SimAtomic
  • How it works
  • Use cases
  • Pricing
  • Docs
Schedule Discovery Call Login

Privacy Policy

Last Updated: September 23, 2026

1. Who Is Responsible

SimAtomic, LLC ("SimAtomic," "we," "us") provides the SimAtomic website, account portal, molecular simulation services, APIs, and assistant integrations. This Privacy Policy explains how we process personal data when you use these services or contact us. Our privacy contact is info@simatomic.com.

SimAtomic is the controller for account administration, billing, inquiries, and service security. Where we process personal data in customer content solely on a customer's instructions, the customer determines the purposes and our processor obligations must be covered by the processing terms required by applicable law. Those terms may form part of a service agreement. This notice does not replace them; an individual account does not itself require a customer processing agreement.

This is a privacy notice, not a request for consent. Using SimAtomic does not constitute consent to optional marketing, tracking, or international transfers.

2. Information We Use and Why

  • Account and sign-in: Google provides your account identifier, name, and email address when you sign in. We also maintain SimAtomic account, workspace and project identifiers, permissions, API access records, and authentication credentials. These let us identify your account, protect access, and provide the service. We do not receive your Google password.
  • Discovery calls and support: we receive your name, email, message, and any project details you choose to provide. We use them to respond, arrange calls, and investigate issues. The website contact form sends your submission through Formspree.
  • Files and compute jobs: we process uploaded molecular structures and other input files, filenames, simulation settings, job identifiers, status, timestamps, results, and usage records to run jobs, deliver results, troubleshoot, and account for compute credits. Avoid including unnecessary personal data in filenames, files, or support messages.
  • Payments: when you pay, we use account and billing contact details, transaction references, purchased credits, balances, and usage records to administer the purchase. Stripe processes payment details on its payment page; do not send card details through our contact form or an assistant chat.
  • Technical and security information: service and error logs can contain account or job identifiers, filenames, request information, timestamps, and error details. Hosting and delivery systems also process network information, including IP addresses, to receive requests and return responses; their access logs may record it. We use operational information to deliver, secure, and troubleshoot the service, not for advertising profiles or IP-based geolocation.

We do not install advertising pixels or audience analytics trackers on the website or in the app. We do not sell personal data or share it for cross-context behavioral advertising. Technical logs and compute usage records are separate from advertising or browsing analytics.

Account identity and authentication information are needed for a signed-in account; the inputs needed for a job must be supplied to run it. A name, reply address, and message are required to use the discovery-call form. You choose whether to use these features. Additional project context is optional.

3. GDPR Legal Bases

Where the GDPR applies, we rely on the following bases for our processing as controller:

  • Contract or steps you request before a contract: creating and administering your personal account, providing requested jobs and support, arranging a requested discovery call, and administering your purchases.
  • Legitimate interests: managing relationships with business contacts and users of organization accounts, maintaining a secure and reliable service, investigating technical issues and abuse, and establishing or defending legal claims. These interests are subject to your rights and a balancing assessment; they are not a blanket permission to collect additional data.
  • Legal obligations: applicable accounting, tax, lawful disclosure, and data protection requirements.
  • Consent: optional activities for which the law requires consent. If we introduce marketing communications or non-essential tracking requiring consent, we must ask separately before starting. You may withdraw consent without affecting earlier lawful processing.

We do not use your personal data for profiling or solely automated decisions that produce legal or similarly significant effects about you. Automated scientific calculations and routine credit accounting are used to provide the features you request.

4. Cookies and Browser Storage

The public website does not set its own advertising or analytics cookies. The account app does use authentication cookies and browser storage:

  • Google sign-in security cookie: __Host-simatomic-google-state protects the sign-in flow against request forgery. It expires after 10 minutes and is cleared when the callback is handled.
  • Administrator session cookie: __Host-simatomic-admin is used for authorized administrator access and expires after 1 hour. Both authentication cookies are marked Secure, HttpOnly, and SameSite=Lax.
  • Account local storage: the app stores the signed-in account and session under accessToken. Ordinary sign-in credentials expire after 8 hours; the portal clears them on sign-out or when it detects expiry. Credential expiry does not itself erase storage from an inactive browser.
  • Workspace and interface storage: local storage remembers working state such as simulation selections, saved job references, and tour progress. Session storage holds temporary interface state. Session storage normally lasts for the tab's session; local storage has no automatic browser expiry and remains until cleared by the app or your browser.

