ThrustLab Privacy Policy

Effective date: August 21, 2026

Version: 1.0 (replaces version 0.1-interim, effective 2026-06-24) Effective date: August 21, 2026 Applies to: thrustlab.com and all ThrustLab services operated by Upwash LLC

Plain-language summary (not a substitute for the policy below): We aim to collect only what we need to run an engineering-simulation service — your email, your simulation work, and billing records held by Stripe. We do not sell your personal information. We do not run ads. In the European Economic Area, the UK, and Switzerland, analytics cookies and identifiers are set only if you accept them; elsewhere Google Analytics runs on an opt-out basis (declining the banner, the "Do Not Sell or Share" control, or a Global Privacy Control signal turns it off), and PostHog waits for your acceptance everywhere. Error monitoring, bot protection, and routine server logs always run to keep the service working. A Global Privacy Control signal from your browser is honored automatically for everyone. When you ask us to delete your data, we do — except a short list of records described in Sections 8 and 9: legal consent and billing evidence, records we need for legal claims, an anti-fraud refund record, de-identified catalog contributions, and residual copies in backups until they rotate out.

1. Who we are and how to reach us

ThrustLab is operated by Upwash LLC, a United States limited liability company.

Privacy contact: [email protected]

Mailing address: available on request via [email protected]

For questions about the Terms of Service see /terms; for billing and refunds see /refund; for cookie details see /cookies; all channels reach us at [email protected].

2. Scope

This policy covers personal information we collect when you visit thrustlab.com, join the beta waitlist, create an account, run simulations, subscribe to a paid plan, or contact us. It does not cover third-party websites we link to, or the independent practices of the payment processor (Stripe) beyond what we describe in Sections 3 and 6.

3. Information we collect

We collect information from four sources: what you give us, what your use of the service generates, what our billing processor reports to us, and what your device transmits. We do not collect your name, date of birth, phone number, or postal address at registration — the signup form asks only for an email address and a password.

3.1 Information you give us

CategoryWhat it includesWhen it is collected
Account credentialsEmail address; password (stored only as a salted hash — we cannot read your password)Account registration
Beta waitlist applicationFirst and last name, occupation, organization, and any free-text you enter about your projectsWhen you apply to the beta waitlist (before an account exists). If you later create an account, this application is linked to it and your name is carried onto your account profile.
Account preferencesUnit system (metric/imperial) and similar settingsAccount settings
Simulation contentPowertrain configurations, component selections, project names and notes, custom airfoil geometry you import, propeller geometry images you upload for processingAs you use the product
Catalog submissionsMotor/battery specifications you submit to the shared component catalog (name, manufacturer, specification data, source URL, notes)When you submit a component. Approved submissions become part of the shared catalog available to all users — this is the purpose of the submission, and you receive account credits in exchange.
Support correspondenceEmails you send to our contact addresses and our repliesWhen you contact us

3.2 Information generated by your use of the service

Simulation results and usage: solver outputs, plots, and usage patterns (which features you use, how many simulations you run). Your projects and results are private to your account unless you explicitly create a share link (see Section 3.5).

Credit and subscription ledger: an append-only record of credit grants, purchases, and usage tied to your account.

3.3 Consent records

When you accept the Terms of Service at signup, and again when you consent to automatic renewal at checkout, we record a consent record containing: the version of the terms in force at that moment (resolved on our servers, never taken from your browser), the type of consent, the price you consented to (for renewal consent), your IP address, your browser user-agent string, and a timestamp. These records are our legal evidence that you agreed to the terms and to auto-renewal, and they are retained on a fixed schedule described in Section 8 — including after account deletion.

Your analytics/cookie-consent choice is currently recorded only in your browser (local storage), not on our servers.

3.4 Billing information

Payments are processed by Stripe. Your card number is entered directly into Stripe's systems and never touches or is stored on ThrustLab's servers. We store: your Stripe customer identifier, your subscription state (plan, price, billing period, cancellation flags), and charge and refund identifiers. If a charge is refunded, Stripe provides us a card fingerprint — a token that does not reveal your card number and cannot be reversed to reconstruct it — which we retain solely to recognize a card that has already received a refund, enforcing our once-per-account, once-per-card refund limit (see /refund). That fingerprint is the only card-derived value we ever store.

3.5 Content you choose to make public

Nothing you create is public by default. The public surfaces are:

Share links (/share/...): you may generate an unguessable link that lets anyone who holds it view a simulation's configuration and results without an account. The shared page shows your simulation data but not your identity, email, or billing information. Shared pages are marked not-for-search-indexing. You are shown a warning before the link is created.

