Source Robotics
Privacy Policy
Last updated: 11 September 2026
Sim2Bot can be used locally without an account. Local simulation data stays in your browser unless you explicitly use a cloud feature. We currently do not use advertising, sell personal data, or run session-replay tools. We do use a product-analytics service, described in section 5, which records how the application is used rather than what you build with it.
1. Who is responsible for your data?
Source robotics d.o.o. is the controller of personal data processed through Sim2Bot.
- Legal name
- Source robotics d.o.o.
- Registered office
- Julija Knifera 5, 10020 Zagreb, Croatia
- Company registration
- MBS 081562517
- OIB / VAT ID
- 91353424251 / HR91353424251
- Contact
- info@source-robotics.com
No data protection officer is currently appointed. Privacy requests may be sent to the email address above.
2. When this policy applies
This policy applies to the Sim2Bot browser application, accounts, cloud storage, public scene sharing, and related support communications. Third-party websites, identity providers, and documentation sites have their own privacy notices.
3. Information we process
Local simulator information
Scenes, preferences, imported files, robot state, and other working data may be stored in browser storage such as IndexedDB and local storage. This information remains on your device unless you explicitly save, upload, share, or transmit it. Local Python and bridge traffic normally stays between software on your device or network and is not relayed through the Sim2Bot cloud service.
Account and authentication information
When you create or use an account, we process identifiers such as your email address, account ID, profile name, avatar, authentication status, and provider metadata. Password authentication is handled by Supabase Auth. If you choose Google, GitHub, or Discord sign-in, that provider also processes the sign-in under its own terms and privacy notice.
Cloud content
When you deliberately use cloud features, we process the scenes, robots, objects, assets, thumbnails, names, metadata, ownership records, storage sizes, and sharing settings needed to provide them. A public scene share creates a public copy and an unguessable share token. Anyone with the link may access that shared copy until it is revoked or removed.
Technical, security, and communication information
Hosting, authentication, and storage providers may process IP addresses, request times, browser/device information, authentication events, and security logs. If you email us, we process your address, message, attachments, and our response. If you are signed in and choose Send in the feedback form, we process your description, selected impact or mood, app version, and any diagnostic snapshot you choose to attach. Reports first enter a restricted review queue. If you choose Download draft, the report is saved only to your device.
Diagnostic attachment is optional. Standard diagnostics contain coarse performance and scene-count ranges. If you explicitly select Detailed diagnostics, the report also includes the app build, browser and operating-system family, viewport and GPU renderer, environment and performance presets, and exact performance and simulator model counts. More detail can help us reproduce and debug a problem. The preview shows the exact sanitized snapshot before sending. Diagnostics do not include scene contents, robot names, source files, telemetry, camera data, local paths, account details, or credentials.
4. Why we use information and our legal bases
- Provide requested services and accounts: performance of our contract or steps requested before entering one.
- Store and share content you select: performance of our contract and your explicit sharing instruction.
- Secure, debug, and protect Sim2Bot: our legitimate interests in reliable operation, fraud prevention, abuse prevention, and service security.
- Answer requests and disputes: performance of our contract, our legitimate interests, and where applicable compliance with legal obligations.
- Comply with law and establish legal claims: compliance with legal obligations and our legitimate interests in protecting legal rights.
Sim2Bot does not currently use personal data for targeted advertising, marketing email, product analytics, session replay, or automated decisions that produce legal or similarly significant effects. We will update this policy before enabling such processing.
5. Service providers and recipients
- Cloudflare: website delivery, security, DNS, and private-preview access control.
- Supabase: authentication, database, file storage, and account-deletion functions.
- Resend: delivery of authentication emails such as sign-in links, confirmations, and password resets. Resend processes the recipient address and message content, and uses Amazon SES as its own sub-processor for delivery.
- PostHog (EU region): product analytics. It records which features are used and which errors occur, so we can find problems and decide what to improve. Scene contents, uploaded files, robot data, file names, and message text are never sent to it, and IP-based geolocation is disabled. Analytics is disabled entirely when the application is built without an analytics key.
- Cloudflare Turnstile: a bot check shown on some authentication requests, loaded only when configured.
- Google, GitHub, or Discord: only when you choose the corresponding third-party sign-in method.
- Cloudflare Pages: hosts the marketing page, the application, and the documentation site as separate deployments.
- Professional advisers or authorities: only when reasonably necessary to obtain advice, protect rights, or comply with law.
Authentication messages are sent through Resend, configured as the SMTP provider for Supabase Auth. We do not disclose user content to other users unless you explicitly create a public share or another feature clearly tells you it will do so.
6. International transfers
Some providers or their subprocessors may process data outside Croatia or the European Economic Area. Where required, we rely on provider data-processing terms, adequacy decisions, Standard Contractual Clauses, or another lawful transfer mechanism. You may contact us for further information about safeguards relevant to your data.
7. How long information is kept
- Account information is kept while the account exists and removed when verified account deletion completes, subject to the exceptions below.
- Cloud scenes, robots, objects, and assets are kept until you delete them or the account.
- Public share copies are kept until sharing is revoked, the scene is deleted, or the account is deleted.
- Local browser data remains until you remove it through Sim2Bot or your browser/device controls.
- Support correspondence is normally kept for up to 24 months after resolution, unless a longer period is needed for a dispute or legal obligation.
- Security and infrastructure logs follow operational and provider retention periods and may be retained longer when needed to investigate abuse or protect legal rights.
- Deleted information may remain in protected rotating backups for up to 60 days and is not restored except for disaster recovery.
- Records that must be retained by law may be kept for the required period.
8. Account deletion and local data
Account settings provide an account-deletion action. The deletion service revokes public scene shares, removes account-owned cloud files, verifies removal, and then deletes the authentication account. If cleanup fails, the account is retained so deletion can be retried. Deleting an account does not erase local browser data; remove that separately using Sim2Bot’s reset controls or your browser settings.
9. Cookies and browser storage
Sim2Bot uses browser storage for essential application preferences, local project data, and authentication state. During the private preview, Cloudflare Access also uses authentication cookies to protect the hosted application. We currently do not place advertising or analytics cookies. Blocking essential storage may prevent accounts, saved preferences, or local projects from working correctly.
10. Your privacy rights
Depending on applicable law, you may request access, correction, deletion, restriction, objection, or portability of your personal data. Where processing is based on consent, you may withdraw it without affecting earlier lawful processing. We may need to verify your identity. Send requests to info@source-robotics.com.
You may also complain to the Croatian Personal Data Protection Agency (AZOP) or another competent supervisory authority in your country.
11. Security and children
We use technical and organisational safeguards appropriate to the service, but no internet service can guarantee absolute security. Sim2Bot accounts are intended for people aged 18 or older. We do not knowingly offer accounts to children.
12. Changes and contact
We may update this policy as Sim2Bot changes. Material changes will be identified by a new date and, where appropriate, an in-product notice. Questions and privacy requests may be sent to info@source-robotics.com.