Privacy Policy

Version: 2026-05-31


This Privacy Policy explains how Diospyros Holdings LLC, a Wyoming limited liability company that operates the SimCheck.ai platform (“SimCheck”, “we”, “us”, “our”), collects, uses, discloses, and protects information in connection with the SimCheck Services. It applies to our web console, APIs, and edge software, and to visitors, account holders, and Authorized Users. It does not apply to third-party services you separately use.

1. Roles: Controller and Processor

  • Account and platform data. For information about your account, organization, and use of the Services, we generally act as a controller (or “business” under U.S. state law).
  • Customer Data. For data you upload or generate through the Services — including SIM/eSIM and subscriber-related data, test configurations, and test results and artifacts — you are the controller and SimCheck acts as a processor/service provider on your behalf, processing it under your instructions, the Terms of Service, and any data processing addendum (“DPA”). You are responsible for the lawfulness of that data and for providing required notices and obtaining required consents.

2. Information We Collect

Information you provide.

  • Account information: name, email address, authentication identifiers, organization membership and role, and preferences.
  • Billing information: plan, subscription status, and billing records. Card/payment details are collected and processed by our payment processor (Stripe), not stored by us.
  • eSIM and SIM data: eSIM activation credentials (LPA activation codes, including single-use download codes), ICCIDs, and related profile metadata you upload.
  • Test configuration and content: flows, schedules, locations, target networks, and customer-authored scripts.
  • Support and communications: messages, requests, and feedback you send us.

Information generated by use of the Services.

  • Test results and artifacts: measurements, statuses, and diagnostic artifacts that may include packet captures (PCAPs), voice recordings (audio samples), screen captures or recordings, and AT-command logs.
  • Operational and log data: access and usage logs, quota and metering data, device and connection metadata, audit records of access to sensitive resources, and security event data.
  • AI-assisted features: prompts and conversations you submit to the in-app assistant and related metadata.

We do not intentionally collect special-category personal data through the account layer; do not submit such data except as appropriate within Customer Data you are authorized to process.

3. How and Why We Use Information

We use information to: provide, operate, secure, and improve the Services; authenticate users and manage organizations and roles; allocate and manage Edge Devices and modems; execute and report tests; provide AI-assisted features; process billing and enforce quotas; maintain audit trails and tenancy isolation; detect, prevent, and investigate fraud, abuse, and security incidents; communicate with you; and comply with legal obligations and enforce our agreements.

Legal bases (where GDPR/UK GDPR applies). We rely on: performance of a contract (providing the Services); legitimate interests (securing and improving the Services, preventing abuse); consent (where required, e.g., certain communications); and compliance with legal obligations.

4. Where Data Is Stored and Processed

Platform data is hosted on Google Cloud Platform / Firebase in the us-central1 region in the United States. Data is encrypted in transit (TLS) and at rest. Test artifacts are stored in cloud object storage and accessed through short-lived signed URLs; raw artifact bytes are not served directly. If you access the Services from outside the United States, your information will be transferred to and processed in the United States; where required, we implement appropriate safeguards for international transfers (e.g., Standard Contractual Clauses).

5. Sub-Processors and Disclosures

We share information with service providers that process it on our behalf, under contracts requiring appropriate protection, including:

Provider Purpose
Google Cloud / Firebase Hosting, database, storage, authentication
Stripe Subscription billing and payment processing
Anthropic AI-assisted in-app assistant features
Brevo Transactional email (invitations, notifications)

We may also disclose information: to comply with law, legal process, or lawful requests; to enforce our agreements; to protect the rights, safety, and security of SimCheck, our customers, or others; and in connection with a merger, acquisition, financing, or sale of assets (subject to this Policy). We do not sell personal information, and we do not “share” it for cross-context behavioral advertising as those terms are defined under U.S. state privacy laws.

6. Retention

We retain information for as long as needed to provide the Services, operate our business, and meet legal, accounting, or reporting obligations. Test artifacts and certain operational data are subject to retention limits and may be deleted automatically on a rolling basis. Customer Data is retained per your configuration and the Terms/DPA, and is handled on account or organization termination as described there and by applicable law.

7. Your Rights

Depending on your jurisdiction, you may have rights to access, correct, delete, port, restrict, or object to the processing of your personal data, and to withdraw consent. Residents of certain U.S. states may have rights to know, access, delete, correct, and opt out of sale/sharing (which we do not do), and to be free from discrimination for exercising these rights. To exercise rights, contact privacy@simcheck.ai; we will verify and respond as required by law. Where SimCheck acts as a processor on your behalf, requests from individuals will be referred to the relevant Customer (controller). You may also have the right to lodge a complaint with a supervisory authority.

8. Cookies and Analytics

The Services use cookies and similar technologies necessary for authentication, session management, and security, and may use limited analytics to operate and improve the Services.

9. Security

We maintain administrative, technical, and organizational measures designed to protect personal data, including encryption in transit and at rest, access controls, tenancy isolation, audit logging, and short-lived signed access to artifacts. No method of transmission or storage is completely secure; we cannot guarantee absolute security.

10. Test Subjects and Third-Party Data

Tests run against live mobile networks and may involve telephone numbers, SIMs, or other identifiers. You are responsible for ensuring you have the authority and any required consents to test the numbers, SIMs, eSIMs, and networks you submit, and for the lawfulness of any third-party personal data within Customer Data.

11. Children

The Services are not directed to children and are intended for business use. We do not knowingly collect personal data from children.

12. Changes

We may update this Privacy Policy from time to time. When we make material changes, we will post the updated policy with a new version, update the date above, and provide notice where appropriate (for example, by email or within the Services). Your continued use of the Services after the update takes effect constitutes acceptance.

13. Contact

Diospyros Holdings LLC 30 N Gould St Ste N, Sheridan, WY 82801 Privacy questions or requests: privacy@simcheck.ai