Sign inRequest access

What we keep, and why.

Short, because we keep very little. It follows the same sections as our full privacy policy, which is with a solicitor and will replace this page once reviewed. For builds, runs and evidence, see Security.

1. What we collect

The waitlist. Your email address, and whatever else you chose to tell us: your name, what you test, which agent you use, your note, the page you signed up from and any campaign tags in its link. We also record whether you ticked “Email me product updates”, and when.

Double opt-in. We send one email asking you to confirm the address. Until you click it, you’re not on the list, and we won’t email that address again.

Your account. Your email address, your sign-in method, your organisation and its API keys (we keep a hash; the secret is shown once), plus what you run: builds, run records, evidence and usage for billing. Signing in sets a session cookie on the app. This marketing site sets none.

What we send. Your invite, and anything needed to run your account. Product updates only if you ticked the box — it starts unticked. Every email has a one-click unsubscribe link.

2. This website

Static pages. No cookies, no analytics, no tracking pixels, no third-party scripts. Fonts are served from this domain. The server that hosts it keeps standard request logs for a few days.

Product analytics, when we turn them on, are recorded on our server when you do something in the product — signed up, connected, ran. Nothing runs in your browser to collect them, and they never include screenshots or build contents.

3. Who we share it with

We don’t sell or share your details. These providers run parts of the service for us, and only for the job named:

ProviderWhat it does for usWhere
Our hosting providerHosts the server and the encrypted backupsEU
GitHubSign-in with GitHub, reviewer access to evidence, CI sign-inUS
ResendDelivers our email: sign-in links, invites, the waitlistUS
StripeTakes payment on paid plans. Card details go to Stripe, not usUK, IE, US
CloudflareDNS, and serves this website and the status page. API traffic doesn’t pass through itGlobal
SentryError reports from our servers. Server-side, when enabledEU
PostHogProduct analytics. Server-side only, when enabledEU

The simulators run on Macs we own, in the UK. Your builds and evidence are there only while a run is in progress. There’s no model provider on the list because there’s no model in the hosted path.

4. How long we keep it

Evidence lasts as long as your plan says: 7 days on Free; 30, 90 or 180 days on paid plans. Uploaded builds are kept for 7 days. Your account lasts until you close it. Invoices are kept for as long as UK tax law requires. Backups roll off within 30 days.

5. Your rights, and getting it removed

You can ask for a copy of what we hold, ask us to correct it, or ask us to stop using it. Email hello@simbase.dev; we reply within a month and don’t charge.

To have everything removed — waitlist entry, account, runs, evidence, keys — email hello@simbase.dev with “Delete my data” in the subject, and we’ll confirm when it’s done. Unsubscribing from updates doesn’t remove you from the waitlist unless you ask.

Last updated 23 September 2026