Legal & Policies
Privacy Policy
- Legal entity
- Patcher LLC
- Effective
- August 26, 2026
- Last updated
- August 26, 2026
- Version
- 3.2
- Contact
- info@patcher.me
This Privacy Policy explains how Patcher LLC (“Patcher,” “we,” “us,” or “our”) collects, uses, discloses, retains, and protects personal information when you use Patcher's website, iOS app, accounts, ordering, measurement, support, AI-assisted features, and related services.
Patcher LLC is located at 235 E Canaan Rd, East Canaan, CT 06024-2603, United States. Privacy questions or requests may be sent to info@patcher.me.
1. Privacy by design
Patcher is designed to keep raw measurement data on your device by default. Raw RGB images, depth arrays, confidence maps, camera transforms, local boundary edits, and rejected scan frames used for measurement are processed locally and are not intentionally uploaded to Patcher merely because you scan a repair.
The server generally receives the smaller summaries needed to quote, reproduce, fulfill, support, and audit an order, such as geometry measurements, quality/warning flags, calculation versions, selected boundaries, quantity recommendations, and order information.
Separate upload features have separate purposes and permissions. An operational/support upload is not automatically a research upload.
2. Information we collect
Depending on the features you use, Patcher may collect the following categories.
Account and contact information
- email address;
- phone number if you provide one for delivery or support;
- account/user identifier;
- authentication and account-recovery information;
- guest-order access/recovery information; and
- the changeable use-case answer you submit, Patcher's server-derived Business/Consumer segment, and the date that preference last changed.
The current questionnaire offers Measure & document pavement and Repair my property. Patcher stores the exact answer and derives Business only from Measure & document pavement; Repair my property maps to Consumer. If an older app submits the legacy Purchase Gem Patch answer, it also maps to Consumer. This saves your current preference and supports first-party use-case analysis. It is not a permanent B2B/B2C identity, does not grant authorization, does not change the available app interface, and can be changed later in Settings.
Order and delivery information
- name and delivery address;
- billing-related contact information;
- postal code;
- products, quantities, prices, discounts, taxes, shipping charges, order status, and order history;
- shipment/tracking and delivery status;
- returns, replacements, refunds, support, warranty, recall, and product-safety records; and
- consent/acceptance records connected with an order.
Payment information
Patcher uses Stripe and Apple Pay for physical-product orders where enabled. Patcher stores transaction status and provider identifiers needed to reconcile an order. Patcher Pro is a separate digital subscription processed by Apple through StoreKit; the app reads Apple's verified current entitlement and may retain signed-derived subscription metadata locally for account display.
Patcher does not intentionally receive or store raw payment-card numbers, CVV, or Apple Pay payment cryptograms.
Scan and measurement information
The app may create camera/depth information, user-confirmed boundaries, geometry measurements, quality signals, warnings, device/calculation versions, and quantity estimates.
Raw capture data stays on-device by default. Successful measurement records are stored in protected, install-scoped local app storage so you can use History, reports, and exports. Those records may include an optional recent device coordinate as described below. Patcher may receive measurement summaries and warning/version information when needed for a quote, order, support, or another user-requested feature.
Location and postal code
You may enter a ZIP code manually. If you choose Use current location, the iOS app may request when-in-use location access and use Apple-provided geocoding to derive a postal code.
Location also provides optional site context for saved measurement history. Saving a measurement does not display a new location prompt. If when-in-use access is already authorized, the app may copy an already-available location into that local record only when the fix is no more than five minutes old and reports horizontal accuracy between 0 and 1,000 meters. The local record contains raw latitude, longitude, and reported horizontal accuracy and is shared by app sessions using that installation.
Patcher's current design sends the derived postal code, not the device's raw latitude/longitude, to Patcher for the initial availability/shipping calculation. Saving a measurement does not send its raw coordinate to Patcher APIs. The local coordinate remains on the device unless you separately choose a feature with its own upload terms. Patcher does not request background location. You can delete an individual saved measurement; completing in-app account deletion also removes customer-visible saved measurement records and corrupt recovery snapshots from the device while retaining non-location identifiers used only to prevent restoration of consumed free-measurement allowance.
Photos and support content
You may choose to submit photos, messages, troubleshooting materials, or other support content. Patcher collects only the content you choose to submit for the stated purpose.
AI-assisted estimate explanations and damage assessment
If you use an AI-assisted feature, Patcher may process an allowlisted estimate summary or photos you confirm plus the minimum measurement/product context needed for the request.
If you request an AI explanation of a scan-result estimate, Patcher sends OpenAI only an allowlisted deterministic numeric/status/version summary needed to explain that estimate. The estimate explainer does not receive an image, video, raw scan, point cloud, location, address, free-form scan diagnostics, or payment information. AI-generated explanation prose may be held in Patcher's idempotency cache for up to 24 hours so a retry does not generate another provider request; expired cache entries are purged and entries keyed to an account are removed during account deletion.
