This notice covers BitFlowSim at bitflowsim.com and app.bitflowsim.com, account access, waitlist registrations, and contact messages. We do not sell personal information or use it for advertising.
1. Who we are
Carlos Garcia operates the Service as a sole proprietor doing business as BitFlowSim in Puerto Rico. Contact simplc5000@gmail.com about the information described here.
2. Information we collect
- Accounts and invitations: email, display name, a one-way password hash, account timestamps, invitation tokens and their active or revoked status. Access is currently by invitation.
- Projects: programs, tags, project names and descriptions, scenario configuration, and project folders saved to your account.
- Legal acceptance: accepted Terms and Privacy versions, timestamp, and request IP address and browser user-agent where available. Acceptance of the current Terms includes an explicit adult-eligibility attestation. We do not collect birth dates or identity documents during signup.
- Sessions and recovery: session tokens, IP address, browser user-agent, timestamps, and password-reset verification records linking a temporary reset token to an account.
- Waitlist: name, email, role, optional note and proposed-plan preference, source, and consent version and timestamp.
- Contact: name, email, role, topic, message, and review status.
- Email records: internal waitlist/contact notification recipients, related submission identifiers, provider message identifiers, delivery status, attempts, timestamps, and limited error codes. Password-reset emails are sent through Resend; their delivery records are held by the provider rather than our public-form delivery table. Webhook receipt records contain an event identifier, type, and processing time.
- Abuse prevention and logs: authentication rate-limit keys and counters; keyed hashes of IP addresses for public-form limits; hosting request logs. Cloudflare Turnstile checks for automation on forms when enabled.
Paid billing is not enabled. We do not currently collect payment details or store Stripe customer or subscription records. We will update this notice before introducing payment processing.
3. How we use information
We use this information to provide and secure accounts, invitations, projects and recovery; enforce access and usage limits; answer messages; record agreements; prevent abuse; and comply with applicable law. Waitlist consent is used for launch updates. Projects are private to the account through the app; authorized operator access may be needed for support, security, or legal requests.
4. Service providers
| Provider | Purpose |
|---|---|
| Vercel | Website and app hosting, requests, and operational logs. |
| Turso | Application database hosting and provider-managed copies. |
| Resend | Password-reset emails, internal form notifications, and delivery reporting. |
| Google Gmail | Operator correspondence and internal waitlist/contact notifications. |
| Cloudflare | Turnstile bot protection when enabled on public forms. |
We disclose information to these providers as needed to operate the Service. We may also disclose it when required by law, to protect rights or safety, or in a transfer of the Service subject to applicable notice and legal requirements. We do not share information for cross-context behavioral advertising.
5. Analytics and advertising
We do not currently use analytics, advertising, or cross-site tracking tools in the app or website. Operational logs and abuse prevention still process technical information. We will update this notice and obtain consent where required before adding optional tracking.
6. Cookies and browser storage
The following storage supports sign-in, device preferences, and cached app assets. Preferences may contain project or routine identifiers, but not saved project programs. The historical storage names remain in use so existing preferences continue to work.
| Name and type | Purpose | Duration |
|---|---|---|
__Secure-better-auth.session_token, cookie | App sign-in. Non-HTTPS development uses better-auth.session_token. | 30 days, refreshed during active use, or until sign-out; browser-session only when a caller requests nonpersistent sign-in. Database expiration and cleanup are separate. |
__Secure-better-auth.dont_remember, cookie | Remembers a nonpersistent sign-in request made through the authentication API.
Non-HTTPS development omits __Secure-. | Browser session or until sign-out. |
sim-plc-5000-theme, local storage | Light/dark theme. | Until you clear site data. |
sim-plc-5000-home, local storage | Pinned and recent project identifiers and grid/list preference. | Until cleared; stale project references are pruned when the project list loads. |
sim-plc-5000-routine:*, sim-plc-5000-organizer:*, sim-plc-5000-scenario-view:*, local storage | Per-project open routine, organizer expansion, and scenario view. | Until you clear site data. |
sim-plc-5000-side-panel, sim-plc-5000-layout, local storage | Editor panel visibility and layout. | Until you clear site data. |
sim-plc-5000-*, service-worker cache | App code and static assets. It does not cache authenticated pages or API project responses and is not an offline project backup. | Old caches are replaced when a new app service worker activates, or when you clear site data. |
Unsaved editor and simulation state also lives in memory while the page is open. It is lost when the page closes or reloads. Turnstile, when enabled, may use browser signals or storage for bot checks.
