OurCircuits — Privacy Policy
Effective date: 4 August 2026 · Last updated: 4 August 2026
1. Who we are
Vladislav Miftakhov and Arash Kalhori, Nevada, USA, operate OurCircuits at ourcircuits.com. For privacy questions: vladislavmiftakhov@gmail.com.
For individual accounts, we are the data controller. For institutional accounts, the licensed school or organisation is the controller of its students' data and we act as its processor under the licence agreement — see §10.
2. At a glance
This policy describes what we collect, why, who we share it with, how long we keep it, and what you can do about it. The detail is in the sections below; nothing here replaces them.
Two points that determine most of what follows: simulation runs in your browser, so a circuit you do not save is not transmitted to us except as described for error reporting in §3b; and we do not run advertising, so nothing here is collected for advertising or profiling purposes.
3. What we collect
3a. Things you give us
| Data | When | Why |
|---|---|---|
| Email address | signup | authentication, essential service email |
| Password | signup | authentication — stored only as a hash by our authentication provider; we never see it in plain text |
| Google / GitHub identifier and email | if you sign in with those | authentication |
| Year of birth | signup | to confirm you meet the minimum age of 16 and to apply age-appropriate settings if you are 16 or 17. We ask for the year only, never your full date of birth, and we never display it. |
| Username, profile picture, bio | you choose | your public profile |
| Occupation, experience, contact email, social links | optional, you choose | shown on your profile if you add them. Your contact email is separate from your login email and is never shown to people who are not signed in. Social links are checked for format only — we do not verify that you own an account you link to. |
| Circuits you save, and their titles and descriptions | when you save | to store and, if you choose, publish your work |
| Comments, likes, favorites, follows, group memberships, ratings | when you use them | to operate the social features |
| Direct messages | when you send them | to deliver them to the recipient |
| Reports you file | when you report | safety and moderation |
| Institutional roster information | from your school | to operate an education licence |
| Billing details | if you subscribe | handled by our payment processor — we never receive or store your card number |
3b. Things collected automatically
| Data | Source | Notes |
|---|---|---|
| IP address, browser/device type, pages requested, timestamps | our hosting provider's server logs | standard hosting operation; operational logs retained up to 7 days, deployment records up to 90 days |
| Error and crash reports | in-product error reporting | Reports are stored only in your own browser (a small rolling log of the most recent entries, with the page address removed). They are never transmitted to us or anyone else unless you choose to copy them into a support message. Cleared when you clear browser storage |
| Account activity needed for security | our systems | e.g. login events, rate-limit counters |
We do not use third-party advertising or analytics trackers, and the Service makes no third-party network requests. Our hosting provider gives us first-party, cookieless analytics derived from its own server logs (approximately a 30-day window); it involves no cross-site tracking.
3c. Stored in your browser, not sent to us
Your theme choice (oc_theme), editor colour preferences (oc_editor_prefs), circuits you save locally without an account, and a flag recording that you have seen the intro animation. These live in your browser's local storage. They are functional, not tracking — which is why the Service does not show you a cookie-consent banner. Clearing your browser storage removes them, including any circuits saved only locally.
A note on share links. When you share a circuit by link, the circuit is encoded in the part of the URL after the #. Browsers do not send that part in ordinary page requests, so it does not reach our server logs. Our in-product error reporting runs inside your browser and can see the full address — see §3b. Anyone you give the link to can open the circuit.
4. Why we use it, and our lawful bases (EEA/UK)
| Purpose | Data | Lawful basis |
|---|---|---|
| Create and operate your account | §3a identity fields | performance of a contract |
| Store, display, and share your circuits | content | performance of a contract |
| Social features you choose to use | graph, comments, reactions | performance of a contract |
| Deliver direct messages | messages | performance of a contract |
| Age-appropriate protections and legal age compliance | year of birth | legal obligation; legitimate interests in child safety |
| Safety, moderation, anti-abuse, anti-spam | reports, blocks, logs, admin records | legitimate interests (protecting users, especially minors) and legal obligation |
| Security, debugging, keeping the Service working | error reports, logs | legitimate interests |
| Essential service email (verification, password reset, security) | email address | performance of a contract |
| Notification emails you can turn off | email address, event metadata | legitimate interests, with a working unsubscribe |
| Billing | billing reference | performance of a contract |
| Developing and improving features, including machine-learning features | circuits you publish publicly only — never private circuits, messages, or institutional/student content | legitimate interests, with an opt-out in your settings; off by default for users under 18 |
We do not rely on consent for core account processing, and we do not process your data for advertising or profiling.
