CIRCUIT
Circuit
Menu
Circuit

Privacy Policy

Last updated: 8 October 2026

Who we are

Circuit (meetcircuit.com) is operated from London, UK. We keep the attendance record for the Rooms organisers run on Circuit: who came, and who came back.

The controller is Meet Circuit Ltd, registered in England and Wales under company number 17376774, registered office 86-90 Paul Street, London, EC2A 4NE.

Production data is stored in the United States (AWS us-east-1) via Neon PostgreSQL, and our application servers run there too. UK GDPR applies to your data wherever it is held. See International data transfers below.

Which part of this applies to you

Circuit has three kinds of reader, and they are told different things because different things are true of them.

  • You attend Rooms. An organiser checked you in, or you RSVP’d. You may never have visited a Circuit page.
  • You are a Circuit member. You have an account, and possibly a Card.
  • You run Rooms. You have an organiser account and you decide what happens at your door.

The sections after those three apply to everyone. If more than one describes you, they all apply.

1. If you attend Rooms

What the organiser collects

  • Name, email address
  • Phone number (optional)
  • Social media link (optional)
  • Attendance records: which Rooms you attended, when, and how you were checked in
  • RSVP responses
  • Check-in method (door, self, walk-in, NFC tap, QR, webhook)

What we work out from it

Visit counts, return rates, and whether you are a regular. All computed from attendance records, and shown to the organiser whose Rooms you attended.

Whether you keep your RSVPs. Kept RSVPs count at any organiser on Circuit: where an organiser has chosen it, a strong record lets you RSVP before a Room opens to everyone, on the web or in the Circuit app, or be invited sooner. Missed RSVPs count only at the organiser whose Rooms you missed, and only for nights where the door was run. Nobody is shown a score.

Who’s Here

Some Rooms let guests make themselves visible to other people in the room. It is opt-in, and you can withdraw at any time.

The list is open from 6 hours before the Room starts until 24 hours after it starts. Only your name and avatar are shown. Your email address and your attendance history are never visible to other guests.

If a member brought you as their guest

A Circuit member can bring one guest. If they gave us your name and email address, they told us they had your permission, and we emailed you to say so. That email carries a link that takes you off the list, and you can use it without asking them.

We hold your name and email for that Room’s date and delete them 30 days after it. The extra time is so that somebody who has taken themselves off a list cannot simply be added again. You have no account with us and never need one.

2. If you are a Circuit member

Membership adds an account, and everything below follows from having one. None of it applies to a guest who has simply been checked in.

When you join, we record that you confirmed you are 18 or over, and when. We do not ask for your date of birth.

Your profile

Display name, bio, photo, and your membership status. Your member code is the short identifier embedded in a Circuit Card. You control what a profile shows and can edit or clear it at any time.

Signing in

We store the email addresses you have verified, and you can hold more than one. If you use Sign in with Apple, we also store the stable identifier Apple gives us. Apple may give you a private relay address instead of your own; we store whatever address we receive.

Sign-in codes are stored for 10 minutes and then deleted. Sign-in tokens last until you sign out or delete your account.

Your Circuit Card

A Card is a physical NFC card carrying a member code. When you claim one we record the claim, the time, and the IP address and browser the claim came from, so a Card cannot be quietly taken over by somebody else.

Taps and presence

Tapping a Circuit Block, or having your Card tapped at a door, writes a verified attendance record. We keep the evidence for each accepted tap, not only the first, because that is what makes the record checkable.

Presence at a venue expires 2 hours after the tap. It is not location tracking: Circuit does not read your device location, and a tap tells us you were at a specific reader at a specific moment, nothing more.

Who’s here

Who’s here is off unless you turn it on. When it is on and you have checked in at a room, members in that room who also show their names can see yours, for 2 hours after your tap.

You can turn it on for one room at a time, or choose to be visible by default. If your standing choice is Connections only, your name is shown only to members you are connected with, and only when you are both in the room. A standing choice applies from your next check-in, not to a room you are already in, and we keep a record of when you made it and when you changed it. You can change it in your profile on circuit.fm or in Settings in the app, and turning it off takes effect at once.

A choice you make in one room wins over your standing choice, in either direction. Nobody sees who looked, and a member you have blocked is never shown to you, or you to them.

Notifications

If you use the app and allow notifications, we store a device token from Apple, the platform, the device name you gave it, and when it was last seen. We keep a record of what we sent you.

You can turn notifications off in the app, and the token is deleted when the device unregisters or you delete your account.

