PLCFLOW Technologies Inc. collects the minimum needed to run plcSim: an account if you make one, the projects you save, and short-lived technical data to keep the service working and fair. We collect anonymous, cookieless usage analytics to improve the product — never linked to your account, and you can opt out. We run no advertising, and we never sell or rent personal data.
No account, no profile, and none of your work is saved. To stop one visitor from consuming the whole simulator, the API counts concurrent sessions per IP address, so your IP address is held in the server process's memory for the life of your session.
One thing does outlast the visit: a line in our run log recording that a guest ran a simulation, when it started and stopped, and whether the logic was one of our built-in examples or a program of their own. It carries no account, no IP address, and nothing from the program itself. We use it to plan capacity.
Under the GDPR an IP address is personal data, so to be explicit about it: it is never written to our database, never logged for analytics, and never used to build a profile. It exists only in memory, only as a rate-limiting key, and disappears when the session ends. Guest sessions are reaped after about five minutes idle and are capped at one hour of life regardless, so this data is measured in minutes.
Paid plans are not open yet. If you use a Notify me button on the pricing page, we store your email address, which plan you asked about, and the date. If you are signed in we use the address on your account and do not ask you to type one. We keep it for one reason: to email you once when those plans open. It is never sold, never shared, and never sent to our analytics provider, which only records that someone asked and about which plan. Ask us at support@plcflow.io and we will remove you from that list.
Because this form is open to visitors who are not signed in, we also store a one-way hash of your IP address with it, so a single source cannot flood the list. The hash cannot be reversed to an address and is used for nothing else.
If you have an account, your email address, the name on your account, and your plan tier are held by Resend, our email provider, in a list of plcSim accounts. We use that list for one thing: product updates— occasional email about new plcSim features, sent on the basis of the account you hold with us. Every such message carries a working unsubscribe link, as Canada's anti-spam law (CASL) requires, and the same switch is on your account page. Turning it off takes effect immediately and is never undone by us.
We do not currently send any automated account email — no welcome message, no password reset, no receipts from us (invoices come from Stripe). If that changes, this page will say so. The address is never sold or shared for anyone else's marketing, and it is not sent to our analytics provider.
Payments are handled by Stripe, our payment processor. Your card details go directly to Stripe on their checkout and billing pages — we never see or store your full card number. What we keep is your plan, its subscription status and billing period, and identifiers referencing your Stripe customer and subscription records; Stripe keeps the invoice and payment history, which you can access from the billing portal on your account page.
We use PostHog to understand how plcSim is used — which features get used, where imports succeed or fail, and where people give up — so we can make the product better. It is configured deliberately narrowly:
Separately from analytics, we use Sentry to be told when something breaks — a page that fails to load, an import that crashes, an API error. This is how a bug gets fixed rather than silently repeating for everyone who hits it.
Where the GDPR or similar law applies: account data and saved projects are processed to perform our contract with you; billing and subscription data is processed to perform that contract and to meet our legal obligations, such as keeping tax records; rate-limiting data is processed under our legitimate interest in keeping a free service available and resistant to abuse; anonymous product analytics is processed under our legitimate interest in improving the product — kept proportionate by being cookieless, account-unlinked, and opt-out; error reports and the account activity record are processed under our legitimate interest in keeping the service working, secure, and accountable — kept proportionate by carrying no identity in the first case and no program content in the second; product-update email is sent under our legitimate interest in telling account holders what has changed in the product they use — kept proportionate by being infrequent, about plcSim only, and switched off the moment you say so; and anything else is processed with your consent, which you can withdraw.
plcSim sets one cookie: your sign-in session. It is strictly necessary to keep you signed in, so it needs no consent, and it is the reason you see no cookie banner. Our analytics runs cookieless — it sets no cookies and stores nothing in your browser. There are no analytics, advertising, or cross-site tracking cookies. Some preferences (including your analytics opt-out) are kept in your browser's local storage and never leave your device unless you sign in.
We use a small number of infrastructure providers, each handling data only to run the service on our behalf:
This means data may be processed outside your country, including in the United States. Where required, transfers rely on appropriate safeguards such as the European Commission's standard contractual clauses.
Most of what happens in plcSim never reaches our database. When you drop in an L5X, the import and validation step is stateless: the file is parsed as part of the request and nothing from it is written to disk or to a log. The imported program lives in your browser, not on our servers.
If you run it, the program is held in the memory of your simulation session for as long as that session is alive. Guest sessions are dropped after about five minutes idle and are capped at one hour of life regardless. Free accounts keep an unsaved draft in your own browser's storage, which we cannot read. Saved projects on our servers start at Standard, and those are the ones the retention terms above cover.
There is one exception, and it only applies if you use it. Publishing a session as a SCADA endpoint writes that session's program, its current tag values, and the endpoint's credentials to the simulation server's own storage — that is what lets a SCADA client you configured once keep working after we deploy an update. The record is deleted when you take the endpoint down. Publishing an endpoint needs an account; guests cannot do it.
Depending on where you live — including under Canada's PIPEDA and Quebec's private-sector privacy law, the GDPR, and similar laws — you may have the right to access, correct, delete, export, or restrict processing of your personal data, to object to processing based on legitimate interests, and to withdraw consent. Email support@plcflow.io and we will respond within the time your law requires — within one month under the GDPR. You may also complain to your privacy regulator: in Canada, the Office of the Privacy Commissioner (or the Commission d'accès à l'information in Quebec); in the EU or UK, your local data protection authority.
plcSim is aimed at engineers and students of industrial automation and is not directed at children under 13 (or under 16 where local law sets that threshold). We do not knowingly collect their data; if you believe a child has given us data, contact us and we will delete it.
Traffic is encrypted in transit, passwords are stored hashed, and the simulation API never touches the database — it verifies signed tokens instead, so a compromise there exposes no stored accounts. No system is perfectly secure, and we do not claim otherwise. If a breach ever creates a real risk of harm to you, we will notify you and the appropriate authorities as the law requires.
Each running simulation gets its own scan engine, with its own program, its own tag database and its own timers. No engine can see or reach another engine's data, and there is no shared state between them.
Several sessions do run inside one server process, the same way several programs run on one PC. That is a software boundary, not a hardware one. If your work needs a hardware boundary, a single-tenant deployment in your own environment is the honest answer, and it's something we can talk about.
We will update this page when our practices change and revise the date at the top. Material changes will be signalled in the app.
PLCFLOW Technologies Inc. is the controller of the personal data described here, and its Privacy Officer is the person accountable for it. Privacy questions and rights requests: support@plcflow.io.