Privacy Policy
Last updated: 2026-09-24
This policy explains what TEX Vietnam Technology Joint Stock Company (Công ty cổ phần công nghệ TEX Việt Nam, "TEX Vietnam JSC"), trading as TEXVN ("Simulic", "we", "us"), does with personal data when you use simulic.com and its related domains (the "Service"). TEX Vietnam JSC is the data controller. The short version: we keep only what an account needs, we keep nothing about students, and you can export or delete everything yourself.
1. Students: no data
- Students never create an account and never sign in. They open simulations through a link, QR code or embed that their teacher shares.
- When a link is opened, our server checks that the link is still active and returns the simulation. It does not set a cookie, does not fingerprint the device, does not store the IP address, and does not ask for a name, email or any other information.
- The only thing recorded is a count: how many times each link was opened, per simulation and per day. This number is shown to the teacher who made the link. It cannot be traced back to any person.
- Simulations themselves run in a browser sandbox that cannot contact the network, so a simulation cannot collect or send data.
- We never send email to students and never collect student email addresses, including from teachers. If a student or parent contacts us directly, we use the message only to answer it.
2. What we collect from account holders
| Data | Why | Where it comes from |
|---|---|---|
| Email address | To sign you in (we send a sign-in link) and to contact you about your account | You, or your Google account if you sign in with Google |
| Name, country, subject you teach | To show your name in the Service and to understand who uses Simulic | You |
| Preferred interface language | To show the Service and send emails in your language | You (language menu) or your browser |
| Google account identifier | To recognise you when you sign in with Google | |
| Confirmation that you are 18 or older and that you accepted the Terms, with the time | Legal requirement | You |
| Share links you create: simulation, language, settings, title, whether the link is active, and the daily count of how often each link was opened | To run and manage your links | You and the Service |
| Simulations you create with AI: your descriptions (prompts), the generated simulation code and text, versions, and which simulation a remix was based on | To create, store, show and deliver your simulations | You and the AI model |
| Credit history: credits granted, used and refunded, with the job they relate to | To keep your balance correct | The Service |
| Purchase records: transaction reference, credit pack, amount and currency | To add credits to your account and to keep accounting records | Paddle, our payment processor |
| Problem reports you send, with the message and an optional contact email | To fix simulations and answer you | You |
| Time of account creation and last sign-in | To manage inactive accounts and security | The Service |
We do not collect your payment card or bank details: Paddle handles payment as the merchant of record and only tells us that a purchase succeeded.
3. How we use it
- To provide the Service: sign-in, your simulations, your links, credits and purchases. Legal basis: performance of our contract with you.
- To send transactional email: sign-in links, and the "email me this link" message you request. We do not send marketing email unless you ask for it.
- To keep the Service secure and to prevent abuse, for example rate limits on sign-in requests and on simulation downloads. Legal basis: our legitimate interest in running a safe service.
- To understand overall use of the Service through aggregate statistics (numbers per day), never individual behaviour profiles. Legal basis: legitimate interest.
- To comply with law, for example tax records for purchases.
We do not sell personal data, do not show advertising, and do not use your data or your simulations to train AI models.
4. Cookies and analytics
- The Service sets one cookie,
simulic_session, when you sign in. It keeps you signed in for up to 30 days and contains no tracking. It is strictly necessary, so no consent banner is shown. Signing out removes it. - During Google sign-in, Google sets a short-lived
g_csrf_tokencookie to protect the sign-in form. - When you buy credits, the Paddle checkout runs in a Paddle window and may set Paddle's own cookies under Paddle's privacy policy.
- Visitor numbers for the public pages are measured with Cloudflare Web Analytics, which uses no cookies and no persistent identifiers. Nothing is measured inside simulations or on shared links.
5. Who processes data for us
| Provider | What for | Where |
|---|---|---|
| Cloudflare, Inc. | Hosting of the public pages and simulation files, network security, storage of simulations you create, cookieless analytics | Global network; storage in the United States |
| OVHcloud | Hosting of the application server and database | United States |
| Paddle.com Market Ltd and affiliates | Payments, invoices, taxes and refunds for credit packs (merchant of record) | United Kingdom, United States |
| Anthropic, PBC | The AI model that writes simulations. We send your description and, for a remix, the source simulation. Anthropic does not use API data to train its models. | United States |
| Google LLC | Sign in with Google (only if you choose it); the "Share to Google Classroom" button | United States |
| Microsoft Corporation | The "Share to Microsoft Teams" button (only if you use it) | United States |
| Our email delivery provider | Sending sign-in links and the messages you request | United States |
Each provider acts under a contract that limits what it may do with the data. Because our servers are in the United States, your data is transferred there. For users in the European Economic Area, the United Kingdom and Switzerland, transfers rely on the providers' standard contractual clauses or on their participation in the EU-U.S. Data Privacy Framework.
6. How long we keep data
- Your account, links, simulations and credit history: as long as your account exists.
- Sign-in links: 15 minutes, then only a one-way hash for a short time to prevent reuse.
- Purchase records: up to 10 years after the purchase, as required by accounting and tax law, even after the account is deleted. These records are then kept without your name or email.
- Problem reports: until the problem is fixed, then up to 2 years.
- Server logs used for security: up to 30 days.
- Aggregate statistics contain no personal data and are kept indefinitely.
7. Your rights
From the Account page you can, at any time and without asking us:
- See and correct your name, country and subject.
- Export everything we hold about you as a JSON file: profile, links, link counts, simulations (including prompts and code), credit history, purchases and reports.
- Delete your account. This immediately removes your profile, links, simulations and their files, credit history and pending reports. Links you shared stop working. Purchase records are kept in anonymised form as described above.
Depending on where you live, you may also have the right to object to or restrict certain processing, to data portability, and to complain to a supervisory authority (in the EU, your national data protection authority; in the UK, the Information Commissioner's Office). If you have any question or request that the Account page does not cover, email us at [email protected]. We answer within 30 days.
Residents of California and other US states with privacy laws: we do not sell or share personal data for advertising, and we do not use it for profiling with legal effects. The rights above cover your rights to know, delete and correct.
8. Children
Accounts are only for adults. We do not knowingly collect personal data from anyone under 18. Students use Simulic through their teacher's links without giving us any information (section 1). If you believe a child has created an account, email us and we will delete it.
9. Security
All connections use HTTPS. Sign-in uses one-time links instead of passwords, so there is no password to steal. Sign-in tokens are stored only as hashes. Simulation files are served from separate domains in a browser sandbox. Access to the production server and database is limited to the TEXVN team and protected by keys. If we discover a breach affecting your data we will inform you and, where required, the authorities.
10. Changes to this policy
We may update this policy when the Service changes. The date at the top shows the latest version. For material changes we will tell you by email or when you next sign in.
11. Contact
TEX Vietnam Technology Joint Stock Company (Công ty cổ phần công nghệ TEX Việt Nam, "TEX Vietnam JSC").
Registered address: No. 367 - E16, Group 11, Dong Anh Town, Dong Anh District, Hanoi, Vietnam (Số 367 - E16, Tổ 11, Thị Trấn Đông Anh, huyện Đông Anh, Hà Nội).
Email: [email protected].