Privacy policy
Last updated 2026-09-26
This is a draft. It has not been reviewed by a lawyer and it is not legal advice. It describes what the software actually does, checked line by line against the code, and it must be reviewed by a lawyer qualified in Slovenian and EU data-protection law before it is relied on. Anything still marked in orange below is a value nobody has supplied yet.
Your board photographs are used for your identification and its confirmation record, and for nothing else unless you switch that on yourself. Everything we run is in the EU except the companies named in section 5. You can export or delete all of it from your account page without asking us, and delete it from the deletion page without signing in.
1. Who is responsible for your data
The controller is KAUDATA RAČUNALNIŠKO PROGRAMIRANJE D.O.O., Kidričeva cesta 2 B, 3320 Velenje, Slovenia. Registration numbers and tax numbers are on the imprint page.
For anything about your data, write to [email protected]. You will get an answer within one month, which is the period Art. 12(3) allows.
TODO(founder): data protection officer A company of this size and processing profile is unlikely to need one under Art. 37, but that assessment should be written down and kept rather than assumed.
We are the controller for everything described here, including the photographs you upload. We decide what is stored, for how long, which AI provider reads it and what goes into the marking database, and we apply the same answer to every customer. Nobody can instruct us to handle their uploads differently.
That matters if you are a repair shop rather than a lone technician, because you may be a controller of your own customer’s data and may need a data processing agreement with us under Art. 28. Read section 5a before you assume you have one.
2. What we collect
- What you upload. Photographs of a component and the board around it, the marking as we read it, the package, the designator, the device make and model, and the circuit context you type or answer.
- Your account. Email address, and your name and profile picture if you sign in with Google. Locale and country, and the language of the page each identification was asked from and each purchase was made from. No password, because we do not use them.
- Billing. Billing address, country, VAT identification number if you give one, and what you bought. Card details go straight to Stripe and never reach our servers.
- Evidence of your location. Billing country, the country that issued your card, and, where the network in front of our servers tells us, the country your IP address resolves to. EU VAT law requires two of these, and we store each of them we have.
- Confirmations. Whether an identification fixed the board, which part it turned out to be, and any note you add.
- How you arrived. The referring site and any source parameter on your first visit, so we can tell which forum a person came from.
- Technical records. Request logs including IP address.
- What you type into the free-text fields. The circuit context, your answers to the questions we ask back, and any measurement you note down. These go to the AI provider with the photographs, so do not put a customer’s name or contact details in them.
- A team. If you are in a team on the Shop plan: its name, who owns it, who is in it and since when, the team’s monthly count, and the invitations the owner has sent, each with the address it was sent to. Section 3a says who sees what.
- A subscription bought in the app. If you subscribe in the iPhone or Android app, what Apple or Google tells us about that subscription. Section 4a says what that is.
3. Why, and on what legal basis
| What we do with it | Legal basis |
|---|---|
| Running an identification you asked for: reading the photo, retrieving candidates, ranking them and storing the result | Performance of a contract, Art. 6(1)(b) |
| Your account and sign-in, and keeping your history where your plan includes it | Performance of a contract, Art. 6(1)(b) |
| Taking payment, issuing invoices, and keeping the VAT records and the evidence of your location that the law requires | Legal obligation, Art. 6(1)(c), and performance of a contract, Art. 6(1)(b) |
| Recording your confirmation that a part fixed the board, and adding the marking-to-part pair to our marking database | Legitimate interests, Art. 6(1)(f): making the service accurate |
| Keeping the service running and safe: error reports, abuse and fraud prevention, cost limits | Legitimate interests, Art. 6(1)(f) |
| Understanding which parts of the product are used, and which site a visitor arrived from | Legitimate interests, Art. 6(1)(f) |
| Recording that a deletion or an export was asked for and carried out | Legal obligation, Art. 6(1)(c): showing we honoured the request, Art. 5(2) |
| Using your photographs beyond your own identification, to improve the models we use | Consent, Art. 6(1)(a). Off by default, and nothing does this today (see section 4) |
| Running a team on the Shop plan: its members, its invitations, its shared monthly count, and showing each member the identifications the others start in it | Performance of a contract, Art. 6(1)(b): the one the business made with us for its team. For someone invited who has not joined yet, legitimate interests, Art. 6(1)(f): letting them join the team that invited them |
| Recognising a subscription you bought in the app as yours, keeping your access in step with it, and confirming the purchase to Google | Performance of a contract, Art. 6(1)(b) |
We do not sell your data, we do not use it for advertising, and we do not profile you to make decisions about you.
3a. If you are in a team on the Shop plan
A business buys the Shop plan for its staff, and the person who buys it owns the team. Being in a team changes who sees some of your data. This is exactly what.
- Who is in the team. The owner and every member see each member’s email address and the date they joined. The owner also sees the address of each invitation still open.