Curated public results (/r/...): example simulations created by ThrustLab and published for educational purposes.

Approved catalog submissions become shared catalog data as described in Section 3.1.

3.6 Device, log, and anti-abuse data

Server and access logs: like virtually all web services, our servers record request logs that can include IP address, user-agent, and pages requested. Retention is described in Section 8 (target ≤ 90 days).

Bot protection: our signup uses Cloudflare Turnstile to distinguish humans from bots.

Error monitoring: we use Sentry to capture application errors (stack traces and request context, which can include an IP address or account identifier). Sentry is wired both server-side and client-side (browser SDK, session replay disabled). Error monitoring runs regardless of your cookie-consent choice — it is infrastructure telemetry, not behavioral analytics.

3.7 Analytics data (only with your consent)

Product-analytics events (pageviews, feature usage such as "simulation created" or "results viewed") and device/browser characteristics are collected through the analytics providers named in Section 6 only as permitted by the consent gate described in Section 7: in the EEA, UK, and Switzerland, only after you accept analytics via the cookie banner; elsewhere, Google Analytics may collect by default until you decline or opt out, and PostHog collects only after you accept. In every region, collection stops once you decline, opt out via the Do Not Sell or Share control, or send a Global Privacy Control signal.

4. How we use information

PurposeData used
Provide the service: run simulations, store your projects, render your resultsAccount credentials, simulation content, preferences
Process subscriptions, payments, and refundsBilling information, credit ledger
Send transactional email: email verification, welcome, simulation-complete notifications, and the legally required pre-renewal reminders for auto-renewing subscriptionsEmail address, subscription state
Prevent abuse and fraud: signup bot protection, refund-abuse prevention, and signup velocity checksTurnstile verification, device data, card fingerprint (post-refund only), credit ledger
Maintain legal records of your consent to the Terms and to auto-renewalConsent records (Section 3.3)
Keep the service reliable: error monitoring, backups, uptime checksLog data, error reports, encrypted backups
Understand usage and improve the product (only with your analytics consent)Analytics events (Section 3.7)
Respond to youSupport correspondence
Comply with law and enforce our termsAny of the above, as required

We send no marketing or newsletter email today. Every email we send is transactional (verification, welcome, simulation-complete, billing/renewal notices). If that ever changes, marketing email will be opt-in with a working unsubscribe.

Legal bases (EEA/UK). Where EU or UK data-protection law applies to our processing, our legal bases are: performance of a contract (Article 6(1)(b)) for providing the Service, your account, and billing; consent (Article 6(1)(a)) for optional analytics, withdrawable at any time as described in Section 7 and the Cookie Policy; legitimate interests (Article 6(1)(f)) for service security, abuse prevention, error monitoring, and establishing or defending legal claims; and legal obligation (Article 6(1)(c)) for records we are required to retain, such as billing and consent evidence.

5. We do not sell your personal information — and your rights don't depend on where you live

We do not sell your personal information. We do not share it for cross-context behavioral advertising. We run no ad networks and no targeted advertising.

Rather than reciting rights statutes that may or may not apply to a company of our size, we take the simpler position: we voluntarily extend the same core privacy rights to everyone who uses ThrustLab, regardless of where you live and regardless of whether any particular privacy law applies to us. Those rights, and how to exercise them, are in Section 9. Where a specific law (for example, the California Consumer Privacy Act) applies to us and grants you additional rights, you have those too — nothing in this policy waives them.

6. Who we share information with

We share personal information only with the service providers ("processors") we use to operate ThrustLab, listed by name below — never with data brokers or advertisers. Each provider receives only what its function requires and is bound by its own contractual and legal obligations.

