patentOSpatentOSHome

Privacy Policy

Version 2.3 · Effective from August 2026 · Data fiduciary: Cronilex Intellectual Property Services

The 30-second version
  • You choose whether your chat text is stored. New accounts start in Public chat — your messages are saved to your own account so history syncs across devices. Switch to Private chat any time with the toggle under the chat box: then only token counts, latency, intent, and jurisdiction are stored, never the text.
  • Your conversations are not used to train AI models — not ours, and not our AI providers' (Anthropic and OpenAI exclude API data from training by default).
  • Authorised patentOS administrators can access stored Public-chat text and deadline records when needed to operate, secure, troubleshoot, and support the Service. Private-chat text is not available because we do not store it.
  • Documents you upload are stored privately to power your chat and matter features; extracted text is cached for up to 90 days for instant re-use. Deleting your account erases both.
  • Processing your request does send your message to our AI providers (in the United States); under their standard API terms they may retain inputs for up to ~30 days for abuse monitoring — never for training.
  • You can ask us to delete your account and associated data at any time: privacy@patentos.legal.

1. What we collect

When you use patentOS we collect, in order of sensitivity:

  • Account data — your email, name, company name (if provided), country, and an encrypted hash of your password. Required to log you in.
  • Usage metadata — for every chat: input/output token count, cost in cents, response latency, detected intent (e.g. draft-fer-reply), cited jurisdictions, and whether our guardrail flagged the prompt as off-topic.
  • Files you upload — stored privately in our storage (see §2 and the retention table) so your chat and matter features can use them.
  • Matter & deadline records you create — titles, reference numbers, dates, documents, people you attach, notes, status, risk level, jurisdiction, statutory-rule details, and a change history of edits.
  • Billing data (when paid plans are active) — billing address, payment-provider transaction IDs, invoice PDFs. Required by Indian tax law (GST invoices).

2. Chat text and documents — exactly what happens

The Private chat toggle under the chat box controls this. New accounts start in Public chat: your prompts and the AI's replies are saved to your own account so your history follows you between devices — they are never shown to other users. Switch to Private chat and the text is no longer written to our database at all. ChatLog.query reads "[Metadata only: prompt not stored]". Your browser also keeps a local copy of your chat history on your own device in both modes.

To be equally clear about what DOES happen:

  • Your message is sent to Anthropic (and your query to OpenAI for retrieval) to generate the answer. Neither trains on it; both may retain API inputs up to ~30 days for abuse monitoring under their standard terms.
  • Uploaded files are stored in a private bucket so the chat can reference them; they are automatically purged 30 days after upload, or immediately when you delete your account.
  • Documents in your matters are a private vault. Files you attach to a docketing matter are stored — and nothing else: they are never extracted, analysed, or sent to any AI provider. They stay until you delete the document, the matter, or your account.
  • Scanned documents are read on our own servers. If a document has no digital text layer, we read it with local OCR on patentOS infrastructure. AI-assisted reading (sending the document to Anthropic) happens only when you explicitly approve it for that specific document.
  • Extracted text is cached for up to 90 days (keyed by the file's SHA-256 hash) so re-uploading the same file is instant. The cache is scoped to your account and erased on account deletion.
  • Guardrail-flagged prompts are retained in redacted form for moderation review. These are held outside the routine 90-day purge until reviewed and cleared.
  • Authorised administrators can review stored Public-chat records, including prompts, privacy redaction markers, feedback, provider, token/cost totals, latency, and moderation flags. We use this access for customer support, abuse and security review, quality investigation, and operation of the Service. It does not make chats public or visible to other customers. In Private chat, administrators see metadata and the placeholder described above, not your message text.
Switching modes: use the Private chat / Public chat toggle directly under the chat box, or Account → Privacy mode. Changing it takes effect immediately for new messages. It also affects an existing conversation the next time you add to it: because your browser re-sends that conversation when it saves, continuing an old thread after switching to Private erases its previously stored text from our database, and continuing one after switching to Public stores text that had not been stored before. Threads you never reopen keep whatever was stored at the time. Your browser keeps its own local copy on your device in either mode. Either way, your messages are never used to train AI models.

3. Administrative access and deadline operations

Access to the administrator panel is restricted to authorised patentOS personnel. To operate reminders and assist customers, administrators can view deadline records across accounts together with the account holder's name, email address, and plan. The deadline view includes the title, due date, status, risk level, jurisdiction, IP type, statutory rule, and linked matter or compliance-rule identifiers.

Administrators can mark deadlines as done or cancelled and can add an operational note. Those changes are audit-logged. We use this access to run reminder services, resolve support requests, maintain data quality, investigate incidents, and protect the Service. It is not legal supervision: patentOS personnel do not independently verify every deadline or undertake to monitor your portfolio, and you remain responsible for confirming and meeting filing dates.

4. AI training

We never use your conversations or documents to train an AI model, and we call Anthropic and OpenAI through their commercial APIs, which exclude customer content from model training by default (Anthropic policy, Anthropic retention). "Not used for training" is a different promise from "never transmitted" — see the processor table below for exactly what goes where.

5. Who processes your data, where, and for how long

Our production database runs in Supabase Mumbai (ap-south-1). Delivering the product also involves the processors below — including transfers to the United States for AI processing and analytics. We never sell or rent your data.