- What is shared. An identification you start while the team is on the Shop plan is filed under the team. Every member can see it in the team’s history with your email address beside it, and can open, read and continue it: its photographs, what you typed and measured, the answer, and whether it fixed the board. They can add their own measurements and answers to it.
- What stays yours. What you identified before you joined, your account details, your invoices, your answers about the AI provider and your photo-training choice. Publishing an identification to a public link stays with whoever started it. When the team’s plan ends, nothing is shared any more, and each person keeps what they started.
- Invitations. To invite someone, the owner gives us their email address. We keep it with the invitation and email them once, in their own account’s language, or the owner’s if they have no account, naming the team and the owner’s address. The invitation stays open for 14 days, and is deleted at the first daily clean-up after it is accepted, declined, withdrawn or has expired.
- Leaving. If you leave or are removed, what you identified for the team stays in its history. If you close your account, you leave the team at once, and when the account is erased 30 days later, what you identified is erased too, including what the team could see. If the owner closes theirs, the team takes no one new and its plan runs to the end of the period already paid for, but no longer than until the owner’s account is erased. At that erasure the team is deleted, and each member keeps what they identified.
4. Your board photographs
A board photograph is often a customer’s property, and it can show a serial number, an asset tag, a repair sticker or a name. We treat the photographs accordingly.
- They are used to read the marking, to give the model the visual context it needs to rank candidates, and to keep the record of the identification you can look back at.
- They are not used for anything else. Not to train a model, not to build a public dataset, not for marketing. There is a photo training setting in your account, off by default, which is the switch we would use if that ever changed. Today nothing reads it, because no such training or export exists. If we build one, the switch will gate it, it will stay off until you turn it on, and turning it off again will apply from that moment onwards.
- They are stored under keys nobody can guess. Reads go through a signed link that stops working after 15 minutes, so a URL copied out of a page expires.
- Delete your account and all of them go, together with the stored objects themselves. There is not yet a button that deletes a single identification without deleting the account: write to us and we will remove one.
- If you publish a result page, the photographs on it become readable by anyone who has the link, which is the point of a shareable result. Stop sharing on the result page withdraws the link and it stops working. Look at what is in frame before you publish, because we cannot know whose board it is.
- Search engines are asked not to index shared result pages, for the same reason. That is an instruction to a crawler and not a lock: a published link works for anyone who has it.
- An identification made without signing in is kept against a cookie rather than an account, and erased with its photographs 90 days after it was made. If you shared it, the shared link stops working then. Sign in if you want to keep your history, or to remove it sooner yourself.
Please do not upload a photograph containing personal data you have no basis to share with us. If you do it by accident, delete the identification, or write to us and we will.
4a. The mobile app
The WhatSMD app for iPhone and Android phones uses the same service as this website, and everything in this policy applies to it. It adds these:
- An install id. The first time it runs, the app makes a random value, keeps it in the phone's secure storage and sends it with every request. It does for the app what the anonymous key does for the website (section 8): it counts the free identifications made without an account and shows that their results are yours. It is not taken from the phone and says nothing about the phone or about you, and reinstalling the app makes a new one. We never store it as it is, only a keyed hash of it, which is also what the records of which steps of the product were used are kept under (section 7).
- A sign-in code instead of a link. The app signs you in with a six-digit code sent to your email address, because a link would open in the browser rather than in the app. A code works once and for 10 minutes, and we keep only a hash of it until it is used or runs out. Once you are signed in, the app keeps its sign-in token in the phone's secure storage until you sign out.
- Your permission before anything goes to the AI provider. Before the app first sends a photograph, or what you tell it about a circuit, to OpenAI (section 5), it asks you, naming OpenAI. We keep each answer: yes or no, the provider it named, the date of this policy, the time, and the account or install it came from. Without a yes on record, the app's requests that would reach OpenAI are refused. A later no is kept the same way and stops them again. Searching by typing a code never reaches OpenAI and never needs your permission.
- Reports on answers. If you report an answer in the app as wrong, offensive or something else, we keep the reason and any note you write with that identification, to check how accurate the answers are.
- Deleting your account from the app. Signed in, you can delete your account from the app as you can from the account page on the website, with the same result: sign-in stops at once, on every device, and the data is erased 30 days later (section 9).
- Your team. If you are in a team on the Shop plan, the app shows its name, your role, its seats and the team’s monthly count, and the team’s identifications as section 3a describes. Members and invitations are managed on the website.
- Subscribing in the app. The app sells the Tech plan as a subscription through the App Store and Google Play. For those purchases Apple or Google is the seller: they take the payment, charge the VAT, renew, cancel and refund under their own terms, and handle your payment details under their own privacy policies. We never receive your card, your bank details or your Apple or Google account.