ProviderPurposeData touchedLocation
HetznerServer hosting for the application and databaseAll application data at rest and in transitGermany (Falkenstein)
Stripe, Inc.Payment processing and subscription billingPayment card (entered directly with Stripe), billing email, subscription stateUnited States
ResendTransactional email deliveryYour email address and the content of emails we send youUnited States
Google WorkspaceCompany email (the contact@ mailbox)Support correspondence you send us — correspondence only; no product data flows through WorkspaceUnited States/global
Cloudflare, Inc. (Turnstile)Signup bot protection (server-side verification; no browser widget today)Signup verification token, IP address (server-to-server)Global
PostHog, Inc.Product analytics — only after you accept analyticsPageviews, product events, device/browser dataUnited States (US cloud)
Google Analytics 4Web analytics — loaded only after you accept analytics (see Section 7)Pageviews, device/browser dataUnited States/global
SentryError and crash monitoring — not consent-gated (Section 3.6); wired server- and client-sideError reports, stack traces, request contextUnited States
Backblaze, Inc. (B2)Off-site storage of encrypted database backupsEncrypted backup archivesUnited States (US West)
healthchecks.ioBackup-job heartbeat monitoringNone (a "backup ran" ping only — no user data)

We may also disclose personal information: (a) to comply with law, legal process, or an enforceable government request; (b) to protect the rights, property, or safety of Upwash LLC, our users, or the public (including investigating fraud or abuse); (c) to professional advisers (lawyers, accountants, insurers) under confidentiality obligations; and (d) as part of a merger, acquisition, or sale of assets — in which case this policy continues to apply to your data and we will notify you of any successor.

This table serves as our subprocessor list. We will update it when providers change; material changes follow the procedure in Section 13.

7. Cookies, analytics, and tracking

Full cookie-by-cookie detail will live at /cookies. Summary of how the gate actually works:

Strictly necessary storage — your login session and your cookie-consent choices. The application cannot function without this storage.

A consent banner appears on your first visit with Accept and Decline options. You can change your choice at any time.

Consent gate with a regional default: in the EEA, UK, and Switzerland, no analytics storage is used and PostHog does not load until you accept — Google's tag is configured (Google Consent Mode) to deny analytics storage by default in those regions. Elsewhere, Google Analytics runs by default under the opt-out model, and PostHog still loads only after you accept. Google Analytics' advertising storage is denied always — we use no Google advertising products.

Cross-site collection: when analytics are active, the third-party providers named in Section 6 (Google, PostHog) may collect information about your activity over time and across different websites that use their services, subject to their own privacy policies.

Declining analytics never limits your use of the product.

8. How long we keep information

We keep personal information only as long as needed for the purposes above, on the following schedule:

CategoryRetention period or criteria
Account data (email, credentials, preferences, beta-application data linked to your account)Life of the account. On account deletion, removed from live systems within 30 days, and from encrypted backups as they rotate out within 30 days.
Projects, simulations, results, custom airfoilsLife of the account; deleted with the account on the same schedule as above, except information we reasonably must retain to establish, exercise, or defend legal claims, to comply with a legal hold, or in connection with an actual or reasonably anticipated dispute — retained only until the matter concludes (Section 9). Cancelling a paid subscription does not delete your data — your account and content persist on the free tier until you delete the account.
Consent records (Section 3.3)At least 3 years from collection, or 1 year after your account is terminated, whichever is longer — these are legally required evidence of your consent to the terms and to auto-renewal (California's automatic-renewal law sets the 3-year floor). They are retained through and after account deletion.
Billing and refund records (Stripe identifiers, charge/refund history)As long as needed for tax, accounting, dispute, and legal-compliance purposes after the transaction.
Card fingerprint (post-refund anti-abuse record)Retained after account deletion to enforce the once-per-card refund limit. It does not reveal your card number and cannot be reversed to reconstruct it; we use it solely to recognize a card that has already received a refund.
Approved catalog submissionsRetained in the shared catalog after account deletion (the specification data is component data, not personal data; your account association is removed).
Server and access logsTarget ≤ 90 days.
Uploaded propeller geometry imagesNot retained.
Support correspondenceUp to 2 years after resolution, for context on repeat issues.
Error reports (Sentry)Per Sentry's project retention settings.

9. Your privacy rights and how to exercise them

You may request, for your own personal information:

  • Access — a copy of the personal information we hold about you;
  • Correction — fixing inaccurate information (email and unit preferences are self-serve in account settings; anything else, ask us);
  • Deletion — deletion of your account and personal information;
  • Export — a portable copy of your data in a machine-readable format.

How: email [email protected] from the email address on your account. There is no self-serve deletion or export button in the product today — these requests are fulfilled manually by us.

Identity verification: we verify requests by confirming control of the account email. We will not ask for more information than we need. Opt-out requests (analytics, Do Not Sell or Share) require no verification at all.

Timing: we aim to respond within 45 days (and, where EU or UK law applies to your request, within one month). If a request is complex we may extend once by a further 45 days (or, under EU/UK law, by up to two further months), and we will tell you why.

