Legal
Privacy Policy
This policy explains, in plain language, what information Resin EDA collects when you use resineda.com and the Resin application, what it is used for, who else sees it, how long it is kept, and how to get it deleted.
What this covers
This policy applies to the Resin EDA website (resineda.com) and the hosted Resin application. It covers everyone who uses them: visitors, people with a free trial, paid users, and viewers invited into someone else's workspace.
Resin Technologies, Inc., a Delaware corporation operating in California and doing business as Resin EDA, is the controller of the account and workspace information described here. Questions and requests go to hello@resineda.com.
What we collect
Account information: your name, email address, password (stored only as a bcrypt hash), two-factor settings, organization name and role, preferences such as language and theme, and the date you accepted the Terms. If you sign in with Google, we receive your name, email address, and Google account identifier from Google and nothing else.
Project content: everything you create or upload in a workspace, including schematics, PCB layouts, symbol and footprint libraries, bills of materials, design documents, imported files from other EDA tools, manufacturing outputs, comments, reviews, version history, and your conversations with Resin AI.
Usage and diagnostics: which features you use and when (for example that a project was opened or a checkout started), your browser and operating system, IP address, and error reports. Product events are sent to our own analytics store; they contain feature names and outcomes, never design coordinates, net names, file names, or free-form text. Server logs record requests with a correlation ID. There are no third-party analytics or advertising scripts on the site or in the app.
Billing information: your plan, paid-user count, invoices, and payment status. Card details are entered on Stripe's hosted checkout and never reach Resin's servers; we store only the Stripe customer and subscription identifiers.
Support and security records: emails you send us, in-app support requests, and a log of sign-in attempts (email address, IP address, time, and outcome) kept to detect account abuse.
How we use it
We use this information to run the service: authenticate you, store and render your projects, let collaborators work together, answer Resin AI requests, generate exports, bill your workspace, send transactional email (verification, invitations, receipts, security notices), respond to support, and detect abuse. We also use it to find and fix bugs and to see which parts of the product need work.
We may use aggregated or de-identified usage data, such as how many boards were routed last month, to measure product health. We do not sell personal information, do not share it with data brokers or advertisers, and do not use it for advertising.
Resin AI
When you use Resin AI, your messages and the parts of the open project needed to answer them (the design document, component and net lists, schematic and board content, and excerpts of component datasheets) are sent to a model provider: Anthropic by default, or OpenAI. The provider returns a response, and any change the AI makes is written into your project as an ordinary edit that you can review and undo.
We use both providers under their commercial API terms, which do not permit them to train their models on API inputs or outputs. Resin does not train models on your data. We keep a per-request usage record (operation, model, duration, credits consumed) for 180 days for metering and reliability; that record does not contain the text of your prompts or the AI's output. The conversation itself is stored with the project until the project or the account is deleted.
Do not submit information you are not allowed to share, such as third-party confidential material or export-controlled designs, unless your agreements permit it. Part searches you run are sent to DigiKey as search queries; datasheets are fetched from the manufacturer or distributor that publishes them.
Providers who see your data
We use a small number of service providers (sub-processors) to run Resin. Each one receives only the data needed for its job. The current list is:
Railway hosts the application, the API, and the PostgreSQL database, in the United States. Anthropic and OpenAI provide the AI models and receive the content described in the Resin AI section. Stripe handles checkout, invoices, and payment records. Resend delivers transactional email and receives your email address and the message content. Google provides sign-in for accounts that choose it. DigiKey receives component search queries and returns part data. Manufacturing packages you generate may be stored in S3-compatible object storage in addition to the database. We will update this list when a provider is added or removed.
We will disclose information if the law requires it, to protect the rights and safety of Resin, our users, or others, or as part of a merger, acquisition, or sale of the company, in which case this policy will continue to apply to the transferred data.
Workspaces and collaborators
People in your workspace can see your name, email address, and profile, plus the project content, comments, version history, presence, and edits their role allows. Viewers can read, comment, and export; Designers, Leads, and Admins can edit.
Workspace Admins manage members, roles, billing, and workspace settings, and can delete the organization and everything in it. If you were invited into an organization's workspace, that organization's Admins control the projects in it.
Security
All traffic to resineda.com and the API is encrypted in transit with HTTPS. Passwords are hashed with bcrypt. Two-factor authentication (TOTP) is available to every account, with encrypted secrets and hashed backup codes. Sessions use short-lived tokens with an HttpOnly, Secure cookie for refresh. Sign-in is rate limited and every attempt is logged. The full list of controls, and the things we have not done yet, is on the security page.
No online service can guarantee absolute security. If we learn of a breach affecting your data, we will tell you by email without undue delay and explain what happened and what we are doing about it. If you find a security problem, email hello@resineda.com.
How long we keep it
Account and project data are kept for as long as your account or organization exists. When a paid plan ends, your projects remain available to view and export; they are not deleted because a subscription lapsed.
Product analytics events are kept for up to 400 days and AI usage records for 180 days. Temporary export bundles are removed 24 hours after they are generated. Sign-in attempt records and server logs are kept only as long as needed for abuse detection and debugging. Invoices and payment records stay with Stripe for as long as tax and accounting law requires.
You can delete your account, or an organization you administer, from Settings at any time without contacting us. Deletion removes your projects, project repositories, library content, conversations with Resin AI, and account records from the live service. Copies in database backups age out on the backup schedule; we will publish that schedule once it is finalized.
Your rights and choices
In the product you can update your profile, change your password, turn two-factor authentication on or off, export any project in full (KiCad or Altium files plus manufacturing outputs), leave a workspace, and delete your account.
Depending on where you live, you may also have the right to access, correct, port, restrict, or object to processing of your personal information, and to complain to a data protection authority. Email hello@resineda.com from the address on your account and we will respond. We may need to verify your identity, and some requests involving an organization's workspace must come from one of its Admins.
Where data is processed
Resin is hosted in the United States, and our providers process data in the United States and in the other locations where they operate. If you use Resin from elsewhere, your information is transferred to and processed in those locations, which may have different data protection laws than your own. Where the law requires a transfer mechanism, we rely on our providers' standard contractual terms.
Changes to this policy
We will update this policy as the product changes, for example when a provider is added. The date at the top shows the current version. For material changes we will tell you in the product or by email before they take effect.
Questions about this page? Contact the Resin EDA team through support.