- How a purchase finds your account. Signed in, the app gives the store a reference we make from your account's id, so the purchase comes back to the account that made it. It is not your address and names nobody to the store. A purchase stays with the account that made it: restoring it while signed in to another account is refused, and the app then shows the address of the account it belongs to, with most of it hidden.
- What we receive about it. From the app and from Apple's and Google's messages to our server: the store's reference for the subscription, the product and plan, whether it was a test purchase, its state (active, in a grace period, retrying payment, paused, ended, refunded or revoked), when the paid period ends, whether it renews, and the price and currency the store charges. We check Apple's signature on each, and read Google's back from Google, before we use it. We ask Apple and Google about a purchase only by the store's own reference, and tell Google that we have recorded it; we send them nothing else about you.
- How long. The subscription's record is kept while your account exists and erased with it, and holds only the latest summary we verified, never the store's signed receipts. Each message a store sent us is kept on record for 90 days (section 7).
- Deleting your account does not cancel it. Only you can cancel a subscription bought in the app, in the App Store or Google Play. Closing your WhatSMD account leaves it running, and the app, the account page and the deletion page say so first and link to the store.
5. Who else processes your data
We use these companies to run the service, and give each one only what its job needs. The list is built from how this deployment is configured, so it names exactly the companies it sends data to.
| Who | What for, and what they see | Where |
|---|---|---|
| Cloudflare | DNS, and the network edge in front of our serversRequest data in transit, including your IP address | United States |
| Resend | Sign-in links, receipts and account emailYour email address and the contents of those messages | United States |
| OpenAI | The AI model that reads the marking and ranks the candidatesYour photographs, as image data, and the circuit context you type. Not your name, your email or any account identifier | United States |
We send the AI provider the images and the text, and nothing that names you: no account identifier, no email address, no session identifier.
TODO(founder): AI provider training and retention terms The AI provider above states in its business terms that content sent through its API is not used to train its models, and that is the basis on which this product uses it. It is the provider’s published term rather than something this application switches on: we set no zero-retention or no-training flag on the requests. Confirm the terms that apply to our account, sign the data processing agreement, and record the answer here.
TODO(founder): a data processing agreement and a transfer basis for each company above Where a processor above is outside the EU, the transfer relies either on that company’s certification under the EU-US Data Privacy Framework or on the standard contractual clauses. Confirm which applies to each one, accept or sign each data processing agreement, and list the answer here rather than leaving the reader to guess.
5a. If you are a business photographing a customer’s board
A board on your bench usually belongs to someone else. A photograph of a bare board is a photograph of a thing and not personal data at all. It becomes personal data when it carries something that points at a person: a serial number you can match to a repair ticket, an asset tag, a name sticker, a screen with something on it.
When that happens you are the controller of that data, because you decided to photograph it and to send it to us. What we are is the question, and the honest answer today is that we are a separate controller and not your processor. Three things in how the product works make that so, and each one is a design decision rather than an oversight:
- We use what you send for a purpose of our own. A confirmation you submit can be promoted into our marking database, which is our asset and the thing that makes the next technician’s answer better. A processor may not do that.
- We set the retention periods, and there is no way for you to change them.
- There is no channel through which you could instruct us. There is no per-customer configuration and no contract in which your instructions would be the thing we follow.
The practical consequence is on you rather than on us, and the terms say so: you need your own basis for handing us a photograph that carries your customer’s data, and the cheapest way to have one is not to: frame the shot on the component, and keep names, serial numbers and tickets out of the text fields.
TODO(founder): decide whether to offer an Article 28 agreement A shop with its own compliance obligations will eventually ask for a data processing agreement. One is drafted in this repository, in docs/legal/, together with the list of product changes that would have to be made before it could honestly be signed. It is not on offer yet, and this page will say so until it is.
6. Where your data lives
The application runs on servers we operate ourselves, in the EU. The database runs in the EU.
Photographs and invoices are stored on the application server's own disk.
The companies in section 5 established outside the EU are Cloudflare, Resend and OpenAI. What each one sees is in the table.
