# Patlas Privacy Policy

**Last updated:** September 7, 2026

This Privacy Policy explains what data Patlas ("we," "us," operated by Yodha Systems LLC) collects when you use the Patlas Service, why, and how it's handled. It applies alongside our [Terms of Service](./terms-of-service.md).

If you are using the Service on behalf of an organization (a firm, employer, or client), that organization is our "Customer" and controls the account; individuals it authorizes to use the Service are "End Users." Where this Policy says "you," it refers to whichever of these actually interacts with the Service in context.

**Roles under privacy law.** For personal data of a Customer's own End Users, the Customer is the controller (it decides why and how that data is processed) and Patlas acts as a processor on the Customer's instructions. It is the Customer's responsibility, not Patlas's, to provide any privacy notices to and obtain any consents from its own End Users that applicable law requires for the Customer's use of the Service — this Policy describes what Patlas itself does with data, not what a Customer owes its own End Users.

## 1. What We Collect

**Account and authentication data:**
- Your API key is stored only as a SHA-256 hash — we never store the plaintext key after it's issued to you.
- Your assigned tier (Free / Pay-as-you-go / Subscription) and account status.
- If you sign in with GitHub, we store your GitHub user ID (not your username or email) linked to your hashed API key, so we can recognize returning sign-ins from that GitHub account. GitHub's OAuth flow also requests your email address (a requirement of the library we use to complete the login, not something we choose to collect) — it passes through our server transiently during login but is never stored anywhere.
- A record that you accepted the then-current Terms of Service on a given date, linked to your hashed API key — kept so there's a durable record of acceptance beyond the login flow itself. Unlike the rest of your account data, this record is retained even after you delete your account (see Section 5).

**Usage data**, recorded for every call to a product/analysis tool (`search_prior_art`, `get_patent_detail`, `compare_claims` — not `submit_feedback`, `start_checkout`, or `regenerate_api_key`, which make no upstream/Claude calls and record nothing here):
- Tool name
- A per-request ID
- Which upstream APIs were called to fulfill the request
- Claude token counts and an associated cost estimate
- The patent IDs and result ranks involved in the request (e.g. which candidates a search returned and in what order) — used for click-through/relevance analytics
- Timestamp

**Feedback data**, only when you use `submit_feedback`:
- A helpful/not-helpful signal and an optional free-text comment, linked to the request it refers to

**Billing data:**
- Your Stripe customer ID and subscription item ID. Payment card details are handled entirely by Stripe — we do not receive or store your card number.
- A SHA-256 hash of your API key (never the plaintext key) is sent to Stripe as checkout/subscription metadata, so we can match a completed payment or a canceled/failed subscription back to your account. This is the same one-way hash described above — it cannot be used to authenticate as you.

**Query content:**
- The invention descriptions and other text you submit to `search_prior_art`, `get_patent_detail`, and `compare_claims` are processed to generate results (see Section 2 — this content is sent to Anthropic's Claude API to be analyzed).

**Infrastructure/operational logs:**
- Our hosting provider, Cloudflare, logs standard request metadata as part of operating and securing the Service — including IP address, request headers, approximate geographic region, and timing/error data. This is Cloudflare's operational and security logging (used for abuse prevention, debugging, and uptime monitoring), separate from the application data listed above; we do not separately copy it into our own database.

## 2. Third Parties We Share Data With

To operate the Service, request data is sent to:

- **Anthropic (Claude API)** — the invention description and patent text you submit are sent to Claude for similarity/comparison reasoning. Per [Anthropic's Commercial Terms of Service](https://www.anthropic.com/legal/commercial-terms), API input is not used to train Anthropic's models by default, and detailed retention terms are governed by Anthropic's Data Processing Addendum. **Do not submit information you aren't comfortable sharing with a third-party AI provider** (e.g. as-yet-unfiled, highly sensitive invention details) until you've reviewed [Anthropic's privacy practices](https://privacy.claude.com/).
- **USPTO PatentsView** and **EPO/Espacenet (OPS)** — queried to retrieve patent metadata and claims text; only the search terms/patent IDs needed for the lookup are sent.
- **Stripe** — processes payments and receives usage-metering events (tool-call counts) for Pay-as-you-go billing, plus your customer/subscription identifiers and a one-way SHA-256 hash of your API key (never the plaintext key).
- **Cloudflare** — our hosting/infrastructure provider; processes all traffic to the Service and provides the operational logging described in Section 1.

