Privacy policy
Last updated: September 25, 2026
This policy explains which personal data Circuito processes when you use Circuito, why, how long it is kept and what your rights are.
Who is responsible
Circuito is operated by Circuito ("the operator"), which is responsible for the personal data processed here.
For any question about your data, or to exercise your rights, contact the team you work with through your usual channel.
What data we process
There is no public sign-up: your login is created by the team for your company. We process:
- Account data the team creates for you: your name, email address, phone number, company and preferred language.
- Content you post: replies, new requests, status changes and requested edits to an issue, and the files you upload with them.
- Sign-in security data: a hash of your password (never the password itself), your authenticator-app secret (stored encrypted), hashed recovery codes and the public keys of your passkeys.
- Your settings: notification and digest preferences, the web-push subscriptions of the browsers where you turn push on, and which issues you have already read.
- Technical data: counters of sign-in and other attempts, keyed by email address or IP address, used only to block abuse and deleted after a day.
Cookies
Circuito only uses cookies that are strictly necessary: the session cookie that keeps you signed in, short-lived cookies during sign-in and security checks, and small cookies that remember your colour mode and sidebar layout. There are no analytics, tracking or advertising cookies and no third-party scripts.
Why we process it
- To provide the service: showing you the work done for your company, letting you reply and file requests, and keeping the team informed. This is necessary to perform the agreement between your company and the operator.
- To keep Circuito secure: protecting sign-in, second factors, preventing abuse and scanning uploads. This is the operator's legitimate interest and its obligation to protect personal data.
- To notify you by email or push, only as set in your preferences, which you can change on your Profile page at any time.
Where it is stored
Your data is stored in Circuito's own database. The team's internal work system also holds your account and what you post, so the team can read and act on it; it collects new posts from Circuito, and Circuito itself has no access to that system.
Every file you upload is checked for its type and scanned for viruses before it is stored. Files that fail the checks are refused.
Who can see it
- The Circuito team working on your projects.
- People from your own company who follow the same projects see the replies, requests and files posted there, and your company lead sees your login and the projects you follow. Other companies never see them.
- Service providers that host Circuito and deliver its emails, acting only on the operator's instructions.
Your data is never sold, used for advertising or shared for marketing.
How long we keep it
The current retention periods are:
- In-app notifications: deleted after 180 days.
- Processed profile and language change requests, and requests made by company leads: deleted 90 days after they are processed.
- Your company's activity log: entries are deleted after 730 days.
- Deactivated logins: kept until the team deletes them.
- Posts and files in shared spaces: kept until the space is deleted. The team can set a different period for an individual space; the space shows it when it applies.
- Invitations you send to other people: deleted 90 days after they are accepted, withdrawn or expire. Until then we keep the invited email address so the link works and you can see what you sent.
- Messages, requests and files you posted stay part of your company's work history for as long as the project data is kept.
When a login is deleted, what it contributed is anonymised rather than deleted: it is shown as "Former client", and the name, email address, phone number, password and sign-in security data are removed. This keeps the rest of your company's history intact. A login that never posted anything is deleted outright.
Your rights
- Access and portability: you can ask for a copy of your data. A company lead can also download a ZIP archive of the company's data from the Company page.
- Correction: update your name, email address, phone number and language on your Profile page, or ask the team.
- Erasure: ask your company lead or the operator to delete your login. See above for what happens to what you posted.
- Restriction and objection: you can ask to limit processing, or object to processing based on legitimate interest.
- Complaint: you can lodge a complaint with the data protection supervisory authority where you live or work.
To exercise any of these rights, use the contact details above.
Security
Passwords are hashed with argon2. A second factor (an authenticator app or a passkey) is available and your company can make it mandatory. All traffic is encrypted with TLS (HTTPS), and each person only sees the projects they have been given access to.
Changes to this policy
We may update this policy. The date at the top shows when it last changed; significant changes will be announced in Circuito or by email.