MaximaLabs
Legal

Privacy Policy

How MaximaLabs collects, uses, and protects your data when you use our process-simulation platform.

Last updated: July 26, 2026

1.Who we are and what this covers

MaximaLabs (“we,” “us”) operates a browser-based chemical process-simulation platform at maximalabs.io (the “Service”). This policy explains what information we collect when you create an account, build and run simulations, and use the AI copilot, and how we handle it. It applies to the Service only; sites and tools we link to have their own policies.

2.Information we collect

  • Account information. When you register with an email and password, we store your email address and a securely hashed password. If you sign in with Google, we receive your name, email address, and profile picture from Google’s OpenID Connect scopes (openid, email, profile) — we never receive or store your Google password.
  • Simulation content. The flowsheets, components, thermodynamic settings, results, notebooks, comments, and version snapshots you create. This is your content; we store it so the Service works and you can return to it.
  • Usage and billing metering. A ledger of solves, optimizations, sensitivity runs, and AI calls, used to enforce plan quotas and, for paid plans, to calculate usage-based charges. Payment card details are handled by Stripe, not by us.
  • Technical data. Standard server logs (IP address, browser type, timestamps, requested URLs) generated when your browser talks to the Service, used for security, debugging, and reliability.

3.How we use your information

  • To provide the Service — authenticate you, store and run your simulations, and deliver results.
  • To power the AI copilot when you invoke it (see section 4).
  • To enforce plan limits and bill paid usage.
  • To secure the Service, prevent abuse, and diagnose problems.
  • To send transactional email you would expect (welcome, password reset, collaborator invites, job-completion notices). Marketing/newsletter email is opt-in only and every send carries a one-click unsubscribe.

We do not sell your personal information, and we do not use your simulation content to train machine-learning models.

4.AI processing and the copilot

The AI copilot is optional and only runs when you invoke it. When you do, the relevant simulation context (flowsheet, stream table, unit-op parameters, and your message) is sent over an encrypted connection to Anthropic’s Claude API to generate a response. Anthropic processes this data as our subprocessor to return the response and does not use it to train its models. The AI is never on the critical path of a solve — if it is unavailable, your simulations still run.

5.Subprocessors and third parties

We share data with a small set of service providers, only as needed to run the Service:

  • Anthropic (PBC) — powers the AI copilot; receives simulation context only when you invoke the AI.
  • Google — “Sign in with Google” authentication (only if you choose it).
  • Stripe — payment processing for paid plans; handles card data directly so we never store it.
  • DigitalOcean — cloud infrastructure that hosts the Service and its encrypted backups.
  • Google Analytics — privacy-focused, aggregate product analytics (which features are used, where users get stuck). We send only anonymous usage events and page paths — never your flowsheet content, stream values, or plant names.

6.Storage, security, and retention

  • Your data lives on a dedicated server (local PostgreSQL database and filesystem), reachable only through the app and API.
  • Traffic is encrypted in transit (HTTPS/WSS). Sessions ride a signed, httpOnly cookie; secrets live in server-side environment config, never in the browser or our source repository.
  • We keep nightly database dumps and offsite object-storage backups for disaster recovery.
  • We retain your account and simulation data for as long as your account is active. When you delete content or close your account, we remove it from active systems; residual copies age out of backups on the normal backup rotation.

7.Your rights and choices

  • Access and export — your simulations are yours; you can export stream tables and reports (CSV/PDF) at any time from within the app.
  • Correction — update your account details from Settings.
  • Deletion — delete individual simulations, or contact us to close your account and remove your personal data.
  • Email preferences — manage notification and newsletter preferences, or use the one-click unsubscribe in any newsletter.

To exercise any of these, or if you are in a jurisdiction (such as the EEA/UK under GDPR or California under the CCPA) with additional rights, email contact@maximalabs.io and we will respond.

8.Cookies

We use an essential, httpOnly session cookie (flowsim_session) to keep you signed in, plus a few short-lived httpOnly cookies that exist only during a sign-in redirect (they carry the CSRF token, your language, and how you first reached us across the round trip, then are deleted). We also use local browser storage for preferences such as your theme and language, and for an anonymous, randomly generated visitor id that lets us measure how many people who browse the process gallery go on to create an account. That id is not linked to any identity until and unless you sign up. Google Analytics sets its own first-party analytics cookies (e.g. _ga) to measure aggregate product usage. We do not use advertising or cross-site tracking cookies, and we do not sell your data.

9.Children

The Service is a professional engineering tool intended for use by adults and is not directed to children under 16. We do not knowingly collect personal information from children.

10.Changes to this policy

We may update this policy as the Service evolves. We will revise the “Last updated” date above and, for material changes, provide a more prominent notice. Continued use of the Service after an update constitutes acceptance of the revised policy.

Questions about this document? Contact contact@maximalabs.io.

Stop fighting legacy software. Build your first flowsheet in 60 seconds.