Last updated: 2026-09-09
Terminology: In this document, workspace and organisation mean your team’s isolated account in Patcherly—your subscription, team members, connected sites or apps (“targets”), and the data linked to that account. A user is an individual who signs in to Patcherly (workspace owner or invited team member). Individual user accounts belong to that organisation. Plan features means the capabilities and limits included with your subscription tier (for example monthly fix limits, number of targets, auto-analysis, and auto-apply), as shown on our pricing page and in your dashboard.
This Privacy Policy describes how Shambix di Jany-Laurence Martelli (“Shambix,” “we,” “us”) collects, uses, stores, and discloses personal data in connection with the Patcherly service (Patcherly is a brand of Shambix). We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and other applicable data protection laws.
The data controller is Shambix, Via Tornabuoni 4, 50125 Firenze, Italy. For legal or privacy inquiries: [email protected]. For general questions: [email protected].
Account and profile data (primary account systems): When you register or use the Service, we collect and store: email address, name (first name, last name), phone, company (optional), timezone, date format preferences, dashboard widget preferences, notification preferences, and a hashed password. We also store organisation data for your team (such as name, slug, billing email, and (where applicable) Stripe customer and subscription identifiers). Billing address, VAT / tax IDs, and payment methods used for invoicing are collected and stored by Stripe (Checkout and Customer Portal), not in Patcherly’s primary account database by default. This information is held so we can run authentication, billing coordination, and support.
Usage and technical data: We collect IP address, browser/device information, and request logs as necessary for security, abuse prevention, and operation of the Service (including the dashboard and programmatic access). For the web dashboard we use secure, cookie-based sign-in with server-side checks; connectors use authenticated, short-lived credentials scoped to your organisation and each connected site or app. Where two-factor authentication is enabled, we store the authenticator secret in encrypted form and process one-time verification codes to protect account access and sensitive actions.
Service / operational data (errors and fixes from your environments): Patcherly provides connector software that you install on your servers or targets according to our instructions. The connector reads information that already exists in your environment - such as logs or error output produced by your application, web server, or related stack. We do not create or generate that underlying data on your systems; we process what the connector reads and transmits to us (for example error messages or log lines, stack traces, file paths, severity, and detected language or framework where available). This supports detection, deduplication, analysis, approvals, and applying patches, as well as in-product views (e.g. dashboards, history, and exports of your operational data).
Usage metrics inside Patcherly: Separately, we derive metrics and summaries from how you use the product (e.g. counts of errors, patches, or similar activity). These are generated inside our systems from your usage of Patcherly - they are not a separate feed “from” your targets or connectors in the same sense as raw error lines.
Public website analytics and conversion measurement: On patcherly.com we use Google Analytics 4 (consent-gated via Cookiebot) to understand marketing-site engagement. The dashboard at app.patcherly.com does not load Cookiebot or marketing analytics cookies. When you complete registration or a paid subscription, our servers may send limited conversion events to the same Google Analytics property via Measurement Protocol (for example plan and campaign attribution parameters). Those server events do not include your email address or display name.
Operational records are stored separately from account profile data and keyed by pseudonymous technical identifiers (such as internal organisation ID, target ID, and numeric user ID where needed for audit trails). We do not store your email address or name inside the operational store for workflow or audit records; where the dashboard shows who performed an action, display details are resolved from the account systems when you use the Service.
Analysis and AI: To suggest fixes, we may send error text, tracebacks, and limited excerpts of code or file context to our AI subprocessors. Official Patcherly connector software applies the same style of best-effort pattern redaction to file or code excerpts and to log lines / tracebacks before they leave your environment - intended to catch common secret shapes (API keys, tokens, passwords, and similar). That redaction is heuristic: it cannot recognise every encoding, custom format, or obfuscated value, and a few patterns are tuned for source code (so they may miss or only partially match free-form log text). What reaches our servers is therefore reduced-risk, not a guarantee of zero secrets. Analysis outputs (e.g. explanations and suggested patches in diff form) may be stored so you can review, approve, or roll back changes in the product.
