1. Who we are
Wirescript Studio ("we", "us") provides a browser-based circuit design environment with an AI assistant. For data protection purposes we are the data controller for the information described below. You can reach us any time at hi@wirescriptstudio.com.
2. What we collect
2.1 Account data
- Email address and, if you set one, a display name and avatar.
- Subscription state: your plan, its status and period end, plus the Polar customer and subscription identifiers. We never see or store your card details — those stay with Polar.
2.2 Content you create
- Projects, circuits, the schematic document, and the Wirescript DSL they produce.
- Revision snapshots and the most recent simulation result of each circuit.
- Chat sessions and messages exchanged with the AI assistant.
This content is yours. We store it so the product works: without it your circuits would not survive a page reload.
2.3 Product analytics
Usage events such as page views, editor sessions, saves, simulation runs and AI runs. Each event carries the event name, a timestamp, the path, a per-visit random identifier and a small set of scalar properties. Circuit statistics — how many components, nets and wires a schematic has, whether a simulation succeeded, how long it took — are collected here as well. No schematic or chat content is included in this category.
2.4 AI interaction data
For each turn of an AI run we record the model used, the mode (Ask/Agent, Editor/Debugger), how many messages were in the conversation, how many tools the assistant called, how long the turn took and whether it succeeded. If you leave "Improve the AI with my content" switched on, we additionally store the text of your prompt, the assistant's reply and the resulting circuit DSL. We use this to evaluate and improve the assistant — for example to find the requests where it produces circuits that do not compile.
2.5 Error reports
When something breaks — in your browser, on our servers or in the database — we record the error type, message, stack trace, the page you were on, your browser's user agent and a reference identifier. The reference is the code shown on the error screen; quoting it lets us find the exact record. Error reports contain no schematic and no chat content.
2.6 Technical data
Standard server logs, rate-limiting counters keyed to your account or IP address, and security audit entries for deletions. Free-text fields are passed through a masking filter before storage: email addresses, session tokens, API keys and the final octet of IP addresses are redacted automatically.
3. Why we collect it, and on what legal basis
| Category | Purpose | Legal basis (GDPR Art. 6) |
|---|---|---|
| Account & content | Providing the service you signed up for | Performance of a contract |
| Billing | Taking payment, applying plan limits | Contract & legal obligation |
| Error reports | Keeping the service running and diagnosing failures | Legitimate interest |
| Product analytics | Understanding which features are used and where they fail | Legitimate interest — you can opt out |
| AI interaction content | Evaluating and improving the AI assistant and circuit engine | Legitimate interest — you can opt out |
4. Your choices
- Settings → Data & Privacy in the editor has two independent switches: Product analytics and Improve the AI with my content. Turning either off takes effect immediately for all future collection.
- Declining the cookie banner stops usage events being sent from your browser altogether.
- Error reports cannot be switched off: they carry no content of yours and we cannot operate the service without them.
Switching collection off stops future collection; it does not erase what was already stored. Ask us and we will delete it — see section 7.
5. Who else sees your data
We use a small number of processors, each for a single job:
- Supabase — database, authentication and file storage.
- DeepSeek — runs the AI assistant (shown in the app as WireAI and WireAI Pro). Your prompt, the relevant circuit context and the assistant's tool definitions are sent to DeepSeek for the duration of the request. DeepSeek processes and stores this data on servers in the People's Republic of China, which is outside the EEA and the UK; sending a request to the assistant is a transfer to that country.
- Polar — subscriptions and payments. Polar acts as the merchant of record, so it also issues the invoice and handles sales tax.
- Upstash (Redis) — rate limiting and quota counters. Stores identifiers and counts, not content.
We do not sell your data, and we do not share it with advertisers. We disclose data to authorities only where the law requires it.
6. How long we keep it
- Account and content — until you delete the item or close your account.
- Error reports — 180 days.
- Product analytics and circuit statistics — 400 days.
- AI interaction records — 730 days, so that a model change can be compared against the behaviour of the previous year.
- Billing records — as long as tax and accounting law requires.
7. Your rights
Under the GDPR, the Turkish KVKK and the CCPA you may request access to your data, its correction, its deletion, a portable copy, or object to processing based on legitimate interest. Write to hi@wirescriptstudio.com and we will respond within 30 days. You may also complain to your local supervisory authority.
8. Security
Every row in the database is protected by row-level security, so one account cannot read another's data. Traffic is encrypted in transit; a strict Content Security Policy, origin checks and rate limits sit in front of the application. No system is perfect — if you find a vulnerability, please report it to hi@wirescriptstudio.com before disclosing it.
9. Children
The service is not directed at children under 16. If you believe a child has given us personal data, contact us and we will delete it.
10. Changes
If we change what we collect or why, we will update this page and change the effective date above. Material changes will be announced in the product before they take effect.