CIRCUITPATH / PRE-LAUNCH PRIVACY NOTICE
Privacy notice
Current status: CircuitPath is a pre-launch product. This notice describes the website, Google account verification, waitlist, and reservation foundation that exist today. Live proxy access is disabled in the current release. Reservations are currently paid via Wise (USD) or PayU (INR), verified manually against the invoice number before confirmation. Do not rely on this notice as the final privacy policy for a paid service until the operator identity, contact details, provider list, retention schedule, and applicable-jurisdiction review have been completed.
1. Who this notice is for
This notice applies to the CircuitPath website and the pre-launch interactions available through it, including browsing the site, joining the waitlist, verifying a Google account, and creating a reservation record that is paid via Wise (USD) or PayU (INR). It does not cover websites or services operated by Google, Firebase, Cloudflare, Render, Wise, PayU, or any future residential-network provider; those providers publish their own notices.
Operator and contact: CircuitPath is the product name used on this site. Privacy, support, and abuse requests can be sent to auralisstudiossupport@gmail.com. The operating legal name, registered address, and—where required—a separate data-protection contact must still be published before paid service or live proxy access is enabled.
2. What information we collect
We collect information that is necessary for the current pre-launch flow. Depending on what you do, this can include:
- Google account and identity data: Firebase UID, verified email address, and the name Google makes available to the application. CircuitPath does not receive your Google password.
- Business and use-case information: company, role or title, estimated monthly bandwidth, and your description of the intended authorized workflow.
- Waitlist and consent records: waitlist status, the fact and time of your consent, the version of the consent text shown, and whether launch updates were requested.
- Reservation data: reservation ID, amount, currency, requested or estimated GB, reservation status, idempotency information, terms and consent versions, and timestamps. Reservations are paid via Wise (USD) or PayU (INR).
- Payment and reconciliation data, if enabled: Wise/PayU payment-link and webhook references, amount, currency, settlement status, payment timestamps, refund requests, and the event information needed to reconcile a payment. Payment credentials are entered on the provider's hosted page; CircuitPath does not ask for or intentionally store full card numbers.
- Usage data, only if a proxy service is later launched: account, reservation, entitlement, credential, session, provider-event, byte-count, billable-GB, and event-time records. No live proxy provider is connected today.
- Technical and security data: request and device information made available to the website and hosting infrastructure. The backend uses a request address in an in-memory rate-limit bucket; it does not intentionally save that address in an account, waitlist, or reservation record. Hosting and security providers may maintain their own technical logs under their policies.
- Support and communications: messages you send to us and records of communications or requests sent to auralisstudiossupport@gmail.com.
- Analytics and browser storage: optional Google Analytics data only after you accept analytics. The site stores your analytics choice in browser storage. Firebase may use browser storage needed for authentication and session handling.
Please do not put passwords, payment credentials, government identifiers, health information, or other sensitive personal data in the intended-use field.
3. How we use information
- operate and secure the website, authentication flow, waitlist, and account records;
- verify account ownership and prevent duplicate, fraudulent, or abusive submissions;
- understand the workflow you want to use so we can assess whether it is authorized and compatible with the acceptable-use policy;
- create, protect, reconcile, and support a reservation if that feature is enabled;
- maintain audit records, investigate security or abuse reports, enforce our policies, and comply with law;
- record your request for launch updates and, once a delivery channel is enabled, send updates only when you request them or otherwise provide the required permission; and
- measure and improve the site using optional analytics after consent.
We do not use the intended-use description to authorize unlawful activity, and we do not sell personal information or use it for targeted advertising.
4. Consent, communications, and legal bases
The waitlist form asks you to agree to receive CircuitPath launch updates and to the applicable privacy and reservation language. We record that choice and its version. You may withdraw marketing consent at any time; withdrawal does not undo processing already carried out or affect records we must keep for security, accounting, disputes, or legal compliance.
Where a privacy law requires a legal basis, the basis will depend on the activity and your location. It may include taking steps at your request, performing a contract, complying with a legal obligation, pursuing legitimate interests such as security and fraud prevention, or consent for optional analytics and marketing. The final operating entity must document the jurisdiction-specific basis before the paid service launches.
