Legal
Privacy Policy
Last updated August 4, 2026
This Privacy Policy explains how heypcb ("heypcb," "we," "us," or "our") collects, uses, shares, and protects information when you use heypcb.ai and related services (the "Service"). By using the Service, you agree to this policy. If you do not agree, please do not use the Service.
1. Who we are
heypcb is an AI-assisted PCB design product that works with real KiCad project files. The Service is operated at heypcb.ai. For privacy questions, contact us at privacy@heypcb.ai.
2. Information we collect
Account information
When you sign in, we may collect identifiers associated with your account, such as:
- Email address (magic link or OAuth profile)
- Name, username, and avatar if provided by Google, GitHub, or another identity provider you choose
- Authentication tokens and session identifiers
We use third-party authentication providers (including Google and GitHub) and an auth backend (currently Supabase). Those providers process identity data under their own policies when you authorize access.
Project and design data
To provide the editor and agent, we process design content you create or upload, including prompts, chat messages, schematic and PCB project files, exports (such as Gerbers), learning annotations, and related metadata (project names, timestamps, revision history).
Usage and technical data
We may collect:
- Product usage events (features used, model tier selections, errors)
- Device and log data (IP address, browser type, approximate location derived from IP, referrers, timestamps)
- Local preferences stored in your browser (for example local-mode flags and default model settings)
Payments
If paid plans are enabled, billing details are processed by our payment processor. We do not store full payment card numbers on our servers.
3. How we use information
We use information to:
- Create and secure your account, and keep you signed in
- Run the Service, including the AI agent, board tools, DRC, routing, and exports
- Send service messages (sign-in links, security notices, material product updates)
- Improve reliability, safety, and product quality
- Enforce our Terms of Service and prevent abuse
- Comply with law and respond to lawful requests
We do not sell your personal information. We do not use your project files to train public foundation models. To improve reliability and product quality, we may store a redacted technical copy of Inky turns and verification results for up to one year. Raw attachments and project files are not copied into that learning store. From that store we distil short, generic engineering lessons — and those lessons are shared across accounts: once a lesson has been confirmed by successful builds on at least two different accounts and two different projects, it may be quoted as guidance in another customer’s Inky session. Only that one generic sentence is shared, never your design, and a lesson is refused before it is stored if it names your project, a part designator on your board, or one of your board’s net names. Privacy questions and deletion requests can go to privacy@heypcb.ai.
4. AI providers and processors
Prompts, relevant board context, and tool results may be sent to language-model providers you or we configure (for example through DigitalOcean or other model gateways) so the agent can design and edit boards. Those providers process content only to fulfill your requests and operate their infrastructure, subject to their terms and privacy policies.
We also use infrastructure and service providers for hosting, authentication, storage, analytics, and error monitoring. They may process data only on our instructions and as needed to provide their services.
Product analytics runs on PostHog, keyed on your account’s opaque user id. It records which steps of the product you reach — sign-in, creating a board, running a build turn, checking a design you upload, starting checkout — and never your email or name, your prompts or chat text, tool inputs or outputs, board or schematic content, part numbers, net names, or file contents. It also records the steps you arestopped at: when your plan or free allowance means we decline to start a board or run an Inky message, we record that it was declined, the short machine-readable reason (for example that a plan is needed, or that the free trial is used up), your plan, and the figures the decision was made against — how many boards you own, the board limit, and what share of your free trial has been used. The sentence you are shown is not recorded, and neither is anything about the board you asked for: no name, no id, no description. The free trial is charged from what a message actually costs to run, so a message that runs and then fails is still counted; what we record is that share as a percentage, never a balance or an amount of money. Page addresses are recorded without their query strings, so one-time values that travel in a link — a sign-in code, a checkout session id — are not sent. When something in the app breaks, the failure itself is recorded so it can be found and fixed: the error message and the code location it came from — with query strings stripped from any web address they mention — plus, for each request to the design engine, which kind of operation it was, whether it succeeded, and how long it took. When heypcb itself declines a request before it reaches the engine, it records that it did so and why — view-only access, a plan limit, or a malformed address — together with which plan you were on. Inside the board editor it records which of the four surfaces — schematic, PCB, 3D, product — you were on and for how long, and which named editing command you ran, from which menu, palette or toolbar, and on which surface. Those names are fixed identifiers from the app’s own command list; the wording you see on the button is not sent, because some of it is built from your own work. What you had selected, what a command changed, and every part of the board itself — designators, net names, part numbers, geometry — are never recorded. The editor counts one more thing about itself: when the design engine answers an edit you have just made with something different, so the canvas changes under you, it records that it happened, on which canvas, to how many items and of what sort — a wire, a junction, a note. Never which wire, which net, or where. It also records how the expensive operations ended, in more detail than whether they worked: running verification, the design-rule check