Legal
Privacy Policy
Effective September 8, 2026
This policy explains what data SIMRIX collects when you use SIMRIX Monitor, why we collect it, who we share it with, and the choices you have. It covers the SIMRIX Monitor application and website.
1. Data we collect
Account data. Your name, email address, hashed password (if you sign in with a password), workspace name, and team membership and roles. If you sign in with Google we receive your name, email address, and profile image from Google.
Billing data. Plan, billing interval, subscription status, and invoice history. Card details are collected and stored by our payment processor — we never receive or store full card numbers.
Monitoring data. The URLs you configure, monitor settings, and the results of each run: screenshots, page text and HTML snapshots, content hashes, HTTP status codes, timings, error messages, and any AI-generated summary of a change or failure.
Usage and diagnostic data. Application logs, audit log entries for significant workspace actions, error reports, and API key usage counts.
2. Data captured from the sites you monitor
When a monitor runs, we capture whatever is on the page at that moment. If a monitored page displays personal data — customer names in an admin view, for example, or your own details in a logged-in workflow — that data will appear in the stored screenshot and page snapshot.
You control this. Point monitors at pages that do not expose personal data where you can, and use element or region selectors to narrow what is captured. You are the controller of any personal data captured this way; we process it on your behalf.
3. How we use data
- To operate the Service: run monitors, detect changes, send alerts.
- To authenticate you and enforce workspace permissions.
- To bill your subscription and enforce plan limits.
- To generate summaries of detected changes and failures using an AI provider.
- To provide support, investigate incidents, and diagnose errors.
- To send service and account email. We send marketing email only if you opt in, and every marketing message includes an unsubscribe link.
We do not sell personal data, and we do not use your monitoring data to train machine learning models.
4. Legal bases (EEA and UK)
Where GDPR applies, we rely on: performance of a contract (operating the Service and billing you); legitimate interests (securing the Service, preventing abuse, improving reliability); consent (marketing email, where required); and legal obligation (tax and accounting records).
5. Subprocessors
We share data with the following providers so they can perform services for us. Each is bound by contractual confidentiality and security obligations.
- Cloudflare (R2) — Object storage for screenshots and page snapshots
- Stripe — Subscription billing and payment processing
- Resend — Transactional and alert email delivery
- OpenAI — Generating change summaries and failure explanations
- Sentry — Application error monitoring
- Google — Optional single sign-on for account access
We also use a cloud hosting provider and a managed PostgreSQL database to run the application. Some of these providers process data in the United States; where required we rely on Standard Contractual Clauses or an equivalent transfer mechanism.
6. Retention
Account and billing records are retained for as long as your account is active and afterwards as required for tax and legal purposes. Screenshots and page snapshots are retained on a rolling window and are deleted automatically once they age out. Run history and audit log entries are retained while your workspace is active.
When you close your account we delete workspace data after a reasonable period, except records we must keep by law.
7. Security
Data is encrypted in transit. Passwords are stored salted and hashed — never in plain text. Access to production systems is limited to personnel who need it. API keys are stored as hashes and shown in full only once, at creation.
No system is perfectly secure. If we become aware of a breach affecting your personal data we will notify you and any relevant regulator as required by law.
8. Cookies
We use strictly necessary cookies to keep you signed in and to protect against cross-site request forgery. We do not use advertising cookies or third-party tracking cookies.
9. Your rights
Depending on where you live, you may have the right to access, correct, delete, port, or restrict processing of your personal data, to object to processing, and to withdraw consent. California residents may request disclosure of the categories of personal information collected and may opt out of any sale or sharing — we do not sell or share personal information as those terms are defined under the CCPA.
To exercise a right, email [email protected]. We will respond within the period required by applicable law. You may also lodge a complaint with your local data protection authority.
10. Children
The Service is not directed to children and we do not knowingly collect personal data from anyone under 18.
11. Changes to this policy
We may update this policy. If a change is material we will give reasonable notice by email or in the application before it takes effect.
12. Contact
Privacy questions and requests: [email protected].
SIMRIX, [street address], [city, state, ZIP], United States
See also our Terms of Service and Privacy Policy.