CIRCUIT BLASTER LLC — PRIVACY POLICY Effective date: September 11, 2025 Legal entity: Circuit Blaster LLC (Texas, USA) Contact email: circuitblaster@gmail.com Mailing address: PO Box 2008, Waskom, TX 75692 1) SCOPE This Privacy Policy covers: - The Circuit Blaster desktop application - The circuitblaster.com website (including landing pages) - In‑app and email support channels Circuit Blaster primarily serves users in the United States. We do not target the EU/UK or other non‑U.S. markets. 2) INFORMATION WE COLLECT We collect only what’s needed to run accounts and subscriptions. A. Account & Profile - Email, username, Supabase user_id - Optional avatar (image stored in Supabase Storage) B. Billing & Subscription - Stripe customer ID, subscription ID, price/plan, status, period timestamps - We do not receive or store card numbers C. Website & Hosting Logs - IP address, user agent, timestamp in access logs (for security/operations) - Hosting/CDN logs are kept about 30 days D. Support - Emails sent to circuitblaster@gmail.com (and any attachments/screenshots) E. What We Do Not Collect - No project files/PDFs from the app—your work stays on your device - No analytics/pixels/ads (no GA, no Meta, no remarketing) - No formal telemetry or crash reporting tools - No third‑party data from resellers or marketplaces 3) HOW WE COLLECT - Directly from you (account creation, settings, support emails) - Supabase authentication (necessary cookies and sb-* localStorage for sessions) - Stripe webhooks (subscription events) - Hosting/CDN access logs 4) HOW WE USE INFORMATION - Authentication & account management (email, user_id; password handled by Supabase) - Subscriptions & billing (Stripe IDs, plan/status, event timestamps) - Security/fraud (access logs, CSRF protection) - Support (to respond to your messages) - Legal/records (billing history and event logs) We do not use profiling or automated decision‑making beyond checking your plan/role to enable Pro features. 5) COOKIES & LOCAL STORAGE - Only essential Supabase auth/session cookies and sb-* localStorage entries - No analytics, advertising, or cross‑site tracking cookies - “Do Not Track” signals are not supported 6) WHERE DATA LIVES & WHO PROCESSES IT (U.S.-BASED) - Supabase (Auth, Postgres, Storage): U.S. region; Row Level Security (RLS) enabled - Stripe (Payments): subscription/customer IDs and related metadata - Vercel (Website/CDN/Logs): U.S. data centers; ~30‑day access logs - Gmail (Email): support inbox/attachments These vendors act as our service providers/processors and handle data in the United States. We do not intentionally transfer data internationally. 7) SECURITY - TLS in transit; provider‑managed encryption at rest - Access to production systems is limited to the founder/authorized staff for support and billing - We minimize the data we hold 8) RETENTION & DELETION - Account & profile data: kept until you request deletion - Stripe events/billing records: retained as needed for accounting and legal obligations - Access logs: about 30 days (hosting defaults) - Support emails: retained as needed to handle your request - Backups (Supabase‑managed): approximately 7 days; deletions propagate per provider schedule To access, export, correct, or delete your data, email circuitblaster@gmail.com. We target a response within 30 days. 9) APP‑SPECIFIC NOTES - No cloud sync of project files; your plans/PDFs remain local on your device - The app requires internet for authentication; tokens/settings may cache locally; you may be logged out if offline - No auto‑updates; you download updates manually - No AI or cloud processing of your content 10) CALIFORNIA PRIVACY NOTICE (CCPA/CPRA) We do not “sell” or “share” personal information for cross‑context behavioral advertising. No “Do Not Sell/Share” link is required. Categories collected (as defined by CPRA): - Identifiers (email, username, Supabase user_id; Stripe customer/subscription IDs) - Internet/network activity (IP, user agent in access logs) - Commercial information (plan, status, billing events) Sensitive personal information: not collected California rights: access, correction, deletion, and use of an authorized agent. We verify requests (e.g., by confirming account email). We do not discriminate for exercising rights. Contact: circuitblaster@gmail.com. 11) CHILDREN Circuit Blaster is intended for users 13+ and is not directed to children. We do not knowingly collect data from children under 13. 12) LAW‑ENFORCEMENT & LEGAL REQUESTS We disclose user data only in response to a valid and lawful request. We will notify you before disclosure when permitted by law and when we have contact information for you. 13) CHANGES TO THIS POLICY We may update this Policy. We will revise the Effective date above and, for material changes, provide notice on the site and/or in‑app. 14) GOVERNING LAW Texas, USA. 15) CONTACT Email: circuitblaster@gmail.com Postal: PO Box 2008, Waskom, TX 75692 This Policy is intended as clear, practical notice for U.S. users and is not legal advice. If we expand to new regions or add analytics/telemetry, we will update this Policy accordingly.