and walkthrough forms are kept until the conversation is finished and then deleted on request, and in any case are reviewed and cleared periodically.
Cached language model responses are keyed by a hash of the prompt and are deleted with the twin they belong to.
Who else touches it
Sub-processors, listed by name
A small number of third parties are involved in running this service: hosting, email delivery, payment processing, and an optional language model provider that is used only when a key is configured.
They are listed on their own page with what each one does and what it can see, because a list that lives inside a policy document is a list nobody reads. That page also says how notice is given when the list changes.
- No advertising networks
- No analytics product that profiles visitors across sites
- No data brokers, no enrichment services, no resale of anything
Your rights, and how to use them
Ask through the contact page. You will get a reply from a person, and the intention is to act within thirty days.
- Access: a copy of what is held about you. Most of it you can already export yourself through the product.
- Rectification: correct anything wrong. Account details are editable on your profile.
- Erasure: delete your account and its content. This is a button in the product, not a request you have to make.
- Restriction: ask for processing to be paused while a dispute is resolved.
- Portability: facts, assumptions, graph nodes, run results and briefs read back as JSON through the API, and briefs export as a document.
- Objection: object to processing based on legitimate interests, which in practice means the usage meters and audit lines.
- Withdraw consent: unsubscribe from any marketing email at any time, with no effect on your account.
- Complain: to the data protection authority where you live or work. Doing that does not require asking here first.
No automated decision with a legal or similarly significant effect is made about you. The simulation makes decisions about invented agents inside a model of your company, which is not the same thing and does not fall under that heading.
If you self host, none of these requests come here, because none of your data is here. You are the controller and the operator of your own install.
Cookies, children, changes and contact
Cookies
This site sets the cookies WordPress sets: a session cookie when you sign in, and a preference cookie if you leave a comment or set a display option. If payment is handled through Paid Memberships Pro and Stripe, the checkout sets what those need to process a payment. There is no advertising cookie, no cross site tracker and no third party analytics tag on this site. Because nothing here is used for advertising or profiling, there is no consent banner, which is a deliberate choice rather than an oversight.
Children
This is a product for businesses. It is not directed at children, it is not marketed to anybody under sixteen, and accounts are not knowingly created for them. If you believe a child has created an account, say so on the contact page and it will be removed.
Changes to this policy
When this changes in a way that affects you, the change is noted on the changelog with a date and, for anything material, sent by email to account holders before it takes effect. Silent edits to a privacy policy are a bad habit and this site does not practise them.
Contact
Use the contact page. It reaches a person directly. There is no data protection officer, because the business is not of a size or nature that requires one, and inventing a title for somebody who does not exist would be worse than saying that plainly.
If your counsel needs something changed, say so
This document is meant to survive a legal review rather than to look like it has already had one. Specific objections are more useful than general ones.