Privacy Policy

Last updated: July 21, 2026

What we collect

Account information

When you register, we store your email address, an associated user ID, and a hashed version of your password . We also store your account role and when your account was created.

Session data

When you log in, we create a session that expires after 7 days. This is stored server-side and linked to your account. A session cookie is set in your browser so we know you're logged in.

Simulation data

When you run a simulation, we store the full SimulationCraft profile you submitted (which includes your character setup, gear, talents, and APL), the results of the simulation, timestamps (when you queued it, when it started, when it finished), how many CPU threads were allocated, and whether it succeeded or failed. Simulations are executed on cloud compute workers (see "Third-party services" below), which receive the profile for the duration of the run.

To avoid re-running identical simulations, a normalized copy of the simulation input and its results is kept in a server-side cache for up to 14 days.

Completed simulation jobs are automatically deleted after 24 hours. Up to your 100 most recent reports are kept on the server for your report history. Reports older than 30 days are automatically deleted.

Please note that during the beta this data will be fully associated with your account and be manually reviewed: what you sim, how often, how long it takes, and the results. This is used to find bugs, spot performance issues, and figure out what to build next. The data will never be shared with anyone and will never be used publicly. After the beta, access will be narrowed to aggregated, anonymised metrics only.

Shared reports

If you share a report, a copy is stored on the server with a short public ID. Anyone with the link can view it. Shared reports expire after 6 months.

Feedback

If you submit feedback through the app, we store your message, its category (bug, feature, or general), and, if you're logged in, your user ID.

Your library

If you're logged in, your saved character profiles, APL profiles, spell overrides, and starred spells are stored on the server, linked to your account, so they follow you across devices. When you first log in, any of this data already saved in your browser is copied to the server and removed from your browser.

Browser local storage

We store editor preferences, layout state, and your current character/APL configuration in your browser's local storage. If you're not logged in, your library (characters, APL profiles, spell overrides, starred spells) is also kept here. This data never leaves your browser, except for the one-time library migration described above when you log in.

What we don't collect

  • No third-party analytics
  • No tracking pixels or advertising cookies
  • No data is sold to or shared with third parties
  • No IP address logging beyond what the web server produces in normal operation

Why we collect this data

  • Account & session data: to let you log in and manage your account
  • Simulation data: to run your simulations, show you results, and manage the job queue
  • Report history: so you can review your recent simulation results
  • Your library: so your characters, APL profiles, spell overrides, and starred spells are available on any device you log in from
  • Shared reports: so you can share results with others via a link
  • Feedback: so we can read your bug reports and feature requests

Where your data is stored

All data is stored on the server that runs SimCode. The only exceptions are simulation runs, which are executed on the cloud compute workers described below, and transactional emails, which are delivered by our email provider.

How long we keep your data

  • Account data: until you delete your account
  • Sessions: 7 days, then automatically expired
  • Simulation jobs: automatically deleted 24 hours after completion
  • Cached simulation results: up to 14 days
  • Your library: (characters, APL profiles, spell overrides, starred spells) until you delete the items or your account
  • Report history: up to 100 reports are kept per user; reports older than 30 days are automatically deleted
  • Shared reports: available for 6 months, then expired
  • Feedback: kept indefinitely unless you request deletion

Your rights

Under the GDPR and similar privacy regulations, you have the right to:

  • Access — request a copy of all data we hold about you
  • Rectification — ask us to correct inaccurate data
  • Erasure — ask us to delete your data (you can also delete your account directly from the account page, which removes your account and associated data)
  • Portability — request your data in a machine-readable format
  • Object — object to processing of your data, including the beta-period usage analysis described above
  • Withdraw consent — you can stop using the service at any time and request deletion of your data

To exercise any of these rights, contact us via email at [email protected]

Legal basis for processing (GDPR)

  • Contract: account, session, and simulation data are necessary to provide the service you signed up for
  • Legitimate interest: beta-period usage analysis to improve the tool, provided it does not override your rights
  • Consent: feedback submissions and shared reports are voluntary actions you choose to take

Cookies

We use session cookies to keep you logged in: one holding your session token and one short-lived cached copy of your session data. Both are strictly necessary for the service to function and do not require consent under GDPR.

Third-party services

SimCode does not use any third-party services for analytics or advertising. We use the following providers to operate the service:

  • Cloud compute workers (Modal, Fly.io): simulations run on on-demand compute machines. The worker receives your SimulationCraft profile for the duration of the run and returns the results; nothing is retained there after the run finishes.
  • Email delivery (Brevo): account emails (signup confirmation codes and login links) are sent through Brevo, which processes your email address for delivery.

Everything else stays on our server.

Children's privacy

By using the Service, you confirm that you are older than 16. SimCode is not directed at children under 16. We do not knowingly collect data from children under 16. If you believe a child has created an account, contact us and we will delete the account and all data associated with it.

Changes to this policy

The date at the beginning of the page will be updated for any and all changes. For significant changes (especially anything that expands what data we collect or how we use it), we'll make reasonable efforts to notify existing users.

Contact

If you have questions about this policy or want to exercise your data rights, please reach out at [email protected]