Fix outcomes (product behaviour): We may record whether a suggested fix succeeded, failed, or was rolled back. Recording happens on every plan and is strictly scoped to your organisation. On paid plans (Core and Pro, the “patch memory” feature), the Service additionally uses those recorded outcomes - together with an error signature and a coarse error fingerprint - as context for future AI analysis so it can avoid proposing the same unsuccessful fix. That is per-organisation patch-efficacy inside Patcherly - not using your code to train third-party foundation models for general-purpose commercial AI; subprocessors may still process content as described above when generating analysis.
What we do not intend to collect: We do not ask you to upload your full codebase, production database dumps, or your end-customers’ databases to Patcherly. We do not store credit card numbers. Payments are handled by Stripe; Stripe processes card data according to its own terms and certifications.
Secrets and logging: The safest rule is simple: do not print secrets into application or server logs. Besides Patcherly, users who can read those logs—your own team, Patcherly Support, compromised accounts, or intruders on the host, as well as your hosting or platform provider where their terms allow access—could reuse what appears in plain text. Patcherly’s connector-side redaction helps reduce accidental leakage when errors are forwarded, but it is not a substitute for careful logging. If sensitive values still appear in log lines or tracebacks, they may still reach us despite best-effort redaction, and the underlying exposure on your systems would remain. Configure logging and error reporting so passwords, API keys, tokens, and unnecessary personal data are never emitted.
Accidental personal data in logs: Error and trace text reflects what your applications and servers already write into logs or error output. We only receive what the installed Patcherly connector reads from your environment and sends to us; we do not generate additional content on your systems or pull data beyond what that connector is designed to collect and transmit. We apply minimisation and technical safeguards (e.g. path exclusions, sanitisation of file context for analysis as described above), but what you log and send remains your responsibility.
Optional chat notifications (Slack, Microsoft Teams, Discord, and similar): If your workspace connects an official Patcherly chat integration (from the Patcherly dashboard or, for Slack, from the Slack Marketplace listing), we store OAuth connection metadata (for example workspace or tenant identifiers, chosen channel identifiers, and encrypted access tokens) in our primary account systems and send notification text you configure (such as error summaries and patch status) to the channel you select. We do not read your chat history, detect messages from those platforms except as required to operate the connection, or use chat content for AI training. Which events are posted is controlled per integration by your workspace administrators. Disconnecting removes our ability to send further messages through that integration. Processing is based on contract (providing the Service you requested) and our legitimate interests in delivering operational alerts. The connected platform may also process data under its own terms; see our Subprocessors and data flows page.
Optional Patcherly Desktop app: If you use the optional desktop client, it loads the same hosted dashboard in a local window and may show operating-system notifications for events you enable under your desktop notification preferences. Session cookies and CSRF tokens stay in the app’s local profile store on your device; Patcherly does not receive a separate copy of those cookies beyond normal dashboard/API use.
When you create a Patcherly account on our public website or dashboard (for example at patcherly.com or app.patcherly.com), we collect the information you submit - typically your email address, name, and any choices on that form (such as a mandatory privacy confirmation and an optional opt-in to occasional product-update emails).
Account signup and onboarding: We use this information to create and operate your account, provide the Service (including pairing official connector software such as the WordPress plugin from WordPress.org), and contact you about your account, billing, onboarding, and service-related messages as described at signup. This processing is based on your consent (GDPR Art. 6(1)(a)) where you opt in on the form, and otherwise on contract or legitimate interests as needed to provide the Service. You may withdraw marketing consent at any time (for example via unsubscribe links or by emailing us at [email protected] or [email protected]); withdrawing consent does not affect the lawfulness of processing that took place before withdrawal.
Product updates (optional checkbox): If you opt in, we may send you occasional emails about Patcherly features and news. Each message includes an unsubscribe link so you can stop these updates at any time (you can also contact us to withdraw marketing consent).
