Data Security
Last updated: August 28, 2026
This page explains exactly how ThermoSketch handles your data, in plain terms you can verify against our Privacy Policy.
At a Glance
| Data | How Long We Keep It |
|---|---|
| Design geometry, simulation inputs and outputs | Never stored on our servers, on any plan |
| Usage records (counts and timestamps only) | 40 days in your account, then archived for 24 months |
| Account activity records (sign-ins, plan changes) | 24 months |
| Payment, refund, and payment dispute records | 24 months |
| AI chat text (only if you use the chat) | Delete it yourself at any time, otherwise removed within roughly 48 hours |
| Diagnostics submission (only if you send one) | Deleted within 7 days of your support ticket closing |
| Error logs | 90 days |
| Request and response payloads held by Modal | Up to 7 days, on Modal's own platform |
| Signed-in session kept in your browser | Expires after 5 days without use |
Zero Retention for Design and Simulation Data
Your design geometry and your simulation inputs and outputs are never stored on our servers, on any plan, whether you are on the free tier or a paid subscription. You submit your parameters, we run the calculation, and the results are returned directly to your browser. There is no cloud project-storage feature. When you want to keep a copy, use the Download button in the results area to save a .json file to your own device.
There are two exceptions, and you opt into each one yourself. The first is a diagnostics submission after a failed calculation. The second is the optional AI chat feature, where the text of your conversation is stored so the assistant can follow the thread across turns, and can be deleted at any time. Both are described below.
What We Log
Our system logs record only operational metadata: your user ID, which tool you used, which action you took (a solver run, a PDF export, a CSV export, or an AI chat turn), whether it succeeded, when it happened, which plan you were on at the time, and token counts for AI chat. They do not record your simulation parameters or geometry.
Usage records are shown in your account for 40 days. They are then moved to an archive and kept for 24 months from the date of the record, so that we can answer a payment dispute raised long after the transaction, after which they are deleted automatically. Error logs record an error type, the tool and endpoint involved, and a truncated message with design values stripped out. They are kept for 90 days.
Staying Signed In
When you sign in, your session is kept in your browser so you can move between our website and our tools without signing in again on each one. If you do not use the Service for 5 days, that session expires and you will be asked to sign in again.
You can sign out at any time from the account menu. If you think someone else has access to your account, use Sign Out All Devices on your profile page. This signs out every browser and device, including the one you are using. It can take up to an hour for sessions already open elsewhere to be fully cut off, so we also recommend changing your password.
Sending Diagnostics After a Failure
If a calculation fails, you can choose to click Send Diagnostics to submit all of the inputs you had set when it failed, including the full contents of any CSV curves you uploaded, to our support team for investigation. The app shows you exactly what will be sent before you decide, and it is deleted within 7 days of your ticket being closed. This only happens when you click Send. Nothing is sent automatically. Apart from the AI-assisted features described below, this is the only situation where your simulation data reaches our backend. It does not change how we handle your data during normal use of the Service.
How Modal Processes Your Calculations
Your calculations run on Modal's infrastructure. While a calculation is being processed, Modal's platform temporarily stores encrypted request and response data for up to 7 days as part of its own operations, after which it is deleted automatically. Modal's terms restrict access to that data by Modal personnel to providing the service and addressing service or technical problems, and its Data Processing Addendum requires that anyone with access be bound by confidentiality. We cannot shorten that retention window.
AI-Assisted Features
Some paid plans include AI-assisted features, such as a chat assistant that can run analysis tools for you. When you use these features, your current session's design parameters, tool-call context, and chat messages are sent to a third-party AI provider to generate a response. We can switch providers without changing the product, so the providers we use may include Anthropic, OpenAI, or Google (Gemini/Vertex AI). Each provider's commercial API tier does not train on your data by default, based on their own published policies. See our Privacy Policy for each provider's exact data-retention window.
The text of your chat conversation is stored on our servers so the assistant can follow the thread across multiple turns; we do not store snapshots of your computed results. You can delete a conversation at any time using "New chat" in the tool, which clears it from our servers, and any conversation you do not delete is automatically removed after a short period of inactivity, about 24 hours, and no later than roughly 48 hours. All chat history is deleted when you delete your account.
Who We Work With
| Provider | What It Does |
|---|---|
| Modal | Runs your calculations. See the section above for how it handles your data |
| Supabase | Hosts our authentication and account database |
| Cloudflare | Hosts our website and content delivery, and provides a bot-protection check on our sign-in, sign-up, and password-reset forms |
| Dodo Payments | Processes your subscription payments as our merchant of record. It handles your card details directly, and we never see or store them |
| Resend | Delivers account-related emails, such as confirmation codes |
| Zoho | Hosts our support mailbox |
Our Privacy Policy has the full list, including retention periods and where each provider processes your data.
For EU and UK Users (GDPR)
This section describes how the GDPR applies to ThermoSketch if you are in the EU or the UK. We do not collect or store your design geometry or simulation data, so there is no cloud-storage feature requiring your consent, and no consent banner for it.
What we do collect is your account and subscription data, records of your usage measured as counts and timestamps, records of account activity such as sign-ins and plan changes, and records of payments, refund requests, and payment disputes. Account and subscription data are necessary to provide the Service under our contract with you. The usage, activity, and dispute records rest on our legitimate interest in operating the Service, metering the plan you purchased, and defending payment disputes. A diagnostics submission rests on your consent, which you give each time you send one.
Our Privacy Policy sets out the legal basis for each category, your full rights including access, correction, and deletion, and what is kept after you delete your account.
This page is a plain-language summary. Where it and our Privacy Policy differ, the Privacy Policy governs.