Privacy policy
What we collect, where it goes, and who else can see it.
Last updated 6 August 2026
Who runs this
Patron-AI is operated by a single individual, reachable at igorkakaroff@gmail.com and +91 82528 56197. There is no other staff and no third party with routine access to your content.
What we hold
- Account details — the name and email address of each staff member with an account, and a hashed password. Passwords are stored hashed and cannot be read back by us.
- What you type — the questions asked and the answers returned, kept so conversations survive between sessions.
- Documents you upload — the case files sent to the reader, and the analyses produced from them.
- Usage records — for each request, the time, the model used, and the token counts. These exist to work out cost and to raise invoices. They do not contain the text of your questions.
There are no advertising trackers, no analytics scripts, and no third-party cookies. The only cookie set is the one that keeps you signed in.
Who else sees it
To answer a question or read a document, the relevant text has to be sent to the model providers we use. Those are:
- Anthropic — for chat answers. Content sent through the API is not used to train their models.
- Google — for reading uploaded documents. Content sent through the paid API is not used to train their models.
These providers process data outside India. If that is a problem for the material you intend to put in, please raise it with us before uploading it rather than after.
We also use Amazon Web Services to store uploaded files and database records, in the Mumbai (ap-south-1) region; Vercel to serve the application; and Razorpay to take payment. Razorpay receives only billing details — never the contents of your conversations or documents.
We do not sell your data, and we do not share it with anyone beyond the providers listed above except where we are compelled to by law.
Who can see your work inside the office
Every record belongs to exactly one office, and that boundary is enforced by the database itself rather than by application checks alone. No office can see another's material.
Within an office, the supervising officer can see the work done under the office's account, including conversations started by staff. Staff members should treat their use of Patron-AI as visible to their supervisor and not as private.
How long we keep it
Conversations, documents, and analyses are kept until the office asks us to delete them, or until 90 days after the last account in that office is closed, whichever comes first. Usage and invoice records are kept for eight years, as tax law requires. Backups are retained for 35 days, so deleted material can persist in backups for that period before it ages out.
Your rights
You can ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete it. Write to igorkakaroff@gmail.com. We will respond within 30 days. If a request would delete records we are legally required to keep — invoices, principally — we will tell you which ones and why.
Security
Traffic is encrypted in transit. Files and database contents are encrypted at rest. Access to production systems is limited to the operator. If we ever discover a breach affecting your data, we will tell the affected office without delay and describe what happened, what was exposed, and what we have done about it.
Changes
If this policy changes in substance we will email every account holder before the change takes effect. The date at the top of this page shows when it was last revised.