Connections with other members

Members can connect with each other. A connection is two-sided by construction: both people act, and neither can create one alone. Seeing another member’s circle requires a live connection, and you can block or report another member at any time.

Rooms your Connections share with you can shape where you are invited.

Rooms Signal finds for you

When you check in at Rooms, Circuit can use that, together with other members’ check-ins, to find Rooms you might want to go to. If several members who go to the same Rooms you do start going somewhere new, that Room can appear in your Signal.

It only ever works in aggregate. Nobody is shown to you, and you are never shown to anyone. We never tell you who, how many, or why: a Room found this way is labelled “Signal” and nothing else. It needs at least five people, and it never changes because of one person. It uses only verified check-ins, never what you saved, said you were going to, or your phone’s location. Organisers never see any of it.

We do not store who you overlap with. We keep only totals per Room, and the list of Rooms found for you, which you can see, export or remove.

We do this because it is how Circuit helps you find Rooms worth going to (legitimate interests). It is on unless you turn it off. “Use my attendance to help Circuit route people” on your Card switches it off: your check-ins then help nobody else, and no Rooms are found for you this way. You can turn it back on at any time.

Paying for things

Paid RSVPs and Card purchases are processed by Stripe, which receives what it needs to take the payment. We do not store card numbers. We keep the record of the hold and the transaction.

Deleting your membership

Deleting your account removes, in one action: your sign-in tokens, codes and verified addresses; your devices and notification settings; your connections, circle access, blocks and reports; your saved rooms; your Card claims; and the receipts from any identity merge.

Your attendance record at an organiser’s Rooms is treated the same way as any guest’s: it is anonymised rather than deleted, so the organiser keeps a count of who was in the room without keeping you.

3. If you run Rooms

What we hold about you

  • Name, email address
  • Password, stored as a bcrypt hash. We cannot read your password.
  • Billing information, processed by Stripe. We do not store card numbers.
  • API credentials, if you use the API

Your role

Circuit and organisers are joint controllers under GDPR Article 26 for attendance data collected at check-in. Circuit provides the infrastructure; you determine the purpose. A joint controller agreement governs how responsibilities are allocated.

Circuit is Data Controller for member profile data, which is the account a member creates with us rather than with you.

You must have a lawful basis for collecting guest email addresses and attendance data, and you should tell your guests that attendance is recorded via Circuit and point them here. If a guest asks you for their data, we will help you answer.

Co-hosts added later

You may add a co-host to a Room after guests have RSVP’d. If that happens we email those guests before anything is shared, and they can object using the link in that email. If they object, their record stays with the original hosts only.

Enterprise and API access

API responses can be configured to return hashed email addresses (SHA-256) rather than plaintext. Outbound webhooks are signed with your secret. All API access is logged, including the requesting IP address and key identifier.

4. Your rights

Under the UK GDPR and EU GDPR, you have the right to:

  • Access. View your data at circuit.fm/my if you are a member, or meetcircuit.com/me as a guest, or request a full export.
  • Portability. Download your attendance records and profile data.
  • Rectification. Update your name, email or profile at any time.
  • Erasure. Request deletion. Your attendance records are anonymised: your name is replaced and your email permanently removed, while the timestamps stay in the organiser’s aggregate count without being linked to you. Members, see Deleting your membership above.
  • Withdraw consent. Unsubscribe from any Circuit email using the link it carries. Opt out of Who’s Here, profile features or notifications at any time.
  • Object. Write to hello@meetcircuit.com.
  • Complain. You may lodge a complaint with the Information Commissioner’s Office at ico.org.uk/make-a-complaint/.

Legal basis: contract performance (running the service), legitimate interest (operating and securing it), and consent (marketing, profile features, cross-venue recognition, Who’s Here, notifications).

5. How long we keep things

  • Guest records. While the organiser’s account is active. Guests with no attendance for 12 months are automatically anonymised.
  • Member accounts. Until you delete them. A membership does not lapse because you have not attended: you can hold a Card and not come for a year without ceasing to be a member. After an account is deleted, Circuit keeps a one-way fingerprint of a university email address that was used for a complimentary Card, solely to prevent the same address being used for a second one.
  • Sign-in codes. 10 minutes.
  • Sign-in tokens, devices, connections, Card claims. Until you sign out, unregister the device, or delete your account.
  • Guest details of someone a member brought. 30 days after the Room’s date, then hard-deleted.
  • Tap evidence. Kept alongside the attendance record it evidences.
  • Notification delivery records. 90 days.
  • Organiser accounts. Until deleted. On deletion all Rooms, guests, attendance records and associated data are permanently removed.
  • Payment records. Retained as long as legally required. Company and tax record obligations can require us to keep a transaction after you have asked us to delete everything else.
  • Audit logs. Retained for security and compliance.
  • Email delivery records. Retained as an audit trail. Pending emails are deleted if you unsubscribe or ask for erasure.

