Version 2.3 · Effective from August 2026 · Data fiduciary: Cronilex Intellectual Property Services
When you use patentOS we collect, in order of sensitivity:
The Private chat toggle under the chat box controls this. New accounts start in Public chat: your prompts and the AI's replies are saved to your own account so your history follows you between devices — they are never shown to other users. Switch to Private chat and the text is no longer written to our database at all. ChatLog.query reads "[Metadata only: prompt not stored]". Your browser also keeps a local copy of your chat history on your own device in both modes.
To be equally clear about what DOES happen:
Access to the administrator panel is restricted to authorised patentOS personnel. To operate reminders and assist customers, administrators can view deadline records across accounts together with the account holder's name, email address, and plan. The deadline view includes the title, due date, status, risk level, jurisdiction, IP type, statutory rule, and linked matter or compliance-rule identifiers.
Administrators can mark deadlines as done or cancelled and can add an operational note. Those changes are audit-logged. We use this access to run reminder services, resolve support requests, maintain data quality, investigate incidents, and protect the Service. It is not legal supervision: patentOS personnel do not independently verify every deadline or undertake to monitor your portfolio, and you remain responsible for confirming and meeting filing dates.
We never use your conversations or documents to train an AI model, and we call Anthropic and OpenAI through their commercial APIs, which exclude customer content from model training by default (Anthropic policy, Anthropic retention). "Not used for training" is a different promise from "never transmitted" — see the processor table below for exactly what goes where.
Our production database runs in Supabase Mumbai (ap-south-1). Delivering the product also involves the processors below — including transfers to the United States for AI processing and analytics. We never sell or rent your data.
| Processor | Purpose | Data | Location | Retention |
|---|---|---|---|---|
| Anthropic (Claude API) | Generates AI answers and drafting output; runs web search for cited sources | Your chat messages and derived search queries. Scanned documents are read with OCR on our own servers — a document only goes to Anthropic when you explicitly approve AI-assisted reading for that document | United States | Not used for training. May be retained by Anthropic for up to ~30 days for abuse monitoring under standard API terms |
| OpenAI (embeddings API) | Converts queries and knowledge-base content into numerical vectors for source retrieval | Your query text (for retrieval matching) | United States | Not used for training by default. May be retained by OpenAI for up to 30 days for abuse monitoring. The resulting vectors are stored by patentOS under our own retention policy |
| Supabase | Database and private file storage | Account data, usage metadata, matters, deadlines, uploaded files, invoices | India (Mumbai) — production; Singapore — test environment | Per the retention table below |
| Vercel | Website hosting, content delivery, and cookieless page analytics | Standard web-server request data (IP, user agent, pages viewed) | Global CDN (primary compute: Singapore region) | Short-term operational logs |
| PostHog | Product analytics and session replay — ONLY with your cookie consent | Page views, feature-usage events, masked session recordings. Never prompt or document content | United States | Until you withdraw consent or request deletion |
| Sentry | Error monitoring | Technical error reports (stack traces, request metadata) | United States / EU | 90 days |
| Langfuse | AI-pipeline telemetry | Token counts, latency, prompt hashes, and message counts only — content capture is disabled | EU / United States | Operational telemetry window |
| Upstash | Rate limiting and abuse prevention | Hashed request-counter keys derived from account ID or IP | Global (edge) | Counters expire automatically (minutes to 7 days) |
| Resend | Transactional email (welcome, password reset, deadline reminders, invoices) | Your email address and the message content | United States | Provider delivery logs |
| Razorpay / Stripe | Payment processing (when paid plans are active) | Payment details (handled by the provider — card numbers never touch patentOS), billing address | India (Razorpay) / United States (Stripe) | Per provider policy + 7-year Indian tax records |
| USPTO, EPO and WIPO (patent offices) | Live patent and application searches when your question looks like a prior-art or status lookup | The text of your question, used as the search query. We do not send your account identity | United States (USPTO), Europe (EPO), Switzerland (WIPO) | Per each office's own policy — these are public registries |
| Google Cloud (BigQuery) | Queries the Google Patents public dataset for prior-art results | The text of your question, used as the SQL search term | United States (the public dataset is US-hosted) | Query logs per Google Cloud policy; we store no copy there |
| Google Patents (patents.google.com) | Fetches the page for a specific patent number you mention | The patent number only — not your question text | United States | Standard web-server logs |
| Hostinger / SMTP (alternative mail route) | Transactional email when patentOS is configured to send over SMTP instead of Resend | Your email address and the message content | Per mailbox provider | Provider delivery logs |
| Data | Retention |
|---|---|
| Chat usage metadata | 90 days |
| Chat text (Public chat only — prompts and replies) | Kept in your account until you delete the conversation or your account. In Private chat there is nothing to keep — the text is never written to our database. |
| Your browser's local copy of your chat history | Stored on your own device in both modes. Kept for 1 hour while signed out, 6 hours on the Free plan, and up to 1 year on paid plans. Clear it any time from Settings → Privacy mode → "Clear chat history on this device". |
| Account data (email, name) | Until you delete the account |
| Email delivery log | We record that an email was sent to you — recipient address, subject line, provider and whether it succeeded. We never store the message body. Deleting your account removes your address and the link to you from these records; the anonymous delivery outcome is kept for deliverability diagnostics. |
| Chat file uploads | 30 days, or until account deletion — whichever is sooner |
| Matter documents (docketing) | Until you delete the document, the matter, or your account |
| Matter and deadline records | Until you delete the relevant record, matter, or account, subject to any audit or legal-retention requirement |
| Document extraction cache | Up to 90 days; erased on account deletion |
| Guardrail-flagged prompts | Retained for moderation review and abuse investigation. Unlike ordinary chat metadata these are deliberately excluded from the 90-day purge, so they persist until reviewed and cleared, or until you delete your account. |
| AI-provider side (Anthropic / OpenAI) | Up to ~30 days under their standard API abuse-monitoring terms; never used for training |
| Billing records / GST invoices | 7 years (Indian tax law) — these survive account deletion because the law requires it |
Under India's Digital Personal Data Protection Act, 2023 (DPDPA) and the EU GDPR you can ask us to:
Email privacy@patentos.legal and we'll respond within 30 days (DPDPA / GDPR statutory window).
When we change this policy in a way that affects what we collect or how we use it, we'll email every active user 30 days before the change takes effect. The version number above moves up with every substantive change. (v2.1: corrected document-retention description, added the full processor table and AI-provider retention disclosure, made analytics consent-gated. v2.2: new accounts default to Public chat — chat text is saved to your own account — with a visible Private/Public toggle under the chat box.) (v2.3: disclosed restricted administrator access to stored Public-chat records and deadline records, including administrators' ability to update deadline status and add operational notes.)
Data fiduciary: Cronilex Intellectual Property Services.
Grievance Officer: Samendra Patil
Email: privacy@patentos.legal
Postal address: 2604, Building B8, Blueridge Township, Above HDFC Bank, Hinjewadi Phase 1, Pune, Maharashtra 411057
We acknowledge grievances within 72 hours and aim to resolve them within 30 days. If you are unsatisfied with our response, you may complain to the Data Protection Board of India or your local supervisory authority.