Privacy Policy
Last Updated: April 8, 2026
Data Controller: Circuit Software Pty Ltd, Sydney, NSW, Australia
Contact: privacy@withcircuit.com
Circuit Software Pty Ltd ("Circuit," "we," "our," or "us") operates Circuit at withcircuit.com. This Privacy Policy explains how we collect, use, disclose, and protect your information when you use our services.
Circuit is autonomous product intelligence for builders — a continuous system that turns customer feedback into prioritised, build-ready specs. We are committed to protecting your privacy and handling your data transparently.
1. Information We Collect
1.1 Account Information
- Email address, name and profile picture (from Google sign-in)
- Company or organisation name (optional)
- Billing information (processed securely by Stripe; we never see or store credit card details)
1.2 Customer Feedback Data
When you upload or connect feedback sources, we may collect:
- Feedback text and associated metadata
- Customer identifiers (names, emails, or IDs if included in your data)
- Source information (CSV upload, feedback widget, Slack, Google Sheets, API, manual entry)
- Timestamps and categorisation data
- Star ratings and page URLs submitted via the feedback widget
- Screenshots attached to widget feedback (may contain visible on-screen content)
- Transcript recordings and structured notes uploaded for analysis
- Revenue band or customer tier if included in your data
1.3 Usage and Technical Data
- IP addresses and approximate location (country/region level)
- Browser type, operating system, and device information
- Pages visited, features used, and interaction patterns
- Date and time of access
1.4 Integration Data
When you connect third-party services, we access:
- Slack: Messages from channels you select for feedback collection
- GitHub: Repository name, structure, and context (to improve spec file paths)
- Google Sheets: Spreadsheet content you choose to import as feedback
OAuth tokens for integrations are encrypted at the application layer.
1.5 AI Assistant Data
When you use Ask Circuit, we store your questions, AI-generated answers, referenced help articles, and your feedback on answer quality.
2. How We Use Your Information
3. AI Processing and Automated Decision-Making
3.1 What AI Does
- Classification: Automatically categorises feedback by type, sentiment and topic
- Prioritisation: Scores feedback based on volume, revenue impact, urgency and other factors
- Spec Generation: Creates build specifications from prioritised feedback
- Pattern Recognition: Identifies trends and patterns in your feedback data
- Behavioural Learning: Learns from your actions (such as which specs you ship or correct) to improve future prioritisation and spec quality
- Competitive Signals: Identifies competitor mentions in your feedback to surface switching risks and feature gaps
- AI Assistant: Answers your questions using a knowledge base and your workspace data
3.2 Privacy Protections
- PII Stripping: Personal identifiers (names, emails) are automatically removed before data is sent to AI providers
- No Model Training: Your data is NOT used to train third-party AI models. We use API services that do not train on customer data by default
- Data Minimisation: Only the minimum necessary data is sent for processing
3.3 AI Providers
- Anthropic Claude API — Primary spec generation and theme classification
- OpenAI API — Text embeddings, feedback classification, and fallback spec generation
All providers confirm that API data is not used for model training under their commercial API terms.
4. Data Sharing and Sub-processors
We do not sell your personal data to third parties.
5. International Data Transfers
Circuit is operated from Australia. Your data may be transferred to and processed in countries outside your jurisdiction, including:
- United States — Where our cloud infrastructure and AI providers are located
- Australia — Where Circuit is headquartered
For transfers outside of the EEA or UK, we rely on Standard Contractual Clauses and Data Processing Agreements with all sub-processors.
6. Data Retention
6.1 Subscription Cancellation
When you cancel, your data is retained for 30 days to allow resubscription. After 30 days, all data is permanently deleted. Request immediate deletion at privacy@withcircuit.com or via Settings → Delete Workspace.
7. Data Security
- Encryption in Transit: TLS 1.3
- Encryption at Rest: AES-256; integration tokens encrypted with Fernet (AES-128-CBC)
- Access Controls: All queries scoped to the authenticated user at application and database layers
- Authentication: OAuth 2.0 with optional MFA/2FA
- Infrastructure: AWS App Runner (SOC 2 compliant)
- Monitoring: Sentry with PII automatically redacted
8. Your Rights
8.1 All Users
- Access: Settings → Account → Export Data
- Deletion: Settings → Account → Delete Workspace
- Correction: Update inaccurate information
- Withdraw Consent: Opt out of analytics cookies via cookie settings
8.2 EU/UK GDPR
Portability, restriction, objection to legitimate interest processing, and human review of automated decisions.
8.3 Australia (Privacy Act 1988)
Access, correction, complaints to the OAIC, and information about automated decision-making.
8.4 California (CCPA/CPRA)
Know, delete, opt-out (we do not sell data), and non-discrimination.
Contact privacy@withcircuit.com — we respond within 30 days.
9. Cookies and Tracking
9.1 Essential (Always Active)
Authentication, security, user preferences.
9.2 Analytics (With Consent)
Google Analytics — usage patterns, feature adoption. Sessions linked across withcircuit.com and app.withcircuit.com.
10. Data Breach Notification
We will notify the relevant supervisory authority within 72 hours and affected individuals without undue delay if there is high risk. Australian users: OAIC notified per the Notifiable Data Breaches scheme.
11. Children's Privacy
Circuit is a B2B service not intended for under-18s. Contact privacy@withcircuit.com to report any such data.
12. Changes to This Policy
Material changes notified by updated "Last Updated" date, email, and in-app notification.
13. Contact Us
Email: privacy@withcircuit.com
Address: Circuit, Sydney, NSW, Australia
Website: https://withcircuit.com
Supervisory authorities:
- Australia: OAIC — oaic.gov.au
- EU: Your local Data Protection Authority
- UK: ICO — ico.org.uk
14. Data Processing Agreement
Enterprise customers requiring a DPA for GDPR compliance: contact privacy@withcircuit.com.