No optional analytics or advertising cookies are currently enabled, so no optional-tracking consent banner is shown. You can clear or block cookies and site data in your browser. Blocking the session cookie prevents sign-in. Clearing site data removes device preferences and cached assets; it does not delete server-held projects. Account deletion cannot remotely clear preferences or downloads on all your devices.
7. Email
Service emails include password recovery and necessary account or policy notices. Waitlist launch updates require your separate opt-in; email simplc5000@gmail.com to withdraw it. Any marketing email we send will include a way to opt out. Contact submissions are used to answer your message and are not marketing subscriptions.
8. Retention and deletion
- Accounts and projects: kept while your account exists. Account deletion removes the account, projects, folders, sessions, authentication records, legal acceptances, tester invitation, and outstanding account reset records from the application database. Invitations without an account can be removed on request.
- Waitlist: until you request removal or 12 months after public launch, whichever comes first. The operator records that launch date for cleanup; the invitation-only period is not that launch.
- Contact messages and form email-delivery records: up to 24 calendar months, unless you request earlier deletion. Deleting a submission also removes its linked application delivery records.
- Sessions and reset records: sessions normally expire after 30 days unless refreshed by active use. Nonpersistent sessions requested through the authentication API expire after 24 hours. Recovery tokens expire after one hour. Expired database rows are removed in daily maintenance. Signing out ends that session.
- Rate limits: authentication records are eligible for cleanup after 48 hours without an attempt and public-form records after 24 hours. Daily maintenance removes eligible rows. These records are independent of account deletion.
- Webhook receipts: kept for 24 calendar months to identify previously processed email events.
Daily maintenance processes time-based deletion. A deadline may pass before the next daily run. A request covering your account does not automatically remove separate waitlist or contact submissions; you can request those as well.
Application deletion does not erase mail already delivered to the operator, provider logs, backups, or files you downloaded. We review relevant mailbox and provider-held copies when handling a deletion request, delete or request deletion where available, and explain any retention required by law or outside our direct control. Provider backup and log expiry follows each provider's configured retention; we do not promise immediate erasure from those systems.
9. Security
We use HTTPS, password hashing, access restrictions, and rate limiting. No service is completely secure. We respond to security incidents and notify affected people and authorities as required by applicable law, including applicable Puerto Rico breach-notification requirements.
10. Your choices and rights
You can view, edit, and export projects in the app. You can delete your account from Account after confirming your password. The protected operator account is managed separately. Email us to request access, correction, removal of invitations, waitlist/contact data, or help deleting an account you cannot access.
We will respond to privacy requests within 45 days. We may need to verify that you control the relevant account or email address. Do not send identity documents unless we specifically explain why they are needed and agree on a suitable method. We will not discriminate against you for exercising applicable privacy rights. Because we do not sell information or share it for advertising, there is no such processing to opt out of through a Global Privacy Control signal.
11. Adult eligibility
The Service is for people who have reached the age of majority where they live, which is 21 in Puerto Rico. We do not offer access to minors through guardian permission or school-managed accounts. We do not knowingly collect children's information. Contact us if you believe an ineligible minor has provided information so we can investigate and arrange deletion. Adult classroom participants use individual accounts under the Terms of Use.
12. Where information is processed
We operate from Puerto Rico. Our providers may process information in the United States and other countries where they operate. Processing locations and protections may differ from those in your place of residence.
13. Changes
The date and version above identify this notice. We notify you of material changes in the app or by email and ask you to acknowledge the current notice through the app's legal-update flow.
14. Contact
Send privacy questions and requests to simplc5000@gmail.com.
Questions about this document? Email simplc5000@gmail.com.