All legal documents

Privacy Policy

How we collect, use, and protect your personal data, including your rights under GDPR and CCPA.

Last updated: August 3, 2026

1. Overview and Effective Date

This Privacy Policy explains how Privacy, Visually Simplified | Privasim (“we”, “us”, or “our”) collects, uses, discloses, and safeguards your information when you use our website and services (the “Service”). It applies to all visitors, registered users, and subscribers.

This policy is effective as of August 3, 2026. We may update it from time to time; material changes will be announced via email or an in-app notice. Your continued use of the Service after a change constitutes acceptance of the revised policy.

2. Data Controller and Contact

Privacy, Visually Simplified | Privasim is the data controller for personal data processed under this policy. For privacy inquiries, contact us at contact@privasim.com.

3. Lawful Basis for Processing (GDPR / UK GDPR)

Where GDPR or UK GDPR applies, we process personal data on the following lawful bases:

  • Performance of a contract (Art. 6(1)(b)) — to provide the Service you signed up for.
  • Consent (Art. 6(1)(a)) — for optional analytics, marketing, and cookies.
  • Legal obligation (Art. 6(1)(c)) — to comply with tax, accounting, and regulatory requirements.
  • Legitimate interests (Art. 6(1)(f)) — for security, fraud prevention, and service improvement.

4. Information We Collect

Account data: name, email address, and authentication credentials (managed via our auth provider).

Usage data: diagrams and presentations you create, prompts you submit to AI features, generated outputs, interaction logs, device/browser information, IP address, and approximate location.

Billing data: name, billing address, and the last four digits of your payment method. Full card details are handled by our payment processor and never touch our servers.

Support communications: the contents of emails and support tickets you send us.

5. AI Processing and Training

Some features use AI models to generate diagrams, presentations, and text from your prompts. Your prompts and generated outputs are processed to return results to you.

We do not use your prompts or generated content to train AI models. Where a third-party AI provider is used, your data is transmitted under a Data Processing Agreement that prohibits training on customer data. Inputs may be retained by the provider only for the duration needed to serve the request and applicable abuse-monitoring windows, after which they are deleted.

6. How We Use Your Information

  • To provide, operate, and maintain the Service.
  • To create and manage your account and authenticate you.
  • To process payments and deliver subscriptions.
  • To generate AI outputs in response to your prompts.
  • To communicate with you about your account, updates, and security.
  • To detect, prevent, and address fraud, abuse, and security issues.
  • To comply with legal obligations.

7. Cookies and Tracking Technologies

We use cookies and similar technologies for authentication, security, and analytics. See our Cookie Policy for details and how to manage them.

8. Subprocessors and Third Parties

We engage trusted third-party providers to deliver the Service. A current list of subprocessors, their roles, and locations is maintained at Subprocessors. We only share data with providers under written agreements requiring confidentiality and appropriate security.

9. Data Retention

We retain personal data only as long as necessary for the purposes set out in this policy:

  • Account data: until you delete your account or request erasure.
  • Usage and AI data: for the active life of your account, then deleted within 90 days.
  • Billing records: as required by tax and accounting law (typically 7 years).
  • Support communications: up to 2 years.
  • Security logs: up to 12 months.

10. International Data Transfers

Your data may be processed in countries with different data protection laws. Where data is transferred outside the EEA, UK, or Switzerland, we rely on Standard Contractual Clauses or other lawful transfer mechanisms approved by the European Commission.

11. Your Privacy Rights

Depending on your jurisdiction, you may have the following rights. To exercise any of them, email contact@privasim.com.

  • Access — request a copy of your personal data.
  • Rectification — correct inaccurate or incomplete data.
  • Erasure — request deletion of your data (“right to be forgotten”).
  • Restriction — limit our processing of your data.
  • Portability — receive your data in a structured, machine-readable format.
  • Objection — object to processing based on legitimate interests.
  • Withdraw consent — at any time, without affecting prior processing.
  • Complain to a supervisory authority — e.g. your local data protection authority.

California residents also have rights under the CCPA/CPRA, including the right to opt out of the “sale” or “sharing” of personal information and to limit use of sensitive personal information. We do not sell personal information. To submit a verifiable consumer request, contact us at contact@privasim.com.

12. Children's Privacy

The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you are under 13, you may not use the Service. If you are between 13 and 17, you may use the Service only with the consent of a parent or legal guardian.

If we learn we have collected personal information from a child under 13 without verifiable parental consent, we will delete it promptly. To report such data, contact contact@privasim.com.

13. Data Security

We implement appropriate technical and organizational measures — including encryption in transit and at rest, access controls, and regular security reviews — to protect your personal data. No method of transmission or storage is fully secure, but we strive to use commercially acceptable means to protect your data.

14. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify affected users and the relevant supervisory authority without undue delay, and in any case within 72 hours of becoming aware of it, where required by law.

15. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated version on this page with a revised “Last updated” date. For material changes, we will provide notice via email or an in-app banner at least 30 days before the change takes effect.

16. Contact Us

Questions about this Privacy Policy can be sent to contact@privasim.com.