Privacy notice

Privacy Policy

This notice explains how Simly handles website, account, instructor, institution, and student simulation data.

Effective and last updated: September 1, 2026

1. Who operates Simly

Simly is operated by Tim Wu, operating as Simly. Simly is the service name and is not currently a separate legal entity. References to “Simly,” “we,” “us,” or “our” in this policy mean Tim Wu operating the service.

Privacy questions and verified requests can be sent to privacy@simly.health.

2. Scope and privacy roles

This policy applies to the Simly website, web application, and related support operations. Simly is educational simulation software. It is not intended for clinical care, and users must not enter information about real patients or other protected health information.

Institution-sponsored use

When a school or other institution sponsors use of Simly and directs how student education records are used, the institution ordinarily controls those records and Simly processes them to provide the requested service. The institution agreement may add or change institution-specific instructions. Requests concerning those records may need to be routed to the institution, and Simly will assist it.

Direct interactions

Simly determines how it handles public website inquiries, direct account and support information, service security data, and its own business records.

3. Data we handle

Depending on how you use the service, we may handle:

  • Account data: name, email address, role, authentication provider identifier, and account timestamps.
  • Institution and instructor data: school affiliation, instructor invitation and access records, scenarios, session settings, and institution contacts.
  • Student simulation records: session membership, display name, assigned or selected role, simulated orders and results, notes, checklist actions, content viewed, event timing, and debrief records.
  • Technical data: IP address and ordinary request, browser, device, session, error, and security information generated when the website or app is used.
  • Communications: information included in demo requests, institution coordination, support messages, and privacy requests.

Authentication is provided through Clerk and, when selected, Google. Simly does not receive your Google password. The authentication providers handle login credentials under their own notices.

4. How we use data

We use data to:

  • create and secure accounts, verify access, and prevent unauthorized use;
  • run live simulations, preserve session state, generate debriefs, and support instructors and students;
  • administer institution programs and follow an institution's documented instructions;
  • diagnose errors, maintain reliability, and protect the service;
  • respond to questions, requests, and institution coordination; and
  • meet legal obligations and establish or defend legal claims.

We do not sell personal data and do not use it for targeted advertising.

5. Institution programs, product improvement, and research

This privacy policy is not a research consent form.

Using Simly does not by itself consent a student or instructor to unrelated human-subject research.

Simly may support an institution's documented program evaluation or service assessment. For Simly's own product improvement, the default is aggregate or appropriately de-identified information that is not reasonably linkable to a person.

Simly will not use identifiable or readily re-identifiable student-level data for independent research unless there is separate written institutional authorization and the institution's IRB, HRPP, or other responsible body has documented the applicable determination. If consent is required, it must be obtained separately before that research use. A coded or pseudonymized dataset may still be re-identifiable and is not described as anonymous merely because direct names and emails were removed.

6. When data is disclosed

We disclose data only as needed for the purposes above, including to:

  • Your institution: instructors and authorized institution contacts may access the educational records and reports their program creates.
  • Service providers: Clerk for authentication, Google when Google sign-in is selected, Railway for application hosting and operational logs, Neon for database hosting, and Cloudflare for domain, network, or security services.
  • Public web resources: the public site currently requests fonts from Google, and a simulation scenario may request an image from a disclosed source such as Wikimedia or NCBI. Those hosts receive ordinary web-request information when a browser loads the resource.
  • Legal and safety recipients: when reasonably necessary to comply with law, protect people or the service, investigate abuse, or establish or defend legal claims.
  • A successor: if the service is reorganized, financed, sold, or transferred, subject to appropriate confidentiality and this policy's protections.

Providers may process data in the United States or other locations where they operate. Institution agreements may impose additional restrictions or list additional approved providers.

7. Retention, deletion, and institution records

Account deletion

When our authentication provider reports an account deletion, or after we verify a valid deletion request, Simly removes or replaces active account identity promptly and no later than 30 days. This includes the account email, display name, authentication identifier, and any legacy credential value in Simly's active application database.

Student records

For a deleted student account, Simly also detaches the durable student-profile link from session participation, replaces copied join names with a generic label, and marks the retained seat ineligible for research analysis. Shared simulation facts—such as an order occurring at a certain time—may remain in non-identifying form when the institution needs the education record. Free text supplied by users is reviewed separately because it may contain information the account did not supply.

Instructor and institution records

For a deleted instructor account, Simly removes the instructor's account identity on the same schedule. Institution-owned scenarios, completed sessions, and related educational records may remain under a generic account anchor or be transferred to an institution-authorized successor. Personal drafts are handled under the institution agreement and institution instructions.

At the end of an institution's program, its written agreement controls. If it does not specify another schedule, Simly offers the institution a 30-day period to request an export, then deletes or de-identifies that institution's records in active systems unless retention is required by law or requested by the institution for a permitted educational purpose.

Logs, backups, and separate business records

Routine application request logs are generally retained for seven days in the current hosting configuration. Deleted data may remain temporarily in provider backups and disaster-recovery copies until those copies age out under the provider's normal schedule. Those copies are not used for ordinary operations, and deletion is reapplied if a backup is restored.

Security incidents, privacy-request receipts, contracts, program administration, and support correspondence may be kept separately for as long as reasonably necessary for their purpose, legal requirements, or legal claims. Completion receipts record the request and actions taken without retaining the identifier that was deleted.

8. Your choices and requests

You may ask to access, correct, export, or delete personal data by emailing privacy@simly.health. We will verify the request before acting and may ask for information needed to locate the account. Do not send passwords, authentication tokens, patient information, or unnecessary sensitive data by email.

If your institution provided your access, it may be the appropriate party to answer a request about your education record. We will route or support the request rather than changing an institution-controlled record without authority. Rights and exceptions vary by location, and we will honor applicable law and the institution's lawful instructions.

9. Security, simulated data, and age

Simly uses measures designed to protect service data, including authenticated access, signed deletion webhooks, encrypted provider connections, scoped operational access, and log redaction. No internet service can guarantee absolute security.

Do not enter real patient data. Simly is for simulated educational cases and is not designed to receive protected health information or to serve as a clinical health record.

The service is intended for postsecondary education and is not directed to children under 13. An institution planning participation by minors must contact Simly first so the institution and Simly can establish appropriate permission and privacy controls.

10. Changes and contact

We may update this policy as the service changes. The effective date at the top identifies the current version. If a change materially affects an active institution program, we will notify the institution and, where appropriate, users through the service or their registered email.

Questions or privacy requests:
Tim Wu, operating as Simly
privacy@simly.health