← All legal documents

Privacy Policy

Edition 2026.09.4 · Effective 26 September 2026

What personal data Simorg Oy collects across simorg.tech, the Logos platform, Simorg Desktop and the machine service, why, who receives it, how long it is kept, and the rights you have over it.

1. Who is responsible for your data

Simorg Oy, Business ID 3615774-7, Kalevankatu 26 A, 00100 Helsinki, Finland, is the controller of the personal data described in this policy. Write to info@simorg.tech about anything in it. We have not appointed a data protection officer, because our size and what we process do not require one; the same address reaches the person responsible for privacy.

2. What this policy covers

This policy covers simorg.tech, the Logos web application and its APIs, Simorg Desktop, the Simorg machine service and the simorg command, the emails we send, and the newsletter. Simorg Desktop and the machine service have a supplement, the Desktop and Machine Service privacy notice, about what leaves your computer and what never does; it is shown in the app before you sign in and published at simorg.tech/legal/desktop-privacy.

It does not cover what your agents do with data. An agent you create or run processes data under your control, on machines you choose, and you are responsible for it and for the people it serves. Nor does it cover the websites, registries, container engines and payment pages of other companies that the Services link to or work with; each has its own notice.

3. Your account

When you register we collect your email address, a username, a password and, if you choose, a display name, a tagline, a description, a website, social links and a profile picture, together with the preferences you set: theme, notification choices, the layout of your Logos, and what you told us you intend to use Simorg for. We use them to run your account, show you as the owner of what you make, send you the emails the account needs, and answer your requests.

Your username, display name, profile picture, tagline and description, and your public agents and artifacts, are visible to everyone; that is what a profile is for. Members of a Team see each other’s names and handles and the email address each was invited at.

4. Signing in, and keeping the account safe

Your password is stored only as a salted hash and cannot be read back. If you turn on two-step verification, its secret and recovery codes are stored encrypted. Email-verification and password-reset links are stored as hashes with an expiry.

Every session is bound to the device it was opened on. In a browser that is a random secret the browser keeps and presents as a fingerprint; on a computer running the machine service it is a fingerprint derived through one-way functions from the operating system’s machine identifier, which itself never leaves the computer. A token presented from another device is refused. We keep a history of when you signed in, and from which kind of client, which you can see under Settings → Your data.

We keep an audit log of security-relevant actions on your account — who did what, to what, and when — so that a mistake or a misuse can be traced.

5. Plans and payment

If you subscribe to a paid plan we collect the name or company name, billing email, address and, for a business, the VAT or tax identifier you enter, and we send them to Stripe, our payment provider, which validates the tax identifier and works out the tax to charge. Your card number never reaches us: you enter it into a form served by Stripe, which stores it and charges it. We keep the card’s brand, its last four digits, its expiry month and the reference Stripe gives us, so that Billing can show which card paid what.

Invoices are kept for 6 years from the end of the year they were issued in, because the Finnish Accounting Act requires an invoice to be kept as it was issued. When you delete your account the invoices stay, with everything joining them to you removed, and are deleted automatically when that period ends.

6. Your machines

When a computer of yours is registered as a machine, the machine service sends a description of it — its name and host name, operating system and version, architecture, processor, cores, memory, disk size and free space, time zone and locale — and, while it runs, which agents are placed on it and whether their containers are up. Your machine page shows exactly that. The fingerprint described in section 4 identifies the machine to the platform. A machine record is deleted when you remove the machine.

7. Your agents, sources, files and published work

Everything you create on the platform — agents, their settings and environment variables, source repositories, uploaded files, artifacts and their releases, the Logos you arrange them on, whom you follow and what you subscribe to — is stored so that it can be shown to you and to the people you share it with. Environment variables are encrypted at rest. Data an agent exchanges with a surface such as the Workbench or the Brain travels encrypted end to end, and the platform relays it without reading it.

A public artifact is visible to everyone, under the address and the licence you gave it. Section 13 explains what becomes of it if you leave.

8. Product analytics and error reports

With your consent, simorg.tech and the Logos application record how they are used and what goes wrong in them, so that we can find the screens that confuse people, the steps that take too long and the errors that happen most often. A record holds which pages and features are opened and in what order, whether an action succeeded, the shape of an error together with the last few screens before it, the version of the application, the operating system, the browser, the language, the time zone, the size of the window, the page you came from, any campaign parameters in the address you arrived by, and the country resolved from your IP address.

