Privacy Policy
Effective October 6, 2026
This policy explains how NMajor Studios LLC, a Wyoming limited liability company, handles personal information for PatchReply at patchreply.com. For what the Chrome extension does on your device, see the extension privacy policy.
1. What we collect
- Account data: your email address, name, whether your email is verified, a password hash if you set a password, your Google account identifier if you sign in with Google, and account dates.
- Session and security data: session tokens and expiry dates, IP address and browser user agent for each signed-in session, and rate-limit records. Sign-in rate limiting briefly stores the IP address and route (deleted within a day); our other counters store keyed hashes instead of IP addresses.
- Public links: when you publish a Review report, we store its title, notes, Text edits, page titles and addresses (with query strings and fragments removed), element and location details, capture environment details (browser, operating system, screen), and the screenshots you chose to include.
- Waitlists: if you join a waitlist (for PatchReply Team or the Chrome extension), your email, the optional team size, role, and use description you give, which button you came from, and when you joined. We use this only to tell you when that product is ready and, for Team, to ask one or two questions about how you review. A notice of each new signup (with the same details) goes to our support inbox in Chatwoot so we can follow up. To leave a waitlist, reply to any waitlist email or use the contact form, and we’ll remove you, including the Chatwoot notice. Deleting your account also removes waitlist entries for that account’s email. We also count how often each waitlist button is clicked, without any personal data.
- Support and privacy requests: your email, optional name, request type, and message.
- Email delivery records: for verification, sign-in, password-reset, email-change, and account-deletion emails.
- Technical logs: Cloudflare processes request details such as IP address, URL, and timestamps to deliver and secure the site.
- Public website analytics: page paths, referrers, browser/device details, approximate country, anonymous visitor identifiers, and performance metrics. These help us understand use of public pages. They are not linked to your account or review content.
2. The homepage voice demo
If you try voice on our homepage, your recording (up to 30 seconds) is sent to Cloudflare Workers AI for transcription and the text is returned to your browser. We don’t store the recording or the transcript. We keep only hashed counters to enforce daily limits.
3. How we use information
- to provide accounts and public links you request, and to show your links in your dashboard;
- to send account emails you trigger (verification, sign-in links, password resets, email changes, account deletion);
- to answer support and privacy requests;
- to prevent abuse and secure the service; and
- to comply with law.
Where privacy law requires a legal basis, we rely on performing our contract with you, our legitimate interest in running and protecting the service, legal obligations, or your consent where required. Apart from the waitlist announcements you sign up for, we only send transactional email.
4. Public links are public
Anyone with a public link can read the report and its screenshots and copy them. Links ask search engines not to index them, but that isn’t access control. Links expire 30 days after publishing or renewal and are deleted 7 days later unless renewed.
5. Service providers
- Cloudflare: hosting, Workers, D1 database, R2 file storage for public links, Workers AI for the homepage demo, network security, and logs.
- AhaSend: delivery of account emails.
- Google: only if you choose “Continue with Google,” to confirm your identity and email address.
- Rybbit, self-hosted at
rybbit.nmajor.net: aggregate analytics on public website pages, including page paths, referrers, browser/device details, approximate country, and performance. Query strings, account pages, public Review reports, and review capture interfaces are excluded. We do not send Notes, screenshots, form contents, or account identities to analytics. The Chrome extension does not use analytics. - Chatwoot (self-hosted at
chatwoot.nmajor.net) and MXroute: receiving and answering messages submitted through our contact and privacy request forms.
We don’t sell personal information, share it for cross-context behavioral advertising, or use it to train AI models. We may disclose information when required by law, to protect people or the service, or in a merger or sale with appropriate privacy obligations.
6. Cookies
We use one essential cookie to keep you signed in. We don’t use advertising or analytics cookies. See the cookie notice.
7. Retention
- Account data: until you delete your account.
- Public links: until you delete them, or 7 days after they expire.
- Sessions: up to 30 days of inactivity, or until you sign out.
- Rate-limit records: up to about a day after their window ends.
- Support and privacy requests, email delivery records, and provider logs: as long as needed to answer requests, secure the service, and meet legal duties.
8. Deleting your data
You can delete your account from Settings after confirming by email. That deletes your account, sessions, and sign-in methods, and stops and deletes all your public links. Our database provider keeps short-term backups (up to 30 days) for recovery. Reviews saved in the extension stay on your device.
9. Your rights
Depending on where you live, you may have rights to access, correct, delete, or port your personal information, to object to or restrict processing, to withdraw consent, and to appeal. Use the privacy request form. We may verify your identity before acting, and we won’t discriminate against you for exercising your rights.
10. Children
PatchReply isn’t for children. Accounts must belong to someone old enough to enter a binding contract. If you believe a child gave us personal information, contact us and we’ll delete it.
11. International transfers and security
We and our providers may process information in the United States and other countries. We use HTTPS, password hashing, access controls, server-side authorization, input limits, and rate limits. No service can guarantee absolute security; tell us through the contact form if you suspect a problem.
12. Changes
We’ll post a new effective date when we update this policy and give notice or ask for consent where the law requires.
13. Contact
Privacy: privacy request form. Everything else: contact form.