bellcrank

Bellcrank — Data Privacy Policy

Last updated: 23 August 2026

This policy describes which personal data Bellcrank (the "Service") processes, why, where it is stored and which rights you have. It is written to match what the Service actually does — a browser-based suspension-kinematics simulation tool — and nothing more.

The controller responsible for the processing described here is Bellcrank UG (haftungsbeschränkt), Schneefinkenweg 12A, 81827 München, Germany ("Bellcrank", "we").

1. Data we process

Account data. First name, last name and e-mail address, collected at signup. Passwords are handled exclusively by AWS Cognito (our identity provider); we never store or see your password. Cognito also records your acceptance of the Terms of Use and of this policy (timestamped), your e-mail confirmation state and account status. We also store the IP address and a device identifier of your most recent successful login or session refresh, which we use as a session-security measure: signing in from a new IP address or a new device invalidates the access tokens issued to your earlier browser sessions. The device identifier is a random value generated by your browser and stored in its local storage; it does not identify your physical device or hardware, only that browser installation. Both values are overwritten on each new login/refresh and are not kept as a history.

API keys. If you create an API key to access the Service programmatically, we store its label, creation date and last-used date; the key itself is stored only as a one-way hash and cannot be retrieved after creation. Using the Service through an API key is the same account activity as using the web application, and counts toward the same tier limits.

User content. The suspension assemblies, motions, simulation results and file exports you create. These are engineering data; we treat them as confidential and do not analyze them beyond operating the Service.

Usage and billing data. Subscription tier, simulation-credit counters and coarse product events (signup, run, gate-hit, upgrade) used for metering tier limits and understanding aggregate product usage.

Payment data (Stripe). Payment for paid subscriptions is handled by Stripe, which acts as merchant of record: your purchase of a paid plan is concluded with Stripe as reseller of the Service. When you start a checkout we pass your name, e-mail address and an internal account reference to Stripe; your billing address, payment details and any VAT ID you choose to provide are entered by you directly on Stripe's hosted checkout and billing-portal pages and never reach our servers. From Stripe we receive and store a customer reference and the state of your subscription (status, plan, seat count, price, currency and billing period) — never card numbers. Stripe sends invoices, receipts and payment-failure notices for paid subscriptions directly to your e-mail address, and handles refunds.

Team data. If you create or join a team, we store the team's name, its membership and which member owns it. Your name and e-mail address are visible to the other members of your team in the team's member list, and content stored in the team's shared space is accessible to the team's members. If you invite someone to a team, we process the e-mail address you provide in order to deliver the invitation.

Student-team verification. If you apply for a student team, we process the full name and university you provide, together with your account e-mail address, to verify eligibility for education pricing. As part of the application you upload a proof-of-enrollment document (PDF, PNG or JPEG, up to 10 MB); we store it in our private object storage (Amazon S3) solely to verify your eligibility, and only our administrators can view it. Review is performed manually by our staff; no third-party verification service is involved. The document is deleted as soon as the request is approved or denied, or if the team is dissolved before review, and in any case no later than 90 days after upload — see "Retention" below.

In-app feedback. If you send feedback from inside the Service, we receive your message together with your account e-mail address as an e-mail (through Amazon SES) and use it only to handle the feedback.

Administration audit data. Our staff can adjust your subscription manually (for example to grant a complimentary plan or to help with a billing problem), manage a team's account (for example its seat count or ownership) or revoke your API keys. Every such administrative change is recorded in an audit trail containing your account id and e-mail address, the acting staff member, the action, its timestamp and the staff member's IP address. Staff-facing usage dashboards show per-account metrics together with the account's e-mail address.

Technical data. Two kinds of technical logs are kept. Standard application/server logs (IP address, timestamp, request path, status) are retained for a limited period for security and debugging — see "Retention" below. Separately, our content-delivery network (Amazon CloudFront) keeps standard access logs of requests to our websites and the application, which also record the visitor's IP address; these are retained for 90 days. Authentication tokens are stored in your browser's local storage; we set no advertising or cross-site tracking cookies.

Contact form. If you write to us through the contact form on our public website, the name, e-mail address and message you provide. We receive it as an e-mail (through Amazon SES) and use it only to handle your inquiry; it is not added to a database or to any marketing list.

Bot protection. Our contact form is protected against automated abuse by Cloudflare Turnstile. When it is active, Cloudflare receives your IP address and signals about your interaction with the page to tell humans from bots. Turnstile is privacy-preserving: Cloudflare does not use this data to profile you or to track you across other sites.

2. Purposes and legal bases

3. Where your data lives

The Service runs on Amazon Web Services in the EU (Frankfurt, eu-central-1): the database on Amazon RDS, files on Amazon S3, identity on Amazon Cognito, e-mail via Amazon SES, and our public websites are delivered through Amazon CloudFront. AWS acts as our processor under its Data Processing Addendum. Domain DNS is managed by Cloudflare, and — where enabled — the contact form's bot check runs on Cloudflare Turnstile; where Cloudflare processes personal data it acts as our processor and may transfer it outside the EU under the EU standard contractual clauses.

Payment and billing data for paid subscriptions is processed by Stripe as merchant of record. Stripe processes this data as an independent controller under its own privacy policy and may transfer it outside the EU subject to appropriate safeguards (such as the EU standard contractual clauses).

4. Sharing

We do not sell personal data and do not share it with third parties, except: (a) AWS as hosting/identity/e-mail/CDN processor; (b) Stripe as merchant of record and payment processor for paid subscriptions (see section 1); (c) Cloudflare as DNS and, for the contact form, bot-protection (Turnstile) processor; (d) the members of a team you have joined, who can see your name, e-mail address and the content in the team's shared space; (e) where required by law.

5. Retention

Account data is kept while your account exists. If you delete your account, account data and user content are deleted within 30 days, except where law requires longer retention (e.g. invoices). Audit records of administrative subscription changes are retained after account deletion as part of our accountability records, together with audit records of administrative student-team verification decisions — the outcome, the reason for a denial, and the requester's name, university and e-mail address — kept as part of that same accountability record. Result exports expire automatically 7 days after generation. Application/server logs and CloudFront (CDN) access logs are both retained for up to 90 days. A student-team proof-of-enrollment document is deleted as soon as its request is approved or denied, or if the team is dissolved before review, and in any case no later than 90 days after upload; nothing about the document itself is retained afterward beyond what is captured in that audit record.

6. Your rights

Subject to applicable data-protection law (including the GDPR where it applies), you have the right to access, rectify, erase and export your personal data, to restrict or object to processing, and to lodge a complaint with a supervisory authority. Contact us at the address below; we respond within one month.

7. Security

Transport encryption (TLS) everywhere, encryption at rest for the database and file storage, passwords never stored by us (Cognito-managed), and least-privilege access to production systems.

8. Changes

We will announce material changes to this policy in the Service before they take effect. The "Last updated" date at the top reflects the current version.

Contact

Bellcrank UG (haftungsbeschränkt), Schneefinkenweg 12A, 81827 München, Germany.

Data protection inquiries: info@bellcrank.io