CircuitCircuit
How It WorksPricingIntegrationsAbout
Blog
Changelog
Docs
Schedule a callLog inSign up

Privacy Policy

Last Updated: April 8, 2026

Data Controller: Circuit Software Pty Ltd, Sydney, NSW, Australia

Contact: privacy@withcircuit.com

Circuit Software Pty Ltd ("Circuit," "we," "our," or "us") operates Circuit at withcircuit.com. This Privacy Policy explains how we collect, use, disclose, and protect your information when you use our services.

Circuit is autonomous product intelligence for builders — a continuous system that turns customer feedback into prioritised, build-ready specs. We are committed to protecting your privacy and handling your data transparently.


1. Information We Collect

1.1 Account Information

  • Email address, name and profile picture (from Google sign-in)
  • Company or organisation name (optional)
  • Billing information (processed securely by Stripe; we never see or store credit card details)

1.2 Customer Feedback Data

When you upload or connect feedback sources, we may collect:

  • Feedback text and associated metadata
  • Customer identifiers (names, emails, or IDs if included in your data)
  • Source information (CSV upload, feedback widget, Slack, Google Sheets, API, manual entry)
  • Timestamps and categorisation data
  • Star ratings and page URLs submitted via the feedback widget
  • Screenshots attached to widget feedback (may contain visible on-screen content)
  • Transcript recordings and structured notes uploaded for analysis
  • Revenue band or customer tier if included in your data

1.3 Usage and Technical Data

  • IP addresses and approximate location (country/region level)
  • Browser type, operating system, and device information
  • Pages visited, features used, and interaction patterns
  • Date and time of access

1.4 Integration Data

When you connect third-party services, we access:

  • Slack: Messages from channels you select for feedback collection
  • GitHub: Repository name, structure, and context (to improve spec file paths)
  • Google Sheets: Spreadsheet content you choose to import as feedback

OAuth tokens for integrations are encrypted at the application layer.

1.5 AI Assistant Data

When you use Ask Circuit, we store your questions, AI-generated answers, referenced help articles, and your feedback on answer quality.


2. How We Use Your Information

PurposeDescriptionLegal Basis
Provide the ServiceOperating Circuit, processing feedback, generating specsContract
AI ProcessingClassifying feedback and generating specifications using AIContract
Behavioural LearningLearning from your actions to improve prioritisation and spec qualityLegitimate Interest
Service CommunicationsAccount notifications, security alerts, product updatesLegitimate Interest
Service ImprovementAnalysing usage patterns to improve CircuitLegitimate Interest
Security & Fraud PreventionProtecting against malicious activityLegitimate Interest
AnalyticsUnderstanding how users interact with CircuitConsent

3. AI Processing and Automated Decision-Making

3.1 What AI Does

  • Classification: Automatically categorises feedback by type, sentiment and topic
  • Prioritisation: Scores feedback based on volume, revenue impact, urgency and other factors
  • Spec Generation: Creates build specifications from prioritised feedback
  • Pattern Recognition: Identifies trends and patterns in your feedback data
  • Behavioural Learning: Learns from your actions (such as which specs you ship or correct) to improve future prioritisation and spec quality
  • Competitive Signals: Identifies competitor mentions in your feedback to surface switching risks and feature gaps
  • AI Assistant: Answers your questions using a knowledge base and your workspace data

3.2 Privacy Protections

  • PII Stripping: Personal identifiers (names, emails) are automatically removed before data is sent to AI providers
  • No Model Training: Your data is NOT used to train third-party AI models. We use API services that do not train on customer data by default
  • Data Minimisation: Only the minimum necessary data is sent for processing

3.3 AI Providers

  • Anthropic Claude API — Primary spec generation and theme classification
  • OpenAI API — Text embeddings, feedback classification, and fallback spec generation

All providers confirm that API data is not used for model training under their commercial API terms.


4. Data Sharing and Sub-processors

CategoryProvidersPurpose
Cloud InfrastructureAWS, Supabase, Vercel, CloudFrontHosting, database, CDN
AI ProcessingAnthropic, OpenAIClassification, embeddings, spec generation (anonymised)
CachingUpstash (Redis)Performance caching
Payment ProcessingStripeSubscription and billing
EmailResendTransactional and status notifications
Error MonitoringSentryApplication reliability (PII redacted)
AnalyticsGoogle AnalyticsUsage patterns (with consent only)

We do not sell your personal data to third parties.