or the electrical-rule check, auto-routing, checking whether a board can be ordered, exporting the manufacturing files, and generating the 3D view each record which of five endings they reached — finished, finished with something left unmeasured, declined before anything ran, timed out, or failed — together with how long it took and the counts involved. For verification, the names of any checks that did not run are recorded, so a green result that measured nothing is visible as one; for the order gate and a blocked export, the short fixed identifiers of the checks that blocked it. The findings themselves are never recorded — not a violation’s message, not the nets or designators it names, and not the name of the file you download. Before an account exists, it records that an idea was submitted from the home page and whether there were any words in it — never the words — and that a sign-in was started, by which of the four doors (a provider, an emailed link, or a password) and whether a destination was waiting, never your address and never the destination itself. When a plan wall is shown, it records the short machine-readable reason and which screen showed it, once per reason per screen. After a subscription exists: a change of plan records the plan moved from, the plan moved to, the billing interval, and whether that was a move up, a move down or a switch of interval; a cancellation records the plan that ended; and switching the extra-usage limit records that it moved and in which direction. No amount is recorded on any of those — the direction is worked out by comparing plan names, never prices. It also records how you judgeInky’s work, because that is how we tell whether it is getting better or worse: after a build turn that changed your board, the letter grade and score our own checker gives the board, and the fixed names of the checks that failed — never the sentence a check writes about them, which can quote your designators and net names. When you keep or undo a set of agent edits, we record which you chose and how long the prompt was up; when you undo or redo, we record how many steps it moved and in which direction, which control you used and roughly how recently the agent had touched the board. When you rate an Inkyanswer with a thumb, and the rating is stored, we record whether it was up or down — never the note you may write with it, and never which message it was about. Screen contents, prompts, and design data are never part of these reports. The one money-shaped value analytics carries is the dollar size of a completed credit purchase; card details, invoices, and payment-processor identifiers stay with our payment processor. Session replay — a recording of what a page looked like as you used it — is off by default, and where it is switched on it runs only on the marketing, sign-in and dashboard pages, never on a board or editor screen, with every field you type in and all on-screen text masked and every image, canvas and drawing blocked — including the board previews on your dashboard, so the artwork of your design is never part of a recording. A replay shows layout and clicks rather than your content or your design. Analytics uses no cookies, honours your browser’s Do-Not-Track setting, and does not autocapture clicks or on-screen text. Analytics requests are proxied through heypcb.ai. Local-mode identities are never identified. Product analytics is separate from the learning store described in section 3 and is not governed by it.
5. Local mode
The Service may offer a local or offline-oriented mode where cloud account history is limited or unavailable. Local preferences and some session state may still live in your browser. Cloud features such as synced history and OAuth accounts require an online account.
6. Cookies and similar technologies
We use cookies and local storage for authentication and preferences. You can control cookies through your browser settings; disabling them may break sign-in or other features. Product analytics sets no cookies — PostHog keeps an anonymous id in local storage only, and honours Do-Not-Track.
7. How we share information
We share information only as needed:
- With service providers who help us run heypcb (auth, hosting, AI, payments)
- When you choose to export, download, or share project files yourself
- If required by law, regulation, legal process, or to protect rights, safety, and integrity of the Service and users
- In connection with a merger, acquisition, financing, or sale of assets, with notice where required
8. Data retention
We retain account and project data for as long as your account is active and as needed to provide the Service. We may retain limited logs and backups for security, fraud prevention, and legal compliance for a reasonable period after deletion. You may request account or project deletion by emailing privacy@heypcb.ai.
9. Security
We use industry-standard safeguards appropriate to the nature of the data we process. No method of transmission or storage is fully secure; you use the Service at your own risk and should keep exports of designs that matter to you.
10. International transfers
We may process information in the United States and other countries where we or our providers operate. Those locations may have different data-protection laws than your home country.
11. Your rights and choices
Depending on where you live, you may have rights to access, correct, delete, or export personal information, or to object to or restrict certain processing. To exercise these rights, contact privacy@heypcb.ai. You may also revoke OAuth access from your Google or GitHub account settings.
If you are in the EEA, UK, or similar jurisdictions, our legal bases include performing our contract with you, legitimate interests in operating and improving the Service, and consent where required (for example certain cookies or marketing).
12. Children
The Service is not directed to children under 13 (or the minimum age required in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will take appropriate steps.
13. Changes
We may update this Privacy Policy from time to time. We will post the updated version on this page and revise the "Last updated" date. Material changes may also be communicated in-product or by email when appropriate. Continued use of the Service after changes become effective constitutes acceptance of the updated policy.
14. Contact
Questions about this Privacy Policy: privacy@heypcb.ai
Website: https://heypcb.ai
Related: Terms of Service