When you use the “Send us a message” form on our public website (before you have a Patcherly account), we collect your name, email, subject, and message, and your choices from that form: a mandatory confirmation that you have read this notice for contact enquiries, and an optional opt-in to occasional product update emails about Patcherly.
Contact enquiry (mandatory checkbox): We use what you send only to respond to your enquiry and for related follow-up about that conversation, in line with what you confirm in the form. This processing is based on your consent (GDPR Art. 6(1)(a)) for that specific contact. You may withdraw consent or object to further processing of your message content by contacting us at [email protected] or [email protected]; withdrawing consent does not affect the lawfulness of processing that took place before withdrawal. If your enquiry relates to an existing customer relationship, we may also rely on legitimate interests or contract as appropriate for ongoing support.
Product updates (optional checkbox): If you opt in, we may send you occasional emails about Patcherly features and news, separate from our reply to your message. Each marketing message includes an unsubscribe link (you can also contact us to withdraw marketing consent).
Contact form submissions are delivered to our team by email and processed on the systems described in our Subprocessors and data flows page.
We process your data on the following bases:
Account and profile: We retain this data for the life of your account and for a limited period after termination or completion of deletion, where required for legal, tax, or operational purposes.
Operational data (errors, analyses, audit logs): The detailed, per-error operational store (individual error records, analysis results, patch outcomes, and audit entries) is retained for a window that depends on your plan: thirty (30) days on the Personal plan, ninety (90) days on the Core plan, and indefinitely on the Pro plan. After this window, records are pruned daily by an automated retention service. If you downgrade to a shorter window, we apply a thirty (30) day grace period during which the longer of the previous and new windows continues to apply, so a billing-cycle change does not retroactively remove data you were entitled to keep. Aggregated metrics and AI-usage records are not subject to this per-plan window (see below).
Aggregated metrics and AI-usage records: Aggregated event-level metrics (errors detected, fixes applied, rollbacks, time saved, money saved) and AI-usage records (token counts and cost per provider/model) are retained indefinitely for the life of the workspace, using pseudonymous identifiers, for product reliability and internal reporting.
Service-wide anonymised patch-quality aggregates: Patcherly maintains a separate, service-wide patch-quality archive used to compute Patcherly-wide success / rollback rates and AI-confidence trends across all workspaces. Each entry is an aggregate (success / rollback / dismissal counts and aggregated confidence and latency values) grouped only by categorical attributes (language, framework, error category, calendar month). By design, this archive contains no workspace identifier, no user identifier, no error identifier, no target identifier, no IP address, no user-agent string, and no free-form text fields. Because the archive contains no personal data within the meaning of the GDPR, it is retained indefinitely and is not deleted when an individual workspace is deleted or when an individual error is removed under the per-error or audit-retention pruning paths. Removal from this archive in exceptional cases (e.g. test-data clean-up or a regulator-mandated erasure) is available only to Patcherly Staff through a restricted internal process and is never available to customers through self-service.
Service-wide anonymised AI-usage aggregates: Patcherly also maintains a separate service-wide AI-usage cost archive used to compute Patcherly-wide cost and token trends across all workspaces. Each entry is an aggregate (request count, prompt / completion / total token counts, total cost in USD) grouped only by categorical attributes (AI provider, model, whether your own or platform-provided credentials were used, target type, target language, target framework, calendar month). By design this archive contains no workspace identifier, no user identifier, no error identifier, no target identifier, no prompt text, no completion text, no IP address, no user-agent string, and no free-form text fields. Because the archive contains no personal data within the meaning of the GDPR, it is retained indefinitely and is not deleted when an individual workspace is deleted, when an individual error is removed, or when the underlying per-workspace AI-usage records are deleted at the end of the standard seven hundred and thirty (730) day retention window. The same restricted Patcherly Staff process that applies to the patch-quality archive applies here.
