Trust & legal
Privacy Policy
What the current application stores and processes, and the controls available to users.
Guest use
Guest simulations do not require an account. Project autosaves and tutorial status are stored in this browser's local storage. Clearing site data removes those local records.
Google Sign-In and Firebase
If you sign in, Firebase Authentication processes your Google account identifier, name, and email address. YDK Simu Lab stores your user identifier, profile preferences, policy acceptance version and time, tutorial state, and cloud projects in Firestore. The application does not store your Google profile image in Firestore.
Feedback
The public feedback form prepares a message to support@ydksimulab.com in your installed email application. The website does not transmit or store that draft. Include only the category, subject, message, optional reproduction details, optional page or experiment name, and optional reply email needed for support.
AI assistant
The assistant requires Google sign-in. The request text, selected interface language, and Firebase ID/App Check tokens are sent only to the protected endpoint for verification; tokens are not sent to Gemini or stored in assistant logs. If you include the current experiment, Gemini receives only a bounded educational summary of approved object types, display names, selected physical values, constraints, measurements, graph summaries, and simulation settings—not identity data, raw object IDs, private project metadata, saved projects, or source code. The Gemini key stays on the server. Rate limiting uses short-lived one-way network-address and account-identifier hashes; minimized abuse records contain a reason category and expiry time, not request text, original addresses, email, project contents, credentials, or model output. Do not submit personal data or secrets.
Subscriptions and Dodo Payments
If you start a paid plan, Dodo Payments processes checkout, payment details, taxes, invoices, receipts, refunds, and its hosted customer portal. YDK Simu Lab stores minimized private mappings between your Firebase account and Dodo Payments customer/subscription records, verified status and billing-period dates, recurring-consent version/time/locale, and processed-event identifiers or hashes. YDK Simu Lab does not store card numbers or full webhook payloads.
Devices, favourites, and watermark settings
The service stores a one-way hash of a random installation registration, a friendly device name, first-seen and last-active dates, ordered favourite object identifiers, and watermark preferences. It does not use invasive hardware or browser fingerprinting.
Cookies, storage, and analytics
Firebase and Google Sign-In may use essential browser storage or cookies for authentication and security. We use Vercel Web Analytics and Speed Insights to understand page visits and performance, such as page views, browser/device performance metrics, and general usage trends. We use this information to improve YDK Simu Lab. We do not use it to collect passwords or private experiment content.
Retention and controls
Local records remain until cleared. Cloud profile and project records remain until deleted or the service's retention process removes them. Signed-in users can delete projects individually and can request deletion of their YDK Simu Lab cloud data and authentication record from Profile settings.
Children and regional rights
The interface uses neutral, age-appropriate language, but the service owner has not established a verified age-assurance or parental-consent program. Schools, guardians, and the owner must assess child-privacy, student-record, international-transfer, and regional legal requirements before deployment.
Security and contact
Access rules restrict private Firestore records to their authenticated owner, but no online system is risk-free. Send privacy questions, access requests, and deletion requests to privacy@ydksimulab.com. Use support@ydksimulab.com for general technical help.