Sign-in and security storage supports features you request. Other storage must remain limited to what is necessary for the requested feature, or use consent where required. You can sign out and clear site data in your browser; this may remove saved settings and require you to sign in again. Clearing browser storage does not delete your server-side account or files.

Some pages load fonts, styles, or visualization libraries from third-party delivery services, including Google Fonts, Cloudflare, and jsDelivr. Those requests disclose network information such as your IP address and browser request headers to the provider. Google sign-in and Stripe's separate payment pages also have their own privacy and storage practices.

5. ChatGPT, Codex, and Other Connected Assistants

When you choose to connect an assistant, SimAtomic receives the tool requests, selected files or file URLs, job settings, and account authorization needed to perform the requested actions. The connection is not permission to collect your full chat history. We process the inputs and resources passed to our tools; include only the information needed for your task.

The assistant provider, such as OpenAI for ChatGPT and Codex, receives the responses to those requests. These can include job identifiers and status, requested file or project information, results, error messages, and links to downloads or analysis dashboards. Files and results may contain confidential research information. Review what you authorize the assistant to upload or retrieve. A download or dashboard link can grant access to its content, so share it only with intended recipients.

We use data received through a connection to provide and secure the requested service, deliver support, and meet legal obligations. We do not use it for advertising profiles or to train AI models. The assistant provider's handling of conversations and returned data is governed by its own terms, privacy policy, and your account settings.

Do not send passwords, API keys, authentication codes, payment card information, government identifiers, or patient data in chat or tool inputs. Authenticate only through the designated secure sign-in or authorization flow.

You can disconnect SimAtomic in the assistant's settings, revoke your API key in the SimAtomic account portal, or contact us for help. Disconnecting does not stop already submitted jobs or delete previously exchanged data. To request deletion from SimAtomic, email info@simatomic.com; contact the assistant provider separately about copies it holds.

6. Who Receives Information

Access is limited to the purposes described here. The relevant recipients include:

  • SimAtomic personnel and contractors who operate the service or handle support.
  • Infrastructure providers, including Google/Firebase for website hosting, AWS for application infrastructure and account records, and Scaleway for compute or storage used by simulation jobs.
  • Google for sign-in, Formspree for contact-form submissions, and Stripe for payments.
  • Google email services for receiving mail sent to our SimAtomic addresses. This includes sender and recipient details, message content, and attachments needed to handle inquiries, support, and privacy requests.
  • Content-delivery providers described in Section 4, and an assistant provider when you enable the connection described in Section 5.
  • Your organization's authorized administrators and collaborators, according to the workspace access you or your organization grant.
  • Authorities, professional advisers, or other recipients where disclosure is required by law or necessary and lawful to protect rights, address abuse, or handle a business transfer subject to appropriate confidentiality and data protection requirements.

Where a provider processes data on our behalf, applicable law requires appropriate processing terms and safeguards. Some providers also act as independent controllers for their own sign-in, payment, security, or other services, as explained in their privacy notices.

7. Retention and Deletion

We handle deletion manually. To request account closure, an export, or deletion, email info@simatomic.com. Our standard retention schedule is:

  • Account records, project files, inputs, and results: kept while your account or project is maintained to provide the service. We remove the relevant data from active systems within 30 days of account closure or receipt of a deletion request, or sooner where the law requires, subject to the exceptions below. We may need proportionate identity verification; any legally permitted extension is handled as described in Section 9.
  • Discovery-call inquiries: up to 6 months after the last substantive exchange if no customer relationship follows. Information needed for an ongoing customer relationship follows the relevant account, support, or billing period instead.
  • Support correspondence: up to 12 months after the issue is resolved or the last substantive exchange, whichever is later.
  • Operational and security logs under our control: up to 90 days after the record is created. A necessary subset may be kept longer for a specific security incident or legal claim under the exceptions below.
  • Billing and accounting records: up to 7 years after the end of the relevant financial year where needed for accounting, tax, or legal claims. This does not extend the retention of research files or unrelated correspondence. A different period applies where applicable law requires it.
  • Privacy-request records: a minimal record of the request, response, and action taken for up to 3 years after completion, to demonstrate how we handled it. We delete additional identity-verification material once it is no longer needed for verification.
  • Browser data: the cookie lifetimes and local-storage behavior are described in Section 4. Clearing browser storage or letting a link or credential expire does not delete the underlying server-side files or account.

Backups and provider copies. Recovery copies that we control are removed within 90 days after deletion from active systems. We also request deletion from providers processing the data on our behalf. Removal from a provider's residual systems follows its applicable deletion terms; for example, Google's Cloud Data Processing Addendum allows up to 180 days after deletion becomes unrecoverable by the customer, subject to legal requirements. During the remaining recovery period, copies are restricted from ordinary use; if a backup is restored, we reapply the deletion before returning the data to ordinary use.

