Privacy Policy

Last updated: August 17, 2026

Data We Collect

  • Account information— your email address, used for authentication and communication.
  • Patent claims and analysis inputs— the text you submit for patentability analysis.
  • Usage analytics— anonymous interaction data (pages visited, features used) to improve the service.

How We Use Your Data

We use submitted claims and supporting material to provide the requested assessment. Patentopia does not use submitted claim text or documents to train a shared model.

Data Retention

Anonymous assessment data is automatically deleted 24 hours after submission. Authenticated assessments that remain incomplete and are not recorded as direct-payment cases, including credit-funded assessments, are deleted 30 days after their last recorded update. Completed assessments and direct-payment cases are deleted 24 months after their last recorded update, unless erased sooner. Account and legally required accounting records follow their separate retention obligations.

Third-Party Services

We use the following third-party services to operate Patentopia:

  • Seven Consult ApS — platform operation and development.
  • Supabase — authentication and database hosting.
  • Vercel — hosting and serverless runtime.
  • OpenRouter — model inference for patent analysis.
  • OpenAI — embeddings used for search and evidence grounding when configured.
  • Google Cloud — patent-data queries and OCR when configured.
  • Bright Data — proxied prior-art retrieval when configured.
  • European Patent Office (EPO OPS) — patent bibliographic and prior-art retrieval.
  • Crossref — scholarly-literature metadata retrieval.
  • Stripe — payment processing.
  • Resend — transactional email delivery.

These providers process data only as necessary to deliver their services and are bound by their own privacy policies.

Security & Data Processing

Data is encrypted in transit (TLS) and uses provider-managed encryption at rest. Supported case paths also use application-layer encryption. Access is controlled through authentication, owner and organization checks, row-level security (RLS), and fail-closed service boundaries. Privileged actions on an assessment — approvals and amendments — are written to an append-only audit log.

Anonymous case data submitted without an account is automatically deleted after 24 hours. For a full description of how we process personal data on behalf of our customers, see our Data Processing Framework (GDPR Art. 28).

GDPR Compliance

If you are located in the European Economic Area, you have the right to access, correct, or delete your personal data, and to object to or restrict its processing. To exercise these rights, contact us at the address below.

Contact

For privacy-related inquiries, reach us at info@patentopia.ai.