Version 1.3 · Effective August 26, 2026
This Privacy Policy explains how ThermoSketch LLC ("ThermoSketch," "we," "us," or "our"), a Wyoming limited liability company, collects, uses, and protects information in connection with your use of the ThermoSketch website, applications, and engineering simulation and analysis tools (collectively, the "Service") at thermosketch.com and its subdomains. This Policy is incorporated by reference into our Terms of Service.
This Policy applies to all users of the Service, regardless of location, and reflects our commitment to offering the same core set of rights and protections to everyone, rather than a different tier of rights depending on your country.
Regardless of whether you are on a free or paid plan, ThermoSketch does not store your design geometry or simulation inputs and outputs on our servers. Calculations are performed in memory and results are returned directly to your browser; if you want to keep a project, you download it to your own device. This is a deliberate product design choice, not a technical limitation, and it applies to every plan. Two narrow, opt-in exceptions are the diagnostics submission and the AI chat feature, both described below.
We do keep a limited record of your account, your subscription, your payments, and how much you used the Service, measured as counts and timestamps rather than content. We keep some of those records for a period after you delete your account, so that we can meet accounting obligations and handle payment disputes. Section 9 states exactly what is erased and what is kept.
| Category | Examples | Where It Is Stored |
|---|---|---|
| Account and identity data | Email address, password hash or OAuth identifier (currently Google) | Supabase (our authentication and database provider) |
| Subscription and billing status | Plan tier, subscription start and end dates, Payment Processor subscription ID | Supabase |
| Payment card data | We do not collect or store this. Card details are handled entirely by our payment processor and merchant of record ("Payment Processor"), currently Dodo Payments. | Held by Payment Processor only |
| Usage records | Which tool you used, which action you took (solver run, PDF export, CSV export, AI chat), whether it succeeded, when, which plan you were on at the time, and token counts for AI chat. No geometry, no parameters, no results. | Supabase (shown in your account for 40 days, then archived; see §5) |
| Account activity records | Sign-ins and sign-outs, password changes, subscription creation, plan changes, cancellations, refund requests, and data export or deletion requests, each with a timestamp | Supabase (see §5) |
| Payment and refund records | Payment and invoice identifiers issued by the Payment Processor, amount, currency, date, which plan, the billing period covered, the last four digits and the network of the card used, the country on the billing record, and refund identifiers and amounts | Supabase (see §5) |
| Refund request records | The reason you selected, the explanation you chose to write, the usage figures recorded at the moment you submitted, the estimated amount shown to you, and our decision | Supabase (see §5) |
| Payment dispute records | Identifiers, reason codes, and the outcome of any payment dispute or chargeback raised against a transaction | Supabase (see §5) |
| Error logs | Error codes, tool name, non-identifying technical metadata (explicitly stripped of coordinates, dimensions, and other design values) | Supabase and error monitoring tooling (retained 90 days) |
| Diagnostics submission (only if you click "Send Diagnostics" after a failed calculation) | All of the inputs you had set when the calculation failed, including the full contents of any CSV curves you uploaded, submitted directly from the app to our backend and forwarded to our support team | Sent via our transactional email provider to our support mailbox; deleted within 7 days of ticket closure |
| AI chat history (only if you use the AI-assisted chat feature) | The text of your chat messages and the assistant's replies, which may include parameters you describe in words. Computed simulation results are not stored. | Supabase (deletable on demand, and auto-deleted; see §5 and §6) |
| Free-tier abuse-prevention data | A one-way hash of your email address, plus the date of an account deletion | Supabase (retained after account deletion; see §5) |
| Deleted-account record | A keyed one-way fingerprint of your email address, the customer and subscription identifiers issued by the Payment Processor, the dates the account was created and its email address verified, and the deletion date. Created only if the account had at least one payment. | Supabase (survives account deletion; see §5 and §9) |
What we do not collect or store: your design geometry (for example flow-channel layouts or heat-source placement), simulation input parameters, or simulation results. If you use the AI chat feature, any parameters you type into the chat in words are part of the stored chat text described in §6, until that conversation is deleted. There is currently no cloud project-storage feature, on any plan, and we do not currently plan to add one; if that ever changes, we will update this Policy first and seek your consent before any such feature is enabled for your account.