Limited exceptions. We delete data sooner when it is no longer needed. We retain only the records necessary for a specific legal obligation, unresolved dispute, fraud or security investigation, or legal claim beyond the standard period. We review such exceptions and explain any applicable refusal, extension, or continued retention when responding to a deletion request, unless prohibited by law. These exceptions do not permit indefinite retention of all account data.

The schedule covers copies we hold in our service, contact-form inbox, support mailbox, and working files. Disconnecting an assistant does not close your SimAtomic account, cancel jobs, or delete data already exchanged. An assistant or payment provider acting independently keeps its own records under its own policy; contact that provider about those records.

8. International Processing

SimAtomic is based in the United States. We and our providers can process information in the United States and other countries where the relevant service operates. Storage location and remote access depend on the provider and feature; we do not promise that all information remains within the European Economic Area (EEA).

The standard terms of our infrastructure and payment providers include the following transfer arrangements, where applicable to the service and data involved:

  • AWS: its GDPR processing addendum and Standard Contractual Clauses apply automatically to customers subject to the GDPR.
  • Firebase Hosting: its Data Processing and Security Terms provide for Google's applicable transfer solution and Standard Contractual Clauses where required.
  • Scaleway: its processing agreement forms part of the service contract and addresses transfers outside the EU and Standard Contractual Clauses where required.
  • Stripe: its Data Transfers Addendum provides for the Data Privacy Framework where applicable and Standard Contractual Clauses as a fallback. Stripe has both processor and independent-controller activities.

Formspree describes its use of Standard Contractual Clauses in its security statement. Google's email services have processing and transfer terms that apply according to the relevant account agreement. Google sign-in and connected assistant providers also process information under their own applicable privacy notices and terms.

For transfers subject to GDPR Chapter V, an applicable adequacy decision or other lawful transfer safeguard is required, together with any necessary assessment and supplementary measures. Acceptance of the Terms of Service or this notice is not consent to an international transfer. Contact info@simatomic.com for information about the destinations and safeguards relevant to your data or to request a copy of applicable contractual safeguards, with necessary confidential details redacted.

9. Your Rights and Choices

Where the GDPR applies, you may request access to your personal data, correction, erasure, restriction, and portability, subject to the conditions in that law. You may object to processing based on legitimate interests for reasons relating to your situation, and to direct marketing at any time. Where processing relies on consent, you can withdraw it at any time.

Email info@simatomic.com to make a request. We respond without undue delay and normally within one month. If a request's complexity or number requires up to two additional months, we will explain the extension within the first month. Requests are normally free; any lawful refusal or fee must be explained. We may ask for proportionate information if we have reasonable doubts about identity; do not send identity documents unless needed and specifically requested through a suitable secure channel.

You have the right to complain to a supervisory authority, particularly in the EEA country of your habitual residence, workplace, or the alleged infringement, and to seek a judicial remedy. You do not have to contact us first. Find an authority in the EDPB directory.

If we process the data on an organization's behalf, we will assist or direct your request to the relevant controller. We remain responsible for requests concerning processing for which we are the controller. Account suspension or termination does not remove these rights.

Residents of other jurisdictions may also have access, correction, deletion, and portability rights. Where California privacy law applies, we do not sell or share data for cross-context behavioral advertising, and there is no such activity to opt out of through Global Privacy Control. You may use an authorized agent subject to appropriate verification, and we will not discriminate against you for exercising applicable privacy rights.

10. Security and Sensitive Information

We use access controls, authenticated requests, and secure connections to protect personal data. Keep credentials and download links confidential. No service can guarantee absolute security.

SimAtomic is a scientific research tool, not a service for patient records or other sensitive personal data. Do not upload identifiable health, genetic, biometric, or other special-category personal data. Molecular research data is not necessarily personal data, but material linked to an identifiable person may be. Our account service is intended for adults aged 18 or older; contact us if a child has supplied personal data so we can address it.

11. Changes and Contact

We will update this notice when our practices change and provide any notice or separate consent required before new processing begins. The date above identifies the current version.

For privacy questions, requests, or concerns, contact SimAtomic, LLC at info@simatomic.com.

Registered office: 131 Continental Dr, Suite 305, Newark, DE 19713, USA.

© 2026 SimAtomic. All rights reserved.

Terms of Service Privacy Policy