← ChaplainSim

Version 1.0 · Effective 6 August 2026

Privacy

ChaplainSim is an invited pilot with 10–15 trainees. This page describes what we actually do with your data during that pilot, in plain terms.

What we collect, and why

  • Your email address — to check you are on the invitation list and to send sign-in codes. There is no password.
  • An optional display name — only to greet you. Leave it blank and nothing changes.
  • Your conversations — which scenario, which responses, in which order, and the feedback generated when you finish. This is what makes it possible to leave a conversation and come back to it.
  • Your reflections — the text you write after a conversation, if you write any.
  • Missing-response reports — when you tell us a response you would have used was not offered.
  • Product events — that a scenario was started, that a turn was taken at a particular node, that a save failed. See below for what these can and cannot contain.
  • Payment status, if you subscribe — your plan and whether it is active. Never your card details; those stay with Stripe.

If you asked to join the pilot through the form on our home page, we also hold the address you gave and anything you wrote about where you are training, so we can reply. That is used for nothing else: it is not a mailing list, it is not shared, and it is deleted once we have written to you and the pilot has closed.

Your reflections

Reflection text is treated as the most sensitive thing in the system. It is:

  • readable only by you when you are signed in;
  • never included in product analytics;
  • never included in error reports or server logs;
  • never sent to any AI provider, and never used to train any model;
  • encrypted at rest by the database platform.

Administrator access to reflection content is restricted operationally and technically, and is intended only for a documented legal or safety obligation. Who may do this, and in what circumstances, is a decision that must be recorded before the pilot opens.

Do not enter identifiable patient information

The patients in ChaplainSim are fictional. Please do not write anything about a real patient into a reflection or a report — no names, dates, wards, or details that could identify someone. The app shows a reminder wherever you can type, and does a rough check in your browser for things that look like real detail. That check never leaves your device and never blocks you from saving.

Product analytics

We record a small, fixed list of events so we can see where scenarios lose people: scenario started, turn taken, attempt completed, attempt resumed, reflection saved, missing response submitted, sign-in completed, onboarding skipped, and turn submission failed.

Each event may carry the scenario, the version, the node, the choice, the turn number, and bucketed values such as “6–10 minutes” or “100–300 characters”. Anything not on that list is dropped before storage. Event properties never contain reflection text, report text, email addresses, display names, or patient dialogue.

We do not rank trainees, score individuals, or infer anything about your beliefs.

Where AI is and is not used

No AI runs while you are using ChaplainSim. The patient’s words, the responses you choose from, and the feedback you receive are all written in advance by a human author and reviewed by a clinical or CPE educator before publication. No large language model is called when you start a scenario, take a turn, read feedback, or save a reflection.

AI was used to help draft scenario material before review. Every line was edited by the named author and approved by the named reviewer, and the approved content is fixed by a checksum so it cannot change without going through review again.

The reviewer is not independent of ChaplainSim. The chaplain who reviewed and approved this pilot’s scenarios is connected to the people who operate it, rather than an outside auditor. It is a real clinical review by a qualified chaplain, and their name is recorded against every published version — but you should know it is not arm’s length. Ask us for the reviewer’s name and qualification and we will tell you.

Your reflections, your email address, your display name, and your individual records are never sent to an AI provider.

If you pay us

We never see your card. Card details are entered on Stripe’s own payment page and are held by Stripe. They do not pass through ChaplainSim and we could not retrieve them if we wanted to.

What we do store against your account is the minimum needed to know what you have access to:

  • the plan you are on, and whether it is active, past due or cancelled;
  • when the current period ends, and whether you have asked to cancel at that point;
  • the number of seats, if an organisation is paying;
  • Stripe’s own identifiers for your customer and subscription records.

Paying changes what you can open. It changes nothing about who can read what you write: a reflection on a paid plan is exactly as private as a reflection on the free one, and an organisation paying for your seat gets no sight of your conversations.

Invoices and payment records are kept for seven years, because Singapore tax law requires it. That is longer than the retention periods below, and it applies even if you delete your account — we keep the record of the transaction, not your conversations.

Processors and hosting

Your data is stored and processed in Singapore (AWS ap-southeast-1), via Supabase. If you are outside that region, using ChaplainSim means your data is transferred there.

We use these processors:

  • Vercel — application hosting in Singapore (sin1)
  • Supabase — managed Postgres database in Singapore (AWS ap-southeast-1)
  • Resend — delivery of sign-in code emails
  • Stripe — payment processing and card handling

How long we keep things

While the pilot runs, your account and its contents are kept so you can return to them. After that:

  • Conversations you finished, and their feedback and reflections: 2 years.
  • Conversations you started and left: 1 year from when you last touched them.
  • The text of missing-response reports: 2 years. The anonymous record that a report was made about a particular moment is kept longer.
  • Anonymous product events: 2 years, after which anything that could link them to you is removed.

You can delete everything sooner from your account page at any time.

Access, correction, export and deletion

You can see everything you have written from inside the app. To correct something, edit it. To get a copy, email the pilot administrator and we will send your profile, attempts, feedback, reflections and reports as a JSON file — normally within five working days.

To delete everything, use Account. Deletion removes your profile, your attempts and their feedback, your reflections, and the text of your reports. We keep the anonymous event counts that tell us where a scenario loses people, with your user ID, attempt IDs and any other value that could link them back to you removed.

Contact

Questions about any of this, and any request to see, correct, export or delete your data, go to hello@chaplainsim.com.

ChaplainSim is operated by Simplimar Pte Ltd.

This page describes the invited pilot. It requires jurisdiction-specific legal review before any public or commercial launch.