Cold Creek Pigging Simulator
Privacy Policy
Cold Creek Pigging Simulator is built by Ironclad Digital LLC. Unlike our field apps, this one runs in a browser and has accounts, so it does hold data on a server. The short version: we store your email address and the simulator runs you choose to save, and we run error monitoring so we find out when the thing breaks. There is no advertising, no marketing analytics, and no cross-site tracking, and we do not sell or share anything.
What we collect
Your email address and password. Creating an account requires an email address, which we use to identify your account and to send the confirmation link. Passwords are handled by our authentication provider and stored only in hashed form. Nobody at Ironclad can read your password.
Sign-in records. Our authentication provider keeps the ordinary records a login system keeps, which can include the time of a sign-in and the IP address it came from. That exists to make accounts work and to spot abuse.
Runs you save. When you save a run, we store the name you give it, the configuration you set, the pipeline segments, any anomalies placed on the line, and the date it was created. The frame-by-frame telemetry from a run is not saved. Runs are tied to your account.
A word about what you type into a run
The simulator does not need real line data to work, and we did not build it expecting any. But it lets you set lengths, elevations, wall thicknesses, grades and pressures, so if you choose to model an actual line, those values are what gets saved, under whatever name you give the run.
We say that plainly because your employer may treat line details as confidential, and that is a decision for you and them, not for us. If in doubt, run the presets or made-up numbers. The simulator behaves the same either way.
Error monitoring
We use Sentry to tell us when the application throws an error, because the alternative is finding out when a user gives up and leaves. When an error occurs, Sentry receives a report containing the error itself, the page it happened on, the browser and version, and the release of the application.
Two details worth stating plainly rather than burying:
Session replay, on errors only. When an error fires, Sentry records a reconstruction of the moments leading up to it, so we can see what sequence caused it. It is not always-on: no replay is recorded for a session that does not error. All text is masked and all media is blocked in that recording, so it shows the shape of the interaction rather than the contents of what you typed.
Reports route through our own domain. Error reports are sent through a path on this application rather than directly to Sentry, so that content blockers do not silently discard them. We mention it because it means a browser extension that would normally block error reporting will not block ours.
A small sample of requests, on the order of one in ten, also carries performance timing so we can see what is slow. See Sentry’s privacy policy.
What we do not do
No advertising, no marketing or product analytics, no cross-site tracking, no advertising or social media pixels, and no cookies beyond the ones that keep you signed in. We do not build a profile of you, we do not sell or rent your information, and we do not share it with anyone for their own purposes. Fonts are served from our own domain, so loading a page does not call out to a font provider.
Who else touches it
Three service providers process data on our behalf, and only to run the product:
Supabase provides the database and the authentication system. Your account record and your saved runs live there. See Supabase’s privacy policy.
Vercel hosts the application and serves it to your browser. Like any web host, it processes the basic request information a server sees. See Vercel’s privacy policy.
Sentry receives the error reports described above. See Sentry’s privacy policy.
None of them is permitted to use your data for their own purposes, and we use no other processor for this product.
Keeping it separate
Saved runs are protected at the database level by row-level security, so a signed-in account can only read and write its own runs. That rule is enforced by the database itself rather than by application code, which means a bug in the application cannot hand one user another user’s runs.
How long we keep it
Saved runs stay until you delete them or ask us to close your account. We do not expire them on a schedule. Account records stay for as long as the account exists.
Deleting your data
You can delete any run you saved, from inside the application.
To close your account and delete everything attached to it, email privacy@ironcladintegrity.com from the address on the account. We will delete the account and its runs and confirm when it is done. There is no self-service account deletion in the application yet.
Your rights
Depending on where you live, you may have the right to ask what we hold about you, to get a copy of it, to correct it, or to have it deleted. Email the address above and we will honor the request. We will not charge you for it or treat you differently for asking.
Security
Traffic is encrypted in transit, passwords are stored hashed, and access between accounts is separated at the database level. No system is perfectly secure, and we will not pretend otherwise. Do not put anything into this simulator that would cause you real trouble if it were exposed.
Children’s privacy
Cold Creek Pigging Simulator is a professional training tool and is not directed to children. We do not knowingly collect information from anyone under 13. If you believe a child has created an account, email us and we will remove it.
Changes to this policy
If this policy changes, the updated version will be posted here with a new date. If a change materially affects what we collect or who we share it with, we will say so rather than quietly reposting.
Contact
Questions about privacy? Email privacy@ironcladintegrity.com.