Last Updated: June 30, 2026
We collect as little as we can. To sign you in we use your email (via Google Sign-In or a one-time email link) — essentially that's it. Payments are handled entirely by Stripe as merchant of record; we never see or store your full card details. Your code and firmware are processed in memory to run your simulation and then deleted — we don't inspect them, keep them, or train AI on them. Each customer runs in a dedicated, isolated instance. We log limited technical metadata (including your IP address at our edge) for security and abuse-prevention, and delete those logs after 30 days. We do not sell your personal information or share it for cross-context behavioral advertising.
This summary is for convenience only. The full policy below is what legally applies.
This Privacy Policy explains how Refract Systems, Inc. (a Delaware corporation with its principal place of business in Sunnyvale, California) (“Company,” “we,” “us,” or “our”) collects, uses, discloses, and protects personal information in connection with the website at virtmcu.com (the “Site”) and the VirtMCU simulation platform accessed via the Site, MCP servers, or APIs (the “Service”). “You” includes any user of the Site or Service, including autonomous AI agents or integrations you configure. By using the Site or Service you acknowledge this Policy.
Two-plane architecture (what this means for your data): The control plane (virtmcu.com) knows who you are and what you paid (email, authentication, subscription/billing); the simulation engine (api.virtmcu.com) knows only an opaque API token hash and runs your firmware. The engine never touches your identity, sign-in, or billing data. This Policy covers both planes as operated by Company.
We do not intentionally collect special categories of personal data (GDPR Art. 9) and ask that you not embed such data, or the prohibited data listed in Terms of Service §13, in firmware/source.
For individuals in the EEA, UK, and Switzerland, the applicable lawful basis under the GDPR/UK-GDPR is stated below. We do not rely on a consent bundled into our Terms as the basis for these operational purposes.
Where we rely on legitimate interests, we have balanced them against your rights; you may object (see Section 8). We do not use your Customer Content to train machine-learning models.
We do not sell your personal information and do not share it for cross-context behavioral advertising. We disclose personal information only as follows:
The Service's simulation processing occurs in us-central1 (United States), and other processing may occur in the United States. Where we transfer personal information of individuals in the EEA, UK, or Switzerland to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), the UK International Data Transfer Addendum, and the Swiss addendum as applicable, together with a transfer impact assessment and supplementary measures (encryption in transit, hashed credentials, ephemeral isolated processing). Our DPA incorporates the SCCs by reference and completes their annexes. You may request a copy of the relevant transfer mechanism from privacy@virtmcu.com.
When you delete your account, we cancel billing and delete your account data, API keys, and profile after the scheduled quarantine period; certain records may be retained where required by law or to resolve disputes.
Subject to conditions and exceptions, you have the right to access your personal data; rectify inaccurate data; erase (“right to be forgotten”); restrict or object to processing (including processing based on legitimate interests and direct marketing); data portability; and, where processing is based on consent, to withdraw consent at any time without affecting prior processing. You also have the right to lodge a complaint with your supervisory authority. We will not discriminate against you for exercising these rights.
EU/UK representative (Art. 27): because the Service is offered to individuals in the EU and UK, Company intends to appoint an EU and/or UK Article 27 representative; the representative's name and contact will be published here on appointment.
If you are a California resident, you have the right to know/access the categories and specific pieces of personal information we collect, use, and disclose; delete personal information; correct inaccurate personal information; and opt out of the “sale” or “sharing” of personal information. We do not “sell” personal information and do not “share” it for cross-context behavioral advertising (as those terms are defined under the CPRA), so there is nothing to opt out of. We do not use or disclose sensitive personal information for purposes requiring a right to limit. We honor authorized-agent requests and will not discriminate against you for exercising these rights.
Contact privacy@virtmcu.com. We will verify your request (typically via your account email) and respond within the timeframe required by applicable law. You may appeal a denied request where the law provides an appeal right.
For users in the EEA/UK, we obtain consent via a cookie/preference control before setting the non-essential Firebase Analytics cookie, consistent with the ePrivacy rules, and you may withdraw consent at any time.
We implement technical and organizational measures designed to protect personal information, including TLS/HTTPS encryption in transit, storage of API keys only as SHA-256 hashes, per-session tenant isolation (one ephemeral, single-use environment per session), network-isolated compile sandboxing, WAF/DDoS protection at the edge, and least-privilege access controls. No method of transmission or storage is completely secure; we cannot guarantee absolute security.
If we become aware of a personal-data breach affecting your personal information, we will notify affected users and, where required, the relevant supervisory authorities without undue delay and consistent with applicable law (including, where the GDPR applies, the 72-hour authority-notification standard). Where we act as a processor of your Customer Content, we will notify you (the controller) without undue delay per our DPA.
The Service is intended only for users 18 and older. We do not knowingly collect personal information from anyone under 18, and the Service — including the Student plan — is not directed to minors. A valid .edu email does not qualify a minor to use the Service; Student-plan users must represent that they are 18 or older and currently enrolled (Terms of Service §1.2, §7.5).
No K-12 / education-records use: the Service may not be used for K-12 instruction, by or on behalf of a K-12 school or district, or to collect, process, or store student education records. The Service is not designed for and is not to be used in any manner subject to COPPA, FERPA, or state student-privacy laws (e.g. California SOPIPA). If we learn we have collected personal information from a person under 18, or that an account is being used for prohibited K-12/education-records purposes, we will delete the information and/or terminate the account. If you believe a minor has provided us personal information, contact privacy@virtmcu.com.
All subscription billing and payment processing is handled by Stripe as our merchant of record via Stripe Managed Payments. Stripe processes payments, calculates and remits applicable sales tax and VAT/GST, and handles your payment information under its own privacy policy and PCI-DSS standards. We never receive or store your full card details.
The Site or Service may link to or integrate with third-party sites and applications. We are not responsible for their privacy practices; review their policies before use.
We may change this Policy from time to time. We will notify you of material changes by email to your account address or by a prominent notice on the Site; material changes take effect 30 days after notice, and non-material changes or clarifications take effect on posting. Please review this page periodically.