Apart from the AI chat text described above, the only other route by which your simulation parameters reach our backend is diagnostics submission: if a calculation fails, you may explicitly opt in, separately, for that specific incident, to send all of the inputs you had set when it failed, including the full contents of any CSV curves you uploaded, to our support team so we can investigate. The app shows you exactly what will be sent before you decide. Nothing is sent unless you click "Send" each time; this does not create a general-purpose cloud storage or project-history feature.
We also do not collect your IP address, device fingerprint, or precise location for the purpose of operating your account, metering usage, or handling refunds and disputes.
We use the information described above to: (a) create and maintain your account and authenticate you; (b) provide, operate, and maintain the Service; (c) process subscriptions and communicate with our Payment Processor about your billing status; (d) enforce usage quotas and detect abuse; (e) show you your own usage and account activity so that you can check it; (f) review and decide refund requests you submit, and communicate with you about them; (g) establish, exercise, and defend legal claims, including responding to payment disputes and chargebacks raised against a transaction; (h) provide customer support and respond to your requests; (i) comply with legal obligations, for example tax recordkeeping related to subscription revenue; and (j) improve the Service based on aggregated, non-identifying usage metadata.
Where the General Data Protection Regulation ("GDPR") applies, our legal bases are:
Where we retain records after you have asked us to delete your account, we rely on Art. 17(3)(b), compliance with a legal obligation, and Art. 17(3)(e), establishment, exercise, or defence of legal claims. Section 9 describes exactly what this covers.
You have the right to object to processing based on our legitimate interests. See §9.
| Data | Retention Period |
|---|---|
| Account and subscription data | For the life of your account. After deletion, see §9 |
| Sign-in session kept in your browser | Up to 5 days after you last use the Service. After that you are signed out and asked to sign in again |
| Payment and billing records held by Dodo Payments | Retained independently by Dodo Payments, our Payment Processor and merchant of record, under its own legal and tax obligations, even after your ThermoSketch account is deleted. See §7 and §9 |
| Usage records | Shown in your account for 40 days. Retained in an archive for 24 months from the date of the record, then automatically deleted |
| Account activity records | The 20 most recent entries are shown on your account's Security page. Retained for 24 months, then automatically deleted |
| Payment and refund records | 24 months from the date of the payment |
| Refund request records, including any explanation you wrote | 24 months from the date of the request |
| Payment dispute records | 24 months from the date the dispute is resolved |
| Deleted-account record | 24 months from the date of deletion |
| AI chat history (text of your chat messages and the assistant's replies) | Deletable on demand using "New chat" in the tool. Any conversation you do not delete is automatically removed after a short period of inactivity (about 24 hours, and no later than roughly 48 hours), and all chat history is deleted when you delete your account |
| Free-tier abuse-prevention record (hashed email) | 30 days from account deletion, then automatically purged |
| Error logs | Retained 90 days |
| Diagnostics submission | Deleted within 7 days of the related support ticket being closed |
| Design geometry, simulation inputs and outputs | Not stored on our servers at any time (see §2 and §7) |
Why 24 months. Card networks allow a cardholder to dispute a transaction well after it was made. For services delivered over time, that window can extend to roughly 18 months from the transaction, and the dispute process itself takes further months to conclude. Twenty-four months covers that period with a margin and no more. The records kept for this purpose are counts, identifiers, amounts, and timestamps, not the content of your work.
