Privacy Policy
Last updated: July 27, 2026
This Policy describes what data Torit collects, why we collect it, how it is stored and shared, and the choices you have.
1. Overview
This Privacy Policy explains how Torit (“Torit,” “we,” “us,” or “our”) collects, uses, stores, shares, and protects personal data when you use our website, studio, APIs, and related services (the “Service”).
We built Torit to help people design hardware projects. We collect the data needed to run accounts, store projects, process payments, improve the product, and provide AI-assisted generation — and we aim not to collect more than that.
If you have questions, contact support@torit.sh.
2. Who is responsible
Torit is the controller of personal data processed in connection with the Service, unless otherwise stated for a specific processing activity.
We operate from Dhaka, Bangladesh, and may process data using infrastructure and vendors in other countries as described below.
3. Information we collect
We collect the following categories of information, depending on how you use the Service:
- Account data: email address, display name, username, authentication identifiers (for example Firebase UID), and profile settings
- Authentication data: session cookies / tokens and related sign-in metadata from our auth providers
- Project content: prompts, chat messages, pipeline graphs, firmware, schematics, pin maps, BOMs, CAD/assembly artifacts, comments, attachments you upload, and similar design data
- Billing data: subscription plan/status, Polar customer IDs, order/credit purchase records, and related billing metadata (card details are handled by Polar, not stored by Torit as full payment card numbers)
- Usage and product analytics: feature usage events, AI credit/token counters, performance metrics, and approximate technical metadata (device/browser type, pages viewed) when analytics is enabled
- Support communications: emails and messages you send to support@torit.sh
- Technical logs: IP address, request metadata, error reports, and security logs needed to operate and protect the Service
4. How we collect information
We collect information directly from you (account setup, prompts, project edits, support requests), automatically when you use the Service (logs, cookies/local storage for preferences and sessions, analytics if consented), and from processors that help us run the Service (for example Polar for payments, Firebase for authentication).
5. How we use information
We use personal data to:
- Provide, maintain, and secure the Service
- Authenticate users and manage sessions
- Store and sync your projects across sessions and devices
- Run AI inference and automated tooling on prompts and project context you submit
- Enforce plan limits, credits, and subscription entitlements
- Process payments, invoices, refunds, and tax-related billing records through Polar
- Respond to support requests and communicate about the Service
- Monitor reliability, debug issues, prevent abuse, and improve product quality
- Comply with legal obligations and enforce our Terms of Service
6. AI processing
When you use AI features, prompts, relevant project context, and related instructions may be sent to model providers to generate responses and artifacts. Those providers process the content as our processors (or independent controllers where required by their terms) for the purpose of returning inference results.
Do not submit secrets, passwords, private keys, regulated personal data, or confidential third-party information into prompts unless you are comfortable with that content being processed by our AI providers under their terms and this Policy.
We may use aggregated or de-identified product signals to improve the Service. We do not sell your personal data.
7. Legal bases (where applicable)
If you are in a jurisdiction that requires a legal basis for processing (for example the EEA/UK), we typically rely on: performance of a contract (providing the Service you requested); legitimate interests (securing and improving the Service, preventing abuse); consent (non-essential analytics/cookies where required); and legal obligation (tax, accounting, or lawful requests).
10. Data retention
We retain account and project data for as long as your account is active and as needed to provide the Service. After account deletion or an inactivity period, we delete or anonymize personal data within a reasonable time, except where we must retain records for legal, security, billing, or dispute-resolution purposes.
Backups and logs may persist for a limited period after deletion and are then purged on a rolling schedule.
Billing records may be retained for tax and accounting obligations.
11. Security
We use administrative, technical, and organizational measures designed to protect personal data, including transport encryption, access controls, rate limiting, and least-privilege operational practices.
No method of transmission or storage is perfectly secure. You are responsible for protecting your account credentials and for not uploading highly sensitive secrets into project content or prompts.
12. International transfers
Because we use global cloud and AI providers, your data may be processed in countries other than your own, including the United States and other locations where our vendors operate.
Where required, we rely on appropriate transfer mechanisms (such as contractual protections with vendors) to safeguard personal data.
13. Your rights and choices
Depending on your location, you may have rights to access, correct, delete, export, or restrict processing of your personal data, and to object to certain processing or withdraw consent.
You can decline analytics cookies via the consent banner. You can update some profile information in-product. For account deletion, data export, or other privacy requests, email support@torit.sh with the subject “Privacy request.”
We may need to verify your identity before fulfilling a request. We will respond within the time required by applicable law.
If you are in the EEA/UK, you may also lodge a complaint with your local supervisory authority. If you are a California resident, you may have rights under the CCPA/CPRA; we do not sell personal information.
14. Children
The Service is not directed to children under 13 (or the minimum age required in your jurisdiction). We do not knowingly collect personal data from children below that age. If you believe a child has provided us personal data, contact support@torit.sh and we will take appropriate steps to delete it.
15. Changes to this Policy
We may update this Privacy Policy from time to time. We will post the updated Policy on this page and revise the “Last updated” date. For material changes, we may also provide additional notice (for example by email or in-product).
Continued use of the Service after an update becomes effective means you acknowledge the updated Policy.
16. Contact
Privacy questions or requests: support@torit.sh.
Also see our Terms of Service for rules governing use of Torit.
See also our Terms of Service.