Last updated: June 2026
SimLytix ("we", "us", or "our") provides web and desktop software for managing Standardized Patient (SP) programs at medical education institutions. This Privacy Policy explains how we collect, use, and protect information when you use SimLytix.
When you create an account, we collect your name, email address, and password (stored as a secure hash). This information is used to authenticate you and manage your organization's access.
If you enable two-factor authentication (MFA), a TOTP secret is generated and stored in your account via Supabase Auth. This secret is used only to verify your identity at login and cannot be used to access your account without your password.
Data you enter into the application — including SP records (names, email addresses, contact details), scheduling information, event details, payroll records, and department data — is stored securely in your organization's account. This data belongs to your institution.
Each SP in your roster is assigned a persistent unique access token used to provide passwordless access to the SimLytix SP portal (simlytix.com/portal). These tokens are stored in your organization's account and are tied to the SP's record. Tokens allow SPs to submit availability without creating a SimLytix account.
SimLytix records a log of significant actions taken within the application — such as creating events, assigning SPs, changing team member roles, and sending invitations. Each log entry records the user's name, the action taken, and the timestamp. Audit log entries are automatically purged after 1 year.
When SimLytix sends an email on behalf of your organization (such as an assignment confirmation or availability request), a record is created containing the recipient's name, email address, message type, subject line, and timestamp. This log is visible to administrators in the Communications page and is automatically purged after 90 days.
We may collect basic error and crash reporting data to help us diagnose and fix issues with the application. This does not include the content of your operational data.
We do not sell, rent, or share your data with third parties for marketing purposes.
Your data is stored using Supabase, a cloud database platform hosted on Amazon Web Services (AWS) infrastructure in the United States. Supabase provides:
The following automatic retention periods apply to data stored in SimLytix:
If you cancel your account, you may request deletion of your organization's data by contacting us at support@simlytix.com within 30 days of cancellation.
SimLytix uses the following third-party services:
Each of these services has its own privacy policy governing how they handle data.
SimLytix is designed for managing Standardized Patient programs, which involve trained actors and employees — not real patients. The application is not intended to store Protected Health Information (PHI) as defined by HIPAA. If your institution requires a Business Associate Agreement (BAA), please contact us to discuss your requirements.
Depending on your location, you may have the right to:
To exercise any of these rights, contact us at support@simlytix.com.
We may update this Privacy Policy from time to time. We will notify active users of material changes via email. Continued use of SimLytix after changes constitutes acceptance of the updated policy.
If you have questions about this Privacy Policy, please contact us at support@simlytix.com.