Certain paid plans may include AI-assisted analysis features, for example an AI chat assistant that can call analysis tools on your behalf. When you use the AI chat, the text of your conversation, meaning your messages and the assistant's replies, which may include parameters you describe in words, is stored on our servers so the assistant can follow the thread across multiple turns. We do not store snapshots of your computed simulation results. You can delete a conversation at any time using the "New chat" control in the tool, which clears it from our servers. Any conversation you do not delete is automatically removed after a short period of inactivity, about 24 hours, and no later than roughly 48 hours, and all chat history is deleted when you delete your account.
Third-party LLM providers. To power these features, we use one or more third-party large language model ("LLM") providers. As of the date of this Policy, our LLM provider or providers may include Anthropic, OpenAI, and/or Google (Gemini/Vertex AI). Our system is designed to switch between these providers, for example for cost, performance, or availability reasons, without requiring a change to the product itself. We do not currently use any LLM providers other than those listed above. If this list changes in the future, we will update this section first.
What is sent, and what the provider does with it. When you use an AI-assisted feature, your current session's design parameters, tool-call context, and chat messages are transmitted to the active LLM provider to generate a response. We use each provider's commercial or business API tier, not free consumer products. Based on each provider's own currently published policies: Anthropic and OpenAI do not use commercial API inputs and outputs to train their models by default, and retain request data only briefly for abuse-monitoring purposes, approximately 7 days for Anthropic's API and 30 days for OpenAI's API; Google's paid Gemini API and Vertex AI similarly do not train on your prompts or responses by default and retain data only for a limited period for safety and abuse-detection purposes. These are the providers' own policies, not commitments ThermoSketch makes on their behalf. Please refer to each provider's current privacy documentation for authoritative, up-to-date terms.
Separate obligation: AI system disclosure. Where required by applicable law, for example the EU AI Act's transparency obligations for AI systems that interact with people, effective August 2, 2026, the product interface itself, not just this Policy, will clearly disclose when you are interacting with an AI system.
We use the following service providers ("sub-processors") to operate the Service. We choose providers with independent security certifications where possible and disclose known limitations honestly below.
Anthropic, OpenAI, and/or Google: third-party LLM providers powering AI-assisted features on certain paid plans. See §6 for details on data sent and each provider's retention and training policies.
Cloudflare: front-end hosting, content delivery network (CDN), and a bot-protection challenge (Turnstile) on our sign-in, sign-up, and password-reset forms. The bot-protection check processes limited technical signals from your browser to tell humans apart from automated abuse. It is not used for advertising or cross-site tracking.
Modal: computational backend for running simulations (SOC 2 Type II certified). Important disclosure: while our own application code does not persist your design data, Modal's infrastructure retains encrypted request and response payloads for up to 7 days as part of its own platform operations, after which they are automatically deleted. Modal's terms restrict access to those payloads by Modal personnel to providing the service and addressing service or technical problems, and its Data Processing Addendum requires that anyone with access be bound by confidentiality. This is outside our code's control, and we disclose it so you have a complete and accurate picture. We do not claim your data "never touches a disk."
Supabase: authentication and database hosting for account, subscription, usage, payment, and refund records (SOC 2 Type II certified; encrypts data at rest).
Dodo Payments: our Payment Processor and merchant of record for paid subscriptions. It handles your payment card data, billing, and invoicing, and it issues any refund we approve under our Refund Policy. It also administers payment disputes and chargebacks raised against your transaction. See Dodo Payments' own privacy policy for how it handles your payment information.
Dodo Payments acts as the merchant of record for your purchase and, in that capacity, is an independent controller for your payment and billing records. Deleting your ThermoSketch account does not delete these records. Dodo Payments retains them for as long as required by its own applicable tax, accounting, and financial recordkeeping obligations. If you create a new ThermoSketch account later using the same email address, Dodo Payments may recognize you as a returning customer based on its own records, independent of your ThermoSketch account history.
Resend: transactional email delivery. It sends account-related emails, for example the one-time code that confirms an account-deletion request, subscription notices, and refund request correspondence, and it forwards diagnostics submissions to our support team. It processes the recipient email address and the contents of those messages solely for the purpose of delivering them.
