1. Scope
This Privacy Policy applies to the Tersa EDA website, account services, web and mobile applications, engineering workspaces, remote APIs, and Tersa MCP services (collectively, “Tersa”). Tersa EDA is the product and service name used in this policy. This page is public and does not require a Tersa account.
2. Information you provide
Depending on the features you use, we may process:
- your email address, display name, email-verification state, and account preferences;
- a password verifier for email/password accounts—we do not store plaintext passwords;
- support messages and beta-access requests you choose to send;
- projects, schematics, model data, netlists, simulation settings, requested measurements, and results that you submit to engineering features;
- MCP authorization choices, granted scopes, connection identifiers, tool names, execution status, duration, job identifiers, error codes, and usage totals.
3. Google Sign-In and Google user data
When you choose “Continue with Google,” Tersa receives a signed identity token and uses the Google account subject identifier, verified email address, and display name to authenticate you and create or access your Tersa account. Tersa does not receive your Google password and does not request access to Gmail, Google Drive, Google Calendar, contacts, or other Google Workspace content for this sign-in flow.
Google user data is used only to provide and secure account sign-in, account recovery and user-facing Tersa features. We do not sell Google user data, use it for targeted advertising, transfer it to data brokers, determine creditworthiness, or use it to train generalized AI or machine-learning models. We disclose it only to service providers acting for Tersa when necessary to operate or secure the service, or when legally required.
After verification, Tersa stores the Google account subject identifier, verified email address, display name, and email-verification state as part of the linked Tersa account. The Google identity token is processed transiently to verify the sign-in and is not stored as an account credential.
Tersa’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
3A. Sign in with Apple
When you choose Sign in with Apple, Tersa receives a signed Apple identity token, a stable provider subject, and the email address and name that Apple makes available. Tersa verifies the token signature, issuer, audience, expiry, and one-time nonce on the server. Apple credentials are used only for authentication, account security, and account deletion.
Deleting an Apple-backed Tersa account requires a fresh Apple authorization. Tersa exchanges that one-time authorization code server-side and asks Apple to revoke the resulting grant before deleting the Tersa account and associated cloud data.
4. Engineering content and MCP execution
Tersa processes engineering content to save your work, validate inputs, run requested simulations, return structured results, diagnose failures, enforce quotas, and protect the service. Native simulation work is executed in constrained infrastructure. Privacy-safe MCP activity records exclude full netlists, access tokens, and response payloads; simulation jobs themselves may contain the input and result needed to perform the task you requested.
5. Technical data, cookies, analytics, and telemetry
We process security and operational data such as timestamps, truncated or security-relevant network information, browser or application type, authentication events, request status, diagnostics, and service performance. The public website uses SecurePrivacy to manage consent, Google Analytics 4 for consent-controlled analytics, and Ahrefs Web Analytics to understand site performance and discovery. You can change cookie choices through the consent controls shown on the website.
Application telemetry follows an allowlist. It must not contain passwords, tokens, email addresses, display names, free-form user text, project names, netlists, model contents, component values, result vectors, contacts, photos, advertising identifiers, or precise location. Raw mobile telemetry is retained for no more than 30 days; an unsent local queue is limited to seven days.
6. How we use information
- provide authentication, account, project, simulation, synchronization, dashboard, and MCP features;
- send requested verification, password-recovery, security, and support messages;
- protect accounts, prevent abuse, rotate or revoke credentials, and enforce service limits;
- debug failures, monitor reliability, understand aggregate feature usage, and improve user-facing functionality;
- comply with law, enforce our Terms, and protect users, Tersa, and the public.
7. When information is shared
We do not sell personal information. We may share the minimum necessary information with infrastructure, content-delivery, authentication, analytics, consent-management, email, and security providers that process data for Tersa under appropriate restrictions. This includes services used to host the public site and APIs, deliver email, verify Google identity tokens, and operate consented analytics. We may also disclose information when required by law, to respond to lawful process, or to protect rights and safety. If Tersa is reorganized or transferred, applicable information may move with the service subject to this policy and law.
8. Security
We use HTTPS, access controls, network separation, bounded execution, audit and monitoring controls, and credential rotation. Passwords are processed with a salted password derivation function. Access and refresh credentials are random values and only their cryptographic hashes are persisted. Google ID tokens are verified server-side for issuer, signature, audience, expiry, subject, and verified email. No method of storage or transmission is completely secure, so we cannot guarantee absolute security.
9. Retention and deletion
We retain account and product data for as long as needed to provide Tersa, maintain security, resolve disputes, meet legal obligations, and operate backups. Sessions and one-time action credentials expire or are revoked. Operational retention is limited according to the type and purpose of the record; raw mobile telemetry is limited as described above.
You may delete your account and associated personal data through the Tersa account deletion page, from the account settings in the Tersa app, or by emailing help@tersaeda.com from your registered address. Account deletion removes active account credentials, linked sign-in identities, sessions, and account-scoped MCP activity. Some records may remain temporarily in protected backups or when retention is required for security, fraud prevention, dispute resolution, or law. We will explain any material exception that applies to your request.
10. International processing
Tersa and its providers may process information in countries other than your own. Where required, we use appropriate safeguards for international transfers and apply this policy to the information wherever it is processed.
11. Children
Tersa is intended for engineering, education, and technical work and is not directed to children under 13. If local law requires a higher minimum age to consent to online services, that higher age applies. Contact us if you believe a child provided personal information without the required authorization.
12. Your choices and rights
Depending on your location, you may have rights to access, correct, export, restrict, object to processing of, or delete personal information. You may sign out, revoke MCP client grants from the MCP dashboard, change cookie consent, or ask us to act on a data request. We may need to verify your identity before fulfilling a request.
13. Changes to this policy
We may update this policy as Tersa evolves. We will update the effective date and provide additional notice when a change materially affects how personal or Google user data is used.
14. Contact
For privacy questions or requests, email help@tersaeda.com. For general product questions, email hello@tersaeda.com.