Dormant Personal-plan workspace cleanup: For workspaces on the Personal (free) plan only, if no user login activity and no active/connected target activity are observed for twelve (12) continuous months, we may classify the workspace as dormant. We send at least thirty (30) days' notice before deletion. If no user logs in during the notice period, the workspace and related data may be deleted. Paid plan workspaces are excluded while a paid subscription remains active.
Backups (Patcherly infrastructure only): We retain disaster-recovery backups of our own primary account systems for a limited period for disaster recovery and legal compliance (by default up to approximately 90 days). Those backups are protected using encryption in transit and at rest where applicable (including hosting-provider storage encryption); optional application-level GPG encryption of backup files may be enabled by Patcherly Staff. Older backups are removed according to our backup policy. These backups are not copies of your source tree or of connector pre-apply file snapshots on your servers: the connector creates those snapshots only on your environment, and Patcherly does not receive, access, transmit, or store them (see our Subprocessors and data flows page). In-app notifications (dashboard inbox messages) are retained for approximately ninety (90) days whether or not they have been read, then permanently deleted by an automated daily task; they are not included in full MongoDB disaster-recovery dumps.
After retention: We delete or anonymise data when it is no longer needed for the purposes above, subject to legal retention requirements.
We use subprocessors (e.g. hosting providers, Stripe, email services, AI providers, Cookiebot) to operate the Service. A list of subprocessors and data flows is published in our Subprocessors and data flows page; transfer mechanisms are set out in our Data Processing Agreement. Data may be processed in the European Economic Area and in other countries; where we transfer data outside the EEA, we use appropriate safeguards (e.g. adequacy decisions, Standard Contractual Clauses) as described in the DPA.
You have the right to: access your personal data; rectify inaccurate data; erase your data (right to be forgotten); restrict processing; data portability; object to processing; and withdraw consent where processing is based on consent. You also have the right to lodge a complaint with a supervisory authority. Under GDPR, individuals typically contact the authority in their country of residence or habitual residence (or where an alleged infringement occurred); authorities may cooperate across borders, but procedures depend on national law.
Practical notes: Portability in Patcherly means you can download data we hold about you (e.g. via the dashboard export); we do not offer a separate industry-standard “move to another vendor” format. Objecting to processing that is necessary to provide the Service you asked for may mean we cannot continue that processing while still delivering the same service - contact us so we can explain options (which may include ending the subscription).
How to exercise your rights:
Team members vs workspace owners: If you joined a workspace as an invited team member (you do not own a workspace), deleting your account removes only your personal login. The workspaces you were invited to, their billing, targets, and other team members’ accounts are not deleted. If you own one or more workspaces, you must delete extra owned workspaces before you can delete your account; deleting your account when you own exactly one workspace also deletes that workspace and follows the rules below for team members who belong only to that workspace.
What happens when you request deletion:
What is removed from Patcherly’s primary account systems after hard deletion (typical case for the account owner’s organisation): user record; organisation(s) tied to that account; connected targets and related configuration; in-app notifications and session credentials tied to the user; and related records removed according to our deletion procedures. Payment card data is handled by Stripe under Stripe’s retention rules.
What may be retained or flagged elsewhere:
We implement technical and organisational measures to protect your data, including encryption (in transit and at rest where applicable), access controls, and secure development practices. No system is completely secure; we encourage you to protect your account credentials and to report any suspected breach to us.
Separation of account data and operational data: We intentionally keep account and profile information (e.g. identity and billing-related fields) in a different technical environment from day-to-day operational data (errors, fix workflow, metrics). That separation reduces what each environment holds and limits exposure if a component were compromised. It does not guarantee that no incident can ever occur.
The Service is not directed at individuals under 18. We do not knowingly collect personal data from children under 18. If you become aware that a child has provided us with personal data, please contact us and we will take appropriate steps.
We may update this Privacy Policy from time to time. We will post the updated policy on this page and update the “Last updated” date. If changes are significant, we may notify you by email or through the Service. We encourage you to review this policy periodically.
For privacy or data protection: [email protected]. For general support: [email protected].