Privacy Policy
Effective date: August 12, 2026 · TheDigicar LLC
The short version
SmokeViz is built to know as little about you as possible. The whole thing — model parsing, the flow simulation, the rendering — runs in your browser on your own machine. The 3D models you load are never uploaded, and the site's security policy is configured so the application cannot send data to any other website.
No accounts, no cookies, no local storage, no ads, no third-party trackers, no selling of data. We don't even remember your settings between visits, because we store nothing on your device.
The one thing the site sends anywhere is a tiny anonymous beacon to our own server — a page name and, occasionally, a feature name — so we can count visits. It carries no identifier of any kind. Separately, like every website, our hosting provider's infrastructure briefly sees your IP address in order to deliver the pages.
That's the plain-English gist. The full policy below is what's binding.
1.Who we are & what this covers
This Privacy Policy describes how TheDigicar LLC ("SmokeViz," "we," "us") handles information when you use the SmokeViz website and web application at smokeviz.com — a browser-based aerodynamic flow visualiser (the "Service"). It should be read together with our Terms of Service.
2.What we deliberately do not collect
- Receive your 3D models. The files you load are parsed, simulated, and rendered entirely on your device. They are never transmitted to our servers or anyone else's. The site's Content-Security-Policy (
connect-src 'self') makes the browser itself block any attempt by the application to send data to a third-party origin. - Have accounts. There is no sign-up, no sign-in, and therefore no name, email address, or password to collect.
- Set cookies or store anything on your device. No cookies, no localStorage, no sessionStorage, no IndexedDB — nothing persists between visits, not even your unit preference.
- Track you across the web. No advertising trackers, no ad networks, no social media pixels, no fingerprinting, no third-party analytics scripts or SDKs of any kind.
- Sell or rent personal information. To anyone, for any purpose. We also do not "share" personal information for cross-context behavioral advertising.
- Process payments. The Service is free; we collect no payment information.
3.What we collect and why
The Service works without giving us any personal information. Here is the complete list of what it handles:
| Information | Source | Why we have it |
|---|---|---|
| Anonymous usage counts (a page name and, for certain in-app actions, a predefined event name) | Automatic — the first-party beacon described in Section 4 | To count visits and see which features are used, without identifying anyone. |
| Standard operational log data (IP address, user-agent, requested resource, timestamp), processed transiently by our hosting infrastructure | Automatic — Amazon Web Services (S3 and CloudFront), like virtually every website | To deliver the site and for security and abuse prevention. See Section 6. |
We collect no other categories of personal information. We do not collect your models, geolocation, contacts, biometric data, health data, or payment data. Where the GDPR applies, our legal basis for the processing above is our legitimate interest in operating, securing, and improving the Service (Art. 6(1)(f)); the impact on you is minimal because the data is anonymous or transient.
4.Analytics: how we count visitors without tracking you
We use a small custom analytics system, not a third-party tracking service. On each page load, and when certain in-app actions occur, the page sends a beacon to /api/collect on our own origin containing only:
- a page name (for example,
"index"), and - optionally, a predefined event name for the action.
That is the entire payload. The beacon carries no cookie, no user or device identifier, and no content from your session — never any part of a model. On the server these requests only increment anonymous aggregate counters; event names not on our allow-list are discarded. The counters cannot be traced back to any person, which is the point.
That's it — no analytics cookies, no fingerprinting, no third-party analytics scripts. Because there is nothing stored on or read from your device, no consent banner is required, and none is shown.
5.Cookies & local storage
SmokeViz sets no cookies and does not read or write localStorage, sessionStorage, IndexedDB, or any other client-side storage. Models you load are held in memory only and are gone when you close or reload the tab. Your GPU is used locally, via WebGPU, to run the simulation and draw the picture — it is not a data source we receive anything from.
6.Hosting & operational logs
The Service is static files served from Amazon Web Services — Amazon S3 storage behind the Amazon CloudFront content delivery network, hosted in the United States. Like most web infrastructure, these providers process IP addresses and user-agent strings transiently in order to deliver the site, defend it against abuse, and maintain standard operational logs. We use that data only for security and service operation, and we do not use it to identify users. AWS acts as our service provider (processor) and processes data only to provide its services to us.
7.How information is shared
There is very little to share, and we share it only as follows:
- With service providers. Amazon Web Services hosts and delivers the site, as described in Section 6. No other third party is involved.
- Legal and safety. We may disclose information if required by law or legal process, or as reasonably necessary to protect the rights, safety, or property of users, the public, or the Service.
- Business transfers. If TheDigicar LLC is involved in a merger, acquisition, or sale of assets, information may transfer as part of that transaction, subject to this policy's commitments.
We never sell personal information, and we share nothing with advertisers — there are no advertisers.
8.Data retention
- Your models: never received, so never retained.
- Anonymous usage counters: contain no personal information and may be kept indefinitely as aggregate statistics.
- Operational logs: processed transiently by our infrastructure and retained only briefly for security and operations.
9.Security
The site ships with a strict Content-Security-Policy and related security headers, and is served exclusively over HTTPS. The CSP's connect-src 'self' directive means the browser mechanically prevents the application from transmitting anything to another origin — the strongest protection, though, is that we simply do not hold the data a breach could expose.
10.Your rights & choices
Depending on where you live — including under the EU and UK GDPR and the California Consumer Privacy Act (CCPA/CPRA) — you may have rights to access, correct, delete, or obtain a copy of your personal information, to object to or restrict its processing, and to not be discriminated against for exercising those rights. California residents: we do not "sell" or "share" personal information as the CCPA defines those terms, so there is nothing to opt out of.
Because we hold no accounts and no identifiers, the honest answer to most requests is that we have nothing on file about you to act on. The anonymous counters cannot be linked to an individual, so — as GDPR Article 11 contemplates for processing that does not require identification — we are generally unable to connect them to a requester, and we are not obliged to collect extra information about you just to satisfy a request. If you are in the EEA or UK, you also have the right to lodge a complaint with your supervisory authority.
To exercise any right or ask questions, email thedigicar@gmail.com (subject: "Privacy"). We will respond within the time required by applicable law. Authorized agents may submit requests with proof of authorization.
11.Children
The Service is intended for users 18 and older and is not directed to children under 13 (or the higher age required in your jurisdiction). We do not knowingly collect personal information from children — indeed, we collect no personal identifiers from anyone. If you believe a child has provided us personal information, contact us and we will delete it.
12.Users outside the United States
The Service is operated from the United States and hosted on AWS infrastructure in the United States. If you access it from elsewhere, you understand that the limited technical data described above will be processed in the United States, where privacy laws may differ from those of your jurisdiction.
13.Changes to this policy
We may update this Privacy Policy from time to time — for example, if a future version of the Service changes what data is handled. The current version, with its effective date, will always be posted at this page. For material changes we will provide prominent notice within the Service. Your continued use of the Service after an updated policy takes effect constitutes acceptance.
14.Contact
Questions or requests about privacy:
TheDigicar LLC
Email: thedigicar@gmail.com (subject: "Privacy")