Legal

SIMS Privacy Policy

Effective: July 12, 2026 Last updated: July 12, 2026 Version: 2026-07-12.v1

This Privacy Policy explains how Finepoint Science LLC ("Finepoint," "we," "us," or "our") handles information when you visit SIMS websites, create or administer a SIMS Cloud account, use a SIMS workspace, purchase AI credits, request support, or communicate with us.

SIMS is a business service. We use information to provide, secure, bill, support, and improve the service. When you request AI work, selected prompts, files, messages, and context are transmitted to external AI providers. We do not sell Customer Content or use it to train generalized AI models.

Use of SIMS Cloud is also governed by the Terms of Service.

1. Scope and roles

This Policy applies to SIMS Cloud, the SIMS marketing site, account and billing administration, and related support communications. It does not govern a customer-controlled on-premise deployment or a separate Finepoint laboratory service, which may have different notices and responsibilities.

Finepoint is responsible for account, service, security, marketing, and billing information that it determines how to use. For workspace information processed on behalf of an Organization, the Organization generally determines why the information is submitted and Finepoint acts as its service provider or processor. Organization administrators are responsible for their users, notices, permissions, and lawful instructions. SIMS is not directed to children, and users must be at least 18.

2. Information we collect

Account and Organization information includes names, business email addresses, credentials stored as secure hashes, verification and recovery records, Organization names, roles, permissions, invitations, preferences, and administrator instructions.

"Customer Content" includes documents, records, files, messages, prompts, instructions, retrieved context, AI output, approvals, audit events, configuration, and other material submitted to or created in a workspace. Content can include personal information chosen by the Organization or its users.

Billing information includes billing contacts and addresses, tax location and exemption information, purchase and consent records, credit balances and usage, receipts, disputes, and Stripe customer, invoice, payment, and balance-transaction identifiers. Full payment-card numbers and security codes are collected by Stripe rather than stored by SIMS.

Technical and communications information includes IP-derived request data, browser and device characteristics, session and essential-cookie identifiers, timestamps, routes and actions, diagnostic and security logs, support requests, feedback, and messages you send us.

3. How we use information

We use information to create and authenticate accounts; provide tenant isolation, documents, workflows, collaboration, audit history, and requested AI features; administer permissions; process payments and tax; deliver notices; answer support requests; and maintain service records.

We also use information to prevent fraud and abuse, investigate security events, debug and improve reliability, measure capacity and billing accuracy, reconcile providers, enforce our agreements, comply with law, and protect customers, Finepoint, providers, and the public.

Depending on the context and applicable law, we process information to perform a contract, follow an Organization's documented instructions, comply with legal obligations, pursue legitimate business and security interests, or with consent. We may use statistics that are aggregated or de-identified so they do not reasonably identify a customer, person, or Customer Content.

4. AI processing

When a user requests an AI feature, SIMS sends the prompts, instructions, files, messages, retrieved workspace context, model settings, and related request metadata selected for that request to external AI model or tool providers. Those providers process the material on provider-operated systems to return output. Processing may occur outside the user's or Organization's jurisdiction.

Our current core model provider is Anthropic. Provider availability and the models or tools used can change, and we will update this Policy or provide appropriate notice when a change materially affects personal-information handling. Finepoint does not sell Customer Content or use it to train generalized AI models. We contract for provider data-handling protections appropriate to the service and use provider controls intended to prevent training on submitted business content where available.

Users and Organizations choose what to submit and must have the rights, notices, and consents needed to do so. Do not place passwords, authentication tokens, private keys, payment-card data, government identifiers, or other access credentials or secrets in AI prompts or files. Do not submit protected health information, export-controlled information, or other specially regulated data unless Finepoint has expressly agreed in writing that the relevant service is configured to receive it.

5. Payments and tax

Stripe processes payment methods, Checkout, invoices, refunds, disputes, fraud signals, billing addresses, and tax calculations. Information supplied directly to Stripe is also governed by Stripe's privacy notice. SIMS receives the provider identifiers, status, amounts, fees, tax results, and limited billing details needed to maintain an accurate tenant ledger and support payments.

If an administrator enables automatic top-up, we retain the authorization, selected threshold and amount, payment-method reference, charge history, and later changes or revocation. We use that information only to operate and account for the requested billing feature, prevent fraud, resolve disputes, and comply with financial and tax obligations.