Zoho: hosting for our mailboxes, including the support inbox (support@thermosketch.com). When you submit diagnostics or otherwise email our support address, your message, including the inputs and any uploaded CSV data you chose to send, is received and stored in that mailbox, and is deleted within 7 days of the related support ticket being closed. Correspondence relating to a refund request or a payment dispute is retained for the period stated in §5 for those records.
We do not sell your personal information to third parties, and we do not share it with third parties for their own independent marketing purposes.
Our sub-processors may process data in regions outside your own country. Specifically:
Supabase (account, subscription, usage, payment, and refund records) is hosted on AWS in the us-west-2 (Oregon, USA) region.
Modal (computational backend) operates a multi-cloud, multi-region infrastructure; container execution is not pinned to a single region and the majority of capacity is located in the continental United States, though capacity in other regions may be used. By default, request and response routing and staging of payloads larger than 2 MiB occurs through Modal's control plane in us-east (Virginia, USA), regardless of which region actually executes the computation. We have not configured a fixed execution region for Modal as of the date of this Policy; if we do so in the future, for example to align with Supabase's region, this section will be updated accordingly.
Where applicable, we rely on our sub-processors' own compliance mechanisms, such as Standard Contractual Clauses, SOC 2 certifications, or equivalent data protection frameworks, to safeguard cross-border transfers. Because design geometry and simulation data are never stored on our servers in the first place (see §2), these regional disclosures concern account, subscription, usage, payment, and refund records rather than your design content.
Regardless of where you are located, you have the right to: (a) access the personal information we hold about you; (b) request a copy of it in a portable format; (c) request correction of inaccurate information; (d) request deletion of your account and associated personal information (the "right to be forgotten"); and (e) object to processing we carry out on the basis of our legitimate interests.
Signed in, you can exercise (b) and (d) yourself. The Usage page in your account settings downloads a copy of your account details and your Usage Records as a CSV file. That download covers the records shown in your account, which is the most recent 40 days. The Profile page deletes your account. Both steps confirm with a one-time code sent to your email address.
For (a), (c), and (e), for records older than the download covers, or if you cannot sign in, see the contact details in section 15. We will respond to and complete access, correction, export, and deletion requests within 30 days. Because we do not store design geometry or simulation data in the first place, an export or deletion request will not include any such data; there is none to export or delete.
Deleting your account removes your identity from our systems. Specifically, we erase your email address, your name if we hold one, your password hash or OAuth identifier, and your AI chat history. Diagnostics you submitted were never stored in our database. They exist only in our support mailbox and are deleted within 7 days of the related ticket being closed, as described in §7. If you want them removed sooner, ask us. Your subscription with the Payment Processor is cancelled first, so that you are not billed again. In the rare case where we cannot cancel it at that moment, we tell you before you continue, explain what it means, and let you decide whether to proceed or to cancel it yourself first.
We keep a minimal set of transaction and dispute records for 24 months from the relevant date, and no longer:
| What we keep | Why |
|---|---|
| Payment and invoice identifiers, amounts, currency, dates, plan, billing period, card last four digits and network, and the country on the billing record | Accounting obligations, and evidence of what was purchased if a payment is later disputed |
| Refund request records, including the reason you selected, any explanation you wrote, the usage figures at the time, and our decision | Evidence that a request was made, considered, and answered |
| Payment dispute records | Defending a dispute, which can be raised long after the payment |
| Usage records reduced to counts and timestamps, with no geometry, parameters, or results | Evidence that the service you paid for was actually delivered |
| Account activity records | Evidence that the account was accessed and used by its holder |
| A keyed one-way fingerprint of your email address | So that we can match a dispute back to the correct transaction |
| The date your account was created, the date your email address was verified, and the date it was deleted | Evidence of how long the account existed and that its address was confirmed, which is what a card issuer asks for when a payment is disputed as unrecognised |
About the fingerprint. It is produced using a secret key that is not stored in our database. It lets us confirm whether an email address we have been given, for example by our Payment Processor when a payment dispute is raised, corresponds to a past transaction. It cannot be used to recover an email address from our records. After deletion, the records above are no longer linked to a name or an email address that we hold.
