Uart Debug Terms of Service

Privacy Policy

Effective October 2, 2026

Uart Debug is an experimental browser-based AVR and UART tool. This policy explains what the project processes when you use the site, Google sign-in, compilation, or the AI assistant.

Who is responsible

The Uart Debug project operator is responsible for this service. For privacy questions or data requests, email uartdebug@gmail.com.

Information we process

  • Google sign-in. Google provides a stable account identifier, profile name, email address, and email-verification status. Uart Debug stores a keyed pseudonymous form of the identifier, the profile name for account display, an optional display name you choose in your profile, a masked email, and account timestamps. Changing the display name does not change your Google identity. It does not store Google access tokens or refresh tokens.
  • Sessions and installation identity. Signed cookies identify the browser installation and login session. The installation cookie can last up to 400 days; the session cookie can last up to 30 days. They support authentication, AI Credits, and abuse prevention.
  • Browser-local project data. Without Google sign-in, AVR working files and the project canvas remain in the browser and are not written to an account record. The canvas includes requirements, questions, answers, and the selected device. Interface preferences remain local. Canvas storage also supports unsigned and offline use.
  • Signed-in workspace synchronization. After Google sign-in, Uart Debug may store a complete snapshot of the AVR file workspace and the project canvas in account-scoped SQLite. The file snapshot can contain file names, file contents, C source, YAML specifications, guide edits, grouping, and the file-list state needed to restore the workspace. The canvas is stored separately. Chat history saved by earlier versions may remain in the account records, but the canvas workflow does not use it as AI context. Writes are bounded and independently revisioned; stale revisions are rejected rather than silently replacing newer account data. Before a cloud copy replaces browser-local data, the browser may keep a bounded local recovery copy for conflict and account-switch safety. These recovery copies stay in browser storage and are removed when site data is cleared.
  • AI requests. Account synchronization by itself does not send canvas or workspace data to Google or OpenAI. When you explicitly process the canvas, its requirements, annotations and answers, selected MCU and package, and any current project source, YAML specification and guide are sent to OpenAI to clarify or generate requested project material. A stable pseudonymous browser safety identifier and a per-request ID are also sent for abuse prevention and operational tracing. Google identifiers, profile names, email, and authentication cookies are not included.
  • Official documentation lookup. If local technical references are insufficient, the server may request a public documentation page from Microchip. These requests use the page URL; the canvas, project files, and account identifiers are not sent to Microchip. Retrieved public references may be cached on our server.
  • Usage and security records. The service records request identifiers, model and token usage, AI Credit accounting, timestamps, and pseudonymous account/device links. Web-server logs may include IP address, requested URL, time, referrer, and user agent.
  • Compilation and serial access. Compilation source is written to a temporary server directory and removed after the job. Web Serial data stays between your browser and the selected device and is not sent to Uart Debug servers.

Why we use it

We process this information to provide the requested tools, authenticate users, restore signed-in canvases and AVR workspaces, allocate and account for AI Credits, keep project updates consistent, secure the service, investigate failures, and prevent abuse.

Service providers

DigitalOcean hosts the service. OpenAI processes AI-request content with API storage disabled for application responses; OpenAI may retain limited data for abuse monitoring under its API data controls. Google provides authentication. Google does not receive the synchronized AVR workspace, canvas, or retained legacy chat history from Uart Debug. These providers process data under their own terms and privacy commitments.

We do not sell Google user data, use it for advertising, or send it to OpenAI. Uart Debug does not use Google identity data to train a general AI model.

Retention

  • OAuth login transactions expire after about 10 minutes.
  • Login sessions expire after up to 30 days.
  • Browser installation cookies expire after up to 400 days.
  • Operational web and service logs are normally kept up to 14 days.
  • The canvas workflow does not create separate private server-side AI draft specifications. Legacy draft files from earlier versions may remain until operator cleanup or a handled data request; the current workflow does not run the earlier draft cleanup process.
  • Pseudonymous account, device, and AI Credit ledger records are retained while needed to operate access and prevent repeated free-limit abuse. Automated expiry for these records is still under development.
  • Retained legacy chat history, the latest AVR workspace snapshot, and the latest canvas snapshot are retained with the account data until replaced or removed through an operator-handled data request. Automatic expiry and a self-service deletion/export interface are not currently available.

Your choices and deletion

You may use the non-AI AVR and UART tools without Google sign-in. You can sign out at any time, clear site cookies/local storage in your browser, and revoke Uart Debug in your Google Account connections. Signing out, clearing browser storage, or revoking Google access does not by itself erase a previously synchronized server copy. There is currently no self-service account-data export or deletion control. To request access, correction, or deletion of server-side account data, email uartdebug@gmail.com. Because the service stores only a masked email, the operator will provide verification steps and may ask for recent session or request details. Some minimal accounting or security records may be retained where necessary to prevent fraud or comply with law.

Security and international processing

The service uses HTTPS, signed opaque cookies, restricted server secrets, and pseudonymous identifiers. No online system is completely secure. Hosting and providers may process information in the United States or other countries where they operate.

Children

The service is not directed to children who cannot legally consent to this processing. A parent or guardian should supervise use where local law requires it.

Changes

Material changes will be reflected here with a new effective date. If a change introduces a new use of Google user data, Uart Debug will provide notice and request any required consent before that use begins.