Patchy Cloud Privacy Notice
Last updated: October 5, 2026
This notice covers Patchy Cloud: the service at cloud.patchyhq.com, its sign-in and waitlist pages at accounts.patchyhq.com, and the patchy command line tool. The patchyhq.com website and PatchPage each have their own notice.
The short version: we store what your company publishes and saves, so that we can run it. We record who did what, by id and without the content, so that we can operate, secure and improve the service. Patchy Cloud’s databases, file storage and server logs are in the United States. We do not sell anything, show ads or train models on your data.
Two kinds of information
- Your company’s content. Patches, tables, files and connections belong to your company, and we handle them on its behalf. Your company decides what goes in and who sees it. Questions about that content go to your company’s admins first.
- Account and usage records. These are ours to look after, and the rest of this notice is mostly about them.
What we hold
- Your account. Your name, email address and how you sign in, held with Clerk, our sign-in provider. If you joined the waitlist, your email address. Clerk sends sign-in codes and invitations, and sees the device and network details that signing in involves.
- Company records. Your company’s name and handle, its members and their roles, invitations and the addresses they went to, and the machines each person has logged in: a name, when it was created and last used, and a hash of its token. We also keep who published or changed each patch, and when.
- Company content. Every published version of a patch, its tables and files, its description, connection settings with their credentials encrypted, a snapshot of each connected database’s table and column names, the lines a patch writes to its own log, and a log of the calls patches make. For raw SQL queries against your own database that log includes the first 8 KB of the query text.
- Usage records. One record for each request: the route, the ids of the person, company and patch involved, the time it took, the outcome and the sizes. A record of key changes to a company, its people and its patches, such as a company created; a person invited, joining, changing role, deactivated or reactivated; a machine logged in; a connection added or removed; or a patch published, shared, retired, restored, rolled back, reassigned, deleted or removed for good. Those carry the ids of the people, machines, patches, invitations and connections involved; roles and states, such as who can open a patch; version numbers; a patch’s tier, size and number of handlers, and how many versions a removal took with it; the kind of connection, such as Postgres; how a person joined; whether admin rights were used; whether a login replaced an earlier one; and whether an invitation email went out. A request from the
patchycommand line tool also records its version, the command and the coding agent the tool detected, such as Claude Code or Codex, or that it detected none. These records leave out page content, filenames, query text, credentials, cookies, IP addresses and URLs. They carry account ids, not names or email addresses. Records about publishing and running a patch also carry the names its builder gave its tables, file stores, connections and handlers, and which parts of the SDK it uses. They never carry rows or file contents. - Email you send us. Your address and whatever you write.
The patchy command line tool sends nothing except the requests you make to Patchy Cloud. Each request names the tool’s version, the command and the coding agent it detected from a setting that agent makes on your machine, or that it detected none. The tool never sends that setting’s value. Logging in sends your computer’s name as the suggested name for the machine. It keeps its login on your machine.
People who open a public patch
A public patch opens without an account. We count the visit and record the request like any other. If you are signed in to Patchy Cloud, the record carries your account id. If you are not, it carries no person’s id. A patch that runs code does so in a sandbox designed to stop it contacting other sites. A static page can embed an image from another site, and loading it shows that site the reader’s IP address and browser.
How we use it
- To run Patchy Cloud and show each person what they are allowed to see.
- To keep it secure, find faults and help when you ask.
- To understand how it is used, set its limits and, later, to bill for it.
- To understand what people build with it. For that we read usage records and each patch’s name and description, never the code, tables, files or connected databases behind a patch.
- To tell you about changes to the service and these terms.
Who else handles it
We do not sell or share personal information. We rely on these vendors, each acting for us:
- Amazon Web Services, US East: the servers that run Patchy Cloud and patch code, and their logs.
- Neon, US East: the databases and file storage.
- Clerk, US: accounts, sign-in, invitations and the waitlist.
- PostHog, US: usage records.
- Google: email you send us. Google may store it outside the United States.
- Anthropic and OpenAI: the AI tools our team uses to operate and repair the service. They can process company content only when we open it for a reason the terms allow, and our accounts are set so that what they process is not used to train models. They may process it outside the United States.
We may also disclose information where the law requires it or where it is needed to enforce the terms.
How long we keep it
- Company content: for as long as your company keeps it. A deleted patch can be restored for 30 days, and is then removed with its versions, tables and files. A replaced or deleted file is removed within a few days.
- Call logs and database snapshots: while your company exists on Patchy Cloud.
- Database history: 7 days. Server logs: 90 days.
- Usage records at PostHog: up to 7 years, the longest PostHog keeps them on any plan.
- Your account: until you ask us to remove it or your company closes.
- Machine logins: each expires 90 days after it was made, or after 30 days unused.
When your company leaves, the terms say what we export and delete, and when.
Security
Connections to Patchy Cloud are encrypted. Saved database credentials are encrypted with keys we hold, which we need in order to run your queries. Patch code runs in a sandbox designed to keep it apart from your sign-in and from other companies. No service is perfectly secure, and this one is a beta. If we learn that your company’s content was exposed, we tell its admins without undue delay.
Your choices and rights
For anything inside a patch, ask your company’s admins. For your account, email us to ask what we hold about you, or to correct or delete it. Depending on where you live you may have further rights under laws such as the California Consumer Privacy Act. Email us and we will honour any that apply, and we will not treat you differently for asking.
Where it is processed
The beta is offered to companies in the United States, and Patchy Cloud’s databases, file storage and server logs are there. Copies that reach the vendors listed above are held where each vendor says. Google, Anthropic and OpenAI may process or store what reaches them in other countries.
Cookies and Do Not Track
Patchy Cloud uses cookies to sign you in and keep you signed in. Clerk sets those, including the ones it uses to protect sign-in from abuse. We also set cookies of our own that keep a running patch connected to the same server. We set no advertising or analytics cookies, and our own pages run no advertising or analytics scripts in your browser. The usage records described above go to PostHog from our servers. We do not track you across other websites. A static page that a company publishes can embed images from other sites, and those sites may record that your browser loaded them, as they can on any website. The terms forbid publishing a page in order to track its readers. Patchy Cloud does not respond to Do Not Track or Global Privacy Control signals, because it does not track you across other websites.
Children
Patchy Cloud is a tool for work and is not directed to children. We do not knowingly collect personal information from children.
Changes to this notice
If we change this notice we update the date above and email company admins about anything significant.
Contact us
Questions about privacy? Email us.