Privacy Policy

Last updated: June 2026

1. Overview

SimLytix ("we", "us", or "our") provides web and desktop software for managing Standardized Patient (SP) programs at medical education institutions. This Privacy Policy explains how we collect, use, and protect information when you use SimLytix.

2. Information We Collect

Account information

When you create an account, we collect your name, email address, and password (stored as a secure hash). This information is used to authenticate you and manage your organization's access.

Multi-factor authentication

If you enable two-factor authentication (MFA), a TOTP secret is generated and stored in your account via Supabase Auth. This secret is used only to verify your identity at login and cannot be used to access your account without your password.

Operational data

Data you enter into the application — including SP records (names, email addresses, contact details), scheduling information, event details, payroll records, and department data — is stored securely in your organization's account. This data belongs to your institution.

SP portal tokens

Each SP in your roster is assigned a persistent unique access token used to provide passwordless access to the SimLytix SP portal (simlytix.com/portal). These tokens are stored in your organization's account and are tied to the SP's record. Tokens allow SPs to submit availability without creating a SimLytix account.

Audit log

SimLytix records a log of significant actions taken within the application — such as creating events, assigning SPs, changing team member roles, and sending invitations. Each log entry records the user's name, the action taken, and the timestamp. Audit log entries are automatically purged after 1 year.

Communications log

When SimLytix sends an email on behalf of your organization (such as an assignment confirmation or availability request), a record is created containing the recipient's name, email address, message type, subject line, and timestamp. This log is visible to administrators in the Communications page and is automatically purged after 90 days.

Usage information

We may collect basic error and crash reporting data to help us diagnose and fix issues with the application. This does not include the content of your operational data.

3. How We Use Your Information

  • To provide and maintain the SimLytix application
  • To authenticate users and enforce access controls
  • To send transactional emails such as password resets and team invitations
  • To send SP assignment confirmation emails and availability request emails on behalf of your organization
  • To maintain an audit log of actions taken within your organization's account
  • To respond to support requests sent to support@simlytix.com
  • To improve the application based on error reports

We do not sell, rent, or share your data with third parties for marketing purposes.

4. Data Storage and Security

Your data is stored using Supabase, a cloud database platform hosted on Amazon Web Services (AWS) infrastructure in the United States. Supabase provides:

  • Encryption at rest for all stored data
  • Encryption in transit using TLS
  • Automated daily backups
  • Row-level security ensuring each organization's data is isolated

5. Data Retention

The following automatic retention periods apply to data stored in SimLytix:

  • Audit log entries — automatically purged after 1 year
  • Communications log entries — automatically purged after 90 days
  • Inactive SP records — automatically deleted after 2 years of inactivity (status set to inactive and no updates for 2 years)
  • Payroll and financial records — retained for up to 7 years to comply with applicable employment record-keeping requirements
  • All other operational data — retained for the duration of your subscription

If you cancel your account, you may request deletion of your organization's data by contacting us at support@simlytix.com within 30 days of cancellation.

6. Third-Party Services

SimLytix uses the following third-party services:

  • Supabase — database and authentication infrastructure, including MFA factor storage
  • Resend — transactional email delivery (invites, password resets, SP assignment confirmations, and availability requests). SP names and email addresses are transmitted to Resend solely for the purpose of delivering these emails.
  • Sentry — error and crash reporting

Each of these services has its own privacy policy governing how they handle data.

7. HIPAA

SimLytix is designed for managing Standardized Patient programs, which involve trained actors and employees — not real patients. The application is not intended to store Protected Health Information (PHI) as defined by HIPAA. If your institution requires a Business Associate Agreement (BAA), please contact us to discuss your requirements.

8. Your Rights

Depending on your location, you may have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data
  • Export your data in a portable format

To exercise any of these rights, contact us at support@simlytix.com.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify active users of material changes via email. Continued use of SimLytix after changes constitutes acceptance of the updated policy.

10. Contact

If you have questions about this Privacy Policy, please contact us at support@simlytix.com.