If you choose photo damage assessment, Patcher uploads the photos you confirm to private, account-scoped Patcher storage and sends them through Patcher's authenticated server function to OpenAI, a third-party AI service provider. The feature uses the images to classify visible pavement conditions and determine whether readable physical scale and depth references support a material-quantity calculation. Photos without those references may still be described, but they cannot become checkout quantity input. Patcher stores the structured assessment and its private image assets for up to 30 days so you can add requested evidence, resume the assessment, reproduce a quote, or support the transaction. The privacy worker then deletes those stored images and the base assessment, subject to documented legal holds and provider-side handling described below. A minimized calculation/provenance snapshot may remain with a quote, cart, order, support, fraud, safety, dispute, or legal record when reasonably necessary for that separate purpose.
Before Patcher sends user content to OpenAI for the first time, the app must disclose the sharing and ask for explicit permission. You can decline and continue using non-AI functionality where available.
Patcher's OpenAI request is configured with application-state storage disabled where supported (for example, store: false). That setting does not mean all provider-side retention is zero. Under OpenAI's applicable API controls, API content may be retained in abuse-monitoring logs for up to 30 days by default unless approved reduced-retention controls apply, and limited retention may also occur where required for safety or law. Patcher does not opt your API content into model training unless Patcher first changes its configuration and provides any notice/consent required by law and platform rules.
Device, security, and service information
Patcher may collect limited technical and operational information needed to run and protect the Services, such as app version, device/platform type, IP/network information received by servers, authentication events, request/correlation identifiers, security/audit events, error events, and service-performance metadata.
Patcher does not use advertising SDKs or cross-app tracking in the launch configuration described by this Policy.
Notifications
If you opt in after an order, Patcher may store a device push token and notification preferences to provide delivery/order status. You can change notification permission in device settings.
3. How we use information
Patcher uses personal information to:
- create and secure accounts and guest-order access;
- save the selected use-case preference and understand Business/Consumer product demand;
- calculate service availability, shipping, tax, quotes, and order totals;
- measure damage and generate material quantity estimates;
- process payment status, fulfill orders, and reconcile transactions;
- provide tracking, delivery updates, support, returns, refunds, replacements, and product-safety notices;
- provide user-requested AI estimate explanations and damage assessment;
- detect, investigate, and prevent fraud, abuse, and security incidents;
- maintain records needed for accounting, legal claims, recalls, product safety, and compliance;
- improve reliability, safety, and product functionality using limited operational analytics; and
- conduct optional research only when the separate research consent applies.
Patcher does not repurpose a support/operational upload for optional research merely because Patcher possesses the file.
4. Optional research
Research participation is optional, off by default, and is not a condition of ordering.
If Patcher asks to use a scan/photo or related data for research, the consent will identify the purpose and applicable retention period. Patcher records the consent version and your decision. Withdrawing research consent stops future research processing and queues eligible research assets for deletion, but it does not require Patcher to delete transaction, fraud, safety, or other records Patcher must lawfully retain for another purpose.
5. How we disclose information
Patcher may disclose the minimum information reasonably necessary to the following recipients.
Service providers/processors
Patcher may use providers for:
- cloud hosting, database, authentication, and storage;
- payment processing;
- email, notifications, and customer support;
- fulfillment, product supply, shipping, carriers, and delivery;
- geocoding and platform services;
- fraud/security and operational tooling; and
- AI processing, including OpenAI for user-requested AI features.
These providers receive information for the service they perform and are expected to protect it as required by contract and applicable law.
Business transfers
If Patcher is involved in a merger, financing, acquisition, reorganization, bankruptcy, sale of assets, or similar transaction, information may be transferred as part of that transaction subject to applicable law and continuing privacy obligations.
Legal, safety, and security disclosures
Patcher may disclose information when reasonably necessary to comply with law or valid legal process; respond to a product-safety issue or recall; protect users, property, or the Services; investigate fraud or security incidents; or establish, exercise, or defend legal claims.
6. No sale, targeted advertising, or cross-company tracking
Patcher does not sell personal information, use personal information for third-party targeted advertising, or authorize third-party advertising trackers to follow you across other companies' apps or websites in the launch configuration described by this Policy.
Because Patcher does not currently conduct those activities, an opt-out preference signal such as Global Privacy Control does not change an existing sale/targeted-advertising profile. If Patcher ever introduces a covered sale or targeted-advertising practice, it must update this Policy and implement legally required opt-out controls before that processing begins.
7. Retention
Patcher keeps information only as long as reasonably necessary for its stated purpose and documented legal, tax, accounting, payment, fraud, security, warranty, recall, product-safety, support, dispute, and business-record needs.
Current operational rules include:
- Unsubmitted raw scans: remain on-device and are removed through ordinary local/session cleanup rather than intentionally uploaded to Patcher.
