Privacy Policy
Last updated: September 5, 2026
1. Who is responsible for your data
Argus is provided by Simnetiq Ltd, a company registered in England and Wales under company number 16861177, with its registered office at 2 Frederick Street, Kings Cross, London, WC1X 0ND, United Kingdom. We are the data controller for the personal data described here. Contact us about anything in this policy at support@simnetiq.store, or by post at that address.
This policy covers this website, your account and workspace, and the Argus desktop application. It does not cover the websites you visit inside the browser, or the third-party services — proxies, mailboxes, model providers — you connect to it; each has its own privacy notice.
2. What we collect
- Account data: the email address you sign up with, and the authentication tokens that keep you signed in, stored via our authentication provider. Optional details you choose to set (display name, avatar). If you sign in with Google, we receive your email address and basic profile information from Google.
- Acceptance record: the date on which you accepted the current version of our Terms, and whether you did so on the website or in the application. We keep it so that we can show which version you agreed to.
- Workspace data: the name of your workspace, who its members are, and — if you answer the optional questions when you first sign in — whether it is a business, its name, country, website and logo. These are descriptive. They do not change your plan, your price, or the tax you are charged.
- Subscription data: the plan you are on, its status and its history. Payments are processed by our payment providers; we never receive or store your card number, and for crypto payments we hold only the provider’s reference and the amount — never a wallet address or a private key.
- Workspace content: what you create in the desktop application is stored in your workspace database from the moment you save it, so that it reaches every machine you sign in from and can be shared with your team. That is: your browser profiles — their names, fingerprint settings, proxy assignment, tags and folders, and the login details you choose to save on one; your proxies — their addresses, and the country, city and network we resolve for each so the app can match a profile’s time zone to it; cookie sets, including one the application saves from a profile while it is running; datasets and their rows; automations, their parameters, their run logs and schedules; projects and the notes kept on them; mail-account settings and a record of each message an automation sends (recipient and subject, not the body); and the name and platform of each machine you sign in from, so that a run can be directed to one of them.
- What never leaves your device: the browsing state of a launched profile — the cookies inside the browser, its local storage, history and logged-in sessions — the assistant’s conversations and the skills it saves, and the screenshots an automation takes. These live in the application’s data folder on your computer. We do not receive them.
- Workspace encryption (optional): if you turn it on, saved account passwords, proxy credentials, the contents of cookie sets, mailbox credentials, connector configuration and the dataset columns you flag are encrypted on your device before they are sent, with a passphrase we never receive; we hold ciphertext we cannot read. It does not cover fingerprint settings, automation steps and parameters, run logs, project notes, or the recipients and subjects of sent mail — those are stored as written.
- Connections you add: the configuration of mailboxes, model-provider keys and integrations you connect, stored so that the feature works across your devices, and encrypted where workspace encryption is on. The contents of your mailboxes are read by the application on your device and are not stored by us.
- Technical data: our hosting provider records the IP address, time and requested page of each visit to this website, as every web host does, and uses the country the address resolves to in order to apply the territorial restrictions in our Terms. We do not build profiles from these logs.
- Support messages: what you write to us, any screenshots you attach, and the email address and workspace it came from.
3. Why we use it, and our legal basis
| Purpose | Legal basis |
|---|---|
| Creating your account and providing the Service, including sync | Performance of our contract with you |
| Taking payment and keeping billing records | Contract, and our legal obligation to keep tax and accounting records |
| Recording that you accepted the Terms, and which version | Our legitimate interest in being able to show what was agreed |
| Applying territorial restrictions from your IP address | Legal obligation (sanctions law), and our legitimate interest in where we do business |
| Answering your support messages | Contract, and our legitimate interest in supporting customers |
| Keeping the Service secure and preventing abuse | Our legitimate interest in a service that is not misused |
| Telling you about changes to the Service, the Terms or this policy | Contract, and legal obligation |
| Complying with the law, and responding to lawful requests | Legal obligation |
We do not sell your personal data, we do not run third-party advertising trackers, we do not send marketing email you have not asked for, and we do not use your data to train models.
4. Who we share it with
We use the following processors to run the Service. Each acts on our instructions, under a written contract, and only for the purpose named.
| Processor | What it does | Where |
|---|---|---|
| Supabase | Database, authentication, and file storage for synced workspace data | European Union (Ireland) |
| Vercel | Hosting for this website and its server-side routes, including the request logs in section 2 | United States, with a global edge network |
| Cloudflare R2 | Hosting the desktop application installers you download | Global |
| Revolut | Processing card payments. Card details go to them, never to us | European Economic Area / United Kingdom |
| OxaPay | Processing cryptocurrency payments. Used only if you choose to pay in crypto; we pass them the amount and your email address for the receipt | Global |
| Optional sign-in. Used only if you choose “Continue with Google” | United States | |
| Microsoft | Optional mailbox sign-in, for an Outlook or Microsoft 365 account you connect to the application. Used only if you choose it | United States |
| ipinfo.io, ipapi.co, ip-api.com | Resolving where a proxy you add exits to the internet — its country, city, network and time zone — when the application checks it. They receive the proxy’s public address and nothing about you | United States and global |
| Jina AI (r.jina.ai) | Fetching a readable copy of a public web page when a workflow’s “reach” step asks for one. Receives the page’s address; the page text passes through their service on the way back | Global |
| Vercel Analytics | Aggregate, cookieless visit and download statistics for this website. Runs only if you accept it in the consent banner | United States, with a global edge network |
| Resend | Delivering the transactional email we send you: sign-in codes, workspace invitations, renewal reminders, and replies to support messages | United States |
| n8n & Telegram | Internal notifications to our own support staff when a business event happens — a support ticket you open (its subject, the first lines of its text, and how many files you attached; the files themselves stay in our private storage and are read in our support inbox) or a completed payment is relayed to a private staff channel so we can respond quickly | n8n runs on our own server; Telegram is a global service |
Services you connect to the application yourself — a model provider, Slack or Telegram, a spreadsheet or a database, a captcha solver, a proxy vendor — are chosen and keyed by you. What you send them is governed by your agreement with them, not by this table; the application sends it directly from your machine, and we are not in between.
