# Privacy Policy

> What PatternsRadar collects, why, how long it is kept, and how to have it erased.

Canonical: https://patternsradar.com/privacy

Last updated 17 August 2026.

The short version: an email address, what you build in the product, and what the payment provider tells us about your subscription. No advertising, no analytics, no third-party trackers, and one cookie that exists to keep you signed in.

## Who is responsible

PatternsRadar is operated by Bitmask LLP ("we", "us"), a limited liability partnership registered in India (ACX-4249), with its registered office at Wagale Estate, Thane, Thane Maharashtra, India.

For the purposes of the Digital Personal Data Protection Act, 2023, we are the data fiduciary for the personal data described here.

## What we collect

Only what the product needs to work:

- Account: your email address, your name if you give one, and your password, which is stored only as an argon2id hash and is never recoverable in plain text.
- What you create: saved scans, alert settings, alert history, and the names and metadata of your API keys. Keys themselves are stored hashed and are shown once, at the moment you create one.
- What you run: a record of each scan, including the query itself, when you ran it, whether it was your browser or one of your API keys, and how many instruments it matched. It is what shows you your own usage against your plan, and what lets us answer you when you write to us about it.
- Billing: your plan, its status, the period end, and the reference our payment provider uses for your subscription. We never see or store your card, UPI or bank details — Razorpay collects those directly and holds them.
- Technical: your IP address, used to apply rate limits and to investigate abuse, and ordinary server logs of requests, which include the address and the path.

## Cookies

One cookie, and it is essential: a session cookie that keeps you signed in. It is HTTP-only, and it is cleared when you sign out.

There are no advertising cookies, no analytics, and no third-party trackers on this site.

## Why we use it

To run your account and keep you signed in; to save your scans and run your alerts; to send the alert digests you asked for and the occasional message about your account or a change to these documents; to take payment and manage your subscription; to apply rate limits and protect the service; and to answer you when you write to us.

We do not sell your personal data, we do not share it for advertising, and we do not use it to profile you.

## Who else sees it

Only the providers the service runs on, and only what each one needs:

- Razorpay, our payment provider, for subscriptions and payments.
- Resend, our email provider, to deliver alert digests and account email.
- Our hosting and infrastructure providers, which store the data at rest.
- Anyone we are legally required to disclose to, under a valid legal demand.

## How long we keep it

Your account data is kept while your account exists. Delete the account and it goes with it — your saved scans, alerts, alert history, scan history, API keys, notification settings and subscription record are erased at the same time.

The record of scans you run is kept for as long as your plan provides history, which your plan page states and your dashboard shows. After that the queries themselves are deleted and only the daily counts remain.

Two things outlive a deletion. Records of payments, including what our payment provider sent us about them, are kept for as long as tax and company law require us to keep them; the DPDP Act allows retention where another law requires it. Server logs, which contain IP addresses, are kept for a short period for security and then discarded.

## Your rights

Under the DPDP Act you may ask for access to your personal data, correction of it, or its erasure, and you may withdraw consent for anything you consented to.

You do not need to ask us for the common ones. Your data is on your account page, alert email has a switch there and an unsubscribe link in every message, and the same page deletes the account outright. For anything else, or if something does not work, write to us and we will act on it.

Complaints go to our Grievance Officer, Raj Patil, at grievance@patternsradar.com. If we do not resolve it, you may complain to the Data Protection Board of India.

## How it is protected

Traffic is encrypted in transit. Passwords are hashed with argon2id, and session tokens and API keys are stored hashed rather than in the clear, so a leaked backup is not a set of working credentials. Access to production data is limited to those who need it.

No service can promise perfect security. If a breach affects your personal data, we will notify you and the Data Protection Board as the law requires.

## Children

This service is not intended for anyone under 18, and we do not knowingly collect personal data from children.

## Changes, and reaching us

We will update this policy when the product changes. The date at the top says when it last changed, and a material change will be notified by email.

Questions: support@patternsradar.com, or Bitmask LLP, Wagale Estate, Thane, Thane Maharashtra, India.