- Saved measurement records: remain in protected, install-scoped local app storage until you delete them, complete applicable local account-deletion cleanup, or remove the app. A saved record may include the recent location described in Section 2. Non-location measurement identifiers used only to preserve consumed free-measurement allowance may remain after visible history deletion.
- Use-case preference: remains on the account profile until you change it or delete the account. A new answer replaces the previous answer, derived segment, and change timestamp. The preference is included in an eligible account export and is deleted when account deletion removes the profile, subject to the backup limits below.
- Photo damage assessment: confirmed private images, the base structured assessment, and analyzer-run metadata are scheduled for deletion no later than 30 days after assessment creation. A minimized calculation/provenance snapshot may remain with a quote, cart, order, support, fraud, safety, dispute, or legal record for that record's approved period. Account deletion covers account-scoped records and objects subject to documented retention exceptions, legal holds, and backup/provider limitations.
- Scan-result estimate explanation: the allowlisted deterministic summary is used for the requested OpenAI processing, and validated explanation prose may remain in Patcher's retry/idempotency cache for up to 24 hours. Provider-side handling is described in Section 2.
- Operational troubleshooting/scan upload: normally deleted no later than 30 days after the related support/operational need ends, unless a safety, dispute, fraud, legal hold, or other documented lawful reason requires longer retention.
- Optional research upload: retained for the study period described at consent and subject to withdrawal; Patcher's current research-asset architecture uses a 400-day maximum ceiling unless renewed consent or another documented lawful basis applies.
- Rejected/expired quote or cart summary: generally minimized or deleted on a short operational schedule, currently targeted at 30 days.
- Orders, payment references, tax, shipment, refund, warranty, recall, and safety records: retained for the period reasonably necessary for fulfillment and applicable legal/business obligations.
- Security/audit events: retained for a risk-based period with restricted access.
- Backups: age out on provider schedules. If a backup is restored for disaster recovery, Patcher's deletion/tombstone process must be reapplied.
Patcher does not promise immediate deletion from every backup, fraud log, legal record, or service-provider security log when retention remains technically necessary or legally permitted.
8. Security
Patcher uses administrative, technical, and organizational safeguards designed to reduce risk, including authenticated sessions, server-side authorization, row-level data controls, protected server secrets, encrypted network transport, access restrictions, input validation, audit logging, and provider security controls where applicable.
No service can guarantee absolute security. If you believe your account or information has been compromised, contact info@patcher.me.
9. Your choices and privacy rights
Patcher provides users a process to request, as appropriate:
- confirmation of whether Patcher processes their personal information;
- access to or a copy of personal information;
- correction of inaccurate information;
- deletion of eligible information;
- a portable copy of eligible information;
- withdrawal of consent-based processing; and
- appeal of a privacy-rights decision where applicable law provides an appeal.
Where applicable law grants additional rights, Patcher will honor them as required. Patcher may also provide these controls voluntarily when a specific statutory threshold does not apply.
Submit a request through the in-app/web privacy controls where available or email info@patcher.me. Patcher may reasonably verify identity and authority before acting. Patcher may deny or limit a request where permitted or required by law, including to protect another person's information, prevent fraud, complete an order, comply with tax/accounting requirements, preserve product-safety/recall records, or establish or defend legal claims.
Guests may be asked to verify an order number plus a receipt/delivery channel or comparable order-access credential. A privacy response will not disclose whether unrelated customer data exists.
10. Account deletion
If you have a Patcher account, you may initiate deletion from within the iOS app. Patcher may require recent authentication to prevent unauthorized deletion.
Deletion removes or de-identifies account information that Patcher is not legally required or reasonably permitted to retain. Limited transaction, fraud, tax, warranty, recall, product-safety, dispute, security, and legal records may remain with access/use restricted to those purposes.
11. Consent and withdrawal
When Patcher relies on your consent for optional processing, Patcher records the purpose and consent version. You may withdraw consent through the relevant feature, privacy controls, or info@patcher.me.
Withdrawal stops future consent-based processing as soon as reasonably practicable and within any period required by law. It does not retroactively invalidate processing that was lawful before withdrawal or require deletion of records retained under another lawful purpose.
12. Children
Patcher is intended for adults and is not directed to anyone under 18. Patcher does not knowingly permit consumer accounts for children in the launch configuration. If you believe a child has provided personal information contrary to this Policy, contact info@patcher.me.
13. United States launch
Patcher's launch services are intended for the United States. Patcher and its service providers may process information in the United States and other locations where those providers operate, subject to applicable contractual and legal safeguards.
Patcher does not represent that the launch version is configured for the European Economic Area, United Kingdom, or other non-U.S. consumer markets unless those markets are expressly added and this Policy is updated.
14. Changes to this Policy
Patcher may update this Policy as the Services, providers, law, or data practices change. Material changes receive a new version/effective date. If a change requires consent, Patcher will obtain it before beginning the covered processing.
15. Contact
Patcher LLC
235 E Canaan Rd
East Canaan, CT 06024-2603
United States
Email: info@patcher.me
