Simonides

Privacy Policy

This Privacy Policy explains what information Simonides processes, how we use and retain it, and the choices available to you.

Last updated: August 31, 2026

Information We Collect

Effective August 31, 2026. When you use the Simonides hosted AI trial, we process the note title, note text, section headings and content you choose to submit, together with the study materials generated from that content. We also receive anonymous installation, session, and operation identifiers generated by the client; request time and status; client version; section count; model and token-usage metadata; latency; error category; and quota information. Cloudflare receives ordinary network information, including your IP address, to deliver the request. The Service derives a coarse network value from the address for abuse prevention and does not store the raw address in its application database. The Service does not require an account or collect payment information.

How We Use Information

We use submitted content to generate and return the requested study materials. We use identifiers and technical metadata to validate requests, enforce quotas, prevent duplicate processing and abuse, diagnose failures, secure the Service, and understand aggregate reliability and capacity. We do not use submitted note content or generated results for advertising or to train our own models. Where applicable law requires a legal basis, we process information as necessary to provide the Service under these Terms and for our legitimate interests in operating, securing, and improving the demo.

Data Retention

Submitted note content and generated results are processed transiently and are not intentionally written to our application database, analytics dataset, request logs, or AI Gateway payload logs. Generated results are returned to your client, which may store them locally under the client’s own settings. Pseudonymous quota records—including derived hashes, timestamps, operation status, and usage metadata—may be retained for the operational life of the demo to enforce limits and prevent the same operation from being processed more than once. Content-free Analytics Engine telemetry is retained for approximately three months. Custom Worker error logs are currently retained for up to three days, subject to the Cloudflare plan in use. AI Gateway metadata, excluding request and response bodies, is retained according to the gateway’s configured storage limit and deletion settings. We may retain information longer when reasonably necessary for security, legal compliance, or dispute resolution.

Cookies and Tracking

The demo API does not set application cookies, and we do not currently use advertising cookies or cross-site behavioral tracking in connection with the Service. Essential infrastructure may process request and device information needed to deliver and protect the website and API. We do not respond differently to legacy “Do Not Track” browser signals because the Service does not track users across unrelated websites. If we add analytics or other non-essential browser technologies, we will update this notice and request consent where required.

Third-Party Services and Disclosures

We use Cloudflare to host the Service, process AI requests, enforce limits, store pseudonymous quota records, and provide operational analytics and logs. Submitted content and generated results pass through Cloudflare Workers and Workers AI while a request is processed. Payload collection is disabled for our AI Gateway logs, although content-free metadata such as model, status, token usage, cost, and duration may be retained. We do not sell personal information or share it for cross-context behavioral advertising. We may disclose information when required by law, to protect the Service or another person, or as part of a business reorganization, subject to appropriate safeguards. Cloudflare’s own processing is described in its privacy and service documentation.

Security

We use technical and organizational safeguards intended to limit access to submitted content and operational data. These include bounded requests, pseudonymous identifiers, restricted telemetry fields, disabled invocation logging, no-store response headers, and suppression of AI Gateway payload storage. No online service can guarantee absolute security, however, so you should not submit sensitive, confidential, or irreplaceable information.

Your Privacy Rights

Depending on where you live, you may have rights to request access to, correction of, deletion of, or a copy of personal information, or to object to or restrict certain processing. You may submit a request using the contact information below. Because the Service has no user accounts and stores only pseudonymous identifiers, we may be unable to locate or verify information as belonging to you without additional identifiers from your client. We may retain limited records where permitted or required for security, fraud prevention, quota integrity, or legal compliance. You may appeal a denied request by replying to our response.

Children’s Privacy

The Service is intended only for people who are at least 18 years old and is not directed to children. We do not knowingly collect personal information from children under 13. If you believe a child has submitted personal information, contact us so that we can investigate and take appropriate action.

International Processing

The Service and its providers may process information in the United States and other countries where they operate. Those countries may have privacy laws different from the laws where you live. Where required, we use legally recognized safeguards for international transfers.

Changes and Contact

We may update this Privacy Policy as the Service, our providers, or applicable law changes. We will post the revised policy with a new effective date and provide prominent notice of material changes where reasonably practicable. For privacy questions or requests, contact Simonides at legal@simonides.ai.