Data Security

Last updated: August 28, 2026

This page explains exactly how ThermoSketch handles your data, in plain terms you can verify against our Privacy Policy.

At a Glance

DataHow Long We Keep It
Design geometry, simulation inputs and outputsNever stored on our servers, on any plan
Usage records (counts and timestamps only)40 days in your account, then archived for 24 months
Account activity records (sign-ins, plan changes)24 months
Payment, refund, and payment dispute records24 months
AI chat text (only if you use the chat)Delete it yourself at any time, otherwise removed within roughly 48 hours
Diagnostics submission (only if you send one)Deleted within 7 days of your support ticket closing
Error logs90 days
Request and response payloads held by ModalUp to 7 days, on Modal's own platform
Signed-in session kept in your browserExpires after 5 days without use

Zero Retention for Design and Simulation Data

Your design geometry and your simulation inputs and outputs are never stored on our servers, on any plan, whether you are on the free tier or a paid subscription. You submit your parameters, we run the calculation, and the results are returned directly to your browser. There is no cloud project-storage feature. When you want to keep a copy, use the Download button in the results area to save a .json file to your own device.

There are two exceptions, and you opt into each one yourself. The first is a diagnostics submission after a failed calculation. The second is the optional AI chat feature, where the text of your conversation is stored so the assistant can follow the thread across turns, and can be deleted at any time. Both are described below.

What We Log

Our system logs record only operational metadata: your user ID, which tool you used, which action you took (a solver run, a PDF export, a CSV export, or an AI chat turn), whether it succeeded, when it happened, which plan you were on at the time, and token counts for AI chat. They do not record your simulation parameters or geometry.

Usage records are shown in your account for 40 days. They are then moved to an archive and kept for 24 months from the date of the record, so that we can answer a payment dispute raised long after the transaction, after which they are deleted automatically. Error logs record an error type, the tool and endpoint involved, and a truncated message with design values stripped out. They are kept for 90 days.

Staying Signed In

When you sign in, your session is kept in your browser so you can move between our website and our tools without signing in again on each one. If you do not use the Service for 5 days, that session expires and you will be asked to sign in again.

You can sign out at any time from the account menu. If you think someone else has access to your account, use Sign Out All Devices on your profile page. This signs out every browser and device, including the one you are using. It can take up to an hour for sessions already open elsewhere to be fully cut off, so we also recommend changing your password.

Sending Diagnostics After a Failure

If a calculation fails, you can choose to click Send Diagnostics to submit all of the inputs you had set when it failed, including the full contents of any CSV curves you uploaded, to our support team for investigation. The app shows you exactly what will be sent before you decide, and it is deleted within 7 days of your ticket being closed. This only happens when you click Send. Nothing is sent automatically. Apart from the AI-assisted features described below, this is the only situation where your simulation data reaches our backend. It does not change how we handle your data during normal use of the Service.

How Modal Processes Your Calculations

Your calculations run on Modal's infrastructure. While a calculation is being processed, Modal's platform temporarily stores encrypted request and response data for up to 7 days as part of its own operations, after which it is deleted automatically. Modal's terms restrict access to that data by Modal personnel to providing the service and addressing service or technical problems, and its Data Processing Addendum requires that anyone with access be bound by confidentiality. We cannot shorten that retention window.

AI-Assisted Features

Some paid plans include AI-assisted features, such as a chat assistant that can run analysis tools for you. When you use these features, your current session's design parameters, tool-call context, and chat messages are sent to a third-party AI provider to generate a response. We can switch providers without changing the product, so the providers we use may include Anthropic, OpenAI, or Google (Gemini/Vertex AI). Each provider's commercial API tier does not train on your data by default, based on their own published policies. See our Privacy Policy for each provider's exact data-retention window.

The text of your chat conversation is stored on our servers so the assistant can follow the thread across multiple turns; we do not store snapshots of your computed results. You can delete a conversation at any time using "New chat" in the tool, which clears it from our servers, and any conversation you do not delete is automatically removed after a short period of inactivity, about 24 hours, and no later than roughly 48 hours. All chat history is deleted when you delete your account.

Who We Work With

ProviderWhat It Does
ModalRuns your calculations. See the section above for how it handles your data
SupabaseHosts our authentication and account database
CloudflareHosts our website and content delivery, and provides a bot-protection check on our sign-in, sign-up, and password-reset forms
Dodo PaymentsProcesses your subscription payments as our merchant of record. It handles your card details directly, and we never see or store them
ResendDelivers account-related emails, such as confirmation codes
ZohoHosts our support mailbox

Our Privacy Policy has the full list, including retention periods and where each provider processes your data.

For EU and UK Users (GDPR)

This section describes how the GDPR applies to ThermoSketch if you are in the EU or the UK. We do not collect or store your design geometry or simulation data, so there is no cloud-storage feature requiring your consent, and no consent banner for it.

What we do collect is your account and subscription data, records of your usage measured as counts and timestamps, records of account activity such as sign-ins and plan changes, and records of payments, refund requests, and payment disputes. Account and subscription data are necessary to provide the Service under our contract with you. The usage, activity, and dispute records rest on our legitimate interest in operating the Service, metering the plan you purchased, and defending payment disputes. A diagnostics submission rests on your consent, which you give each time you send one.

Our Privacy Policy sets out the legal basis for each category, your full rights including access, correction, and deletion, and what is kept after you delete your account.

This page is a plain-language summary. Where it and our Privacy Policy differ, the Privacy Policy governs.