SimteeBack to home

Privacy

Simtee helps teams build a private map of stakeholders and relationships. This page is the public privacy policy for the service: it explains what personal data we collect, why we use it, which vendors help process it, how long we keep it, and how you can exercise your rights.

Who controls your data

Account data (your email, password hash, login activity, plan) is held by Simtee as the data controller. Workspace content (actors, relationships, notes, briefs you enter) is held by Simtee as a processor on behalf of the workspace owner; the workspace owner is the controller for that data.

What we collect

  • Account: email, password hash, email verification state, plan, login activity.
  • Workspace content you enter: actor names, organizations, roles, scores, notes, relationships, briefs.
  • Usage telemetry for capacity planning and abuse prevention (per-workspace AI cost counters, audit log entries).
  • Transactional email delivery status (via Resend).

Why we use it

  • Provide the service: authentication, workspaces, collaboration, exports, and account management.
  • Security and abuse prevention: login protection, rate limits, audit logs, and session revocation.
  • AI features you choose to run: generating suggestions and briefs from workspace content you submit.
  • Billing and support: plan administration, payment handling, and responding to requests.

The usual legal bases are contract, legitimate interests in operating and securing the service, legal obligations where applicable, and the workspace owner's lawful basis for stakeholder data they choose to enter.

Simtee does not sell workspace data or share it with third parties for advertising or marketing.

How AI is used

AI actions in Simtee use Google Gemini. By default Gemini works only with the information you provide in your workspace; you can optionally enable Google Search grounding for richer suggestions (Account settings). AI output is always presented as a suggestion that you approve, edit, or reject — it never becomes part of your stakeholder map without your action.

Workspace data you enter is never automatically sent to an LLM; it is sent only when you or another workspace member intentionally run an AI action, such as generating suggestions, enrichment, notes-to-data, relationship analysis, or an insight brief.

Under the terms of the Gemini API, Google does not use prompts or responses to improve Google products. If Google Search grounding is enabled, Google may temporarily retain grounding prompts, context, and outputs for debugging and testing.

Please do not enter special-category personal data (data revealing racial or ethnic origin, political opinions, religious beliefs, trade-union membership, health, sex life, sexual orientation, genetic or biometric data) into Simtee. The product is not designed to host such data and we apply prompt-level guardrails against generating it.

Public viewer links

Workspace members can create read-only viewer links. Anyone with the URL can view the workspace until the link is revoked, so treat it as a shared secret. Review your workspace before sharing.

Sub-processors

We rely on these processors to deliver the service: Supabase (database), Render (backend hosting), Vercel (frontend hosting), Google (Gemini AI and optional Search grounding), Resend (transactional email), Stripe (payment processing), and IONOS/Gmail for forwarding privacy requests to our inbox. For intentional EU/UK onboarding, we maintain or put in place appropriate vendor terms and transfer safeguards where required.

We do not currently use non-essential analytics, advertising pixels, or session replay. If that changes, those tools will be disclosed here and gated behind consent where required.

How long we keep data

  • Account and workspaces you sole-own: deleted with your account.
  • Shared workspaces: retained for the remaining members; your membership is removed.
  • Audit log: retained for accountability with user-identifying fields anonymised after account deletion.
  • Usage telemetry: raw telemetry events are pruned after roughly 18 months.
  • AI job inputs and outputs: trimmed once you approve/reject the suggestion; older completed jobs are pruned.
  • Backups: follow the host's backup rotation; deleted data clears one cycle later.

Your rights

  • Access / portability: Account settings → Export my data (returns a JSON archive).
  • Erasure: Account settings → Delete account (sole-member workspaces are deleted; shared memberships are removed).
  • Rectification, restriction, objection: contact us (see below) and we will respond within 30 days.
  • Complaint: if you are in the EU/UK, you can also complain to your local data protection authority.

Contact

Simtee is operated by Josh Jorgensen. For privacy or data protection requests, contact privacy@simtee.org. Postal address details are available on legally valid request where required.

Last updated: 2026-05-27.