Data boundaries

Know what leaves the bench before you connect the AI

YProbe separates local design files, per-request hosted processing, optional product telemetry and remote technician packages. “No telemetry” and “nothing leaves the network” are not treated as the same promise.

The short version: your design files stay on your machine. On hosted tiers, the structured board context required for a diagnosis is processed by the hosted AI service for that request. Product telemetry is a separate data stream with plan-specific controls. Enterprise can use a private endpoint or a fully offline route so diagnostic context does not leave its network.

Four data flows that should not be confused

Local project data

Netlists, BOMs, board graphs, captures, session history and rework records are managed as local application data unless a specific outbound feature needs a defined projection.

Hosted diagnostic requests

The structured board and measurement context needed to answer the current diagnostic question is processed by the configured hosted AI route. This is service processing, not product telemetry.

Product telemetry

Trial and lower paid tiers may contribute anonymised or category-level diagnostic summaries as described by the plan. Pro and Pro+ send no product telemetry, while hosted request processing still applies.

Remote technician tasks

A signed, minimised package contains aliased probe points and expected signals. The netlist, BOM and AI reasoning are structurally absent.

Plan and deployment distinctions

RouteDiagnostic processingProduct telemetryDesign files
TrialHosted AIAnonymised session summaries requiredStay local; structured request context is processed by the service
Light / Light+Hosted AICategory-level fault telemetry; can be disabledStay local; structured request context is processed by the service
Pro / Pro+Hosted AINoneStay local; structured request context is processed by the service
Enterprise private endpointCustomer-selected endpointNoneRouting and retention follow the contracted endpoint configuration
Enterprise fully offlineLocal model or approved offline routeNoneDiagnostic context remains inside the customer network

Outbound features require their own consent

Hosted AI, web search and online component or datasheet lookup have separate consent gates. They default to off rather than relying only on a disabled button in the interface. A user can allow the capability that is needed without implicitly enabling every outbound path.

  • AI provider calls use one shared network boundary for routing, caching, privacy checks and timeouts.
  • Optional search and online component lookup do not inherit AI consent automatically.
  • AI-returned net and component names are validated locally against the imported design.
  • Managed local-data exports exclude credentials, licensing state and private identity keys.

Programming-guide uploads

Configuring a scope from its programming guide uses the PDF you select. Hosted processing requires both hosted-AI consent and a separate guide-upload permission. The provider's request-retention policy applies; use a guide you have permission to share. The setup explains the upload before processing begins.

See how programming-guide setup works.

Credentials and diagnostic logs

AI provider credentials are stored through application settings or the user environment rather than committed with the project. DigiKey credentials use the per-user configuration store. Customer and beta installations cannot enable developer AI API prompt logs through a preference, legacy setting or environment variable; retained developer logging requires a verified developer licence.

Application logs and local session data are still operational records. Teams should apply their normal workstation access, backup and retention controls to the machine running YProbe.

Remote debugging is a projection, not a hidden full session

The technician package is assembled from an allow-list. Net names are replaced with stable per-board aliases, free-text fields are scrubbed and unrelated session fields are never written. Returned results are signed, and measurement verdicts are recomputed on the designer's machine from the raw samples.

See the complete remote PCB debugging workflow.

Website and beta-access data

The public beta form is separate from application diagnostic data. Its purpose, legal basis, retention period and privacy contact are described in the website and beta-access privacy notice. Analytics remain blocked until the visitor explicitly accepts the equally weighted cookie choice.