5. International Data Transfers

Circuit is operated from Australia. Your data may be transferred to and processed in countries outside your jurisdiction, including:

  • United States — Where our cloud infrastructure and AI providers are located
  • Australia — Where Circuit is headquartered

For transfers outside of the EEA or UK, we rely on Standard Contractual Clauses and Data Processing Agreements with all sub-processors.


6. Data Retention

Data TypeRetention PeriodAfter Cancellation
Account InformationDuration of accountDeleted after 30 days
Feedback DataDuration of accountDeleted after 30 days
Generated SpecsDuration of accountDeleted after 30 days
Behavioural Memory90 days, then compressed to quarterly summariesDeleted after 30 days
AI Assistant ConversationsDuration of accountDeleted after 30 days
Widget ScreenshotsDuration of accountDeleted after 30 days
Usage Analytics24 monthsAnonymised or deleted
Payment RecordsAs required by law (typically 7 years)Retained by Stripe per legal requirements
System Backups90 days rollingPurged within 90 days

6.1 Subscription Cancellation

When you cancel, your data is retained for 30 days to allow resubscription. After 30 days, all data is permanently deleted. Request immediate deletion at privacy@withcircuit.com or via Settings → Delete Workspace.


7. Data Security

  • Encryption in Transit: TLS 1.3
  • Encryption at Rest: AES-256; integration tokens encrypted with Fernet (AES-128-CBC)
  • Access Controls: All queries scoped to the authenticated user at application and database layers
  • Authentication: OAuth 2.0 with optional MFA/2FA
  • Infrastructure: AWS App Runner (SOC 2 compliant)
  • Monitoring: Sentry with PII automatically redacted

8. Your Rights

8.1 All Users

  • Access: Settings → Account → Export Data
  • Deletion: Settings → Account → Delete Workspace
  • Correction: Update inaccurate information
  • Withdraw Consent: Opt out of analytics cookies via cookie settings

8.2 EU/UK GDPR

Portability, restriction, objection to legitimate interest processing, and human review of automated decisions.

8.3 Australia (Privacy Act 1988)

Access, correction, complaints to the OAIC, and information about automated decision-making.

8.4 California (CCPA/CPRA)

Know, delete, opt-out (we do not sell data), and non-discrimination.

Contact privacy@withcircuit.com — we respond within 30 days.


9. Cookies and Tracking

9.1 Essential (Always Active)

Authentication, security, user preferences.

9.2 Analytics (With Consent)

Google Analytics — usage patterns, feature adoption. Sessions linked across withcircuit.com and app.withcircuit.com.


10. Data Breach Notification

We will notify the relevant supervisory authority within 72 hours and affected individuals without undue delay if there is high risk. Australian users: OAIC notified per the Notifiable Data Breaches scheme.


11. Children's Privacy

Circuit is a B2B service not intended for under-18s. Contact privacy@withcircuit.com to report any such data.


12. Changes to This Policy

Material changes notified by updated "Last Updated" date, email, and in-app notification.


13. Contact Us

Email: privacy@withcircuit.com

Address: Circuit, Sydney, NSW, Australia

Website: https://withcircuit.com

Supervisory authorities:

  • Australia: OAIC — oaic.gov.au
  • EU: Your local Data Protection Authority
  • UK: ICO — ico.org.uk

14. Data Processing Agreement

Enterprise customers requiring a DPA for GDPR compliance: contact privacy@withcircuit.com.

Product

  • How it works
  • Pricing
  • Integrations
  • Changelog

Resources

  • Blog
  • How to prioritise a backlog without a meeting
  • What good product specs look like now
  • The bottleneck moved
  • How to turn feedback into build-ready specs
  • What is autonomous product intelligence?
  • Docs
  • Quick start guide
  • Working with priorities
  • Working with specs
  • Using with coding tools

Company

  • About
  • Security & 2FA
  • Privacy
  • Terms

Changelog

  • Feedback in
  • Smart priorities
  • Specs out
  • Share back
  • Instinct
  • Foundation
CircuitAutonomous product intelligence.
© 2026 Circuit