Privacy Policy
We collect only what we need, we protect it rigorously, and we never sell it.
Effective date: April 7, 2026
1. Overview
SimPath, Inc. ("SimPath", "we", "our", or "us") operates the SimPath platform — an AI-powered therapy simulation environment designed for clinical psychology students and mental-health professionals in training. This Privacy Policy explains how we collect, use, disclose, and safeguard personal information when you access or use our website, web application, and related services (collectively, the "Service"). By using the Service you agree to the practices described here. If you disagree, please discontinue use and contact us to delete your account.
2. Information We Collect
2.1 Account & Profile Data
- Email address (required for authentication)
- Password (securely hashed using industry-standard encryption — we never store plaintext passwords)
- Preferred display name
- Focus area (e.g., Therapy or HR designation)
- How you heard about SimPath (optional, used for internal analytics)
- Subscription plan and billing cycle (Free, Plus, or Neural)
- Communication consent flag (whether you opted into product updates)
2.2 Session & Practice Data
- Text messages exchanged during simulation sessions
- Voice audio captured during voice-enabled sessions — audio is streamed for real-time transcription and is not persisted to disk beyond the duration of active processing
- Session scoring data (therapeutic competency scores across four dimensions)
- AI client persona selections
2.3 Career Application Data
If you submit a job application through our Careers portal, we collect your name, email address, phone number, location, resume, cover letter, LinkedIn and portfolio URLs, years of experience, salary expectations, and availability.
2.4 Usage & Technical Data
- IP address, browser type, and operating system (collected by our hosting infrastructure)
- Pages visited, features used, and time spent (aggregated, not individually profiled)
- Admin action logs for users with administrator access
3. How We Use Your Information
- To create and manage your account and authenticate your identity
- To operate the simulation platform and deliver AI-powered session responses
- To transcribe voice input and return real-time responses using industry-standard AI APIs
- To calculate and display post-session competency scores
- To send product updates and announcements where you have consented
- To process and review job applications
- To detect, investigate, and prevent fraudulent or abusive activity
- To comply with legal obligations and enforce our policies
- To improve platform reliability through aggregated, de-identified analytics
4. We Do Not Train AI Models on Your Data
We do not use your session conversations, voice audio, or any personally identifiable information to train, fine-tune, or improve AI models — ours or our providers'. Your practice data is not a product. Session data processed by our AI service providers is governed by their standard API data usage policies, which prohibit use of API inputs and outputs for model training by default.
5. Third-Party Services
We share data with the following sub-processors solely to operate the Service:
| Provider | Purpose | Data Shared |
|---|---|---|
| Authentication & Database Provider | Authentication, database, and file storage | Account data, session data, application data |
| AI Service Provider | AI responses, voice transcription, and real-time interactions | Session messages, voice audio (ephemeral), session context |
| Infrastructure & Hosting Provider | Web hosting and serverless infrastructure | Request metadata (IP, headers) — no application data stored |
We do not sell, rent, or trade your personal information to any third party for advertising or marketing purposes.
For detailed information about our specific service providers and processors (such as for Data Processing Agreements or compliance audits), we maintain a confidential list of all processors and sub-processors. Request access by emailing [email protected] with your compliance requirements, and we will provide this information under a standard Non-Disclosure Agreement.
6. Data Retention
- Account data is retained for the lifetime of your account. Upon account deletion we remove your personal identifiers within 30 days, subject to any legal hold obligations.
- Session transcripts and scores are retained to power your Progress dashboard. You may request deletion at any time.
- Voice audio is processed in-memory during the session and is not persisted to storage.
- Job application data is retained for up to 12 months after a hiring decision, unless you request earlier deletion.
- Server logs are retained for up to 90 days for security and debugging purposes.
7. Security
We protect your data using TLS 1.3 in transit and AES-256 at rest. Authentication is managed via Supabase using token-based session handling to authenticate requests. We apply row-level security on all database tables, rate-limit authentication endpoints, restrict CORS to approved origins, and enforce strict Content Security Policy headers. Our infrastructure is hosted on SOC 2 Type II certified systems. For a full overview, see our Security page.
8. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access — request a copy of the personal data we hold about you
- Rectification — correct inaccurate or incomplete data
- Erasure — request deletion of your account and associated personal data
- Portability — receive your data in a structured, machine-readable format
- Objection / Restriction — object to or restrict certain processing activities
- Withdraw consent — opt out of marketing communications at any time via account settings or by emailing us
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days. For EEA/UK residents, you also have the right to lodge a complaint with your local supervisory authority.
9. GDPR & International Transfers
If you are located in the European Economic Area (EEA) or United Kingdom, our legal basis for processing your data is: (a) performance of a contract (to provide the Service), (b) your consent (for marketing communications), or (c) legitimate interests (security, fraud prevention, and product improvement). When transferring data outside the EEA we rely on Standard Contractual Clauses and our sub-processors' data processing agreements. All our service providers maintain appropriate safeguards for international data transfers consistent with GDPR requirements.
10. California Residents (CCPA)
If you are a California resident, you have the right to know what personal information we collect, the right to delete it, and the right to opt out of its sale. We do not sell personal information. To submit a verifiable consumer request, email us at [email protected] with the subject line "CCPA Request".
11. Minors
SimPath is intended for adults (18+) enrolled in accredited academic or professional training programs. We do not knowingly collect personal information from children under 13. If we learn that we have inadvertently collected such information, we will delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email (to registered users who have opted in) and by posting a notice on the Service at least 14 days before the change takes effect. Continued use after the effective date constitutes acceptance of the revised policy.
13. Contact
For privacy-related questions, requests, or concerns, contact us at: [email protected].
SimPath, Inc.
[email protected]