Privacy Policy
Privacy Policy
This Privacy Policy explains what personal information SimuCrew collects (including Google account data via Supabase Auth), how we use it, the legal basis for processing, who we share it with, how long we keep it, and the rights you can exercise. Operator: SimuCrew. Contact: hello@simucrew.com.
Operator and who we are
SimuCrew (https://simucrew.com) is operated by SimuCrew. In this Privacy Policy, “we”, “us”, and “our” mean SimuCrew. Our contact email for privacy, data-subject requests, and Google user-data inquiries is hello@simucrew.com.
Our Terms of use are published at https://simucrew.com/terms. This Privacy Policy is published at https://simucrew.com/privacy. You can read both pages without signing in.
What SimuCrew is (and is not)
SimuCrew is an AI audience simulation tool for marketing and creative feedback. You paste a draft (copy, image, public link, or short video description), and we return simulated audience comments plus a summary so you can fix blind spots before publishing.
SimuCrew does not create, edit, host, or distribute non-consensual intimate imagery (NCII), sexual deepfakes, deepfake pornography, or any sexual content involving minors. We do not offer image- or video-generation features for fabricating real people’s likenesses in intimate contexts. The product is marketing and audience-feedback rehearsal only.
We do not sell personal information. We do not use Google user data for advertising.
Information we collect
We collect only what we need to run accounts, security, billing, and the simulation product.
Google account information (when you choose Continue with Google). Sign-in is provided by Supabase Auth. When you connect Google, Google authenticates you and, with your consent, shares with our auth provider the basic profile data needed to create or link your SimuCrew account. That typically includes your email address, your name, your profile photo if Google provides one, and a stable Google account subject / user id. We do not request Google scopes beyond what Supabase Auth needs for this basic profile sign-in. We do not receive your Google password.
Email sign-in. You may instead create and use an account with an email one-time code (OTP). In that case we store the email address you provide and verification metadata needed to complete sign-in.
Account and product data. We also store: when you joined and last signed in; language preference; optional display name; plan and entitlement status; rehearsal history (submitted copy or link text, file names and descriptions — not raw video file bytes — plus the AI thread and summary); team membership on Main Stage; and technical cookies required for authentication and CSRF protection.
Payment data. Card numbers are collected and processed by Stripe on Stripe-hosted pages. We never see or store your full card number. We keep plan status, renewal dates, and Stripe customer / subscription references.
Technical and security data. Server logs and similar operational records may include IP address, user agent, and request timing for security, abuse prevention, and debugging.
How we use it
We use Google account data and other account data to authenticate you, create and maintain your SimuCrew account, keep you signed in across sessions and devices, show your display name and (if provided) profile photo in the product, enforce plan limits, save and restore your rehearsals, send transactional email (sign-in codes and team invites), process paid subscriptions, and secure the service against abuse.
We use rehearsal content so the product can run the AI audience simulation and show you history and summaries. Draft text and related inputs are sent to AI model providers only to generate simulated comments and summaries for your rehearsal.
We do not sell personal information. We do not use Google user data for advertising, for unrelated profiling, or to train public foundation models for products that are not SimuCrew. We do not use Google user data to create NCII or any sexual deepfakes.
Legal basis
Where the GDPR or similar laws apply, we process personal data on these bases: (1) performance of a contract — creating your account, providing SimuCrew features you request, and delivering paid plans; (2) legitimate interests — securing the service, preventing abuse, understanding aggregate reliability of the product, and improving clear product defects, balanced against your rights; (3) legal obligation — keeping records required for tax, accounting, or lawful requests; and (4) consent — where we rely on your consent for a specific optional processing step (for example, connecting Google sign-in), which you may withdraw by disconnecting Google access or deleting your account, without affecting processing already completed lawfully before withdrawal.
If you are in a jurisdiction that requires a different framing, the same practical purposes apply: account operation, product delivery, security, billing, and compliance.
Sharing (processors — we do not sell your data)
We share personal data only with service providers that process it on our instructions to run SimuCrew, not to sell it. Current processors include:
Supabase — Postgres database and Supabase Auth, including the relay of Google sign-in identity data to create sessions.