We will tell you before adding a processor that handles your personal data. We may also disclose data where the law requires it, to establish or defend legal claims, or to a competent authority on valid legal process. If we are ever part of a merger or acquisition, data may transfer to the acquirer under this policy.
Business customers can ask for our standard data processing agreement at support@simnetiq.store. It incorporates the processor list above and our commitment to tell you before that list changes. Organisations that need their workspace held in a database of their own, in a region of their choosing, can ask about a dedicated instance at the same address; our security page describes what that involves.
5. International transfers
Some of the processors above are outside the United Kingdom and the European Economic Area. Where personal data is transferred out, we rely on the UK International Data Transfer Agreement or the UK Addendum to the European Commission’s Standard Contractual Clauses, together with the Standard Contractual Clauses themselves for transfers out of the EEA, and on an adequacy decision where one exists for the destination. You can ask us for details of the mechanism used for a particular transfer.
6. Cookies and analytics
We set only the cookies needed to keep you signed in, plus one that remembers the language you chose if you pick one. There is no advertising and no cross-site tracking on this site. Our Cookie Policy lists what is set and why.
If you accept it in the consent banner, we measure how this website is used with Vercel Analytics: aggregate page views, referrers, and which installer downloads are clicked. It sets no cookies, does not identify you across sites, and we see only aggregated statistics. If you decline, it does not run at all, and either way it never runs inside the Argus desktop application.
7. How long we keep it
| Data | Kept for |
|---|---|
| Account, workspace and synced data | While your account is active, then deleted within 30 days of a deletion request |
| Acceptance record | Six years after the account is closed, the limitation period for a contract claim |
| Payment and invoice records | Six years from the end of the financial year, as UK tax and company law require |
| Support messages | While your account is active and for up to two years after the last message, then deleted |
| Website request logs | Retained by our hosting provider for a short rolling window and not exported by us |
| Profiles moved to Trash | Purged automatically after 30 days |
| Automation run logs and variables, in the workspace database | Deleted automatically after 14 days |
| Screenshots an automation takes of visited pages | Kept only on your device; deleted automatically after 14 days |
To delete your account, email us at support@simnetiq.store from the address on the account, or use the “Delete account” option in the desktop app, which opens a request to us. We handle deletions by hand rather than automatically, so that a shared workspace is never left without an owner. We act within 30 days and confirm when it is done. Deletion is permanent and removes your account and its cloud data; we keep the payment records we are legally required to retain.
A profile’s browsing state on your own device — the browser’s cookies, history and logged-in sessions — is removed when you delete the profile there, or when you uninstall the application and remove its data folder. The profile’s record in your workspace is removed when you delete it in the application, after the Trash window above.
8. Data you collect with Argus
If you use the application to collect information about other people — scraping, lead lists, datasets — you are the controller of that data and responsible for having a lawful basis for it, for telling the people concerned, and for honouring their rights. Section 7 of our Acceptable Use Policy sets out what that involves. For data of that kind that you choose to sync, we are your processor and act only on your instructions.
9. Who at Simnetiq Ltd can see your data
Access is limited to the people who need it to run the Service and support you. Being straightforward about one particular case: our internal administration pages read the database through a privileged connection that bypasses the row-level security rules applied to ordinary accounts. Staff using those pages can therefore see workspace names, plans, subscription history, profile counts, and the support messages you send us. They are used to provide support, to apply or correct a plan, and to investigate abuse. They are not used to browse customer data for any other reason, and they cannot read anything you protected with workspace encryption.
10. Your rights
If the UK or EU GDPR applies to you, you have the right to: be informed about how we use your data; access a copy of it; have inaccurate data corrected; have data erased; restrict how we process it; object to processing based on our legitimate interests; receive your data in a portable format; and, where processing is based on consent, withdraw that consent at any time without affecting what came before. You are not subject to any decision made solely by automated processing that produces legal effects for you.
Exercise any of these by emailing support@simnetiq.store from the address on your account — that is how we verify it is you; we may ask for more if the request concerns a shared workspace. We will respond within one month, extendable by two further months for complex requests, in which case we will tell you within the first month. There is no charge unless a request is manifestly unfounded or excessive.
You also have the right to complain to a supervisory authority. In the United Kingdom that is the Information Commissioner’s Office (ico.org.uk); in the EEA it is the authority in the country where you live or work. We would rather you came to us first, but you do not have to.
11. Children
The Service is not for anyone under 18, and we do not knowingly collect data from children. If you believe a child has given us personal data, tell us and we will delete it.
12. Security
We use encryption in transit, row-level access rules that scope each workspace’s data to its own members, encryption at rest for stored credentials in the desktop application, and optional client-side workspace encryption for the values section 2 lists. Our security page sets this out in more detail. No system is perfectly secure. If a breach ever affects your personal data and is likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, and you without undue delay, as the law requires.
13. Changes
We may update this policy. For minor changes we will revise the “Last updated” date above. For changes that materially affect how we use your data, we will tell you by email or in the application before they take effect.