← Back

Privacy Policy

Last updated: September 12, 2026

SimLabDisplay is a web and iPhone application, operated by BML Innovations LLC, that helps instructors run simulation labs: assigning students to stations, managing rotations, recording sign-offs, and summarizing a lab day. This policy explains what information SimLabDisplay collects, how it is used, and how it is protected. SimLabDisplay is used by educational institutions; the institution remains the owner of its students' educational records, and SimLabDisplay processes that data on the institution's behalf.

Information we collect

SimLabDisplay collects only what it needs to run a lab:

  • Account details: name, email address, and role (student, faculty/TA, or professor), used to sign in. Demo accounts are different: they never hold an email address, and at a dental school they hold no name either, only a seat number. At an undergraduate school a demo account holds the student's name (see "Demo accounts" below).
  • Class and lab data: the classes you belong to, your seat assignment where the lab has seats, the group you work in where the lab works in groups, and the day plans and activities an instructor creates.
  • Activity records: which activities a student has completed, when, and who signed them off.
  • Help and station requests: messages a student sends asking for help, and their status and timing. Requests from demo accounts carry no written message, only the student's identifier, the station, and the timing.
  • A notification token: if you turn on push notifications in the app, a device token that lets SimLabDisplay send them (for example, "you've been moved to a new station"). It identifies the device, not your location or anything on it, and it is deleted when you sign out or turn notifications off.
  • Photos of lab work: if a student chooses to upload them, photographs of their practice work (for example, a prepared tooth), stored privately and visible only to the student and, for class submissions, their instructors. Photographs uploaded from a demo account are held against whatever that account is identified by: a seat number at a dental school, a name at an undergraduate one.

SimLabDisplay does not collect Social Security numbers, grades of record, financial information, or health information, and it does not use tracking or advertising cookies.

Demo accounts

An institution may trial SimLabDisplay using demo accounts. A demo account never holds an email address and never has a password to remember. A student signs in with a four-digit PIN and one other thing, and what that other thing is depends on the kind of school.

  • Dental schools: a seat number. A dental simulation lab is a room of numbered chairs, so a demo student signs up with only a seat number and a PIN. The account holds no name and no email address, and their work is recorded against the seat. The instructor knows who sits at each seat; SimLabDisplay does not, and cannot connect the account to a person on its own.
  • Undergraduate schools: a name. An undergraduate laboratory has no numbered chair to identify a student by, so a demo student there signs up with their name and a PIN. The account still holds no email address. A name is identifying information, and an institution choosing this kind of account should understand that SimLabDisplay holds it, but it is the only identifying thing held: an undergraduate class records no photographs at all(see below), so what is kept is a name, a PIN, and which lab stations were completed.

Which kind an account is follows from the school it is created under, not from anything the student chooses.

  • Photographs are a dental feature only. In a dental school the photograph is the work being assessed (a prepared tooth an instructor reviews), so demo accounts there can upload them, up to a small storage allowance, stored against the seat number and never linked to a name or an email address. Students should photograph their work only, and not faces, badges, or anything else that would identify a person. A student can delete their own photographs at any time, and deleting the account removes them. An undergraduate school has no photograph feature at all. Instructors cannot ask for one and students have nowhere to upload one. Help requests from demo accounts still carry no written message.
  • Demo accounts are not deleted on a timer. A student can delete their own demo account at any time, and a school administrator can close one.
  • To prevent abuse of demo signup, the network address a demo account is created from is kept briefly (no more than a few hours) and then deleted.

Demo records that are in use are otherwise retained like other class records, under the institution's direction.

How we use it

The information is used solely to operate the lab: to sign you in, to place and rotate students through stations, to show instructors a live view of the lab, to record sign-offs, and to generate an end-of-day report for the instructor. SimLabDisplay does not sell your information or use it for advertising.

If your institution has enabled it, an instructor may email students who did not complete their lab work; those emails are sent only to students in that instructor's own class.

Where your data is stored

Data is stored in a managed PostgreSQL database (Supabase), hosted on Amazon Web Services in the United States (US East, Ohio region). It is encrypted in transit and at rest, and the provider maintains SOC 2 Type II certification. The application itself runs on Vercel (also SOC 2 Type II); student data is stored only in the database, not on the hosting layer.

Who can see your data

Access is scoped by role and enforced at the database level, so each person only sees what they are permitted to:

  • A student can see their own class, their seat or group, and their progress.
  • An instructor and their designated faculty/TAs can see the students in their own classes.
  • No one can see data belonging to another instructor's class.

Service providers

SimLabDisplay relies on a small number of providers to operate, who process data only to provide their service and not for their own purposes: Supabase (database and authentication), Vercel (application hosting), and Expo (delivery of push notifications to the iPhone app). If email reminders are enabled, Resend is used to deliver those messages.

Data retention and deletion

Lab and activity records are kept for as long as your institution uses SimLabDisplay, so instructors can reference past labs. An instructor can delete a day plan, which permanently removes its associated assignments, completions, and requests. On request from your institution, account and class data can be exported or deleted. Accounts are never deleted on a timer.

You can delete your own account at any time, from Profile on the website or in the app. If no work of yours has been signed off by a member of staff, the account and everything in it is removed. If work has been signed off, the account is deleted and your name, email address, and photographs are permanently removed — while the sign-off records themselves are kept, without your name attached, as part of your institution's educational record. Those records belong to the institution rather than to us, and accreditation and student-records law require them to outlast the account.

Student records (FERPA)

Some of the information SimLabDisplay handles (such as a student's participation and completion records) may constitute educational records under FERPA. SimLabDisplay acts as a service provider to the institution and handles this data under the institution's direction and any agreement in place. Students seeking to review, correct, or delete their records should contact their institution, which controls those records.

Security

Data is encrypted in transit and at rest, access is restricted by role and enforced at the database, and sign-in is protected by a password. No system is perfectly secure, but SimLabDisplay is built to limit access to the minimum each person needs.

Changes to this policy

This policy may be updated as SimLabDisplay changes. The date at the top reflects the most recent revision.

Contact

Questions about this policy or your data can be directed to support@simlabdisplay.com.