5. Providers and disclosures
We use or plan to use the following categories of providers. They process information only for the services they provide and may act as independent controllers for some activities:
- Google Firebase Authentication: Google Sign-In and identity-token verification.
- Google Cloud Firestore: account, waitlist, reservation, audit, payment-reconciliation, entitlement, refund, and—if launched—usage records.
- Cloudflare Pages and Render: hosting and delivery of the frontend and backend. Their infrastructure may process technical request data and operational logs.
- Google Analytics: optional, consent-gated site measurement. It is not loaded by CircuitPath until analytics consent is granted.
- Wise: hosted payment and payment-event processing for USD reservations. CircuitPath verifies each payment against its invoice number before confirmation.
- PayU: hosted payment processing for INR reservations. CircuitPath verifies each payment against its invoice number before confirmation.
- Residential-network providers: none are connected today. Any future provider must pass sourcing consent, privacy, security, revocation, and abuse review before customer traffic or usage data is processed.
We may disclose information to professional advisers, auditors, law enforcement, courts, or other recipients when reasonably necessary to comply with law, protect people or systems, investigate abuse, or enforce an agreement. We do not disclose more than is reasonably necessary for the relevant purpose.
6. International processing
CircuitPath and its providers may process information in countries different from where you live. The location and transfer mechanism can vary by provider and deployment. Before paid service or live proxy access, CircuitPath must document the relevant processing locations and use an appropriate transfer safeguard where required, such as an adequacy decision or contractual safeguards. Review the applicable provider notices for their own international processing.
7. Retention
We keep information only for as long as it is needed for the purpose collected, a legitimate security or operational purpose, or a legal, tax, accounting, dispute, or enforcement requirement. Current records are stored in Firestore and do not yet have a complete automated deletion schedule. That gap must be resolved and tested before paid service or live proxy access.
Our intended baseline is to delete or anonymize inactive waitlist and account information when it is no longer needed; retain payment, refund, and accounting records for the period required by applicable law; retain security and audit data only for a defined operational period; and apply the Google Analytics retention setting selected for the property. A final schedule, including the treatment of backups and legal holds, will be published when the operating entity and jurisdictions are confirmed.
8. Your choices and rights
Depending on your location, you may have rights to access, correct, delete, restrict, or object to processing; receive a portable copy; withdraw consent; and complain to a data-protection authority. To make a request, email auralisstudiossupport@gmail.com. We may ask for reasonable information to verify that the request concerns your account, and we will not use verification information for another purpose.
Analytics does not load until you click “I understand” in the consent banner. If you previously accepted and want to withdraw that choice, clear the site's stored analytics-consent setting in your browser or email auralisstudiossupport@gmail.com for help. Essential authentication and security operations may still function without analytics consent.
9. Security
The current system uses measures including encrypted HTTPS connections, Firebase token verification, UID-based ownership checks, server-side validation, rate limiting, access controls, audit records, signed Wise webhook verification, request-size limits, and fail-closed payment gates. No system can guarantee absolute security. If we become aware of a material incident, we will follow applicable notification obligations.
10. Children
CircuitPath is a business-oriented service and is not directed to children. Do not use the site if you are under the minimum age required to enter a contract in your location. If you believe a child supplied personal information, contact the published privacy address so the operator can investigate and delete it where appropriate.
11. Changes
We may update this notice when the product, providers, law, or data practices change. We will update the version and date at the top. Material changes will be presented through the site or another appropriate channel. A new notice must be accepted where required before a materially different processing activity begins.
12. Contact and publication gate
Privacy, support, and abuse requests can be sent to auralisstudiossupport@gmail.com. The operating entity must still publish its legal name, registered address, and—where required—a data-protection contact before this page is treated as a production-ready legal notice. Until that is done, CircuitPath remains in its pre-launch, no-live-proxy state.
See also: Terms of service, Acceptable-use policy, and Pre-launch reservation terms.