Last updated: August 4, 2026 · Version 3.0
Privacy Policy
This Privacy Policy describes how SOCSimulator LLC ("we", "us", or "our") collects, uses, and shares information about you when you use SOCSimulator.
Table of Contents
1. Information We Collect
Information You Provide
- Account Information: Email address, display name, and password when you create an account.
- Profile Information: Optional information such as job title, organization, and profile picture.
- Payment Information: When you subscribe to a paid plan, payment details are collected and processed by Stripe. We do not store your full credit card number.
- Communications: Information you provide when contacting support or participating in surveys.
Information Collected Automatically
- Usage Data: Information about how you use SOCSimulator, including scenarios completed, time spent, and feature usage.
- Device Information: Browser type, operating system, device type, and screen resolution.
- Log Data: IP address, access times, pages viewed, and referring URLs.
- Account Security and Restriction Data: Email-domain classification, verification state, authentication and abuse signals, temporary-lock or ban status, reason codes, required recovery actions, review decisions, and an audit history. Internal notes and evidence are access-controlled and are not displayed to other users.
- Cookies: We use cookies and similar technologies as described in our Cookie Policy.
- Pseudonymous Account Identifiers: When you are signed in, we attach your account identifier and your public username to product analytics, so that a sequence of events can be recognised as one person's. Your username is already public on your profile page. We do not send your email address, display name, or any answer you type in an operation.
- PostHog Diagnostic Replay: A masked record of the interaction sequence for roughly one in four sessions, used to diagnose product issues. Every input is masked, and request headers, request and response bodies, browser console output, and canvas content are not recorded. Replay never runs on assessment, sign-in, password, MFA, billing, banned-account, or account-recovery pages. This runs under our legitimate interests and you can object at any time — see Your Rights.
2. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve SOCSimulator
- Process transactions and send related information
- Send transactional emails (account verification, password resets, subscription updates)
- Send marketing communications (with your consent)
- Track your progress and provide personalized training recommendations
- Analyze usage patterns to improve our platform
- Detect, prevent, and address technical issues and security threats
- Detect suspected fraud or abuse, apply proportionate account restrictions, present recovery requirements, and review appeals
- Comply with legal obligations
4. Third-Party Services
We use the following third-party services to operate SOCSimulator:
| Service | Purpose | Privacy Policy |
|---|---|---|
| Supabase | Authentication and database | Link |
| Stripe | Payment processing | Link |
| Resend | Transactional emails | Link |
| Vercel | Hosting and infrastructure | Link |
| Umami (self-hosted) | Basic cookieless pageview and event analytics, self-hosted at stats.haridian.com. It does not collect session replay or heatmaps. We rely on legitimate interest and provide the Product analytics opt-out; no third-party data transfer occurs. | Link |
| PostHog (US cloud) | Pseudonymous product events, pageviews, web-vitals measurements, and sanitized application errors are processed under legitimate interest at the US endpoint. Requests are routed through t.socsimulator.com, a first-party subdomain that forwards to the same US project. Autocapture, heatmaps, dead clicks, feature flags, and network timing are disabled, so we never collect the text of the elements you click. Diagnostic session replay is sampled at roughly 25% of sessions, also under legitimate interest; it masks all inputs, excludes request headers, bodies, console output, and canvas, never runs on assessment, sign-in, password, MFA, or billing pages, and can be switched off at any time in Profile → Settings → Privacy. | Link |
| Cloudflare Turnstile | Bot and fraud prevention on public forms such as the waitlist signup. Active only on those forms. | Link |
| Discord | Optional community integration: role sync and notifications for users who link their Discord account. Active only when you link your Discord account; we then share your Discord user ID, Discord OAuth tokens, and subscription tier/rank. Location: US / global. | Link |
For the complete list of processors we use, see our Subprocessors page.
5. Data Retention
We retain your information for as long as your account is active or as needed to provide services. Specifically:
- Account Data: Retained until you request deletion. Where we terminate an account ourselves, its data is deleted within 30 days of termination, except where longer retention is required to establish, exercise, or defend legal claims or to comply with law
- Account Restriction and Review History: Retained with the account until account deletion, except where longer retention is required to establish, exercise, or defend legal claims or comply with law
- Usage Logs: Retained for 90 days
- Payment Records: Retained for 7 years for tax and legal compliance
- Backup Data: Deleted within 30 days of account deletion
- Umami Analytics Events: Retained for up to 12 months
- PostHog Events and Errors: Target 90-day retention
- PostHog Diagnostic Replays: 30-day retention; sampled at roughly 25% of sessions
6. Data Security
We implement appropriate technical and organizational measures to protect your information, including:
- Encryption in transit (TLS) and at rest, provided by our infrastructure providers (Supabase, Vercel)
- Authentication and password storage managed by our identity provider (Supabase Auth)
- Automated dependency-vulnerability monitoring on our codebase
- Encrypted, access-controlled database backups (managed by Supabase)
- Least-privilege access to production data, limited to the company principal
- Sub-processors selected for recognized security certifications (e.g., SOC 2) and bound by data-processing terms
- A documented incident-response process, including breach notification
- Risk assessments for new processing, including a legitimate-interest assessment for product analytics
However, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security.
