Privacy Policy
Draft of 2026-07-11 · Effective date: [none — draft]
The short version: your invention data stays in your vault until you run a feature that needs to send part of it somewhere — and this page lists exactly what leaves, where it goes, and when. There are no analytics scripts, no ad trackers, and no third-party fonts on any page.
1. What we store
- Account data — email address and password hash (password sign-in is handled by our authentication system; we never store plaintext passwords).
- Your Content — invention disclosures, uploaded evidence files, extracted structure, interview answers, generated drafts, figures, review findings, and export packets.
- Search results — prior-art reports and literature matches produced for you, stored so you can revisit them.
- Billing records — your plan, credit balance and usage, and Stripe identifiers. Card numbers never touch our servers (see §3).
- Activity records — an append-only audit log of significant actions on your account (e.g. “patent check run”), kept for integrity and support.
- Applicant details — if you enter them, we store each inventor’s name and residence, one correspondence address, six entity-status answers, and a docket number with the invention. We use these details to pre-fill USPTO Forms SB/16, SB/15A, or SB/15B. They do not leave the Service unless you turn on Include in export. We never collect Social Security numbers or dates of birth. You may delete the details at any time, removing the correspondence record and every inventor entry.
- Connected model keys — if you bring your own model-provider API key, it is stored encrypted at rest; only a masked hint is ever displayed.
2. What leaves our servers, where, and when
Nothing about your invention is transmitted to anyone on page load. Data leaves only when you invoke a feature that needs it, as follows:
| When you… | We send… | To… |
|---|---|---|
| Run Patent Check | Search text derived from your disclosure | PatentsView (search.patentsview.org), a public USPTO-data search service |
| Run the scientific-literature search | Search text derived from your disclosure | Semantic Scholar (api.semanticscholar.org) |
| Use citation / reference checks on an uploaded paper | Bibliographic metadata and reference strings from that document | Crossref, OpenAlex, Semantic Scholar, PubMed, Unpaywall, arXiv, doi.org |
| Run an AI-assisted step (drafting, review, structure extraction) with a model configured | The prompt for that step, which includes the relevant disclosure or draft text | The model provider configured for your account — one of Anthropic, OpenAI, DeepSeek, Moonshot, Alibaba, Google, or Zhipu — under our agreement or your own key |
| Pay or manage billing | Payment details, entered in Stripe’s own component | Stripe — card data goes to Stripe directly and never touches our servers |
Every AI feature also has a deterministic offline mode: with no model configured, those steps run locally on our servers and nothing is sent to any model provider. [FOUNDER: confirm which model provider(s) the hosted product configures by default, and link each provider’s data-use terms]
3. What we deliberately don’t do
- No analytics or advertising scripts, no tracking pixels, no session recording.
- No third-party fonts or CDNs at runtime — every asset is served from our own servers. The one exception is Stripe’s payment script, loaded only on the billing page and only when payments are enabled.
- No sale of personal data, and no use of Your Content to train models. [COUNSEL: verify the training representation against each provider’s terms]
- No reading of your vault by staff except [FOUNDER: define support-access policy].
4. Cookies and local storage
We use a session cookie (to keep you signed in) and a CSRF cookie (to protect forms) — both first-party and required for the Service to function; there are no advertising or cross-site cookies. Your browser’s local storage holds interface preferences only (for example: sidebar width, selected model tier and effort, card-versus-list view).
5. Demo mode
Self-hosted or evaluation deployments can enable a shared local demo account. Demo-mode data is visible to anyone with access to that deployment, is not tied to a personal account, and carries no confidentiality commitment. The hosted product uses individual email-and-password accounts.
6. Retention and deletion
You can delete inventions and uploaded documents in the app at any time; deleting an invention removes the invention record while any evidence files you attached remain in your library until you delete them too. Audit records are append-only and retained for account integrity. Account closure and full erasure: [FOUNDER: define the account-deletion process and retention windows — no in-app account deletion exists today; this must be built or handled via support before this policy ships]
7. Security
Passwords are stored as salted hashes; connected model keys are encrypted at rest; access to Your Content is scoped to your account. No internet service can promise perfect security — if we learn of a breach affecting your data we will notify you. [COUNSEL: breach-notification commitments per applicable law]
8. Your rights
[TO BE COMPLETED BY COUNSEL: jurisdiction-dependent rights (GDPR/CCPA etc.), legal bases, international transfer mechanisms, children’s-privacy statement, and the controller’s identity — depends on the legal entity and where the product operates.]
9. Changes and contact
Changes will be posted here with a new effective date; material changes will be emailed to account holders first. Contact: [FOUNDER: contact email]