6. How we disclose information

We disclose information only as needed to operate the service, follow customer instructions, complete a transaction, protect rights and security, or comply with law. Provider categories include cloud hosting and storage, database and network infrastructure, transactional email, monitoring and support, payment and tax, and AI model and tool processing. Current core providers include DigitalOcean for cloud infrastructure, Brevo for transactional email, Stripe for payments and tax, and Anthropic for AI model processing.

We may disclose information to professional advisers and auditors under duties of confidentiality; to authorities or other parties when reasonably necessary to comply with legal process, investigate fraud or security, or protect legal rights and safety; and in connection with a merger, financing, reorganization, or sale, subject to appropriate confidentiality and notice requirements.

We do not sell personal information or Customer Content. We do not share personal information for cross-context behavioral advertising and do not use third-party advertising trackers in SIMS. Providers may use information only for contracted services and their legally permitted operational purposes.

7. Retention and deletion

We retain account and Customer Content while the Organization uses SIMS and afterward as directed by the Organization, an applicable retention setting or agreement, and legitimate backup, security, dispute, and legal requirements. Controlled records and audit history may be retained for the Organization's configured recordkeeping period and are not silently deleted when a user leaves.

Billing, tax, consent, ledger, security, and legal records may be retained longer when needed for accounting, fraud prevention, dispute handling, enforcement, or law. Backup copies expire through managed rotation rather than immediate deletion. External providers retain information under their contracts, configured controls, and legal obligations.

An authorized administrator may request account closure or deletion through the contact below. We will delete or de-identify eligible information after verifying authority, subject to Organization instructions, other users' rights, immutable financial and audit evidence, active disputes, backup cycles, and legal exceptions. Customers should export information they are entitled to retain before closure.

8. Security

We use administrative, technical, and organizational safeguards designed for the nature of the service and information, including access controls, tenant isolation, credential hashing, encrypted transport, audit logging, restricted provider credentials, backup controls, and security monitoring. We review providers and use contractual safeguards where appropriate.

No system or transmission method is completely secure. Organizations remain responsible for endpoint security, appropriate roles and administrators, protecting credentials, reviewing exports and integrations, and promptly revoking access. Contact us immediately if you suspect unauthorized access or a security incident involving SIMS.

9. Rights and choices

Depending on your location and relationship with an Organization, you may have rights to access, correct, delete, or receive personal information; object to or restrict processing; withdraw consent; or appeal or complain to a regulator. These rights are subject to identity and authority verification, Organization control of workspace records, legal exceptions, and the rights of others.

Begin with your Organization administrator for workspace information controlled by that Organization. You may also contact Finepoint. We may refer a request to the Organization, ask for information needed to verify it, or decline or limit a request where law permits. We will not discriminate against a person for exercising an applicable privacy right.

You can opt out of non-essential marketing messages using the unsubscribe control or by contacting us. Transactional, security, billing, and account messages are part of the service and continue while relevant. SIMS does not sell personal information, so no separate sale opt-out is required.

10. International processing

Finepoint and its providers may process information in the United States, Canada, and other countries where they operate. Those countries may have privacy laws different from the laws where you live. The location of AI processing can also depend on the selected provider, model, and processing-region option.

Where applicable law requires a transfer mechanism or additional protection, we use contractual, organizational, or technical safeguards intended to provide an appropriate level of protection. Contact us for information about safeguards relevant to a particular processing arrangement.

11. Cookies and communications

SIMS uses essential cookies and similar local storage for authentication, security, language, and user-interface state. We do not use third-party advertising cookies or cross-site behavioral tracking. Blocking essential storage may prevent account or workspace features from functioning.

We record when required account, billing, security, and legal notices are sent or accepted. Marketing communications are optional where consent is required. Email delivery providers receive the recipient, message, and delivery metadata needed to send and troubleshoot communications.

12. Changes and contact

We may update this Policy to reflect changes in SIMS, providers, law, or our practices. We will publish the revised version and effective date and provide additional notice or obtain consent when required for a material change. We will not quietly broaden use of previously collected Customer Content for generalized AI training.

Questions, privacy requests, complaints, and data-protection inquiries may be sent to the contact below. Include your Organization, the nature of the request, and a reliable way to respond, but do not send passwords, payment-card data, or other secrets by email.

This Policy is intended to describe our actual practices, not to reduce a privacy, security, or data-protection obligation that cannot lawfully be limited. A separately signed data-processing agreement controls to the extent it expressly conflicts with this Policy for the same processing.

Contact us

Privacy questions and requests can be sent to info@fpscience.com. We may need to verify your identity, authority, and Organization before completing a request.