Legal
Privacy Policy
Last updated:
UnifCAD is operated by Efrain Andres Villanueva Campomanes, a sole trader doing business as Realdsim, in Lima, Peru ("we"), who is responsible for the personal data described here. This policy explains what UnifCAD collects when you use the website unifcad.com, the web application at app.unifcad.com, the UnifCAD Bridge desktop application and the UnifCAD connector for AI assistants; why we collect it; who receives it; how long we keep it; and how you control it. We do not sell your personal data, and we do not use it for advertising.
1. What we collect
Your account
To create an account you give your email address, a password and your name, and you accept the Terms of Service. The password is handled by our authentication provider and is never visible to us. In Settings you can change your name, your password and the illustrated avatar shown next to your name (we do not accept photo uploads).
Your plan and payments
We store your plan (Free, PRO or EDU), its expiry date and the identifiers of your customer account and subscription at our payment provider, Lemon Squeezy, together with the status of your subscription and the link to its customer portal. Lemon Squeezy is the merchant of record: it collects your payment details, billing address and taxes on its own checkout. Your card details never reach UnifCAD.
Educational licences
If you take a seat in an educational licence, or manage one, we store which licence you belong to, your role in it (licence holder, teacher or student), the date you joined and, for a student, the teacher whose class code you used. We also keep a record of when each seat was taken or released. The licence holder and the teachers of your class can see your name and email address — see section 10.
Your projects
Projects are saved in your own browser. On the PRO and EDU plans, projects are also saved to our cloud database so they are available on your other devices: the whole project (schematic, PLC programs, plant, notes), its name and description. Custom devices you create in the device builder are saved to your account in the same way.
One active device per account
Each browser keeps a random identifier. When you sign in it is recorded on your account, so that signing in on a new device ends the session on the previous one. It identifies the browser, not you or your hardware.
Referrals (affiliate programme)
If you arrive through a partner's referral link, a first-party cookie keeps the referral code for 30 days. We record the visit as the code, the page you landed on and a one-way hash computed from your IP address and browser together with the day and a secret value; the IP address itself is not stored and the hash cannot be turned back into it. If you then create an account or buy a plan, the sign-up or the purchase is attributed to that partner. Partners see totals, never who you are.
Analytics — only with your consent
With your permission, we use Google Analytics on the website and in the app to learn which pages and features are used. It is loaded only after you choose "Accept analytics" in the cookie banner; until then, no analytics script is loaded. Rejecting consent keeps analytics disabled. Withdrawing a prior acceptance disables further collection and deletes existing analytics cookies; it does not undo data already sent. You can change your choice at any time from "Cookie settings" at the bottom of the website or in the app's Settings.
Messages you send us
When you write to us, we keep your email address and the conversation to answer you.
Technical records
Like any online service, the providers that host UnifCAD record technical data about requests — such as IP address, time and browser — to deliver the service and protect it from abuse.
2. The AI assistant connector
UnifCAD can be connected, at your choice, to an AI assistant you use (such as Claude, ChatGPT or Cursor). The cloud connector is part of the PRO and EDU plans. When you connect one, you sign in with your UnifCAD account and approve the assistant on a UnifCAD consent page, which names the assistant and the address you return to. The assistant then receives an access token tied to your account; it lets the assistant act only through the connector, never on your account, plan or billing. You can revoke it at any time from the assistant's settings, and you can turn the link off in UnifCAD.
Your conversation with the assistant stays between you and its provider: UnifCAD does not receive it. The assistant sends UnifCAD individual orders (for example "place a contactor" or "read the simulation"); our connector checks that the token is valid and that your plan includes the connector, relays each order to the UnifCAD tab you have open, and returns the result. The connector works only while you are signed in and a UnifCAD tab is open with the link on, and it does not store your projects. It keeps operational logs of when a tab or an assistant connects (with a shortened account identifier) and of which order ran, whether it succeeded and how long it took; it never logs the content of an order or of its result.
The results the assistant receives (for example, the list of devices on your sheet) are processed by the assistant's provider under its own terms and privacy policy.
3. The UnifCAD Bridge desktop application
The bridge connects the app to a PLC or a PLC simulator on your computer or your local network. It listens only on your own computer and accepts connections only from app.unifcad.com. The PLC data it exchanges stays between your browser, your computer and your PLC; nothing is sent to UnifCAD. It contains no analytics and no automatic update service. Pairing with the app stores a protected form (a hash) of the pairing token on your computer, and uninstalling the bridge removes its data.
4. Why we use it
- To provide the service you asked for — your account, your plan, cloud saving, the connector (performance of our contract with you).
- To keep it secure and working — one active session per account, abuse prevention, troubleshooting (our legitimate interest in a secure service).
- To credit partners for the users they refer (our legitimate interest in running the affiliate programme).
- To understand how UnifCAD is used and improve it — only with your consent.
- To answer you and to send messages about your account, security or subscription. We do not send marketing email.
- To meet legal obligations, such as tax and accounting records, which are kept by our payment provider.
5. Who receives it
We share personal data only with the providers that run UnifCAD on our behalf, each for its task:
- Supabase — authentication, database (accounts, plans, cloud projects, custom devices) and sign-in for AI assistants, hosted in the United States (Northern Virginia).