Appeals: if we decline a request, we will explain why in writing, and you may appeal by replying to that decision; we aim to answer the appeal with written reasons within 45 days.

No discrimination: exercising these rights never affects your service, pricing, or credits.

Additional rights for EEA/UK visitors: where EU or UK law applies, you also have the right to object to or ask us to restrict processing based on legitimate interests, the right to withdraw consent at any time (Section 7), and the right to lodge a complaint with your local data-protection supervisory authority (in the UK, the Information Commissioner's Office). We honor these through the same channel as the rights above.

What survives deletion. When we delete your account we delete your personal information, except: (a) consent and billing records retained on the legal schedule in Section 8; (b) the card-fingerprint anti-fraud record described in Sections 3.4 and 8; (c) approved catalog submissions (de-associated from you); (d) residual copies in encrypted backups until those backups rotate out; and (e) information we reasonably must retain to establish, exercise, or defend legal claims, to comply with a legal hold, or in connection with an actual or reasonably anticipated dispute — retained only until the matter concludes. We will tell you this when confirming a deletion request.

10. Global Privacy Control and "Do Not Sell or Share"

Global Privacy Control (GPC): if your browser sends a GPC signal, we honor it automatically, for every visitor, as binding — it switches the Do Not Sell or Share control on and it cannot be overridden while the signal is present. We treat GPC as an opt-out of all non-essential analytics, not merely of "sale" (we sell nothing).

Do Not Sell or Share toggle (on the /privacy page): switching it on turns off all non-essential analytics for your browser. Essential login/session storage is unaffected. We offer this control to everyone as part of the voluntary grant in Section 5, not because a statute compels us to.

Do Not Track: some browsers send a legacy "Do Not Track" (DNT) signal. We do not respond to DNT signals, but we do honor the Global Privacy Control signal as described above.

11. International visitors and data transfers

ThrustLab is operated by Upwash LLC from the United States. Application data is hosted on servers in Falkenstein, Germany (Hetzner), and is also processed in the United States — where we operate the Service and where providers named in Section 6 (for example Stripe, Google, PostHog, Sentry, and Resend) process the categories of data described there. Wherever you use ThrustLab from, you understand that your information will be processed in both locations, where privacy laws may differ from those of your country.

For transfers of EEA/UK personal data to providers in the United States, we rely on the safeguards those providers maintain, including EU–US Data Privacy Framework certifications and the standard contractual clauses incorporated in their data-processing agreements. Upwash LLC is not itself certified under the Data Privacy Framework.

12. Children's privacy

ThrustLab is an engineering tool. It is not directed to children under 13, and we do not knowingly collect personal information from children under 13. We do not collect date of birth, so we rely on our eligibility terms (see /terms) and on reports.

If we learn that we have collected personal information from a child under 13, we will delete it promptly, or, where appropriate, seek verifiable parental consent before any further collection. If you are a parent or guardian and believe your child under 13 has created an account, contact [email protected] and we will act on it.

13. Security

We use reasonable administrative and technical safeguards appropriate to a service of our size: passwords stored only as salted hashes, encrypted connections (TLS) in transit, encrypted off-site backups, access limited to those who operate the service, and payment card data handled exclusively by Stripe so that card numbers never reach our systems.

No internet service can guarantee security, and we do not promise that ours is an exception. If a breach of security affects your personal information, we will notify you and the relevant authorities as required by applicable law.

14. AI and machine-learning training

We do not use your personal information, simulation configurations, simulation results, or uploaded content to train artificial-intelligence or machine-learning models, and we do not sell or license your data to anyone else for that purpose. ThrustLab's simulation engine is built on proprietary models, methods, and data that are developed independently of customer data.

15. Changes to this policy

When we make material changes to this policy, we will: (a) post the updated version at /privacy with a new version number and effective date; (b) notify account holders by email and/or an in-product notice before the change takes effect; and (c) where the change materially affects how we handle your personal information, require you to re-accept before the change applies to you. Non-material changes (typo fixes, clarifications, provider-name updates in Section 6) may be posted with an updated date only. We will retain prior versions and provide them on request.

16. Related policies and relationship to the Terms

Terms of Service — /terms

Refund Policy — /refund

Cookie Policy — /cookies

Contact: [email protected]

This policy is incorporated into and forms part of our Terms of Service (/terms). Any dispute relating to this policy is subject to the Terms' governing-law and dispute-resolution provisions, and if this policy conflicts with the Terms, the Terms / this policy controls as to that conflict.