Privacy Policy
Review draft · 6 September 2026. Adapted from the app policy dated 4 September 2026. Operator details and processing claims await confirmation; this draft does not replace the policy served in the app.
Patches Holdings B.V. is the controller of the personal data described here. This policy covers the Patches app and its marketing website — what we hold, why, who else sees it, and your choices.
What we hold
- Your account
- Your email address, your name if you give one, how you sign in (password, Google, a one-time code or a passkey), and your settings.
- What you put in your apps
- The rows, photos, scanned documents, voice notes and files you add — plus anything an app derives from them, like totals or a next-due date. This is whatever you chose to track, so only you know how sensitive it is.
- Accounts you connect
- If you connect a mailbox or a file store, we hold the access credential for it — encrypted — and the content the connected app reads: the messages, attachments or files that match what you set it up to look for.
- Notifications
- If you turn on reminders, the push subscription your browser issues, so we can ring your device.
- Technical records
- Server logs (IP address, timestamps, what was requested, errors) and a count of how much building and AI processing your account has used.
Why, and on what basis
- To run the service you asked for — build your apps, store your data, extract information from what you capture, send the reminders you set, and share an app with the people you shared it with. Basis: performance of our contract with you.
- To read a connected mailbox or drive, and to send you push notifications. Basis: your consent, given when you connect the account or allow notifications, and withdrawable at any time.
- To keep the service working and secure — diagnosing faults, preventing abuse, and understanding load and cost. Basis: our legitimate interest in a service that stays up and is not abused.
- To meet legal obligations where one applies. Basis: legal obligation.
AI processing
Building an app, and pulling structured information out of your text, photos and documents, is done by AI models we call on your behalf. That means the content being processed — the prompt you wrote, the photo you took, the email an app is reading — is sent to the model provider running that model. We use Anthropic, OpenAI and Google under their business terms, which do not permit your content to be used to train their models, and we do not use it to train models ourselves.
These providers process the content in the United States. That transfer relies on the European Commission's standard contractual clauses.
Reference sources
Some apps fill themselves in from public reference sources — a film's poster, a book from its ISBN. Looking something up sends the search term (a title, a code) to that source; it does not send your account details or the rest of your app. The sources this deployment reads, and their licences, are listed in full on the About Patches page, inside the app.
Who else sees your data
Only these, and only to do their job for us:
- our hosting and database provider, which runs the service in Amsterdam;
- the AI providers named above;
- our email delivery provider, for sign-in codes and notification emails;
- the push service your own browser uses (Apple, Google or Mozilla), which relays notifications to your device — the message itself is encrypted, so the relay cannot read it;
- anyone you deliberately share an app or a link with.
We do not sell your data, we do not share it with advertisers, and we do not profile you. We will disclose data if the law compels us to, and we will tell you when we are allowed to.
Cookies
The Patches app sets one cookie to keep you signed in, and a second one if you open an app someone shared with you. That is all — there are no analytics, advertising or tracking cookies in this product, which is why you have never seen a cookie banner here.
The marketing website
The website at getpatches.app is hosted using OpenAI Sites and Cloudflare infrastructure. Serving a page involves technical information such as your IP address and the requested URL. Hosting providers process technical information to deliver and protect the website.
If a link contains campaign parameters or an advertising click identifier, the website carries those values into links to the Patches app. These values can identify the campaign that brought you here. Our website code does not store them in cookies or browser storage, and we have not added advertising pixels or third-party analytics scripts.
The app’s Amsterdam hosting statement and app-cookie description above describe the app, not the website’s hosting infrastructure.
Keeping it safe
Everything travels over HTTPS. Credentials for accounts you connect are encrypted at rest. Each account's data is isolated from every other account's, and reads that cannot establish whose data they are fail rather than guess. No system is perfectly secure; if we ever have a breach that puts you at risk, we will tell you and the regulator as the law requires.
How long we keep it
Your apps and their data stay until you delete them or close your account. When you close it, we delete your apps and their contents from our live systems straight away; copies inside routine backups disappear as those backups age out of rotation. Server logs are kept briefly for diagnosis and security, then discarded. We keep the minimum we are legally required to keep, for as long as we are required to keep it.
Your rights
You can ask us for a copy of your data, to correct it, to delete it, to restrict or object to what we do with it, or to hand it over in a portable form. You can withdraw a consent — a connected mailbox, notifications — whenever you like, without affecting what was done before you withdrew it.
Two of these you do not need to ask for: every app's data exports to CSV or JSON from inside the app, and deleting an app deletes its data. For anything else, write to privacy@getpatches.app and we will answer within a month.
If you think we have got this wrong, you can complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens, or to the supervisory authority where you live. We would rather you told us first.
Children
Patches accounts are not intended for anyone under 16. If you believe a child has an account, tell us and we will remove it. Adult users may add information about children to family patches, such as birthdays or health records. That information is personal data covered by this policy. Only add another person’s information where you have the appropriate authority and a lawful basis to do so.
Changes to this policy
When what we do with your data changes, this policy changes with it, and the date at the top tells you which version you are reading. If a change matters to you, we will tell you in the app or by email rather than leaving you to notice.
Who we are
Patches Holdings B.V., Netherlands
Registered address: awaiting confirmation.
KvK number: not yet available.
Privacy and legal contact: privacy@getpatches.app