We do not sell your data to third parties, and we do not use your query content to train models we operate ourselves. See our [Terms of Service](./terms-of-service.md) §6 for the full commitment on how we use content you submit.

## 3. Why We Collect This

- **To provide the Service** — fulfilling search/comparison requests requires sending your query to Claude and to patent data APIs.
- **To bill you accurately** — usage records are the basis for Pay-as-you-go metering and dispute resolution.
- **To operate and improve the product** — aggregate usage and feedback data (e.g. rank-level click-through) helps us understand which results are useful.
- **To secure the Service** — infrastructure logs support abuse prevention, fraud detection, and debugging.

## 4. Data Retention

Retention differs by data category and by system — this section is deliberately specific rather than a single blanket promise, since one blanket statement can't accurately describe both what we control directly and what our processors independently retain.

**In our own database (D1), for as long as your account remains active, and until you delete it (Section 5):**
- Account/authentication data, usage data, feedback data, and billing identifiers (Section 1) — no fixed automatic deletion schedule; deletion is self-service and immediate on our side (Section 5), not scheduled.
- A generated Patent Landscape & Prior-Art Audit report (Word document), if you've purchased one — kept for a limited, shorter server-side window (independent of your account's own lifetime) purely so a repeat request doesn't require paying again; requesting it again after that window regenerates it at no extra charge. It is never hosted at a public web address — only delivered directly to your own authenticated session.

**In our own database, surviving your account's deletion:**
- The minimal Terms-acceptance audit record (Section 1) — kept as an audit/compliance record, unlinked from your other data once deleted.
- Data we're independently legally required to retain regardless of a deletion request (e.g. billing/tax records, or data subject to a legal hold).

**With our processors, independent of what we delete on our side:**
- **Stripe** retains billing/payment records per its own retention practices and applicable financial/tax law — deleting your Patlas account does not delete Stripe's own records of a completed transaction.
- **Cloudflare** retains infrastructure/operational logs (Section 1) per its own operational retention practices — this is Cloudflare's logging, not data we hold or control directly.
- **Anthropic** retains API input per its own Data Processing Addendum and Commercial Terms (Section 2) — we do not control Anthropic's retention of content already sent to it before you delete your account.

Deleting your Patlas account stops *us* from collecting or holding more of your data, and removes what we directly control (Section 5) — it does not reach back into a processor's own independently-retained records for data already sent to them, or override a legal hold or a regulatory retention requirement.

## 5. Your Rights

You may:
- Request a copy of the data we hold about your account (contact us — see below).
- **Delete your account and all associated data yourself, without contacting us:** send an authenticated `POST` request to `https://patlas.dev/account/delete`, authenticated the same way your MCP client already is — an `Authorization: Bearer` header carrying your OAuth token (or, if you hold a raw API key, `x-api-key`). We initiate deletion of your account record, usage history, and feedback immediately, and it cannot be undone once done. We also initiate cancellation of any active Stripe subscription as part of the same request — if Stripe cancellation fails (e.g. an outage), your account is *not* deleted and nothing is left half-done: your data stays intact so the request can simply be retried once Stripe recovers, rather than deleting your access while billing continues. We don't require you to email support first. One exception, consistent with Section 4: a minimal record that you accepted a specific version of these Terms on a given date is retained even after deletion, as an audit/compliance record — it is not linked back to any of the data above once deleted. See Section 4 for what a processor (Stripe, Cloudflare, Anthropic) may independently retain regardless of this deletion.
- **Regenerate your API key** to move your account onto a brand-new, independent credential — the old key stops working immediately, while your tier and history carry over to the new one. This is the self-service path to stop a specific, possibly-compromised key from working without losing your account. Note the tradeoff: since your key is normally re-derivable by signing in with GitHub again, regenerating breaks that recovery path going forward — the new key is the only way back into the account afterward, so save it. (We don't offer a separate "pause without replacing" revoke — doing so without also giving you a new usable credential would just lock you out of your own account.)

You can also reach us at support@yodhasystems.com for any of the above, or for anything not covered by the self-service endpoint (e.g. a copy of your data). We aim to respond to those requests within 30 days. Either way, deletion is subject to what we're legally required to retain (e.g. billing/tax records) — see Section 4.

