Privacy Policy
What BoardRepo collects, why it is used, and the choices you have.
Last updated: October 1, 2026
Summary
- We need account details, project files, and product records to operate BoardRepo.
- Your handle, name, and avatar are public. Public projects can be downloaded and indexed. Anyone with a valid private link may open it.
- Members of an organization can see each other's handle, name, and email address.
- AI features send relevant context to an AI service provider. We record Ask and Astra exchanges; project detail and documentation drafts omit request and response contents from drafting analytics and keep usage counts, timing, and outcomes.
- Connected-assistant records may include content the connection was allowed to read.
- We do not sell personal information or share it for behavioral advertising.
Who is responsible for the data
Flintt, Inc., a Delaware corporation at 2261 Market Street STE 13714, San Francisco, CA 94114, United States, operates BoardRepo and is the controller of the personal data covered by this policy. Email privacy questions or requests to [email protected].
What we collect
Account information. We store your email address, handle, and any name or avatar you add. Your handle, name, and avatar are public: they appear on your profile page, on the boards you publish, and next to your comments and Astra Arena entries. Your email address is not shown publicly. If you use a third-party sign-in or repository integration, we receive the account and repository information needed to provide that feature. Repository access is limited to the repositories you select.
Projects and activity. We store projects, original files, versions, generated artifacts, visibility settings, licenses, comments, saved projects, and other actions you take. BoardRepo also records operational data such as pages opened, searches, downloads, feature use, device and network information, timestamps, and errors. Anonymous download counts use a one-way hash of the network address, not the address itself.
BoardRepo Ask and Astra Arena. To answer a question, Ask uses your conversation and the relevant project content. An Astra Arena review uses the board's design data. We keep a record of each exchange, including the request, the board context that was sent, and the answer or review, so we can operate, secure, troubleshoot, and improve these features.
Connected assistants. We record usage and diagnostic information about connected-assistant requests. Those records may include the request and content returned from boards the connection was allowed to read, including private boards when you approved that access. Access credentials are not included in analytics.
KiCad plugin. The plugin sends diagnostic events about its own operation: which step ran, whether it succeeded, how long it took, and the plugin version, KiCad version, operating system, and processor type. Those events carry no design content. They are linked to your account once you sign in and are anonymous before that.
Messages to us. If you report a problem, request another file format, or contact us, we receive the message and the account, project, and technical details needed to respond. A report sent from inside the product also includes the page address and, when the capture succeeds, a screenshot of the page as it appeared to you, which can include board content. The form shows the screenshot before you send it.
Organizations and invitations
If you create or join an organization, its members and admins can see your handle, name, email address, role, and when you joined. Admins manage membership and decide which boards each member can reach. Boards owned by an organization are controlled by its admins, and we act on their instructions for those boards.
An admin can invite someone by email address. We receive that address from the admin and use it only to send the invitation and to match it to an account when the invitation is accepted. Every invitation email includes a link that stops further invitation emails to that address.
Why we use it
- create accounts, authenticate users, and remember granted access;
- run organizations, including memberships, invitations, and board access;
- store, render, analyze, and deliver projects and their versions;
- run BoardRepo Ask, Astra Arena reviews, and connected-assistant tools;
- send sign-in links, invitations, service messages, and replies;
- prevent abuse, enforce limits, investigate incidents, and protect the service;
- diagnose failures and measure how individual features work; and
- evaluate and improve BoardRepo, including the quality of its AI and assistant features.
Cookies, local storage, and session replay
BoardRepo uses cookies and browser storage to keep you signed in, remember access and preferences, and support product features.
Analytics and error-monitoring services may collect product events, device and request information, errors, and limited session replay. Text inputs are masked in replay, though information you submit can still be recorded when it is part of a product event or support record, and a replay can show the layout of a page you had open, including a board page. We do not use advertising cookies or share browser data with advertising networks. You can block or clear nonessential browser storage through your browser. That does not remove records created on our servers when you use BoardRepo.
Service providers
We use service providers to host and deliver BoardRepo, store files, send email, provide optional sign-in and repository connections, process AI requests, monitor errors, understand product use, and handle support messages. They receive only the information needed for the work they perform. We may change providers as BoardRepo develops.
The information involved can include account details, service and request data, project content, AI conversations and relevant board context, usage and device information, diagnostic records, and messages you send us.
We may also disclose information to comply with law, respond to valid legal process, investigate abuse, or protect BoardRepo, our users, or the public. If BoardRepo is involved in a merger, financing, reorganization, or sale, data may be transferred as part of that transaction subject to this policy or notice of a replacement policy.
Public projects and private sharing
A public project, including its files, comments, metadata, and license, can be viewed, downloaded, indexed, and read by people or automated systems. Do not publish personal or confidential information. Private-link and password-protected projects are left out of BoardRepo browse and carry noindex metadata, but noindex is an instruction to crawlers, not an access control. Anyone with a valid private link, and the password where one is set, may be able to open the project.