Vercel — website and application hosting.
Resend — transactional email such as sign-in codes and team invites.
Stripe — subscription and credit-pack payments.
OpenRouter and its underlying model hosts — AI generation of simulated comments and summaries from the rehearsal inputs you submit.
We do not sell personal information. We do not share Google user data with third parties for advertising or for unrelated AI training. Some processors are located in, or store data in, the United States and other countries. We use contracts and, where required, appropriate transfer mechanisms with those processors.
We may disclose information if required by law, regulation, legal process, or to protect the rights, safety, and integrity of users and the service.
Where and how data is stored
Account records, sessions, entitlements, and saved rehearsals are stored in our Postgres database hosted by Supabase. Authentication state, including Google-linked identities, is managed by Supabase Auth. The website and app are hosted on Vercel.
Images and video frames used for vision description are processed transiently to produce a text description for the rehearsal; we do not keep durable media libraries of your uploads. Video files you select for short-clip description do not leave your device as raw bytes for permanent storage on our servers.
What we send to AI model providers
When you start a rehearsal or ask for a summary, our servers send your draft text, public page text for links (on eligible plans), an AI-written description of an image, or descriptions of short video stills, plus the finished thread when you request a summary, to AI language-model providers via OpenRouter and the underlying model hosts. Those providers return simulated comments and summaries.
Please keep confidential, highly sensitive, or personal information you do not want a model provider to process out of drafts. Do not submit content that seeks to create NCII or sexual deepfakes; such use is prohibited.
Cookies and local storage
We set only cookies the product needs to function: Supabase Auth session cookies; mr_csrf for CSRF protection on app actions; mr_site when a temporary site-access password is enabled for /app (marketing pages such as the homepage, Privacy Policy, Terms, and Pricing remain readable without that cookie); and, while older sessions remain, a legacy mr_api cookie. We do not use advertising cookies or cross-site tracking cookies for ads.
Retention
Account data and Google-linked identity data are retained while your account exists. Free plans keep a limited recent rehearsal history; paid plans keep history until you delete items or close the account. You can delete individual rehearsals in History.
When you request account deletion, we delete or irreversibly anonymize personal account data within 30 days, except records we must keep for legal, tax, or accounting reasons (for example certain Stripe payment references), which we retain only as long as those obligations require. Server logs are kept for a short operational period for security and debugging, then rotated.
Your rights (access, delete, export)
Depending on where you live, you may have rights to access the personal data we hold about you, correct inaccurate data, delete data, export a copy of data you provided, restrict or object to certain processing, and withdraw consent where processing is based on consent.
In practice you can: update profile details in the app where available; delete individual rehearsals in History; and request access, correction, export, or deletion of your account and associated personal data by emailing hello@simucrew.com from the address you use to sign in. We will respond within 30 days (or sooner if local law requires).
If you signed in with Google, you can also revoke SimuCrew’s access in your Google Account permissions. Revoking stops future Google sign-in until you reconnect; you can still ask us to delete stored account data. You may also lodge a complaint with your local data-protection authority if you believe we have mishandled your information.
Children
SimuCrew is aimed at professionals and business users. It is not directed at children under 16, and we do not knowingly collect personal data from children under 16. If you believe a child has provided personal data, contact hello@simucrew.com and we will delete it promptly.
Contact
Privacy questions, data-subject requests (access, delete, export), and Google user-data inquiries: hello@simucrew.com.
Operator: SimuCrew.
Product site: https://simucrew.com Privacy Policy: https://simucrew.com/privacy Terms of use: https://simucrew.com/terms
Changes to this policy
We may update this Privacy Policy as SimuCrew evolves. The “Last updated” date at the bottom of this page will change when we do. Material changes that affect how we handle personal data will be reflected on this page before or as they take effect. Continued use of SimuCrew after an update means you should review the revised policy.
Last updated 11 October 2026 · See also Terms of use · Contact: hello@simucrew.com