Patchism LogoPATCHI

Privacy Policy

Last updated: 11/07/2026

This Privacy Policy explains how Patchi ("the App") collects, uses, stores, and protects personal data when you use our website and application available at Patchi.

What data the App collects

Patchi currently offers optional user accounts while preserving a local-first guest mode.

Depending on how you use the App, Patchi may process the following categories of data:

  • Account identity data such as your name, email address, and optional avatar;
  • Authentication and security data such as password credentials, verification status, password-reset tokens, session identifiers, IP address, and user agent information;
  • Anti-abuse verification data processed when protected account actions use Cloudflare Turnstile, such as browser, device, network, and challenge result information needed to distinguish legitimate users from automated abuse;
  • Account lifecycle data such as account role, recent authenticated activity, and deletion status;
  • Technical and infrastructure data such as request logs, diagnostics, browser and device information, date and time of access, service security data, error reports, performance traces, and application logs.

Patchi's core studio-planning data remains local-first in this feature. Guest projects, signed-in studio setups, imported/exported JSON data, and similar planning content stay stored locally in the browser on your device and are not used by Patchi as cloud-synced account storage in the current version of the product.

Why the App processes this data

Patchi processes personal and technical data for the following purposes:

  • To create, verify, secure, and maintain user accounts;
  • To provide sign-in, sign-out, email verification, and password-reset flows;
  • To protect the service against abuse, malicious traffic, and unauthorized access;
  • To operate, monitor, secure, debug, and improve the App;
  • To track account lifecycle status, including authenticated activity and staged deletion handling.

Legal basis

Depending on the processing activity, Patchi relies on one or more of the following legal bases:

  • Performance of a contract or pre-contractual measures for account creation, authentication, and account management;
  • Legitimate interests for operating the App, securing the service, preventing abuse, and troubleshooting;
  • Compliance with legal obligations where retention, deletion, or disclosure is required by applicable law.

Hosting and infrastructure providers

Patchi is currently hosted by Vercel.

As part of hosting and delivering the service, Vercel may process technical and service-generated information such as log files, IP addresses, diagnostics, and request metadata. Vercel describes these categories in its privacy documentation: https://vercel.com/legal/privacy-policy

Hosting provider: Vercel Inc. 440 N Barranca Ave #4133 Covina, CA 91723 United States

Audience analytics are provided by Umami through its cloud analytics platform. The data collected in this context consists of anonymized usage statistics and does not allow Patchi to directly identify individual users.

Account creation and password-reset flows may be protected by Cloudflare Turnstile, an anti-abuse service provided by Cloudflare. Turnstile may process technical information from your browser, device, and network connection to verify that the request is legitimate and to help protect Patchi against spam, automated account creation, credential abuse, and malicious traffic. Cloudflare's privacy information is available at: https://www.cloudflare.com/privacypolicy/

Error monitoring, performance monitoring, and application diagnostics are provided by Sentry, a service operated by Functional Software, Inc. Patchi's Sentry project is configured in Sentry's Europe region. Sentry may process technical diagnostic information needed to detect, investigate, and fix errors, such as error messages, stack traces, application logs, performance traces, affected URLs or routes, browser and device information, operating system, date and time of the event, IP address, request metadata, and account identifiers if they are included in an error context. Patchi does not intentionally send special categories of personal data or sensitive user-created studio-planning content to Sentry.

Sentry's privacy information is available at: https://sentry.io/privacy/

Data recipients

Your data is shared only with recipients strictly necessary to operate Patchi, including hosting, infrastructure, email-delivery, monitoring, diagnostics, and security-related providers involved in account and service operation.

Patchi does not sell your personal data.

International data transfers

Because some service providers may process data outside your country, including in the United States, your data may be transferred outside the European Economic Area.

Where such transfers occur, Patchi relies on appropriate safeguards required by applicable data protection law.

Data retention

Patchi keeps personal data only for as long as necessary for the purposes described in this policy.

In particular:

  • Technical logs and infrastructure data are retained for a limited period as required for security, debugging, and service continuity, or according to the applicable provider retention settings;
  • Account and authentication data are retained while the account remains active or as otherwise necessary to operate and secure the service;
  • If a user requests account deletion, Patchi applies a staged GDPR-aware lifecycle: the account is soft-deleted first and personal data is anonymized after 24 months of inactivity, unless a different retention period is required by law or to resolve a legitimate security issue.

Cookies and similar technologies

Patchi may use strictly necessary technical mechanisms required for core functionality, authentication, session continuity, security, and hosting delivery.

Cloudflare Turnstile may use technical mechanisms necessary to perform anti-abuse verification on protected account actions.

Patchi does not currently use advertising cookies. If non-essential trackers or analytics requiring consent are added later, this policy and related practices will be updated accordingly.

Your rights

If you are located in the European Union / European Economic Area, you may have the right to:

  • Access your personal data;
  • Request rectification of inaccurate data;
  • Request erasure of your data, where applicable;
  • Request restriction of processing;
  • Object to certain processing;
  • Request portability of data, where applicable;
  • Lodge a complaint with your local data protection authority.

To exercise your rights, contact us at: privacy@patchi.io

Data security

Patchi implements reasonable technical and organizational measures to protect personal data against unauthorized access, loss, alteration, or disclosure.

No method of transmission or storage is completely secure, but Patchi seeks to limit risks through appropriate security practices.

Children's privacy

The App is not intended for children under the age of 13, and Patchi does not knowingly collect personal data from children.

Changes to this Privacy Policy

This Privacy Policy may be updated from time to time to reflect changes in the App, legal requirements, or Patchi's data practices.

The updated version will be posted on this page with a new "Last updated" date.

Data controller

The data controller for the processing described in this Privacy Policy is Clément LACAÏLE.

Contact

If you have any questions about this Privacy Policy or your personal data, you can contact Patchi at privacy@patchi.io.