5. Who we share it with
We do not sell your personal information. We share it only with service providers who process it on our behalf, under contract:
| Provider | What it does | What it handles |
|---|---|---|
| Supabase | database, authentication, file storage | account, profile, content, social graph, messages |
| Netlify | website hosting and delivery | request logs |
| Google / GitHub | optional sign-in | your identifier and email, if you use them |
| Supabase (built-in email service) | verification, password reset, notifications | your email address |
We may also disclose information where legally required, to respond to valid legal process, to protect someone's safety, or in connection with a merger or acquisition (in which case we will tell you).
Child-safety reports may be disclosed to law enforcement or the appropriate national reporting body, and we will do so without notice to the reported account where notice would risk harm or interfere with an investigation.
6. Where your data is stored
Our database and file storage are hosted in the United States. If you are in the EEA or the UK, your personal information is transferred to the United States and processed there.
For those transfers we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum), together with our providers' own transfer frameworks.
You may request a copy of the safeguards in place at vladislavmiftakhov@gmail.com.
7. How long we keep it
| Data | Retention |
|---|---|
| Account and profile | while your account exists |
| Circuits | while your account exists, then per §8 |
| Messages | while your account exists. If you delete your account, messages you sent remain visible to the people you sent them to — a conversation is a shared record, and removing one side of it would erase the recipient's own history. Your name is replaced with a removed-account marker. |
| Reports and moderation records | 2 years from resolution, kept even if the account is deleted — a report is a safety record, and deleting it on request would defeat its purpose |
| Administrative action records | 2 years |
| Child-safety reports and related content | preserved as required by law, at minimum for the period the law specifies after a report, and longer if law enforcement asks |
| Institutional consent records | for the licence term and any period required by law |
| Server logs | up to 7 days (operational); deployment records up to 90 days |
| Error reports | stored only on your device; never transmitted; cleared with browser storage |
| Backups | deletion is not instant in backups; residual copies are removed within approximately 7 days |
8. Deleting your account
You can delete your account at any time. When you do:
- Your circuits are deleted, except circuits you posted to a group, which remain so the group's shared work survives.
- Your comments become author-removed placeholders, so conversations stay readable.
- Messages you sent remain visible to the people you sent them to, attributed to a removed account. A conversation is a shared record; deleting your side would erase theirs.
- If other people cloned your circuits, the record that a clone came from a since-deleted account remains, without your name.
- If you own a group, you must transfer ownership first.
- Reports, moderation records, and institutional consent records are kept as described in §7.
- Residual copies persist in backups for a limited period (§7).
Export your work before you delete it — circuit export is available in-product at any time.
9. Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict, or object to our use of your personal information, to receive a portable copy, and to withdraw consent where consent is the basis. Exercise any of these at vladislavmiftakhov@gmail.com; we will respond within the time the law allows. We will not treat you worse for exercising a right.
If you are in the EEA or UK you may complain to your data protection supervisory authority. If you are in California, you have rights under the CCPA/CPRA including access, deletion, correction, and portability; we do not sell or share personal information for cross-context behavioural advertising, and we do not use sensitive personal information for inferring characteristics.
10. Young people
- Individual accounts require you to be at least 16, wherever you live.
- Anyone under 16 can use OurCircuits only through a licensed school or organisation, which provides the required consent and manages the account. Those accounts have messaging disabled, cannot post publicly, and are not publicly discoverable.
- Accounts for 16 and 17 year-olds start with protective settings: the profile is not shown to people who are not signed in, and public circuits are excluded from feature development and machine learning by default.
- We do not show "last active", "online now", or any other presence signal anywhere on the Service, for anyone, because it reveals routine.
- We do not profile young people, show them advertising, or nudge them to disclose more information.
- For institutional accounts the school is the controller; we process student data on its instructions and never for our own purposes. Our institutional agreements are based on the Student Data Privacy Consortium's National Data Privacy Agreement (NDPA).
- If you believe someone under 16 has an individual account, contact arashkalhori25@gmail.com and we will investigate and delete it.
11. Security
Authentication is handled by a specialist provider; passwords are stored only as hashes. Access to user data is restricted by database-level access rules that are reviewed adversarially before release, and administrative actions are logged. No system is perfectly secure. If a breach affects your personal information we will notify you and the relevant regulator where the law requires it.
12. Changes to this policy
We will post updates here and change the "last updated" date. For material changes we will notify you in-product, by email, or both, and keep the prior version available.
13. Contact
| Purpose | Address |
|---|---|
| Abuse, content reports, and child safety | arashkalhori25@gmail.com (Arash Kalhori, moderator) |
| Privacy, data rights, and general support | vladislavmiftakhov@gmail.com (Vladislav Miftakhov) |
Postal: Vladislav Miftakhov and Arash Kalhori, Nevada, USA.