- Vercel — hosting of the website and the web application.
- Fly.io — hosting of the AI assistant connector (in São Paulo, Brazil).
- Lemon Squeezy — checkout, payments, invoices and taxes, as merchant of record.
- Google — Google Analytics, only with your consent.
- Cloudflare — domain name service and delivery of the documentation's videos.
- Your AI assistant's provider — only if you connect one, and only the results the assistant asks for.
- PayPal — only for partners of the affiliate programme, to pay their commissions.
Within an educational licence, the licence holder and the teachers also see the name and email address of the students in their class (section 10). They are users of UnifCAD like you, not providers of ours.
We may also disclose data when the law requires it. Using UnifCAD therefore involves an international transfer of your data from Peru and from your own country: the account database is in the United States, the AI connector in Brazil, and the other providers may process data in the United States or elsewhere, each under its own data-protection commitments. We choose providers that protect the data they process for us.
6. How long we keep it
- Account, plan and cloud projects — while your account exists. Deleting a cloud project removes it at once; deleting your account removes your profile, projects, custom devices and subscription records with it.
- Accounts never confirmed — deleted automatically after 10 days.
- Educational licence membership — while you belong to the licence; it is removed when you leave the class, when you are removed from it or when you delete your account. The record of seats taken and released (an account identifier, the action and its date, with no name or email) is kept while the licence exists.
- Projects in your browser — until you delete them or clear your browser's data.
- Payment and tax records — kept by Lemon Squeezy for the period the law requires.
- Referral cookie — 30 days. Consent cookie — 180 days, after which we ask again. Analytics cookies — as set by Google, up to 2 years, and deleted when you withdraw consent.
- AI connector — no project data is stored; a connection's session ends after 30 minutes without activity.
- Google Analytics — event retention is set to 2 months and user-data retention to 14 months. New activity resets the retention period of the user identifier. These settings do not apply to standard aggregated reports. Withdrawing consent stops further collection; it does not delete data already received by Google.
- Operational logs — under our current plans, Vercel retains runtime logs for 1 hour, Fly.io provides 7 days of application-log search, and Supabase provides 7 days of accessible service logs. These are provider retention or access windows, not a deletion deadline for every provider record. Build records, database audit records and backups are separate categories governed by their respective service settings and purposes.
- Messages — for as long as needed to handle your request.
7. Cookies and storage in your browser
Cookies:
| Name | Purpose | Lasts |
|---|---|---|
unifcad_consent | Remembers your analytics choice on the website and the app. Necessary. | 180 days |
ucad_ref | Keeps a partner's referral code when you arrive through a referral link. | 30 days |
_ga, _ga_* | Google Analytics. Only after you accept analytics. | Up to 2 years |
The app also stores data in your browser's own storage, which never leaves your device unless a feature above sends it: your sign-in session; your projects; the device identifier described in section 1; your preferences (language, theme, layout of the workspace); the pairing with the UnifCAD Bridge; and whether the AI assistant link is on. The website remembers your language choice.
8. Your rights and controls
- See and correct your name and password in Settings, or ask us for a copy of the data we hold about you.
- Take your projects with you by exporting them from the app, or ask us for a copy.
- Delete your account in Settings. If you have an active paid subscription, cancel it first from "Manage Subscription"; the account can be deleted once it ends.
- Withdraw consent to analytics at any time from "Cookie settings".
- Disconnect an AI assistant from its settings, or turn the link off in UnifCAD.
- Object or ask us to restrict a use of your data by writing to us.
Under Peruvian law (Law No. 29733 on the Protection of Personal Data) you may exercise your rights of access, rectification, cancellation and opposition, and you may complain to the National Authority for the Protection of Personal Data of the Ministry of Justice and Human Rights. Depending on where you live — for example under the GDPR in the European Union or the LGPD in Brazil — you may have further rights, including to complain to your own data-protection authority. Write to us and we will answer within the period the applicable law sets, and no later than 30 days.
9. Security
All traffic to UnifCAD is encrypted. Each account can read and change only its own data, passwords are stored only in protected form by our authentication provider, and payment details stay with our payment provider. No service is free of risk; if a breach affects your data, we will tell you and the authorities as the law requires.
10. Age and educational licences
Buying a plan requires being an adult. A person under 18 may use UnifCAD as part of an educational licence held by their school or training provider, or with the permission of a parent or guardian.
UnifCAD is not directed at children under 13. A child under 13 may use it only within an educational licence, where the institution confirms that it has the authority or the parental consent its local law requires. If you believe a child under 13 has given us personal data outside such a licence, write to us and we will delete it.
Within an educational licence, the institution decides who receives a seat. The licence holder and the teacher see the name and email address of each student in their class and the date the student joined. They do not see the student's projects. A student joins by entering a class code and can leave the class at any time from Settings.
11. Changes to this policy
When what we collect or how we use it changes, we update this page and the date at the top. If a change is significant, we will also tell you in the app or by email before it applies.
12. Contact
UnifCAD is operated by Efrain Andres Villanueva Campomanes (Realdsim), Lima, Peru. For any question about this policy or your data, write to [email protected].