On simorg.tech these records are tied to an anonymous visitor id kept in your browser. Inside your account they are tied to the account, because a question such as which features our customers actually reach can only be answered that way, and when you sign up the visitor id from your visits to simorg.tech is linked to the new account so that we can see which page brought you here. Your IP address is stored with a session for 7 days, to tell people from robots and to find abuse, and is then shortened to its network so that it no longer names a computer; the country stays.

We never record your password, any token or credential, the contents of a form, a file name, a file’s contents, your source code or the output of your agents. These records are used only to improve the product, are never used to decide anything about you or your account, and are neither sold nor shared for advertising.

You choose whether this happens in the cookie dialog when you first visit, and you can change your choice at any time from Cookie settings in the site footer or from Settings → Privacy → Analytics in the product. Without your consent nothing is recorded and nothing is stored in your browser for this purpose. Simorg Desktop and the machine service send diagnostics that carry no identifier at all and are not linked to you; the Desktop and Machine Service privacy notice describes them.

9. Contacting us, and hearing from us

A message sent through the contact form is stored with the topic, your email address, the message, the browser it was sent from, the anonymous visitor id of the browser, and the address it was sent from — shortened to its network after 7 days — so that we can answer it and recognise abuse.

If you subscribe to the newsletter we store your email address and send a confirmation link first; nothing else is sent until you confirm. Every newsletter carries an unsubscribe link, and Email preferences on simorg.tech lets you change your choice at any time.

The emails an account needs — verification, password reset, two-step verification, invoices, notifications you have turned on, an erasure notice — are sent through Google’s Gmail API from our Google Workspace account, which means Google processes the address, the name and the content of each such email on our behalf.

Feedback you leave on a documentation page (“was this helpful”) is stored with the page and the anonymous visitor id, and nothing else.

If you report an artifact, an agent or a profile, the report is stored with the reason you chose, what you wrote, your email address if you gave it, your account if you were signed in, the browser and address it came from, and what we decided about it, for 730 days, because the Digital Services Act asks us to keep a record of the notices we receive and how we handled them. We confirm receipt to the address you gave and tell you what we decided.

11. Who receives your data

We do not sell personal data and we do not share it for advertising. It reaches these recipients, each for the purpose stated:

  • Amazon Web Services, which hosts the platform. Our databases, storage and servers are in the Stockholm region (eu-north-1) in the European Union. Downloads and the website are delivered through Amazon CloudFront, whose edge servers around the world see the address of the browser they serve; those access logs are kept for 90 days.

  • Stripe, which processes payments, validates tax identifiers and works out tax. Stripe receives the billing details in section 5 and your card, which we never see.

  • Google, whose Gmail API sends every email the account needs, and therefore processes the address, name and content of those emails on our behalf.

  • Other people on the platform, to the extent you make something public or share it with a Team, as sections 3 and 7 describe.

  • The registries and download servers that container images and artifacts come from, which see the address of the computer that fetches them, as any download does. The agent runtime image is fetched from download.simorg.tech, which is ours.

  • YouTube, only if you play a video that an artifact page embeds. Videos are embedded in privacy-enhanced mode, and nothing is sent to YouTube until you press play.

  • Courts, authorities and professional advisers, where the law requires it or where we need to establish, exercise or defend a legal claim.

  • A successor to our business, if Simorg is sold or merged, in which case we will tell you before your data is transferred.

The country resolved from an IP address for analytics is looked up in a copy of the GeoLite2 database on our own servers; nothing is sent to its publisher, MaxMind.

12. Transfers outside the European Union

The platform is hosted in the European Union. Stripe and Google process some data in the United States. Both are certified under the EU-US Data Privacy Framework, and our agreements with them include the European Commission’s standard contractual clauses as a further safeguard. You can ask us for a copy of those safeguards at the address in section 1.

