Privacy Policy
Last updated: July 24, 2026
1. Who We Are
Unpatched.ai ("we", "us", "our") operates the Unpatched.ai platform, a cybersecurity platform whose primary offering is a chat-based cybersecurity agent. This policy applies to all products and features we offer under Unpatched.ai. If you have questions about this policy, contact us at privacy@unpatched.ai.
Where a business or organization provisions Unpatched.ai for its members (for example, your employer or team), that organization is the controller of the personal data processed through its account, and we act as a processor on its behalf with respect to the conversations and uploads created in that account. We remain the controller of account, billing, and security-log data, including for organization accounts. This policy describes how we handle both.
Where we have entered into a separate data processing agreement with an organization, that agreement governs our processing of personal data on its behalf to the extent it conflicts with this policy. Organizations that require a data processing agreement can request one at legal@unpatched.ai.
2. Information We Collect
2.1 Account Information
When you create an account, we collect your email address and your name. We use your email for sign-in via magic link and for transactional messages related to your account. For team plans, we also collect your team name and billing details.
2.2 Payment Information
Payment is processed by Stripe. We do not store your full card number. Stripe provides us with a tokenized payment method, your billing name, billing address, and the last four digits of your card. See Stripe's Privacy Policy for how they handle your payment data.
2.3 Conversations and Uploads
When you use the chat, we store your conversations — the messages you send, the responses you receive, and any files you upload (such as logs, packet captures, or suspicious samples) — so you can return to them later. Uploaded files are processed in ephemeral, sandboxed environments while the agent analyzes them. This content is stored encrypted and is retained until you delete it (see Section 7). For how we handle the use of your data for model training, see Section 4.
2.4 Automatically Collected Data
When you use our service, we automatically collect:
- IP address
- Approximate geolocation (country, region)
- Browser and client user agent string
- Timestamps of login events and actions
This information is used for security (rate limiting, fraud and abuse prevention, region verification), session management, and operating the service reliably.
2.5 Consent Records
When you sign up, we record timestamps of your acceptance of our Terms of Service and Privacy Policy, your region attestation, and your acknowledgment that this is an experimental platform.
3. How We Use Your Information
We use your information to:
- Authenticate you via magic-link sign-in and manage your sessions
- Operate the chat agent and process the messages and files you submit
- Store and display your conversations so you can resume them
- Process payments and manage your subscription and credit balance
- Send transactional emails (sign-in links, billing notices)
- Enforce rate limits and detect abuse
- Verify your region eligibility
- Maintain audit logs for security purposes
We do not use your information for advertising, profiling, or automated decision-making unrelated to operating the Service.
4. AI Processing and Model Training
The Service uses third-party AI models to power the agent. The messages you send and the files you upload may be sent to the AI provider for processing.
We do not use your conversations or uploads to train AI models, or permit third parties to use them for training, unless: (1) they are flagged for security or abuse review, in which case we may analyze them to improve our ability to detect and enforce violations of our Terms of Service; (2) you explicitly report them to us, for example as feedback; or (3) you have explicitly agreed to their use for such training.
5. How We Share Your Data
We rely on the following categories of service providers, solely as necessary to operate the platform:
- AI providers — your messages and uploaded files are sent to the provider that powers the agent
- Payment processing — Stripe processes payments and stores billing information
- Email delivery — transactional emails are sent through our email delivery provider
- Infrastructure — Unpatched.ai runs on cloud infrastructure providers for compute, edge networking, and storage
- Bot protection — Our sign-in page uses Cloudflare Turnstile to verify that requests come from a human. Turnstile runs invisibly and may process device and browser signals to make this determination. See Cloudflare's Privacy Policy and Cloudflare's Turnstile Privacy Addendum for details.
We may also share your personal data:
- Business transfers — if we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, your data may be transferred as part of that transaction
- Affiliates — with entities that control, are controlled by, or are under common control with us, who will handle it consistent with this policy
- Account administrators — if you access the Service through an account provisioned by an organization (for example, your employer or team), that organization owns and controls the workspace, and its administrators may access, manage, and monitor your use of the Service — including your usage and activity — and the data associated with the account
We may also disclose your personal data when we believe in good faith that doing so is necessary to: comply with applicable law, regulation, legal process, or an enforceable governmental request; enforce our Terms of Service and other agreements, including investigating potential violations; detect, prevent, or address fraud, security, or technical issues; or protect the rights, property, or safety of Unpatched.ai, our users, or the public.
We do not sell, rent, or share your personal information with third parties for their own marketing purposes.
6. Data Storage and Security
Account data, conversations, and uploaded files are stored with our infrastructure providers, encrypted at rest. Uploaded files are processed in ephemeral, sandboxed environments during a conversation. We use TLS for all data in transit, scoped session tokens, access controls, and rate limiting on sensitive endpoints.
If we become aware of a security incident that affects your personal data, we will notify you and, where we are the controller of that data, any applicable regulators, as required by law. Where we act as a processor for an organization account, we will notify that organization without undue delay so it can meet its own notification obligations.
7. Data Retention
We retain your account data for as long as your account is active. Conversations and uploaded files are retained until you delete them or delete your account. Sessions and magic-link tokens expire automatically.
If you delete your account, we will delete your personal data within 30 days, except where we are required to retain it for legal, tax, or compliance reasons.
8. International Data Transfers
Unpatched.ai runs on a global network. Your data may be processed in any country where our infrastructure providers operate. By using the Service, you consent to this transfer.
9. Cookies
We use strictly necessary cookies to keep you signed in and to provide security protections. We do not use tracking cookies or third-party advertising analytics.
10. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access — request a copy of the personal data we hold about you
- Correction — request correction of inaccurate data
- Deletion — request deletion of your personal data
- Portability — request a machine-readable export of your data
- Objection — object to certain processing of your data
- Restriction — request that we limit processing of your data
To exercise any of these rights, contact us at privacy@unpatched.ai.
We do not "sell" or "share" your personal data for cross-context behavioral advertising, and we do not process it for targeted advertising, as those terms are defined under US state privacy laws (including the California Consumer Privacy Act, as amended by the CPRA). We do not knowingly collect or process sensitive personal information to infer characteristics about you. We will not discriminate against you for exercising any of these rights.
11. Legal Bases for Processing (EEA and UK)
If you are located in the European Economic Area (EEA) or the United Kingdom, we rely on the following legal bases under the GDPR and UK GDPR to process your personal data:
- Performance of a contract — to create and operate your account, authenticate you, run the Service, and process payments
- Legitimate interests — to secure the Service, prevent and detect abuse, maintain audit logs, and operate and improve the Service, balanced against your rights and freedoms
- Consent — where we ask for it; you may withdraw consent at any time without affecting prior processing
- Legal obligation — to comply with tax, accounting, and other legal requirements that apply to us
EEA and UK users may also lodge a complaint with their local data protection supervisory authority.
12. Children's Privacy
Our service is not directed to individuals under 18. We do not knowingly collect personal information from children. If you believe we have collected data from a child, please contact us and we will delete it.
13. Changes to This Policy
We may update this policy from time to time. If we make material changes, we will notify you by email or by posting a notice on the service prior to the change becoming effective. Continued use of the service after changes constitutes acceptance of the updated policy. The "Last updated" date at the top of this page indicates when the policy was last revised. See also our Terms of Service.