Privacy Policy
What we collect, what we deliberately do not, and how long anything survives.
01The short version
We collect what is needed to run an account and nothing else. There is no analytics, no advertising, no tracking, and no third-party scripts of any kind. When you load a page from Auddomate, your browser talks to our server and to nobody else.
We do not sell your data, we do not share it with other customers, and we do not use anything you upload to train models.
02What we collect
Account information
Your name, email address, organisation name, and your role within that organisation. Passwords are never stored — we keep only a bcrypt hash, which cannot be reversed to recover the original password.
Your preferences
Language, units, and light or dark theme, so the application looks the same next time you sign in.
Content you create
Site plans you upload and the markup you draw on them, studies, client names, machine profiles, fleets, simulation inputs, telemetry you import, and profile pictures.
Sign-in records
Each sign-in attempt records the email address used, the IP address it came from, whether it succeeded, and when. This exists solely to rate-limit brute-force attempts. These records are deleted automatically after 90 days.
Demo sandboxes
When someone opens a demo we store the IP address it was created from, so that one visitor cannot fill the database. It is deleted with the sandbox.
03What we do not collect
- No analytics or usage tracking. No Google Analytics, no Plausible, no Matomo, no session recording, no heatmaps.
- No third-party requests. Fonts, scripts and images are served from our own server. No CDN, no external font service, no embedded widgets.
- No advertising or marketing trackers, and no pixels from social networks.
- No payment details. We do not currently process payments and no card data reaches our servers.
- No location data beyond the IP address described above, and no device fingerprinting.
04Cookies
Auddomate sets one cookie, a session cookie, and only after you sign in or open a demo. It holds a random session identifier and nothing else. It is marked HttpOnly so scripts cannot read it, SameSite=Lax to limit cross-site use, and Secure when served over HTTPS.
There are no tracking cookies, so there is no consent banner. Your browser also stores small preferences locally — such as whether the sidebar is collapsed — which never leave your device.
If you arrive by a link we posted somewhere — it ends in ?from= and a short word — that word is kept in your browser for the life of the tab and is recorded if you open the demo or press Talk to us, so we know which post brought you. It names the post, not you, and is gone when the tab closes.
05How we use it
We use your information to operate your account, run the calculations you ask for, keep your organisation's data separate from every other organisation's, protect the service from abuse, and respond to you if you contact us.
Every database query is scoped to your organisation. A study, plan or machine belonging to another account is not merely hidden from you — it is not returned at all.
06Who else sees it
People you invite. Anyone in your organisation can see that organisation's studies, plans and machines. That is the point of a shared workspace. Only an owner can invite or remove people.
Our hosting provider. The application and database run on shared hosting, so the provider necessarily has technical access to the server. They do not process your data for any purpose of their own.
Nobody else. We have no other processors, no analytics vendor, and no advertising partners. If that ever changes, this page will say so before it happens.
We may disclose information where we are legally required to, and will tell you unless prohibited from doing so.
07How long we keep it
- Account and content — for as long as your account is open. Delete a study, plan or machine and it is removed from the database; deleting a plan also removes the underlying file.
- Demo sandboxes — deleted automatically a few hours after they are created, along with any files uploaded into them.
- Sign-in records — deleted automatically after 90 days.
- Backups — routine backups may retain deleted data for a short period before being overwritten in the normal cycle.
08Your rights
You can see and correct most of your information directly in the application, under Settings.
- Export — machine libraries and telemetry as CSV, and a whole study as JSON, from Integrations. No request needed.
- Correction — edit your name, email, organisation name and preferences at any time.
- Deletion — delete individual records yourself, or ask us to close the account and remove everything.
- Access — ask us for a copy of what we hold about you.
Depending on where you live you may have further rights over your personal data, including the right to object to processing or to complain to a data protection authority.
09How it is protected
Passwords are hashed with bcrypt at a deliberately slow cost factor. Traffic is served over HTTPS. Session cookies are restricted as described above, and sign-in attempts are rate-limited by both email address and IP address.
Uploaded plans and profile pictures are stored outside the public web root, so they cannot be fetched by guessing a URL — every file request is checked against your organisation first.
No system is perfectly secure. If a breach affects your personal data we will tell you and describe what happened.
10Children
Auddomate is a tool for industrial and commercial use and is not directed at children. We do not knowingly collect information from anyone under 16. If you believe a child has given us personal data, contact us and we will delete it.
11Changes to this policy
We will update this page as the service changes. The date at the top shows when it was last revised. Where a change materially affects how we handle your information we will make a reasonable effort to notify account holders rather than quietly editing this page.
12Contact
Questions about privacy, or a request about your data, can go to legal@auddomate.com.