13. How long we keep it

Account data is kept for as long as your account exists, and deleted when the account is erased, except where a row below says otherwise. Everything else has a period:

WhatHow long
Your account, agents, sources, files, machines, settings, follows and notificationsUntil you delete the account, plus the wait described in section 14
Published artifacts and their releasesUntil you delete the agent that published them and choose where they go; work handed to the Simorg archive stays published without a name
Sign-in history365 days
Invoices6 years from the end of the year they were issued in, detached from the person after an erasure
Product analytics sessions, events and error reports400 days; the IP address is shortened to its network after 7 days
Anonymous page-view continuity on simorg.tech400 days
Documentation feedback400 days
Reports of content, and what was decided about them730 days
Contact-form messages730 days; the address they came from is shortened to its network after 7 days
Newsletter subscriptionUntil you unsubscribe, then 30 days; an unconfirmed subscription is deleted after 30 days
Database backupsSnapshots for 14 days and nightly copies for 90 days, after which erased data is gone from them too
Load-balancer and content-delivery access logs90 days
Audit logFor as long as the account exists; entries about an erased account are deleted with it

14. Deleting your account, and what survives it

Settings → Your data lists everything we hold about your account, with live counts and what happens to each part if you leave, and lets you download all of it as one file and delete the account yourself. Nothing needs to go through us. Deleting takes effect 30 days after you ask; we email you when it is scheduled, every screen says so until it happens, and you can stop it at any point. The wait exists because this is the only action on the platform with no undo, and the person who pressed the button is not always the account’s owner.

Two things survive, both deliberately. Your handle is never given to anybody else: it is written into the address of everything you ever published, in other people’s projects, and releasing it would let a stranger inherit the trust your name earned. We keep it as a keyed hash that can answer “is this taken?” and cannot be read back as a name. And invoices are kept as section 5 describes. Everything else goes: your profile, your agents, your machines, your sources, your files, your sign-in history, your audit entries and your settings.

15. Work you have published

Artifacts other people depend on are never destroyed because you left. When you delete the agent that published them you choose where they go — to another agent, to another person, or to the Simorg archive, where they stay published under an owner who is nobody in particular, so that projects depending on them keep working. Their page then says the publisher has been removed, and never who it was. Old addresses keep resolving through the same kind of keyed hash as your handle, which no one can read back.

16. Your rights

Under the General Data Protection Regulation you have the right:

  • to access the personal data we hold about you — Settings → Your data shows it, and Download my data gives you a copy in a machine-readable file, which is also your right to data portability;

  • to have inaccurate data corrected — your profile, preferences and billing details are yours to edit in the product;

  • to have your data erased — Settings → Your data, as section 14 describes;

  • to restrict processing, and to object to processing based on our legitimate interests, on grounds relating to your particular situation — write to us; for product analytics the switch under Settings → Privacy → Analytics, or Cookie settings in the site footer, stops it at once;

  • to withdraw consent at any time, without affecting what was done before — the same switch for analytics, the unsubscribe link for the newsletter;

  • to complain to a supervisory authority. Ours is the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto), https://tietosuoja.fi/en/. You may also complain to the authority of the country where you live.

For anything the product does not let you do yourself, write to info@simorg.tech. We answer within one month, and we may ask you to confirm your identity first, so that nobody else can exercise your rights for you.

17. Automated decisions

We make no decision about you by automated means alone that has legal or similarly significant effects on you. Rate limits and abuse detection protect the Services and do not decide anything about your account; a person does.

18. Children

The Services are not intended for people under 16, and we do not knowingly collect personal data from them. If you believe a child has given us personal data, write to us and we will delete it.

19. How we protect it

Every connection to the platform is encrypted in transit. Passwords are hashed, secrets are encrypted at rest, and the keys that protect them are held in the hosting provider’s secrets manager rather than in code or configuration. Sessions are bound to devices, two-step verification is offered to everyone, every action is checked against the role the person holds, and the console our staff use to run the platform is a separate system whose accounts can never sign in to the product. Backups are taken automatically. Access to production is limited to the people who operate it, and every security-relevant action is logged.

No system is perfectly secure. If we learn of a breach that is likely to put you at risk, we will tell you and the supervisory authority as the law requires.

20. Changes to this policy

When this policy changes, the edition number and date at the top change too. For a change that materially affects you we tell you by email and in the product before it takes effect, and Simorg Desktop asks you to accept the new edition when you next sign in. Earlier editions are available on request.

21. Contact

Simorg Oy, Kalevankatu 26 A, 00100 Helsinki, Finland. Email info@simorg.tech. Company information is published at simorg.tech/legal/company.