patchhaus

legal

privacy policy.

What Sinuslabs OÜ collects when you use patchhaus.dev and the Patchhaus desktop app, why, who else receives it, and what you can do about it. Last updated 19 September 2026.

Who we are

Sinuslabs OÜ makes Patchhaus and is responsible for your personal data (the "controller"): Sepapaja tn 6, 15551 Tallinn, Estonia, registry code 16567803. Write to hello@sinuslabs.io about anything in this policy.

The short version

The website records analytics only if you accept them in the cookie banner.

The desktop app sends usage statistics only if you turn them on. Anonymous error reports are on unless you turn them off.

When you use the AI assistant, your messages and the project context it needs go through our server to OpenRouter and to the company that runs the model you pick. We don't keep your prompts.

We don't sell personal data or use it for advertising.

Visiting patchhaus.dev

Our server, hosted by Hetzner in the EU, sees your IP address, browser and the pages you request, as every web server does. We use this to deliver the site and keep it secure (legitimate interest). The logs are overwritten on a rolling basis.

The analytics script, PostHog on its EU servers, loads on every page, but it records nothing and stores nothing on your device until you click Accept in the cookie banner. If you accept, PostHog records the pages you visit and how you use them (clicks, scrolling, page speed, and screen recordings with form fields hidden) under a random ID kept in a cookie and your browser's storage for up to a year (consent). Sign-in and password-reset tokens are removed from page addresses before anything is sent. If you decline, or withdraw later with the cookie settings link at the bottom of this page, PostHog stops and the ID is deleted from your browser.

The Pole playground compiles the code you write on our server. We don't store the code. Your IP address is held for 60 seconds to limit how often one address can compile.

Joining the waitlist

You give us your email address and, if you like, what you make, which tools and DAWs you use, and how you heard about us. We use them to tell you when access opens and to decide what to build first (consent: you can withdraw it any time by writing to us). The email is sent through Brevo, in the EU.

If you later create an account with the same email address, your answers are copied into your account. We keep waitlist entries until you ask us to remove yours or the waitlist ends.

Your account

To create an account we need your email address and a password, which we store only as a hash. A company name is optional. If you sign in with GitHub or Google, they give us your email address and name. We use this to run your account, send verification and password emails through Brevo, and keep your AI credit balance (contract).

When the desktop app signs in, we store the device's name and when it was last used, so you can see and revoke it on your account page. If you answer the short questions when you first open the app, your answers are saved to your account so the assistant can tailor its suggestions.

The AI assistant

When you use the assistant, your message goes through our server to OpenRouter (United States), which passes it on to the company that runs the model you picked. That includes the project context the assistant needs: your patch graph, the code and UI files it opens, compile errors, screenshots of the Patchhaus window, and the project's name and folder location. The assistant's replies come back the same way. Model makers include Anthropic, OpenAI, Google and xAI in the United States, and DeepSeek, Moonshot AI, Alibaba (Qwen) and Z.ai in China. "Auto" currently uses Z.ai's GLM. OpenRouter may send a request to the model's maker or to another company that hosts the same model. Two requests can go to a company you didn't pick: if your model can't read images, OpenAI's GPT describes the assistant's screenshots, and a chat with an image you attach switches to Anthropic's Claude. Images the assistant generates for your plugin's design are made by Google's Gemini unless you ask for OpenAI's. We do this to provide the assistant you asked for (contract).

We don't store your prompts or the replies. For each request we record the model, the tokens used and the credits charged, to keep your balance. Your chat history stays on your Mac. OpenRouter and the model providers handle requests under their own terms, and some keep them for a limited time, for example to prevent abuse.

If you connect your own AI agent, such as Claude Code, through Patchhaus's local MCP server, that agent works with its own provider under your agreement with them. Nothing goes through our servers.

The desktop app

Usage statistics are off unless you turn them on during setup or in Settings → Privacy (consent). When they're on and you're signed in, events such as which features you use and whether exports succeed are linked to your account, and the app is screen-recorded with all text hidden. They never include your audio, project files, prompts, chat or code. They go to PostHog (EU) and to our server, which keeps them for 12 months.

Anonymous error reports are on by default; you can turn them off in the same places. They contain the error, where in Patchhaus it happened, your app version and operating system, with your folder names removed, and no ID that ties your reports together (legitimate interest: fixing bugs).

Checking for updates sends the app's version and update channel to our server, nothing that identifies you. Patchhaus opens an audio input only if you choose one in Settings, and your audio stays on your Mac.

Account events

Separately from the settings above, our server records a few account events in PostHog, linked to your email address: signing up, verifying your email, signing in from the app, using AI credits, errors from AI requests, and purchases. We use them to run and bill the service, spot abuse and understand how Patchhaus is used (legitimate interest). You can object by writing to us.

Buying credits or a plan

Payments are handled by Polar (polar.sh), our merchant of record. Polar is the seller: it takes your payment details, handles tax, and processes that data as its own controller under its own privacy policy. We give Polar your email address, your account ID and your IP address (to work out your country and currency), and receive your customer and subscription status. We keep payment and credit records for 7 years, as accounting law requires (legal obligation).

Downloads

App installers and updates are delivered from Supabase storage, so Supabase sees your IP address when you download.

Who else receives data

Hetzner Online GmbH: hosting, in the EU.

PostHog: website analytics, screen recordings and error reports, on its EU servers.

Brevo: sending emails, in the EU.

Supabase: storage for app downloads.

OpenRouter and the model providers named above: the AI assistant.

Polar: payments, as its own controller.

GitHub and Google: only if you sign in with them, as their own controllers.

Transfers outside the EU

OpenRouter and several model providers are in the United States, and some model providers are in China, which has no EU adequacy decision. When your data goes to a provider outside the EU, it's covered by that provider's data-protection terms under the GDPR, such as standard contractual clauses or the EU-US Data Privacy Framework where the provider offers them. Ask us if you want details.

Cookies and browser storage

pw:cookie-consent (browser storage): remembers your cookie choice.

payload-token (cookie): keeps you signed in, for up to 7 days.

oauth_state and oauth_return (cookies): only during a GitHub or Google sign-in, for 10 minutes.

pw-loader-seen (session storage): remembers that you've seen the intro animation during this visit.

ph_… (cookie, browser and session storage): PostHog's analytics ID, set only after you accept, for up to a year. __ph_opt_in_out_… (browser storage) remembers your analytics choice.

How long we keep things

Account data: while your account exists. We delete it within 30 days after you ask us to close your account, except the records below that the law makes us keep.

Payment and credit records: 7 years.

App usage statistics: 12 months.

Website analytics, screen recordings and error reports in PostHog: 12 months.

Server logs: overwritten on a rolling basis.

Waitlist entries: until you ask us to remove yours or the waitlist ends.

AI prompts and replies: not kept by us.

Your rights

You can ask us for a copy of your data, to correct it, to delete it, to restrict or object to how we use it, and to receive it in a format you can take elsewhere. Where we rely on your consent, you can withdraw it at any time; that doesn't affect what happened before. Write to hello@sinuslabs.io. We answer within a month, free of charge.

You can also complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee) or to the data protection authority where you live.

Children

Patchhaus isn't meant for children under 13, and we don't knowingly collect their data. If you think a child has given us personal data, write to us and we'll delete it.

Changes

We update this page when what we do changes, and change the date at the top. If a change matters for account holders, we email them before it takes effect.

Questions? Write to us. You can also review or withdraw your consent via .