7. Your Rights
Depending on your location, you may have the following rights:
- Access: Request a copy of your personal data
- Correction: Request correction of inaccurate data
- Deletion: Request deletion of your data
- Export: Request a portable copy of your data
- Objection: Object to certain processing activities
- Withdraw Consent: Withdraw consent where processing is based on consent
To exercise these rights, contact us at support@socsimulator.com.
Account-restriction review. Security rules may flag an account or apply a temporary restriction based on signals such as a known disposable email domain or suspected credential compromise. The restriction screen gives the general reason and available recovery action. You may contest the decision and request meaningful human review at support@socsimulator.com. A reviewer with authority to restore access will consider the request; automated detection is not treated as conclusive evidence by itself.
When you delete your account, we propagate the erasure request to our processors so that data we have shared with them is also removed. This includes Stripe (where legally permitted; payment records may be retained for tax compliance, see Data Retention).
Umami is self-hosted and cookieless and collects only basic pageview and event analytics. PostHog receives pseudonymous product events, pageviews, sanitized errors, and sampled diagnostic session replay under our legitimate interests (GDPR Art. 6(1)(f)).
Your right to object (GDPR Art. 21). You can object to all of this processing by turning off Product analytics in Profile → Settings → Privacy, and you can object to session replay on its own with the Diagnostic session replay switch in the same place. When you are signed in, a replay objection is stored on your account and applies on every device you use. We also honor the Do Not Track and Global Privacy Control signals your browser sends, which switch off analytics and replay without you having to ask us.
When you delete your account, we erase your data from our application database and propagate erasure requests to processors where applicable. Previously collected analytics may remain pseudonymous until the applicable retention period expires.
For EU residents, see our GDPR page for additional information.
8. California Privacy Rights (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"), gives you specific rights regarding your personal information. This section describes those rights and how to exercise them.
Categories of Personal Information We Collect
In the preceding 12 months, we have collected the following categories of personal information, described in more detail in Section 1:
- Identifiers: such as your name, email address, and account identifiers.
- Commercial information: such as your subscription plan and other subscription information.
- Internet or other electronic network activity: such as usage data, device and log information, and how you interact with the Service.
- Geolocation data: approximate location inferred from your IP address. We do not collect precise geolocation.
We Do Not Sell or Share Your Personal Information
We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA. We have not sold or shared personal information in the preceding 12 months.
Your California Rights
- Right to know / access: Request the categories and specific pieces of personal information we have collected about you.
- Right to delete: Request deletion of personal information we have collected from you, subject to legal exceptions.
- Right to correct: Request correction of inaccurate personal information we maintain about you.
- Right to opt out of sale or sharing: Because we do not sell or share personal information, this right is not applicable and no opt-out is necessary.
- Right to limit use of sensitive personal information: Direct us to limit the use of any sensitive personal information to what is necessary to provide the Service.
- Right to non-discrimination: We will not discriminate against you for exercising any of these rights.
Global Privacy Control
We honor the Global Privacy Control (GPC) browser signal as a valid request to opt out of the sale or sharing of personal information for the browser or device that sends it.
How to Exercise Your Rights
To exercise any of these rights, contact us at support@socsimulator.com. We will verify your request and respond within the timeframes required by the CCPA/CPRA. You may use an authorized agent to submit a request on your behalf.
9. Children's Privacy
SOCSimulator is not intended for children under 16. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date. Your continued use of SOCSimulator after changes constitutes acceptance of the updated policy.
11. Contact Us
If you have questions about this Privacy Policy, please contact us:
- Email: support@socsimulator.com
- Company: SOCSimulator LLC
- Address: 30 N Gould St Ste N, Sheridan, WY 82801
Data protection enquiries reach us at the same address, including requests from individuals in the EEA and the UK and correspondence from supervisory authorities. We route them internally to the people responsible for data protection and respond within the time limits set by applicable data protection law. Where a request is lawful and applies to us, we act on it.