← OurCircuits

OurCircuits — Privacy Policy

Effective date: 4 August 2026 · Last updated: 4 August 2026


1. Who we are

Vladislav Miftakhov and Arash Kalhori, Nevada, USA, operate OurCircuits at ourcircuits.com. For privacy questions: vladislavmiftakhov@gmail.com.

For individual accounts, we are the data controller. For institutional accounts, the licensed school or organisation is the controller of its students' data and we act as its processor under the licence agreement — see §10.

2. At a glance

This policy describes what we collect, why, who we share it with, how long we keep it, and what you can do about it. The detail is in the sections below; nothing here replaces them.

Two points that determine most of what follows: simulation runs in your browser, so a circuit you do not save is not transmitted to us except as described for error reporting in §3b; and we do not run advertising, so nothing here is collected for advertising or profiling purposes.

3. What we collect

3a. Things you give us

DataWhenWhy
Email addresssignupauthentication, essential service email
Passwordsignupauthentication — stored only as a hash by our authentication provider; we never see it in plain text
Google / GitHub identifier and emailif you sign in with thoseauthentication
Year of birthsignupto confirm you meet the minimum age of 16 and to apply age-appropriate settings if you are 16 or 17. We ask for the year only, never your full date of birth, and we never display it.
Username, profile picture, bioyou chooseyour public profile
Occupation, experience, contact email, social linksoptional, you chooseshown on your profile if you add them. Your contact email is separate from your login email and is never shown to people who are not signed in. Social links are checked for format only — we do not verify that you own an account you link to.
Circuits you save, and their titles and descriptionswhen you saveto store and, if you choose, publish your work
Comments, likes, favorites, follows, group memberships, ratingswhen you use themto operate the social features
Direct messageswhen you send themto deliver them to the recipient
Reports you filewhen you reportsafety and moderation
Institutional roster informationfrom your schoolto operate an education licence
Billing detailsif you subscribehandled by our payment processor — we never receive or store your card number

3b. Things collected automatically

DataSourceNotes
IP address, browser/device type, pages requested, timestampsour hosting provider's server logsstandard hosting operation; operational logs retained up to 7 days, deployment records up to 90 days
Error and crash reportsin-product error reportingReports are stored only in your own browser (a small rolling log of the most recent entries, with the page address removed). They are never transmitted to us or anyone else unless you choose to copy them into a support message. Cleared when you clear browser storage
Account activity needed for securityour systemse.g. login events, rate-limit counters

We do not use third-party advertising or analytics trackers, and the Service makes no third-party network requests. Our hosting provider gives us first-party, cookieless analytics derived from its own server logs (approximately a 30-day window); it involves no cross-site tracking.

3c. Stored in your browser, not sent to us

Your theme choice (oc_theme), editor colour preferences (oc_editor_prefs), circuits you save locally without an account, and a flag recording that you have seen the intro animation. These live in your browser's local storage. They are functional, not tracking — which is why the Service does not show you a cookie-consent banner. Clearing your browser storage removes them, including any circuits saved only locally.

A note on share links. When you share a circuit by link, the circuit is encoded in the part of the URL after the #. Browsers do not send that part in ordinary page requests, so it does not reach our server logs. Our in-product error reporting runs inside your browser and can see the full address — see §3b. Anyone you give the link to can open the circuit.

4. Why we use it, and our lawful bases (EEA/UK)

PurposeDataLawful basis
Create and operate your account§3a identity fieldsperformance of a contract
Store, display, and share your circuitscontentperformance of a contract
Social features you choose to usegraph, comments, reactionsperformance of a contract
Deliver direct messagesmessagesperformance of a contract
Age-appropriate protections and legal age complianceyear of birthlegal obligation; legitimate interests in child safety
Safety, moderation, anti-abuse, anti-spamreports, blocks, logs, admin recordslegitimate interests (protecting users, especially minors) and legal obligation
Security, debugging, keeping the Service workingerror reports, logslegitimate interests
Essential service email (verification, password reset, security)email addressperformance of a contract
Notification emails you can turn offemail address, event metadatalegitimate interests, with a working unsubscribe
Billingbilling referenceperformance of a contract
Developing and improving features, including machine-learning featurescircuits you publish publicly only — never private circuits, messages, or institutional/student contentlegitimate interests, with an opt-out in your settings; off by default for users under 18

We do not rely on consent for core account processing, and we do not process your data for advertising or profiling.