6. Third-party processors

  • Neon, a Databricks company (US)
    PostgreSQL database hosting. All Circuit data is stored here. Neon became part of Databricks in May 2025; Databricks is the entity processing the data, and its own sub-processors are listed at databricks.com/legal/databricks-subprocessors.
  • Vercel (US)
    Application hosting. Processes HTTP requests.
  • Apple (US)
    Push notification delivery to iOS devices, and Sign in with Apple where you use it.
  • Stripe (US)
    Payment processing. PCI-DSS compliant.
  • Resend (US)
    Transactional email delivery. Receives email addresses and Room details.
  • Anthropic (US)
    AI processing, scoped to one organiser’s own data.
  • Klaviyo (US)
    Marketing automation. Receives attendance properties only where the organiser has enabled it.
  • Upstash (EU)
    Rate limiting. Stores hashed request identifiers only. No personal data.

7. International data transfers

Circuit is a UK company. Production data is stored in the United States (AWS us-east-1), and our application servers run there too.

US-based processors (Neon/Databricks, Vercel, Apple, Stripe, Resend, Anthropic, Klaviyo) operate under Standard Contractual Clauses (SCCs) or equivalent safeguards.

We do not transfer data outside the UK/US corridor.

8. Cookies and email tracking

  • circuit_guest
    Stores your guest profile identifier. Persistent, approximately 60 days. Lets us recognise you across Rooms without a password.
  • Session cookie
    Organiser and member sign-in. Expires when you sign out or the session ends.

We do not use third-party tracking cookies, analytics cookies, or advertising scripts.

Email tracking. Some emails sent through Circuit by organisers include open and click tracking so the organiser can tell what is landing. Every such email carries a one-click unsubscribe link, which removes you from that organiser’s future emails immediately. Tracking is per-organiser; some organisers do not send tracked emails at all.

9. AI processing

Circuit uses Anthropic (Claude) for natural language insight queries, recognition email composition, and report narration.

Processing is scoped to the organiser’s own data. Guest information from other organisers is never included. Queries, generated SQL and responses are logged for audit and debugging.

Anthropic processes data under their data processing terms. Data sent to Anthropic is not used to train their models.

10. Security

  • Encryption at rest: AES-256
  • Encryption in transit: TLS 1.3
  • Password storage: bcrypt hashing
  • Database access: row-level security enforced per organiser on core tables
  • Audit logging: data access, exports and administrative actions are recorded with IP address, timestamp and actor identity

11. Children

Circuit membership is for people aged 18 and over. If you are under 18, write to hello@circuit.fm and we will delete your account. We do not knowingly collect personal data from children.

12. Applications

If you apply to work at Circuit, or to be a Circuit Society Founding Member, we use what you send us to consider your application and for nothing else.

Careers

When you apply for a role at circuit.fm/careers, we collect your name, email address, university, course and year (optional), a link or handle (optional), your answers and when you could start. The application is sent by email to careers@circuit.fm and is not stored in the Circuit database. It is used only to assess your application, and replies come from that inbox. Each application is deleted from that inbox 6 months after the role closes.

Founding Members

When you apply to be a Founding Member at circuit.fm/society/apply, we collect your name, university, course, phone number, email address, social links (optional), availability, your answers, a video link (optional), and your confirmation that you are 18 or over. Circuit stores the application, and it is used only to choose the cohort. If you are not selected, we delete it six months after applications for your cohort close. For the first cohort, applications close on 31 October 2026. If you are selected, your application is kept as part of your Founding Member record.

Legal basis: steps you have asked us to take before entering into a contract (considering your application), and legitimate interest in recruiting.

You can ask us to delete either kind of application at any time by emailing hello@meetcircuit.com.

13. Changes to this policy

We may update this policy. Material changes are communicated by email to organisers and posted here at least 30 days before they take effect. Corrections to statements that were inaccurate take effect immediately, because leaving something untrue on the page for 30 days would be worse.

The “Last updated” date at the top of this page shows when it was last revised.