pcbx.ai · privacy
Privacy Policy
This policy describes how pcbx (“we”) handles personal data on https://pcbx.ai, the rscircuit Team Platform. It covers GitHub sign-in today and Google sign-in when that provider is enabled. It is written for users and for Google OAuth verification. It is not a substitute for legal advice.
1. Who we are
The service is pcbx, operated at https://pcbx.ai. It is a team workbench for hardware collaboration: projects, reviews, jobs, and GitHub-connected design ingest. Contact: privacy@pcbx.ai.
2. Information we collect
Account identity from the identity provider you choose. For GitHub OAuth this is your GitHub user id, name, email, and avatar. For Google OAuth (when enabled) this is the name, email address, language, and profile image associated with the Google account you authorize — we request the openid, email, and profile scopes only. We do not request Gmail, Drive, Calendar, or other sensitive Google scopes.
Session data: an HttpOnly session cookie set after sign-in (Secure on HTTPS, SameSite=Lax). Cloudflare may log IP address, user-agent, and request metadata as part of operating the Worker.
Workspace data you create or upload: organization and project records, comments, job status, and design artifacts (for example KiCad zipballs stored in object storage). If you bind a GitHub repository, we store the owner/name pointer and use your GitHub OAuth access token solely to fetch that repository as a zipball for ingest. We do not display that token in the browser or in API responses.
Optional product telemetry: Think/agent prompts and tool traces if you use the in-product agent. We do not run third-party advertising pixels.
3. Google user data (Limited Use)
pcbx's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Google account data is used only to authenticate you, create or link your pcbx account, show your name/email/avatar in the workbench, and keep you signed in. We do not sell Google user data. We do not use it for advertising. We do not allow human access except with your permission, for security/legal reasons, or as aggregated non-identifying data. You can disconnect Google at any time by signing out and requesting deletion at privacy@pcbx.ai.
4. GitHub user data
GitHub identity is used to sign you in. The repo scope is used only when you bind a repository and run ingest: the server fetches a zipball of that repo with your token, stores the archive as a project artifact, and enqueues a hardware job. We do not use your GitHub token to modify repositories, post as you, or access unrelated orgs.
5. How we use information
To operate the workbench: authentication, authorization, project collaboration, ingest jobs, and support. To secure the service (abuse, debugging, incident response). To contact you about the account if needed. We do not sell personal data.
6. Sharing
Processors that host the service: Cloudflare (Workers, D1, R2, DNS, logs). Identity providers: GitHub and, when enabled, Google — only for the OAuth flow you start. We do not share your design files with those identity providers except as required to complete OAuth. We disclose data if required by law or to protect the service and other users.
7. Cookies
Essential cookies only: the Better Auth session cookie. Cloudflare may set cookies required to deliver the site. We do not use advertising or cross-site tracking cookies. You can block cookies in your browser; sign-in will then fail.
8. Retention
Account and session records last until you delete the account or the session expires. Bound GitHub tokens are stored until you unbind or we delete the account. Project artifacts remain until you delete the project or we remove the workspace. Cloudflare logs follow Cloudflare’s retention. You can ask us to delete your account and associated personal data at privacy@pcbx.ai.
9. Security
Transport is HTTPS. Session cookies are HttpOnly. OAuth client secrets and session material are not returned to the SPA. See https://pcbx.ai/security. No method is perfect; report issues to security@pcbx.ai.
10. Your rights
You may request access, correction, or deletion of personal data we hold, and you may withdraw OAuth access in your GitHub or Google account settings. Where applicable law gives you further rights (for example access or portability), email privacy@pcbx.ai. We may need to verify the request.
11. International processing
The workbench runs on Cloudflare’s network. Data may be processed in the regions Cloudflare uses to serve your request. Do not upload data you are not allowed to process on that infrastructure (including ITAR/export-controlled design files if they are not permitted).
12. Children
The service is not directed at children under 13, and we do not knowingly collect their data.
13. Changes
We will update this page and the “Last updated” date when the policy changes. Continued use after a change means you accept the updated policy for subsequent use.
14. Contact
privacy@pcbx.ai — privacy requests. security@pcbx.ai — vulnerabilities. Operator: pcbx, https://pcbx.ai.
中文摘要
1. 我们是谁
本服务为 pcbx,站点 https://pcbx.ai,即 rscircuit Team Platform:硬件协作工作台(项目、评审、任务、GitHub 仓库 ingest)。联系:privacy@pcbx.ai。
2. 我们收集什么
身份:GitHub 登录时的用户 id、姓名、邮箱、头像;启用 Google 登录时仅申请 openid / email / profile,使用你授权的姓名、邮箱、头像。不申请 Gmail、Drive 等敏感范围。
会话:登录后的 HttpOnly Cookie(HTTPS 下 Secure,SameSite=Lax)。Cloudflare 可能记录 IP、User-Agent 等访问日志。
你创建或上传的工作区数据:组织/项目、评论、任务状态、设计产物(如 KiCad zip,存于对象存储)。绑定 GitHub 仓库后,我们保存 owner/name,并用你的 GitHub OAuth access token 仅用于拉取该仓库 zipball 做 ingest。Token 不会出现在浏览器或对外 API 响应中。
3. Google 用户数据(Limited Use)
pcbx 对从 Google API 获得的信息的使用与传输,遵守 Google API Services User Data Policy(含 Limited Use)。
Google 账号数据仅用于登录、创建/关联 pcbx 账号、在工作台显示姓名/邮箱/头像、维持登录。不出售、不做广告。可随时在 Google 账号中撤销授权,并邮件 privacy@pcbx.ai 请求删除。
4. 如何使用与共享
用于提供工作台、鉴权、ingest 任务与安全。不向广告商出售个人数据。处理方包括 Cloudflare;身份提供方为 GitHub 与(启用时)Google。
5. 联系
隐私:privacy@pcbx.ai。安全:security@pcbx.ai。