5. Who we share it with

We do not sell your personal information. We share it only with service providers who process it on our behalf, under contract:

ProviderWhat it doesWhat it handles
Supabasedatabase, authentication, file storageaccount, profile, content, social graph, messages
Netlifywebsite hosting and deliveryrequest logs
Google / GitHuboptional sign-inyour identifier and email, if you use them
Supabase (built-in email service)verification, password reset, notificationsyour email address

We may also disclose information where legally required, to respond to valid legal process, to protect someone's safety, or in connection with a merger or acquisition (in which case we will tell you).

Child-safety reports may be disclosed to law enforcement or the appropriate national reporting body, and we will do so without notice to the reported account where notice would risk harm or interfere with an investigation.

6. Where your data is stored

Our database and file storage are hosted in the United States. If you are in the EEA or the UK, your personal information is transferred to the United States and processed there.

For those transfers we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum), together with our providers' own transfer frameworks.

You may request a copy of the safeguards in place at vladislavmiftakhov@gmail.com.

7. How long we keep it

DataRetention
Account and profilewhile your account exists
Circuitswhile your account exists, then per §8
Messageswhile your account exists. If you delete your account, messages you sent remain visible to the people you sent them to — a conversation is a shared record, and removing one side of it would erase the recipient's own history. Your name is replaced with a removed-account marker.
Reports and moderation records2 years from resolution, kept even if the account is deleted — a report is a safety record, and deleting it on request would defeat its purpose
Administrative action records2 years
Child-safety reports and related contentpreserved as required by law, at minimum for the period the law specifies after a report, and longer if law enforcement asks
Institutional consent recordsfor the licence term and any period required by law
Server logsup to 7 days (operational); deployment records up to 90 days
Error reportsstored only on your device; never transmitted; cleared with browser storage
Backupsdeletion is not instant in backups; residual copies are removed within approximately 7 days

8. Deleting your account

You can delete your account at any time. When you do:

Export your work before you delete it — circuit export is available in-product at any time.

9. Your rights

Depending on where you live, you may have the right to access, correct, delete, restrict, or object to our use of your personal information, to receive a portable copy, and to withdraw consent where consent is the basis. Exercise any of these at vladislavmiftakhov@gmail.com; we will respond within the time the law allows. We will not treat you worse for exercising a right.

If you are in the EEA or UK you may complain to your data protection supervisory authority. If you are in California, you have rights under the CCPA/CPRA including access, deletion, correction, and portability; we do not sell or share personal information for cross-context behavioural advertising, and we do not use sensitive personal information for inferring characteristics.

10. Young people

11. Security

Authentication is handled by a specialist provider; passwords are stored only as hashes. Access to user data is restricted by database-level access rules that are reviewed adversarially before release, and administrative actions are logged. No system is perfectly secure. If a breach affects your personal information we will notify you and the relevant regulator where the law requires it.

12. Changes to this policy

We will post updates here and change the "last updated" date. For material changes we will notify you in-product, by email, or both, and keep the prior version available.

13. Contact

PurposeAddress
Abuse, content reports, and child safetyarashkalhori25@gmail.com (Arash Kalhori, moderator)
Privacy, data rights, and general supportvladislavmiftakhov@gmail.com (Vladislav Miftakhov)

Postal: Vladislav Miftakhov and Arash Kalhori, Nevada, USA.