Skip to main content
Back to home

Privacy Policy

Last updated: July 27, 2026

This Policy describes what data Torit collects, why we collect it, how it is stored and shared, and the choices you have.

1. Overview

This Privacy Policy explains how Torit (“Torit,” “we,” “us,” or “our”) collects, uses, stores, shares, and protects personal data when you use our website, studio, APIs, and related services (the “Service”).

We built Torit to help people design hardware projects. We collect the data needed to run accounts, store projects, process payments, improve the product, and provide AI-assisted generation — and we aim not to collect more than that.

If you have questions, contact support@torit.sh.

2. Who is responsible

Torit is the controller of personal data processed in connection with the Service, unless otherwise stated for a specific processing activity.

We operate from Dhaka, Bangladesh, and may process data using infrastructure and vendors in other countries as described below.

3. Information we collect

We collect the following categories of information, depending on how you use the Service:

  • Account data: email address, display name, username, authentication identifiers (for example Firebase UID), and profile settings
  • Authentication data: session cookies / tokens and related sign-in metadata from our auth providers
  • Project content: prompts, chat messages, pipeline graphs, firmware, schematics, pin maps, BOMs, CAD/assembly artifacts, comments, attachments you upload, and similar design data
  • Billing data: subscription plan/status, Polar customer IDs, order/credit purchase records, and related billing metadata (card details are handled by Polar, not stored by Torit as full payment card numbers)
  • Usage and product analytics: feature usage events, AI credit/token counters, performance metrics, and approximate technical metadata (device/browser type, pages viewed) when analytics is enabled
  • Support communications: emails and messages you send to support@torit.sh
  • Technical logs: IP address, request metadata, error reports, and security logs needed to operate and protect the Service

4. How we collect information

We collect information directly from you (account setup, prompts, project edits, support requests), automatically when you use the Service (logs, cookies/local storage for preferences and sessions, analytics if consented), and from processors that help us run the Service (for example Polar for payments, Firebase for authentication).

5. How we use information

We use personal data to:

  • Provide, maintain, and secure the Service
  • Authenticate users and manage sessions
  • Store and sync your projects across sessions and devices
  • Run AI inference and automated tooling on prompts and project context you submit
  • Enforce plan limits, credits, and subscription entitlements
  • Process payments, invoices, refunds, and tax-related billing records through Polar
  • Respond to support requests and communicate about the Service
  • Monitor reliability, debug issues, prevent abuse, and improve product quality
  • Comply with legal obligations and enforce our Terms of Service

6. AI processing

When you use AI features, prompts, relevant project context, and related instructions may be sent to model providers to generate responses and artifacts. Those providers process the content as our processors (or independent controllers where required by their terms) for the purpose of returning inference results.

Do not submit secrets, passwords, private keys, regulated personal data, or confidential third-party information into prompts unless you are comfortable with that content being processed by our AI providers under their terms and this Policy.

We may use aggregated or de-identified product signals to improve the Service. We do not sell your personal data.

8. How we share information

We share personal data with service providers that help us operate Torit, under contractual obligations appropriate to the service. Categories include:

  • Authentication: Firebase / Google authentication services
  • Hosting and storage: cloud infrastructure such as Upstash Redis and/or AWS (DynamoDB, S3) depending on deployment configuration
  • AI model providers: OpenAI, Anthropic, Google (Vertex AI / AI Studio), and similar providers used for generation
  • Payments: Polar (subscriptions, credit packs, customer billing records)
  • Analytics (with consent where required): PostHog and/or Firebase/Google Analytics
  • Error monitoring (if enabled): Sentry or similar
  • Professional advisers and authorities when required by law or to protect rights, safety, and security

If you publish or share a project, the surfaces you expose may be visible to others. Invite emails, private membership details, and private chat history are not intended for public project views.

We do not sell personal data. We do not share personal data for cross-context behavioral advertising as a sale/share under CPRA-style regimes, except where a specific analytics tool requires consent and you have opted in.

9. Cookies and local storage

We use essential cookies/local storage for authentication, security, and core preferences. We may use analytics cookies or similar technologies when you consent via our consent banner.

You can decline non-essential analytics through the consent controls. Browser settings can also block cookies, but essential auth features may not work without them.

10. Data retention

We retain account and project data for as long as your account is active and as needed to provide the Service. After account deletion or an inactivity period, we delete or anonymize personal data within a reasonable time, except where we must retain records for legal, security, billing, or dispute-resolution purposes.

Backups and logs may persist for a limited period after deletion and are then purged on a rolling schedule.

Billing records may be retained for tax and accounting obligations.

11. Security

We use administrative, technical, and organizational measures designed to protect personal data, including transport encryption, access controls, rate limiting, and least-privilege operational practices.

No method of transmission or storage is perfectly secure. You are responsible for protecting your account credentials and for not uploading highly sensitive secrets into project content or prompts.

12. International transfers

Because we use global cloud and AI providers, your data may be processed in countries other than your own, including the United States and other locations where our vendors operate.

Where required, we rely on appropriate transfer mechanisms (such as contractual protections with vendors) to safeguard personal data.

13. Your rights and choices

Depending on your location, you may have rights to access, correct, delete, export, or restrict processing of your personal data, and to object to certain processing or withdraw consent.

You can decline analytics cookies via the consent banner. You can update some profile information in-product. For account deletion, data export, or other privacy requests, email support@torit.sh with the subject “Privacy request.”

We may need to verify your identity before fulfilling a request. We will respond within the time required by applicable law.

If you are in the EEA/UK, you may also lodge a complaint with your local supervisory authority. If you are a California resident, you may have rights under the CCPA/CPRA; we do not sell personal information.

14. Children

The Service is not directed to children under 13 (or the minimum age required in your jurisdiction). We do not knowingly collect personal data from children below that age. If you believe a child has provided us personal data, contact support@torit.sh and we will take appropriate steps to delete it.

15. Changes to this Policy

We may update this Privacy Policy from time to time. We will post the updated Policy on this page and revise the “Last updated” date. For material changes, we may also provide additional notice (for example by email or in-product).

Continued use of the Service after an update becomes effective means you acknowledge the updated Policy.

16. Contact

Privacy questions or requests: support@torit.sh.

Also see our Terms of Service for rules governing use of Torit.

See also our Terms of Service.