AI features and outside assistants
BoardRepo Ask selects the project context needed for a response and sends it with your conversation to an AI service provider. An Astra Arena review sends the public board's design data and check results to an AI service provider in the same way, and publishes the result on the leaderboard until you unlist or delete it. Our providers process this content to produce the answer, under their business terms. We may change AI providers over time. Ask is limited by the project access BoardRepo checks for the request.
An outside assistant connects through a separate consent screen, and a connection has only the permissions that screen showed you: which boards it may read (public boards only, or public boards plus boards you own, and eligible users can include organization boards) and, where the screen offers it, whether it may save boards and new versions for you. A permission you were not shown is one the assistant does not have; a read-only connection cannot edit, rename, publish, or delete your projects. Some read tools can queue derived analysis, such as connectivity, checks, or a review, without changing the source design. The company that operates the assistant also receives whatever the assistant reads and handles it under its own terms and privacy policy. You can revoke a connection in Settings.
BoardRepo makes no automated decision about you that has a legal or similarly significant effect. Automated systems apply rate and storage limits and flag abuse; decisions to hide content or restrict an account are made by people.
Project detail and documentation drafts
When you choose Draft from files or Generate documentation for a personal project, BoardRepo sends a bounded selection of retained filenames, README excerpts, component information, and PCB geometry and connectivity facts to Anthropic. This can include private project information. Files excluded from your upload and detected credentials are left out. Documentation generation uses the saved version's retained files. Organization projects are not included.
Generating a draft does not publish or save it. You review and edit the text before creating the project or saving its details. BoardRepo does not store the temporary drafting request or response as a separate record, and drafting analytics omit their contents. Usage counters and diagnostic events record counts, timing, and outcomes. Anthropic processes the selected information under its commercial API terms and applicable retention policy. You can write every field yourself without using AI.
How long we keep data
We keep account information while the account is open and project content until it is deleted. Deletion removes the project from the active service first; residual copies may remain for a limited time in backups or where we need them for security, legal, or recovery purposes. Database backups roll off within about five weeks.
Sign-in links expire after 15 minutes and invitation links after 24 hours. A signed-in session lasts up to 30 days. A connected-assistant credential expires after 30 days and a KiCad plugin credential after about a year; you can revoke either earlier in Settings. Copyright notice correspondence is kept for three years after the matter is closed.
Retention for operational, security, analytics, diagnostic, Ask, Astra Arena, and connected-assistant records varies with the reason the record exists and the settings of the service providers involved. Some records may remain after a connection is revoked, a review is deleted, or an account is closed. Email us if you need a specific record reviewed or removed.
Legal bases in the EEA and UK
We process account, organization, and project data as needed to provide the service you requested. We use legitimate interests to secure BoardRepo, prevent abuse, diagnose problems, understand use, improve the product, and deliver an organization invitation that a member asked us to send, after considering the effect on the people concerned. We also process data to meet legal obligations. Where consent is legally required, we will ask for it and you may withdraw it.
International transfers
BoardRepo is operated in the United States. Our providers may process data in the United States and other countries. Where required for transfers from the EEA or UK, we use a recognized safeguard such as standard contractual clauses.
Imported GitHub profiles and copyright notices
Some public project pages were imported from public GitHub repositories and are owned by a placeholder profile until the author claims them. For those profiles we hold the GitHub login, display name, avatar, and public repository metadata that GitHub already publishes. We do this to run a public-data directory of electronics projects (legitimate interests). We do not email the address on a GitHub profile. To object, claim the board, or ask us to take the copy down, use the contacts on the copyright page. You do not need an account or a reason. When you object, we hide the copy so it no longer appears anywhere on BoardRepo, and we keep the hidden record only so the same repository is not imported again.
If you send a copyright notice or counter-notice, we keep the correspondence needed to handle it, including the URLs named and the contact details you give us, for three years after the matter is closed. We do not publish those notices.
Your choices and rights
You can edit your profile, change project visibility, delete projects, and revoke connected assistants in the product. You can ask us to access, correct, export, or delete personal information, or object to or restrict certain processing, by emailing [email protected]. We may need to verify that the request concerns your account. We answer within one month, or within 45 days where California law applies, and tell you if a complex request needs longer. We will not treat you differently for making a request. If we refuse a request, we say why, and you can ask us to look at it again. You may also complain to your local data protection authority.
California residents may have rights to know, access, correct, or delete personal information and to receive equal service when exercising those rights. BoardRepo does not sell personal information or share it for cross-context behavioral advertising, so there is no sale or advertising-sharing opt-out to exercise.
Security
We use technical and operational controls intended to protect BoardRepo, but no online service can guarantee perfect security. Keep your own copy of important source files and report suspected vulnerabilities to [email protected]. The current controls are described on our Security page. If a breach of our systems affects your personal data, we will notify you and the authorities that the law where you live requires, without undue delay and within the deadline that law sets.
Children
BoardRepo is not directed to children under 13, and we do not knowingly collect their personal data. Contact us if you believe a child has submitted personal data.
Changes
We will update this page as BoardRepo and its data practices change. For a material change, we will update the date above and give notice where appropriate.
Contact
Email [email protected]. You can also read our Terms of Service.