7. How long we keep it
| What | How long | Why |
|---|---|---|
| Identifications, results and the photographs attached to them, made while signed in | Until you delete your account | They are your working history. There is no per-identification delete button yet, so write to us and we will remove one |
| Identifications made without an account, with their photographs | 90 days, then erased with the photographs | There is no account from which you could delete them, so we do it. A shared link to one stops working when it is erased |
| Your account | Until you delete it. Deletion takes effect immediately and the records are erased 30 days later | The 30 days is a recovery window against an accidental or hostile deletion |
| Confirmed marking-to-part pairs promoted into the marking database | Indefinitely, with your account no longer attached | Once separated from the account it is no longer personal data, and it is what makes the next answer better |
| Invoices, payment records and the evidence of your location behind them | 10 years from the end of the year they relate to | Slovenian VAT law and the EU one-stop-shop rules require it. These cannot be deleted on request |
| The raw record of a payment as the payment provider sent it | 90 days after it arrives, once it has been processed | The order and the invoice are the accounting record. This copy is kept only to investigate a payment that went wrong |
| A subscription bought in the app, as the store last told us about it | While your account exists; erased with it | To keep your access in step with the store's record of what you bought |
| The record of each message Apple or Google sent us about a subscription | 90 days after it arrives | To show which messages were applied, and to answer a question about a subscription |
| Sign-in sessions | 90 days, or until you sign out, or immediately when you delete your account | Long enough not to be asked every week, short enough to expire on a lost device. Expired sessions are deleted daily |
| Sign-in links | 15 minutes. Deleted when used, or daily once expired | A link is only useful for as long as it takes to open the email |
| Sign-in codes (the app) | 10 minutes. Deleted when used, or daily once expired | A code is only useful for as long as it takes to read the email |
| The app's answers about the AI provider | Given signed in: as long as the account, then deleted with it. Given without an account: 13 months | So we can show that you agreed, and to what, for as long as that matters |
| Reports on answers from the app | As long as the identification they are about | They are about that answer and are no use without it |
| Your membership of a team on the Shop plan | While you are in it: until you leave, are removed or close your account, or until the team is deleted with its owner’s account | It is what puts you on the team’s plan and shows you its identifications |
| Invitations to a team, with the address each was sent to | Until accepted, declined, withdrawn or expired after 14 days, then deleted at the next daily clean-up | It holds the address of someone who may never have an account, so it is kept no longer than it is open |
| Account deletion requests made without signing in | The link works for 24 hours. The request is kept for 24 months | It is the record that a request was made and honoured. It holds a keyed hash of the address, never the address |
| The cached answer the model gave for a photograph | Until the entry expires, and never longer than 90 days | It is keyed by a hash of the image rather than by your account, so deleting the account does not reach it; the age limit does |
| Our own record of which steps of the product were used | 13 months, or until you delete your account | Long enough to compare a month with the same month a year earlier, and no longer |
| The log of what an administrator did, and of every export, deletion and erasure | 24 months | It is how we answer for what happened to an account. Your address is removed from it when your account is erased |
| Server and request logs | TODO(founder): confirm how long the hosting platform keeps request logs | These are kept by the hosting platform rather than by our own code, and we will not publish a figure we have not confirmed |
Every period above that we set ourselves is enforced by a job that runs daily and deletes what has reached it. Where a period is marked in orange, another company’s setting decides it and we have not yet confirmed what that setting is.
9. Your rights, and how to use them
Under the GDPR you can ask for a copy of your data, correct it, delete it, restrict or object to what we do with it, and take it elsewhere in a machine-readable form. Where we rely on your consent you can withdraw it at any time, without that affecting what happened before.
Two of those are buttons on your account page rather than an email to us.
- Export. Account, then export. You get a JSON file with your account, every identification, every result, every confirmation, your orders, your invoices, the subscriptions you bought in the app, your team membership and the invitations sent to your address. Identifications a teammate started are theirs, and are in their export rather than yours. TODO(founder): the export omits three things it should carry The usage events, the record of the model calls made for you, and any VAT-number check are held about you and are not in the file. Ask and we will send them; a portability request should not need asking.
- Delete. Account, then delete account. If you cannot sign in, use the deletion page instead: it emails a link to the account’s address, which works once, for 24 hours. Either way the account is closed immediately, your sessions are ended, a subscription paid on this website is set to end with the period already paid for (one bought in the app is not: only you can cancel it, in the App Store or Google Play), and processing stops. The records are erased permanently 30 days later, photographs included. What outlives that is in section 7: the invoices and the VAT records behind them, for 10 years, because tax law requires it; the log that the account was closed and erased, with your address removed; and records keyed by something other than your account, such as a cached model answer or a payment record, until their own period ends.
- Stop sharing. On any result you published, the button beside the share link withdraws it.
- Photo training consent. A single switch in your account settings, off unless you turn it on. Section 4 says what it does and does not currently do.
If you used the service without an account there is no account page to do any of this from, and we cannot tell your identifications from anyone else’s except by the link you hold. They are erased 90 days after you made them; to remove one sooner, write to us with the link.
For anything the buttons do not cover, write to [email protected].
10. Complaining about us
Tell us first if you can, at [email protected]. You also have the right to complain to a supervisory authority. In Slovenia that is the Information Commissioner, Informacijski pooblaščenec, Dunajska cesta 22, 1000 Ljubljana. If you live elsewhere in the EU, you can go to the authority for your own country.
11. Changes to this policy
When this policy changes, the date at the top changes with it. If a change materially affects how we handle what you have already given us, we will email you before it takes effect.