ProcessorPurposeDataLocationRetention
Anthropic (Claude API)Generates AI answers and drafting output; runs web search for cited sourcesYour chat messages and derived search queries. Scanned documents are read with OCR on our own servers — a document only goes to Anthropic when you explicitly approve AI-assisted reading for that documentUnited StatesNot used for training. May be retained by Anthropic for up to ~30 days for abuse monitoring under standard API terms
OpenAI (embeddings API)Converts queries and knowledge-base content into numerical vectors for source retrievalYour query text (for retrieval matching)United StatesNot used for training by default. May be retained by OpenAI for up to 30 days for abuse monitoring. The resulting vectors are stored by patentOS under our own retention policy
SupabaseDatabase and private file storageAccount data, usage metadata, matters, deadlines, uploaded files, invoicesIndia (Mumbai) — production; Singapore — test environmentPer the retention table below
VercelWebsite hosting, content delivery, and cookieless page analyticsStandard web-server request data (IP, user agent, pages viewed)Global CDN (primary compute: Singapore region)Short-term operational logs
PostHogProduct analytics and session replay — ONLY with your cookie consentPage views, feature-usage events, masked session recordings. Never prompt or document contentUnited StatesUntil you withdraw consent or request deletion
SentryError monitoringTechnical error reports (stack traces, request metadata)United States / EU90 days
LangfuseAI-pipeline telemetryToken counts, latency, prompt hashes, and message counts only — content capture is disabledEU / United StatesOperational telemetry window
UpstashRate limiting and abuse preventionHashed request-counter keys derived from account ID or IPGlobal (edge)Counters expire automatically (minutes to 7 days)
ResendTransactional email (welcome, password reset, deadline reminders, invoices)Your email address and the message contentUnited StatesProvider delivery logs
Razorpay / StripePayment processing (when paid plans are active)Payment details (handled by the provider — card numbers never touch patentOS), billing addressIndia (Razorpay) / United States (Stripe)Per provider policy + 7-year Indian tax records
USPTO, EPO and WIPO (patent offices)Live patent and application searches when your question looks like a prior-art or status lookupThe text of your question, used as the search query. We do not send your account identityUnited States (USPTO), Europe (EPO), Switzerland (WIPO)Per each office's own policy — these are public registries
Google Cloud (BigQuery)Queries the Google Patents public dataset for prior-art resultsThe text of your question, used as the SQL search termUnited States (the public dataset is US-hosted)Query logs per Google Cloud policy; we store no copy there
Google Patents (patents.google.com)Fetches the page for a specific patent number you mentionThe patent number only — not your question textUnited StatesStandard web-server logs
Hostinger / SMTP (alternative mail route)Transactional email when patentOS is configured to send over SMTP instead of ResendYour email address and the message contentPer mailbox providerProvider delivery logs

6. How long we keep things

DataRetention
Chat usage metadata90 days
Chat text (Public chat only — prompts and replies)Kept in your account until you delete the conversation or your account. In Private chat there is nothing to keep — the text is never written to our database.
Your browser's local copy of your chat historyStored on your own device in both modes. Kept for 1 hour while signed out, 6 hours on the Free plan, and up to 1 year on paid plans. Clear it any time from Settings → Privacy mode → "Clear chat history on this device".
Account data (email, name)Until you delete the account
Email delivery logWe record that an email was sent to you — recipient address, subject line, provider and whether it succeeded. We never store the message body. Deleting your account removes your address and the link to you from these records; the anonymous delivery outcome is kept for deliverability diagnostics.
Chat file uploads30 days, or until account deletion — whichever is sooner
Matter documents (docketing)Until you delete the document, the matter, or your account
Matter and deadline recordsUntil you delete the relevant record, matter, or account, subject to any audit or legal-retention requirement
Document extraction cacheUp to 90 days; erased on account deletion
Guardrail-flagged promptsRetained for moderation review and abuse investigation. Unlike ordinary chat metadata these are deliberately excluded from the 90-day purge, so they persist until reviewed and cleared, or until you delete your account.
AI-provider side (Anthropic / OpenAI)Up to ~30 days under their standard API abuse-monitoring terms; never used for training
Billing records / GST invoices7 years (Indian tax law) — these survive account deletion because the law requires it

7. Your rights

Under India's Digital Personal Data Protection Act, 2023 (DPDPA) and the EU GDPR you can ask us to:

  • Show you all data we hold on you
  • Correct any inaccurate data
  • Delete your account and associated data (billing/GST records are retained for 7 years as legally required — everything else goes)
  • Export your data in a machine-readable format
  • Withdraw consent for analytics or processing at any time

Email privacy@patentos.legal and we'll respond within 30 days (DPDPA / GDPR statutory window).

8. Cookies and analytics

  • Strictly necessary: next-auth.session-token (keeps you signed in), patentos-currency (INR/USD preference), patentos-country (country inferred from your IP, so prices show in the right currency), and patentos-cookie-consent (remembers your consent choice).
  • Analytics (consent-based): with your consent we use PostHog for product analytics and masked session replay. Rejecting the banner keeps PostHog capturing OFF. Vercel provides cookieless, aggregate page statistics as part of our hosting.
  • No advertising cookies. Ever.

9. Updates to this policy

When we change this policy in a way that affects what we collect or how we use it, we'll email every active user 30 days before the change takes effect. The version number above moves up with every substantive change. (v2.1: corrected document-retention description, added the full processor table and AI-provider retention disclosure, made analytics consent-gated. v2.2: new accounts default to Public chat — chat text is saved to your own account — with a visible Private/Public toggle under the chat box.) (v2.3: disclosed restricted administrator access to stored Public-chat records and deadline records, including administrators' ability to update deadline status and add operational notes.)

10. Contact & grievances

Data fiduciary: Cronilex Intellectual Property Services.

Grievance Officer: Samendra Patil
Email: privacy@patentos.legal
Postal address: 2604, Building B8, Blueridge Township, Above HDFC Bank, Hinjewadi Phase 1, Pune, Maharashtra 411057

We acknowledge grievances within 72 hours and aim to resolve them within 30 days. If you are unsatisfied with our response, you may complain to the Data Protection Board of India or your local supervisory authority.