Privacy Policy
Last updated: 2026-07-13
This is a small, solo-operated service. The privacy policy is short and accurate.
Who we are
simulis (simulis.io) is operated by Naran Labs, a sole proprietorship registered in British Columbia, Canada. "We" in this policy means Naran Labs. Contact: snaran@simulis.io.
What we collect
- Email address — when you sign in, so we can issue magic links and contact you about your account.
- IP-hash — your IP address is salted and hashed into an opaque token for anonymous-tier rate-limiting and abuse prevention. We do not store the raw IP.
- Aggregate site analytics — our public marketing pages use Google Analytics 4 to measure page views, scrolling, and link clicks in aggregate, so we can see whether the site works. It is configured with all Google data-sharing options off, no advertising features, no Google Signals, consent defaults that deny ad storage and ad personalization, and the shortest available retention. It is not loaded on your workspace pages (
/brain), so your access key and library never touch it. - Usage counters — per-account request counters used for rate-limiting and abuse prevention.
What we don't collect
- No ad-tech tracking: the analytics described above measure this site only — no advertising IDs, no ads personalization, no remarketing audiences, no fingerprinting, no cross-site tracking.
- No analytics of any kind on your workspace (
/brain). - No chat processing at all — your AI talks to your library directly over MCP; your conversations never pass through us.
Business messaging (Inbox Copilot)
Inbox Copilot is a separate, not-yet-generally-available surface (shown today as a concept demo). Nothing in this section applies unless you explicitly connect it. If you connect a business's Facebook Page or Instagram professional account to our Inbox Copilot (via Meta's official login flow), we additionally process:
- Messages and comments sent to your connected business accounts — received via Meta's APIs so we can draft replies for your approval. Message content, our drafts, and your approve/edit decisions are stored to run your queue, review log, and per-class statistics.
- Your business website content — crawled at your direction to ground drafts in your actual products, prices, and policies. Every drafted claim carries its source.
- Connection tokens — the Meta access tokens you grant, stored encrypted and used only to receive and send messages on the accounts you connected.
We act as a processor of your customers' messages on your behalf. Platform data is handled in accordance with Meta's Platform Terms; we do not sell it, use it for advertising, or use it to train models beyond serving your account. Disconnecting your account stops all processing; see deletion below.
Data deletion
To delete your data:
- Your whole workspace: self-serve, immediate, and irreversible — open your brain → Connect AI tab → Danger zone → type the confirmation phrase. This deletes your library, every platform connection (access tokens are revoked at the platform), all synced data, and your access key.
- A single ad-platform connection: the Disconnect option on that platform's card (same tab) revokes the stored token and deletes all data synced from that platform immediately, leaving the rest of your workspace intact. You can also remove the simulis app from your platform settings (e.g. Facebook Settings → Business integrations) — syncing stops at once.
- By email: snaran@simulis.io with the subject "Delete my data" — we confirm deletion within 30 days.
Sub-processors
- Vercel — hosting and serverless functions.
- Upstash (Redis) — session and quota storage.
- Google Analytics — aggregate site-usage measurement on public marketing pages only, configured as described above.
- Resend — transactional email (sign-in links, deletion confirmations).
Retention
Account data lives until you delete the account. After deletion, a tombstone marker is kept for 30 days to prevent immediate re-registration with the same email; the data row itself is replaced when you re-register or naturally expires shortly thereafter.
We send only transactional email — sign-in links and deletion confirmations. No marketing email.
Cookies
gs_session — an HttpOnly session token, set when you sign in; strictly necessary for authentication. On public marketing pages, Google Analytics sets first-party _ga cookies to count visits in aggregate; these are not used for advertising and are not set on /brain.
Government and legal requests
If a public authority requests user data from us, our policy is:
- Legality review: every request is reviewed for legal validity — proper legal basis, correct jurisdiction, and appropriate scope — before any response is given.
- Challenge: we contest requests we consider unlawful or overbroad, through objection to the requesting authority or the courts where available.
- Data minimization: where a valid request compels disclosure, we disclose only the minimum information necessary to comply.
- Documentation: we keep a record of every request received, our legal assessment, the parties involved, and what (if anything) was disclosed.
We have never received a national security request. Where the law permits, we notify affected users before disclosing their data.
Your rights
Delete your workspace self-serve as described under data deletion above. For specific access or correction requests, email snaran@simulis.io.
Contact
Email snaran@simulis.io, or reply to your sign-in email — both go to a real inbox.
simulis is a product of Naran Labs, British Columbia, Canada.