Privacy Policy

Effective date: August 23, 2026

BBP Services ("we," "us," "the Service") runs physics-based ground motion simulations on the SCEC Broadband Platform at bbpservices.net, and publishes verification results comparing those simulations against recorded ground motion. This policy describes what data we collect, how long we keep it, and your choices.

1. Information We Collect

Account information

If you register, we collect your email address and a password, stored as a bcrypt hash — we never store or have access to your plaintext password. We also generate an API key so you can use the Service from your own code.

Simulation configurations you submit

When you configure a simulation we store the job specification you submitted: the source parameters, the coordinates and site conditions of the stations you chose, the method and velocity model, and any file you imported. These are retained so that a completed run can describe itself — a downloaded archive does not otherwise record the inputs that produced it. Station coordinates you enter are data you have chosen to give us; treat them as you would any location you publish to a third-party service.

Simulation results

Seismograms, spectra, rupture descriptions, figures and metadata produced by your runs are stored on our infrastructure and are downloadable by you. See Section 5 for how long.

Usage and cost accounting

Because compute and storage cost real money, we meter them per account: the compute time each of your jobs consumed, the machine type it ran on, the number of API calls you made, and the volume of results you are storing over time. This is what lets us tell you what you have used and, where applicable, bill for it.

Information we do not collect

We do not collect precise device location, browsing history outside this site, or payment card details. The Service does not currently process payments.

2. How We Use Information

  • To create and manage your account and API access
  • To run the simulations you submit, and to return their results to you
  • To meter compute and storage against your account, and to show you what you have used
  • To decide whether an account is approved to start compute that we pay for
  • To prevent abuse of the API (rate limiting)
  • To verify your email address (a one-time link sent at registration)

We do not sell your personal information. We do not use your data for advertising. We do not use the contents of your simulation configurations or results for any purpose other than running and returning them to you.

3. Third-Party Services

  • Amazon Web Services — the Service runs on AWS in the US West (Oregon) region. Your simulation configurations and results are processed on AWS compute and stored in AWS object storage.
  • SendGrid — used to deliver transactional email such as address verification and password resets.
  • Cloudflare Turnstile — used at registration to prevent automated signups; it may process technical signals, not tied to your identity, to assess whether a request is automated.
  • USGS (U.S. Geological Survey) — we consume public earthquake catalogue data. No personal information is sent to USGS.
  • Seismic data centres — for verification work we retrieve publicly available recorded seismograms. No personal information is sent to them.

4. Published Verification Results

The Service publishes verification and validation results — comparisons of simulated against recorded ground motion for published earthquakes and for the SCEC validation events. These are generated from public earthquake data and public seismic recordings. They do not include, and are not derived from, any simulation you submit. Your own runs are visible only to you.

5. Data Retention

Account information is retained for as long as your account remains active.

Simulation results are retained for a limited period and then deleted automatically. The retention period is shown alongside your stored results, with the expiry date for each. You can delete any stored result yourself before then, and doing so stops it accruing storage cost. The job record and its cost accounting are kept after the files are deleted, so your usage history remains accurate.

You may request deletion of your account and associated data at any time — see Section 7.

6. Your Choices

  • Delete stored results — remove any dataset you have produced, from your data page.
  • Account deletion — contact us to request deletion of your account and associated data.
  • API key — your key is visible in your account settings and can be regenerated, which immediately invalidates the previous one.

7. Children's Privacy

The Service is not directed at children under 13, and we do not knowingly collect personal information from children under 13.

8. Contact

Questions about this policy or requests regarding your data can be sent to info@bbpservices.net or via our feedback form.

9. Changes to This Policy

We may update this policy from time to time. Material changes will be reflected by updating the effective date above.