If your account never had a payment, there is no transaction to dispute: we keep no payment, refund, dispute, or fingerprint record. Your usage records and account activity records are still kept for 24 months as described above, reduced to counts and timestamps under an account identifier that no longer resolves to you.
Deleting your ThermoSketch account also does not delete payment and billing records held by Dodo Payments, our independent merchant of record, which retains such records under its own legal obligations (see §7). To request deletion or correction of data held directly by Dodo Payments, please contact Dodo Payments.
If you are located in a jurisdiction with specific statutory privacy rights, for example under the EU or UK GDPR or similar regional laws, those rights are provided as described in this section. You may contact us directly at support@thermosketch.com to exercise any of these rights, or to raise any concern about how we handle your personal information, and we will respond in accordance with applicable law. You also have the right to lodge a complaint with your local data protection supervisory authority. We do not currently operate a "sale" of personal information to third parties in the sense used by regional privacy statutes, so rights specific to opting out of data sales are not applicable to how we currently operate.
We use only strictly necessary cookies and similar technologies, such as your authentication session cookie, which is shared across our subdomains, and any cookie or token set by the bot-protection check on our sign-in, sign-up, and password-reset forms (see §7). We do not currently use advertising or cross-site tracking cookies. If we introduce analytics or tracking cookies in the future, we will update this Policy and provide appropriate notice and consent mechanisms, for example a cookie banner, before doing so.
The table below describes what we store on your device and why.
| Purpose | What It Does | How Long It Lasts |
|---|---|---|
| Keeping you signed in | Lets you stay signed in as you move between our website and our tools, so you do not have to sign in separately on each one. | Up to 5 days after you last use the Service |
| Protecting our account forms | Set by our bot-protection provider when you use the sign-in, sign-up, or password-reset forms, so we can tell real users apart from automated abuse. | Short-lived, and controlled by that provider |
| Remembering how you left a tool | Stores small display preferences, such as panel widths and the last items you selected, so a tool looks the way you left it. This stays on your device and is never sent to us. | Until you clear your browser data |
None of these are used for advertising or to track you across other websites.
The Service is intended for users who are at least 18 years old and is not directed at children. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us with personal information, contact us at support@thermosketch.com and we will delete it.
We use TLS encryption for all data in transit. Account, subscription, payment, and usage records at rest are protected by our database provider's platform-level encryption (AES-256).
Our strongest protection for your design and simulation data is architectural: since that data is never stored on our servers (see §2), there is no persistent copy for us to secure or for an attacker to steal from our systems.
For the records we do keep after an account is deleted (see §9), we apply a second architectural protection: the email address is replaced by a fingerprint computed with a secret key held outside the database, so that access to the database alone does not reveal who the records belong to.
For more detail, see our security overview.
If we become aware of a personal data breach, we will act without undue delay to investigate and contain it. Where the breach is likely to result in a risk to your rights and freedoms and notification is required under applicable law, we will notify the competent supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware of it; if that notification is not made within 72 hours, it will be accompanied by the reasons for the delay, as permitted by applicable law. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify the affected individuals without undue delay.
This Policy carries a version number and an effective date, shown at the top of this document. We may update it from time to time. If we make material changes, we will provide notice, such as by email or a notice on the Service, before the changes take effect.
The data controller responsible for your personal information is ThermoSketch LLC. If you have questions about this Privacy Policy or wish to exercise your rights, contact us at support@thermosketch.com, or by mail at:
ThermoSketch LLC, 30 N Gould St, Ste N, Sheridan, WY 82801, USA