**California residents (CCPA/CPRA):** the rights above also cover the right to know what personal information we collect and the right to non-discrimination for exercising your privacy rights. We do not sell or share your personal information for cross-context behavioral advertising.

## 6. Security

We maintain administrative, technical, and organizational safeguards designed to protect your information against unauthorized access, alteration, disclosure, and destruction. These currently include, without limitation: API keys stored as SHA-256 hashes rather than plaintext, encryption in transit (HTTPS/TLS), network-level DDoS and bot-abuse protection via our hosting provider, signature verification on payment-provider webhooks, and continuous uptime monitoring with alerting. No system is perfectly secure, and we cannot guarantee absolute security.

If we experience a security incident affecting your data, we will notify affected customers and, where legally required, the relevant regulator, without undue delay after we become aware of it.

## 7. Cookies

Signing in with GitHub sets two short-lived cookies, both strictly necessary for that login flow, both HTTP-only and Secure, both expiring within 10 minutes, and neither used for tracking, analytics, or advertising:
- `patlas_oauth_flow` — carries your login attempt (which client is requesting access) across the redirect to GitHub and back.
- `state` — a standard OAuth CSRF-protection value set by the GitHub login library we use, verified on GitHub's redirect back to us to confirm the callback actually corresponds to a login we initiated.

## 8. Children's Privacy

The Service is not directed at, and we do not knowingly collect data from, individuals under 18.

## 9. International Users

Patlas is available to customers outside the United States, including in the European Economic Area (EEA), United Kingdom, and Switzerland. This section applies to those users in addition to the rest of this Policy.

**Lawful basis for processing.** We process your data to perform our contract with you (providing the Service you signed up for), for our legitimate interests (billing accuracy, fraud prevention, product analytics), and, where required, with your consent.

**International data transfers.** Patlas and its sub-processors (Anthropic, Stripe, Cloudflare) process data in the United States. Where required by applicable law, transfers of personal data outside the EEA/UK rely on the safeguards each sub-processor maintains as part of its own standard terms: [Anthropic's Data Processing Addendum](https://www.anthropic.com/legal/data-processing-addendum), [Stripe's Data Processing Agreement](https://stripe.com/legal/dpa), and [Cloudflare's Data Processing Addendum](https://www.cloudflare.com/cloudflare-customer-dpa/) each incorporate Standard Contractual Clauses. We have not independently executed a separate SCC agreement with each sub-processor beyond what their own standard terms already provide — if your use of the Service requires confirmation that a specific transfer mechanism applies to your account's tier/plan with each vendor, contact us and we'll help confirm it, rather than us asserting a blanket guarantee here that we haven't individually verified against every plan tier.

**Your GDPR/UK GDPR rights**, in addition to Section 5 above: the right to access, correct, delete, or port your data; the right to restrict or object to certain processing; and the right to lodge a complaint with your local data protection supervisory authority.

**Sub-processors:**

| Sub-processor | Purpose | Data processed |
|---|---|---|
| Anthropic (Claude API) | AI reasoning over patent similarity/comparison | Invention descriptions, patent claims text |
| Stripe | Payment processing, usage metering | Billing/customer identifiers, tool-call counts, a one-way hash of your API key |
| Cloudflare | Hosting, infrastructure, security | All request traffic; operational/security logs |
| USPTO PatentsView / EPO Espacenet | Patent data lookups | Search terms, patent IDs only — no account or billing data |

If we add or change a sub-processor in a way that materially changes how your data is handled, we will update this table and the "Last updated" date.

**Enterprise customers.** Law firms or enterprise customers that need a formal Data Processing Agreement covering their own end users' personal data may contact us to discuss one. We do not yet have a counsel-approved DPA template ready to sign on request — this is tracked as a real gap, not a live offer of an immediately available document.

## 10. Changes to This Policy

We may update this Policy from time to time. Non-material changes are effective upon posting, reflected by an updated "Last updated" date.

Material changes — particularly any change that expands how we use or share your data — take effect no sooner than 14 days after posting. As explained in [Terms of Service](./terms-of-service.md) §15, we do not currently collect an email address for most accounts, so checking this page's "Last updated" date is, today, the actual way you learn of a change — not a formality on top of a separate notice we send you. Where applicable law requires a stronger notice or consent mechanism for a specific change, we will provide it for that change specifically.

## 11. Contact

Questions about this Policy: support@yodhasystems.com. Yodha Systems LLC, New Jersey, USA.
