locsim← Back

Privacy Policy

This policy explains what locsim collects when you buy and use locsim, why we collect it, and what you can do about it. We have tried to write it in plain language rather than boilerplate.

Last updated August 12, 2026

1The short version

locsim never collects the locations you simulate, and never collects your device’s real location. Nothing about where you are, or where you tell your phone you are, is transmitted to us or stored by us. That information stays on your device.

Beyond that:

  • We collect your email address, an optional Telegram handle, and an anonymous device identifier used to lock your license to one device.
  • We never see your card details — Stripe handles payments end to end.
  • This website sets no cookies, and runs no analytics, advertising, or tracking scripts of any kind.
  • We do not sell or share your personal information, and we never have.
  • You can ask us to delete your data at any time.

2Who we are

locsim provides the locsim location simulator for iPhone and iPad. For the purposes of the UK and EU GDPR we are the data controller for the information described here. You can reach us at admin@zolotaai.xyz.

3What we collect

We collect only what we need to sell you a license and keep it working.

  • Email address. Provided by you at checkout and passed to us by Stripe. We use it to send your license key, to send the secure link for managing your subscription, and to contact you about your purchase.
  • Telegram handle. Optional, and only if you enter it at checkout. We use it to identify you if you contact support on Telegram.
  • License records. Your license key, plan, status, expiry date, and the times your license was created, activated, and last validated.
  • Device identifier. When the app checks your license, it sends an opaque identifier generated on your device. We store it solely to enforce the one-device rule described in our Terms. It is not your name, phone number, advertising ID, or IMEI, and it does not tell us who or where you are.
  • Support messages. If you message us on Telegram, we see your message and whatever profile information Telegram shows us.
  • Server logs. Our hosting provider records standard technical data such as IP address, timestamp, and requested URL, to keep the service running and secure.

4What we do not collect

It is worth being explicit, because the product invites the question. We do not collect:

  • Your real location, at any level of precision.
  • The locations, routes, bookmarks, or history you create in the app — those are stored on your device only.
  • Your contacts, photos, messages, calendar, or files.
  • Your card number, CVC, or expiry date.
  • Any behavioural, advertising, or cross-site tracking profile.

5Payments

Payments are processed by Stripe, Inc. Your card details go directly to Stripe and never touch our servers. Stripe acts as an independent controller for the payment information it collects, under its own privacy policy, and it may use device and transaction data for fraud prevention.

We receive from Stripe only what we need: your email address, your subscription’s status and billing period, and confirmation that a payment succeeded or failed. Invoices, receipts, and payment-method changes live in the Stripe customer portal, which you reach from our Manage page.

6How we use your information

  • To deliver your license key, the app download, and setup instructions after purchase.
  • To validate your license and enforce the one-device rule.
  • To manage your subscription, including renewals, cancellation, and the secure portal link.
  • To provide support when you contact us.
  • To detect, investigate, and prevent fraud, key sharing, abuse of our API, and chargeback abuse.
  • To keep the service secure, debug problems, and meet our legal and tax obligations.

We do not use your information to build advertising profiles, and we do not make automated decisions producing legal or similarly significant effects about you.

8Who we share it with

We do not sell your personal information, we do not share it for cross-context behavioural advertising, and we do not disclose it for anyone else’s marketing. We use a small number of service providers, each of which processes data only on our instructions:

  • Stripe — payments, subscriptions, and the customer portal.
  • Supabase — hosts the database holding license records.
  • Netlify — hosts this website and serves it over its network.
  • Resend — delivers your license key and subscription emails.
  • Vimeo — hosts the demo video, and receives nothing unless you press play (see section 9).

We may also disclose information if we are legally required to, if we need to enforce our Terms or protect our rights, safety, or property, or in connection with a merger, acquisition, or sale of assets — in which case we will tell you before your information becomes subject to a different policy.

9Cookies and tracking

This website sets no cookies of its own and runs no analytics, advertising, or tracking scripts. There is no Google Analytics, no advertising pixel, no tag manager, and no cross-site tracking. This is why you are not being asked to accept a cookie banner.

The demo video is the one exception, and it is opt-in. The player is replaced by a static placeholder until you press play; only then does anything load from Vimeo, and it is requested with Vimeo’s "do not track" flag set. If you never press play, Vimeo receives nothing about you. Stripe may set cookies on its own checkout and portal pages, which are governed by Stripe’s privacy policy.

10How long we keep it

We keep license records — including your email address, device identifier, and subscription history — for as long as your subscription is active and afterwards for as long as we need them to prevent abuse, resolve disputes, and meet tax and accounting obligations, which is normally up to seven years.

Server logs are kept for a short period by our hosting provider in the ordinary course. Support conversations remain in Telegram until deleted. Payment records are retained by Stripe under its own retention schedule. If you ask us to delete your data, we will do so except where we are legally required to keep it.

11Security

The site is served over HTTPS, the database is not publicly accessible, payment data never reaches our servers, and the links we email for managing your subscription are cryptographically signed and expire after 30 minutes. Access to production data is limited to those who need it.

No system is perfectly secure, and we cannot guarantee absolute security. Keep your license key private — anyone who has it can use your subscription — and tell us promptly if you believe it has been exposed.

12International transfers

We operate from the United States and our service providers process data in the United States and elsewhere. If you are in the UK, EEA, or another region with different data protection laws, your information will be transferred outside it.

Where such a transfer happens, we rely on appropriate safeguards, including the European Commission’s Standard Contractual Clauses and the UK Addendum, which our providers incorporate into their terms.

13Your rights

Depending on where you live, you may have the right to access the personal information we hold about you, to correct it, to delete it, to receive a portable copy, to object to or restrict how we use it, and to withdraw consent where we rely on it.

To exercise any of these, email admin@zolotaai.xyz from the address you used at checkout, or tell us which address it was. We will respond within the time the law requires — one month under the GDPR, 45 days under California law — and we may need to verify your identity first. We will never charge you or degrade your service for exercising these rights.

Deleting your license record ends your ability to use locsim, since the key can no longer be validated. We will tell you before we act if that is the consequence. If you are in the UK or EEA you may also complain to your local supervisory authority, though we would appreciate the chance to resolve it first.

14California privacy rights

If you are a California resident, the CCPA as amended by the CPRA gives you the right to know what personal information we collect and how we use it, to delete it, to correct it, and not to be discriminated against for exercising those rights.

In the last twelve months we have collected the categories described in section 3 — identifiers (email address, Telegram handle, device identifier), commercial information (your subscription and purchase history), and internet activity (server logs) — for the business purposes in section 6. We have not sold personal information, and we have not shared it for cross-context behavioural advertising. We do not collect sensitive personal information as the CPRA defines it, and we do not knowingly collect personal information from anyone under 16.

Make a request at admin@zolotaai.xyz. An authorised agent may act for you with written permission we can verify.

15Children

locsim is not for children. Our Terms require you to be at least 18, and we do not knowingly collect personal information from children. If you believe a child has given us personal information, email admin@zolotaai.xyz and we will delete it.

16Changes to this policy

If we change this policy we will update the "last updated" date at the top of this page, and for material changes — such as collecting something new or using a new provider — we will give notice by email or on the site before the change takes effect.

17Contact

Privacy questions, data requests, and complaints go to admin@zolotaai.xyz — please use email rather than Telegram for these, so there is a written record and we can verify who you are. General product support remains on Telegram at @sarjxs.