Privacy Policy
Last updated: 13 September 2026
This policy explains what personal data Feynman Circuits ("we", "us") collects, why we collect it, who we share it with, and what rights you have. Feynman Circuits is run by Kishan Dhanak. If you have any question about your data, email us at kishan.dhanak.tech@gmail.com.
In short: you can use the circuit builder without an account, and then we store nothing about you. If you create an account, we store your name, email, a scrambled (hashed) copy of your password and the circuits you save. We don't show ads, we don't use analytics or tracking cookies, and we never sell your data. You can delete your account and all your circuits at any time from My Account.
1. What we collect
If you create an account
- Your email address, used to sign in and to send you account emails.
- Your first and last name.
- Your password, but only as a one-way hash. We can't see or recover your real password.
- The date your account was created and last changed.
Circuits you save
- The circuit itself, its name and description, whether it is public or private, and when it was created and last changed.
- If you make a circuit public, anyone with its link can open it. Your name and email are never shown with a public circuit.
- Circuits you build without saving stay in your browser and are never sent to us. Simulations run in your browser too.
Share links
- A link to a public circuit only contains the circuit's id.
- A link that holds the whole circuit (used when you share without saving) keeps the circuit
after the
#in the web address. Browsers never send that part to any server, so we never receive it.
Password resets
- When you ask to reset your password, we store a 6-digit code, when it expires (after 10 minutes) and how many times it was tried. We email the code to you.
Feedback
- When you send feedback, what you type, and your name and email if you choose to add them, is sent to us by email. It is not stored in the app. You can send feedback without giving your name or email.
QEC experiments
- When you run a QEC experiment, the settings you chose (number of rounds and where you placed errors) are sent to our server to be simulated. We don't store them, and they are not linked to your account.
Technical data
- Like every website, the servers that host Feynman Circuits see your IP address, browser type and the time of each request. Our hosting providers may keep this in their server logs for a short time. We also use your IP address to limit how many requests can be made in an hour, to stop abuse.
- Your browser downloads the Inter font from Google Fonts, so Google receives your IP address when the page loads.
2. Cookies and browser storage
We only use what is needed for the site to work. There are no advertising or tracking cookies.
| Name | Type | What it is for | How long |
|---|---|---|---|
access_token | Cookie | Keeps you signed in. Only set when you sign in. | 30 minutes |
refresh_token | Cookie | Signs you back in when access_token runs out. | 7 days |
theme, settings, tour progress, code panel view | Local storage | Remembers your light/dark theme, your settings, whether you have seen the tour, and which code view you picked. This stays on your device and is never sent to us. | Until you clear it |
The two login cookies can't be read by JavaScript, and are only sent over a secure (HTTPS) connection. Because they are strictly needed to sign you in, they don't need your consent.
3. Why we use your data (legal bases)
- To provide the service you asked for (creating your account, signing you in, saving your circuits, resetting your password). Under GDPR this is "performance of a contract".
- To keep the service safe (rate limits, stopping abuse, security emails such as "your password was changed"). Under GDPR this is our "legitimate interest".
- To answer your feedback, only if you chose to give your email. This is based on your consent, and you can take it back at any time.
Under India's Digital Personal Data Protection Act, 2023, we process your data based on the consent you give when you create an account or send feedback, and for the purposes listed above only.
4. Who we share it with
We don't sell, rent or trade your personal data, and we don't share it for advertising. We only use these service providers, who handle data for us to run the site:
- Vercel: serves the website to your browser.
- Render: runs our backend server.
- Neon (PostgreSQL): stores our database.
- Resend: sends our emails (password reset codes, account emails, feedback).
- Google Fonts: provides the font used on the site.
We may also share data if the law requires it, for example because of a valid court order.
5. International transfers
Our service providers may store or process data in the United States and other countries. Where data from the EU, UK or India leaves those regions, we rely on the safeguards our providers offer, such as the European Commission's Standard Contractual Clauses.
6. How long we keep it
- Account details and saved circuits: until you delete them or delete your account.
- Password reset codes: stop working after 10 minutes, and are deleted with your account.
- Login records: each login stops working after 7 days at most.
- Feedback emails: kept in our inbox only as long as we need them to handle your feedback. Ask us and we will delete them.
- Server logs and backups: kept by our hosting providers for a limited time under their own policies. Deleted data may stay in a backup for a short time before it is overwritten.
7. Your rights
Depending on where you live, you have some or all of these rights:
- See your data: ask us for a copy of the personal data we hold about you.
- Correct it: change your name in My Account, or ask us to fix anything else.
- Delete it: use My Account → Delete Account. This deletes your account and all your saved circuits straight away, and we send one last email to confirm what was deleted.
- Take it with you: download any circuit as JSON, OpenQASM, Qiskit or Q# from the code panel, or ask us for all your data.
- Object or limit: ask us to stop or limit how we use your data.
- Take back consent at any time, for anything based on consent.
- Complain to your data protection authority (in the EU/UK), or to the Data Protection Board of India.
India (DPDP Act): you can also name someone to use these rights for you if you die or become unable to. For any complaint about your data, contact our grievance contact, Kishan Dhanak, at kishan.dhanak.tech@gmail.com. Please contact us before going to the Data Protection Board.
California (CCPA): you have the right to know what personal information we collect, to delete it, to correct it, and not to be treated differently for using these rights. We do not sell or share personal information, as those words are defined in the CCPA.
To use any of these rights, email kishan.dhanak.tech@gmail.com. We will reply within 30 days. We may ask you to confirm the request from your account's email address, to make sure it is really you.
8. How we protect your data
- Passwords are stored only as a one-way hash.
- All traffic uses HTTPS, and the database connection is encrypted.
- Login cookies are secure and can't be read by JavaScript.
- Sign-in, password reset and feedback have rate limits to stop guessing and abuse.
No system is perfectly secure. If a data breach affects your personal data, we will tell you and the authorities when the law requires it.
9. Children
You must be at least 13 to create an account, or have permission from a parent or guardian. We don't knowingly collect data from children under 13. If you think a child has given us their data, email kishan.dhanak.tech@gmail.com and we will delete it.
10. Changes to this policy
If we change this policy, we will update the date at the top of this page. If the change is important, we will also tell signed-in users in the app or by email.
11. Contact
Kishan Dhanak
Email: kishan.dhanak.tech@gmail.com