← Back

Privacy Policy

Last updated: August 11, 2026

SimLabDisplay is a web application, operated by BML Innovations LLC, that helps instructors run simulation labs — assigning students to stations, managing rotations, recording sign-offs, and summarizing a lab day. This policy explains what information SimLabDisplay collects, how it is used, and how it is protected. SimLabDisplay is used by educational institutions; the institution remains the owner of its students' educational records, and SimLabDisplay processes that data on the institution's behalf.

Information we collect

SimLabDisplay collects only what it needs to run a lab:

  • Account details — name, email address, and role (student, faculty/TA, or professor), used to sign in. Demo accounts are different: they hold no name and no email address (see "Demo accounts" below).
  • Class and lab data — the classes you belong to, your seat assignment, and the day plans and activities an instructor creates.
  • Activity records — which activities a student has completed, when, and who signed them off.
  • Help and station requests — messages a student sends asking for help, and their status and timing. Requests from demo accounts carry no written message — only the seat, station, and timing.
  • Photos of lab work — if a student chooses to upload them, photographs of their practice work (for example, a prepared tooth), stored privately and visible only to the student and, for class submissions, their instructors. Photographs uploaded from a demo account are held against a seat number rather than a person.

SimLabDisplay does not collect Social Security numbers, grades of record, financial information, or health information, and it does not use tracking or advertising cookies.

Demo accounts

An institution may trial SimLabDisplay using demo accounts, which are designed to hold no identifying information. A demo student signs up with only a seat number and a four-digit PIN — no name and no email address. Their work, including any photographs they upload, is recorded against the seat number. The instructor knows who sits at each seat; SimLabDisplay does not, and cannot connect a demo account to a person on its own.

  • Demo accounts can upload photographs of lab work, up to a small storage allowance. A photograph is stored against a seat number and is never linked to a name or an email address. Students should photograph their work only, and not faces, badges, or anything else that would identify a person. A student can delete their own photographs at any time, and deleting the account removes them. Help requests from demo accounts still carry no written message.
  • A demo account that is never used to join a class is deleted automatically within about a day.
  • To prevent abuse of demo signup, the network address a demo account is created from is kept briefly — no more than a few hours — and then deleted.

Demo records that are in use are otherwise retained like other class records, under the institution's direction.

How we use it

The information is used solely to operate the lab: to sign you in, to place and rotate students through stations, to show instructors a live view of the lab, to record sign-offs, and to generate an end-of-day report for the instructor. SimLabDisplay does not sell your information or use it for advertising.

If your institution has enabled it, an instructor may email students who did not complete their lab work; those emails are sent only to students in that instructor's own class.

Where your data is stored

Data is stored in a managed PostgreSQL database (Supabase), hosted on Amazon Web Services in the United States (US East, Ohio region). It is encrypted in transit and at rest, and the provider maintains SOC 2 Type II certification. The application itself runs on Vercel (also SOC 2 Type II); student data is stored only in the database, not on the hosting layer.

Who can see your data

Access is scoped by role and enforced at the database level, so each person only sees what they are permitted to:

  • A student can see their own class, seat, and progress.
  • An instructor and their designated faculty/TAs can see the students in their own classes.
  • No one can see data belonging to another instructor's class.

Service providers

SimLabDisplay relies on a small number of providers to operate, who process data only to provide their service and not for their own purposes: Supabase (database and authentication) and Vercel (application hosting). If email reminders are enabled, Resend is used to deliver those messages.

Data retention and deletion

Lab and activity records are kept for as long as your institution uses SimLabDisplay, so instructors can reference past labs. An instructor can delete a day plan, which permanently removes its associated assignments, completions, and requests. On request from your institution, account and class data can be exported or deleted. Demo accounts that are never used to join a class are deleted automatically within about a day.

Student records (FERPA)

Some of the information SimLabDisplay handles — such as a student's participation and completion records — may constitute educational records under FERPA. SimLabDisplay acts as a service provider to the institution and handles this data under the institution's direction and any agreement in place. Students seeking to review, correct, or delete their records should contact their institution, which controls those records.

Security

Data is encrypted in transit and at rest, access is restricted by role and enforced at the database, and sign-in is protected by a password. No system is perfectly secure, but SimLabDisplay is built to limit access to the minimum each person needs.

Changes to this policy

This policy may be updated as SimLabDisplay changes. The date at the top reflects the most recent revision.

Contact

Questions about this policy or your data can be directed to support@simlabdisplay.com.