wispr™
ExploreMy account

SimDex™ · Wisp™

Privacy Policy

Effective September 9, 2026

Who we areInformation we collect and whyOur reasons for processingService providers and sharingCookies and previewsHow long information staysYour choices and rightsSecurity and childrenChanges

Who we are

SimDex operates Wisp, a service for understanding and editing React and Next.js projects. In this policy, “we,” “us” and “our” mean SimDex. For privacy questions or requests, contact simdexapp@gmail.com with “Wisp privacy” in the subject. This policy covers Wisp's public website, accounts, waitlist and hosted workspaces. If you run Wisp locally, you control that installation and its project storage; connected third-party services may process information independently.

Information we collect and why

Accounts and waitlist. We process your email address, verified authentication identifier, display name, optional biography, profile color, interface preferences, join date, member number, approval status and queue order. These support sign-in, account customization, waitlist management and workspace access.

Authentication. Supabase processes email authentication and sessions. Resend delivers sign-in emails. Wisp uses necessary secure session cookies. We process code requests and security metadata to prevent unauthorized access and abuse. Our authentication rate table uses keyed email and IP identifiers instead of storing the raw values there; these identifiers are not necessarily anonymous.

Projects. Opening and using a project processes source files, repository references, package information, analysis graphs, saved edits, diffs, earlier source versions for undo and development-process output. Hosted projects reside on their assigned workspace server. Local projects reside on the device or server running the engine. Closing a browser or stopping a preview does not delete saved work.

Service operation. We and our hosting providers process request and error metadata needed for routing, reliability and security. Provider logs may include IP addresses, browser details and request information. The beta administrator can view account information and access events. Administrators with server access may access hosted project data when operating or supporting the service.

Optional providers. If an AI provider is configured and used, context relevant to the requested operation may be sent to that provider. Usage records can include provider, model, operation, token counts, latency, outcome and estimated cost. Static code analysis and deterministic text edits do not require an AI request. A provider's own terms govern its processing; we do not make a blanket promise about third-party model training or retention.

Contact requests. If you email us, we process the information you provide to answer the request, verify identity where necessary and keep an appropriate record. Avoid sending passwords, sign-in codes, private keys or unnecessary project secrets.

Our reasons for processing

We process information to provide requested services and manage our relationship with you; for legitimate interests in protecting accounts, preventing abuse, maintaining reliability and answering requests; and to comply with applicable legal obligations. Where consent is required for a particular optional activity, we will seek it and explain how to withdraw it. Withdrawal does not invalidate prior lawful processing. Joining the waitlist is not consent to unrelated marketing.

Service providers and sharing

Wisp's current architecture uses OpenAI Sites and Cloudflare for website hosting, routing and account storage, Supabase for identity, Resend for transactional email, and DigitalOcean for our hosted workspace engine. Repository services such as GitHub process repository operations you request. Optional integrations may involve additional providers selected for that feature.

We disclose information as needed to deliver those functions, respond to applicable legal requirements, investigate misuse or protect people and the service. If the business is reorganized or transferred, information may be transferred with it, subject to applicable protections and notice requirements.

The current Wisp application does not sell personal information or implement advertising trackers, cross-site advertising or a personal-data marketplace. This describes Wisp's practices, not every provider's independent services.

Providers may process information outside your country, including in the United States. Applicable legal requirements govern international transfers. Contact us for information about the arrangements relevant to your data. This policy does not claim a particular certification or transfer mechanism that has not been verified.

Cookies and previews

Wisp's essential session cookies keep you signed in. They are Secure, HttpOnly and SameSite=Lax. Signing out clears Wisp's session cookies in that browser and attempts to revoke its provider session; other devices may stay signed in. Blocking necessary cookies can prevent authentication. We have not added optional advertising or website-analytics cookies to this release.

Your chosen light, dark or device-based appearance is also saved in your browser’s local storage. This preference stays on that device and does not require an account.

The cookie notice stores its dismissal in your browser’s local storage so it does not reappear on every visit. This acknowledgement is not marketing consent. You can reopen the notice from “Cookies” in the footer; clearing browser storage removes that preference.

Project previews use a separate origin. Imported applications may load their own services, set cookies or collect data. Those behaviors are controlled by the imported application. Anyone who obtains a running preview URL may be able to view it until the preview stops. Share preview links only with people who should see the application, and avoid exposing confidential data in a preview.

How long information stays

We retain account and waitlist information while needed to maintain the account, manage access and address legitimate security or legal needs. Hosted projects, analysis and undo snapshots persist to support your workspace until removed as part of workspace management or a deletion request. Local installations remain under their operator's control.

We assess retention based on account activity, the purpose and sensitivity of the information, support and dispute needs, and applicable legal obligations. There is no general automatic account-expiry or project-purge schedule in this beta. Expired authentication rate windows are removed on a subsequent authentication request. Provider logs and backups follow the applicable provider arrangements; we cannot promise that deletion from an active system immediately removes every backup copy. Contact us to request deletion or discuss a particular record.

Your choices and rights

You can update profile preferences, sign out and stop previews. For account access, correction, export, deletion, restriction, objection or consent withdrawal requests, email simdexapp@gmail.com. These requests are currently handled manually; account-wide export and deletion are not self-service features. We may ask for reasonable verification to protect your information. We respond under applicable law, including its deadlines and lawful exceptions.

Depending on where you live, you may have additional privacy rights and the right to complain to a data-protection authority. We do not penalize you for exercising applicable rights. Certain information may need to be retained for legal obligations, security or unresolved disputes; we will explain applicable limitations.

Security and children

Wisp uses HTTPS, verified identity, access controls, guarded source edits and encrypted stored gateway credentials. No system can guarantee absolute security. Imported project scripts execute on the assigned engine; the beta is intended for trusted projects and is not a hostile-code sandbox.

Wisp's beta is for users aged 18 or older and is not directed at children. If you believe a child has supplied personal information, contact us so we can investigate and take appropriate action.

Changes

We will update the effective date when this policy changes and provide appropriate notice of material changes. Where required, we will obtain consent before a new use of information. Contact simdexapp@gmail.com with questions about this policy.

© 2026 SimDex™. Wisp™.
PrivacyTermsContact