Legal

Privacy Policy

Last updated: July 16, 2026 (This policy is part of our Terms of Use.)

Patch is built to keep your information on your device, and we don't want to collect more than we need. We've written this in plain language on purpose.

The short version

What Patch reads, and where it stays

On Mac (the full version)

To find security problems, the Mac version reads, on your computer:

All of this is read on your Mac. Patch reads your passwords in memory to check them and to find reused ones, but it never stores the password itself. When it needs to check a password again later, it reads it fresh from your browser rather than keeping a copy.

The one thing Patch does keep on your device is a small cache of password fingerprints — scrambled, one-way codes that are not your passwords and can't be turned back into them — paired with how many breaches each was found in, so it doesn't have to re-check the same password every time. Each fingerprint is scrambled again using a secret key that Patch generates on your Mac and stores in your Keychain, so even a copy of the cache file is meaningless without it. This cache lives only on your Mac. It never contains the actual password, and it's never uploaded.

Patch does not read your autofill data, saved addresses, or payment cards.

On iPhone

Apple's rules don't let apps read your saved accounts, so the iPhone version can't. Instead, you tell Patch which sites you use, and it checks those. The list of sites you add is stored on your device.

You can also check whether your email address appears in known data breaches. When you do, that check is described below.

What leaves your device, and why

We've kept this list short on purpose. These are the only times information leaves your device:

We don't attach your name or identity to these requests, and we don't use them to build a profile of you.

What happens to what you send the advisor

Patch's advisor runs on Claude, made by Anthropic. When you ask a question or send something to be checked, it passes through our service to Anthropic to be answered.

We keep nothing. Our service doesn't store your questions, log them, or write them down anywhere. It passes them along and forgets them.

Anthropic deletes it within 30 days. Under their terms, what you send is automatically deleted from their systems within 30 days. If something you send trips their automated safety systems, they may keep it for up to two years — that's their policy, not ours, and it applies to everyone using their service.

It's never used to train an AI model. That's written into Anthropic's commercial terms, not just our word for it.

We don't attach your name to any of this — there isn't one. Requests carry a random code used only to stop abuse, and even that never reaches Anthropic.

Have I Been Pwned and other outside services

Patch relies on Have I Been Pwned for breach information, on Anthropic's Claude models for the advisor and scam checks, and on Vercel to host the small service those requests pass through. Like any host, Vercel records standard access logs — the fact that a request happened, not what was in it. When information is sent to an outside service, that service's own handling of it applies. We don't control those services and don't warrant their data.

What we don't do

Children

Patch is made for adults managing their own accounts and isn't directed at children. We don't knowingly collect information from anyone under 13.

Changes to this policy

We may update this policy. When we make a meaningful change, we'll update the "last updated" date above, and significant changes will be made clear in the app.

Contact

Patch is made by Plateau Labs LLC. Questions about your privacy or this policy? Email us at hello@patch-security.com.