Privacy Policy
Last updated August 1, 2026
This Privacy Policy explains how PatternAI ("PatternAI," "we," "us," "our") collects, uses, shares, and protects personal data when you use our website, applications, and services (collectively, the "Services"). It covers both PatternAI products: our primary product, Patterns — design generation and the digitising of designs into production/machine files — and our secondary product, Image & Video.
1) Scope
This Policy applies to personal data we process when you:
visit our website or use our apps,
create or use an account,
upload content (prompts, artwork, images, assets),
generate outputs (e.g., designs, production/machine files, images, video),
purchase or manage subscriptions,
contact support or otherwise communicate with us.
This Policy does not cover third-party sites or services that you access through links in our Services.
2) Key Definitions
Personal Data / Personal Information: information that identifies or relates to an identifiable person.
User Content: content you submit to the Services (e.g., prompts, artwork, images, designs, text, metadata).
Output: content generated by the Services (e.g., designs, production/machine files, images, video, compositions).
Processing: operations performed on personal data, such as collection, storage, use, disclosure, or deletion.
3) Personal Data We Collect
3.1 Information you provide
Account and profile data: name (optional), email, login identifiers, profile settings.
User Content: images/photos you upload, prompts, text you submit, and related metadata.
Support and communications: messages, requests, and information you share when contacting support.
3.2 Information collected automatically
Device and usage data: IP address, browser type, device identifiers, pages/screens viewed, actions taken, timestamps, referral URLs.
Log and security data: authentication events, error logs, fraud/abuse signals, rate-limit events.
3.3 Payments and billing data
Payments may be processed by third-party payment processors. We typically receive:
subscription plan, billing cycle, payment status,
transaction IDs and invoice/receipt details,
limited billing/contact info as needed for invoicing and support.
We generally do not store full card details; payment processors handle those directly.
3.4 Cookies and similar technologies
We use cookies and similar technologies (including browser local storage) for sign-in and session handling, security, and remembering your preferences such as language and theme. With your consent, we also use analytics (Google Analytics) and advertising measurement (Google Ads); these are set only after you choose "Accept all," under Google Consent Mode v2, and are not used if you reject non-essential cookies. For the full list of cookies — their purposes and lifetimes — and to change your choice at any time, see our Cookie Policy.
4) How We Use Personal Data
We use personal data to:
1. Provide and operate the Services
Create and manage accounts, authenticate users, enable uploads, generate outputs, store content, and deliver features.
2. Maintain safety, security, and integrity
Prevent fraud, detect abuse, enforce rate limits, secure accounts, and protect users and the Services.
3. Process subscriptions and billing
Manage purchases, renewals, invoices, payment confirmations, and billing support.
4. Customer support
Respond to requests, troubleshoot issues, and communicate about your account.
5. Improve and develop the Services
Debug, monitor performance, and improve reliability, UI, and features (e.g., diagnostics, usage analytics).
6. Legal compliance and enforcement
Comply with legal obligations, resolve disputes, and enforce our terms.
5) Legal Bases for Processing (Where Required)
Depending on your location and applicable law, we process personal data under one or more of these bases:
Contract: to provide the Services you request.
Legitimate interests: to secure, maintain, and improve the Services.
Consent: where required (e.g., certain cookies, marketing communications).
Legal obligation: where processing is required by law.
In India, we aim to provide notices and choices consistent with the Digital Personal Data Protection Act, 2023 (DPDP Act), which establishes lawful processing principles and user rights.
6) AI / Model Improvement Use of User Content
We may use certain User Content and/or Output to improve the Services (e.g., quality, safety, performance), using safeguards such as de-identification and access controls, as described in this Policy and any in-product settings/controls. You remain responsible for the User Content you submit and the Output you use.
7) How We Share Personal Data
We may share personal data with:
7.1 Service providers (processors)
Vendors that help us operate the Services, such as:
cloud hosting and storage,
authentication and security,
email delivery,
analytics and advertising measurement (with your consent),
payment processing and invoicing.
These providers are authorized to process personal data only as needed to provide services to us, subject to contractual obligations.
7.2 Payment processors
To process payments, manage subscriptions, and prevent fraud.
7.3 Legal, safety, and enforcement
We may disclose data if we believe disclosure is necessary to:
comply with law, regulation, or legal requests,
protect the rights, property, and safety of PatternAI, our users, or others,
investigate fraud or security incidents.
7.4 Business transfers
If PatternAI is involved in a merger, acquisition, financing, reorganization, or sale of assets, personal data may be transferred as part of that transaction.
We do not sell your personal data. We use advertising-measurement cookies (Google Ads) only with your consent, and we describe them in our Cookie Policy. If we add further marketing or advertising partners, we will update the Cookie Policy and provide choices where required.
8) Data Retention
We retain personal data for as long as necessary to:
provide the Services,
comply with legal and accounting obligations,
resolve disputes and enforce agreements,
maintain security and prevent abuse.
Retention examples:
Account data: retained while account is active; deleted or anonymized after account deletion, subject to legal requirements.
Uploads / Outputs: retained until you delete them or delete your account, plus a limited period for backups/security logs.
Billing records: retained for the period required by law and accounting rules.
9) International Data Transfers
Your data may be processed in countries other than where you live (e.g., where our vendors operate). Where required, we implement appropriate safeguards (contractual protections and security controls).
10) Security
We use administrative, technical, and organizational measures designed to protect personal data (e.g., access controls, encryption in transit, monitoring). No security system is perfect; you are responsible for using strong passwords and protecting access to your account.
If a personal-data breach occurs, we will act promptly to contain and remedy it, and we will notify the Data Protection Board of India and affected individuals where required by the Digital Personal Data Protection Act, 2023.
11) Your Rights and Choices
11.1 India (DPDP Act) — Data Principal rights
Subject to applicable law, you may have the right to:
access information about processing,
correct inaccurate data,
request deletion/erasure,
grievance redressal,
nominate another person to exercise rights on your behalf.
11.2 Other regions (GDPR/UK GDPR/CCPA-style rights)
Depending on where you live, you may also have rights to:
access, correction, deletion,
restriction/objection to processing,
portability (where applicable),
opt-out of certain targeted advertising (if applicable).
11.3 How to exercise rights
Email privacy@patternai.in with:
your account email,
your request,
any details needed to locate the data.
We may verify your identity before fulfilling requests.
12) Children's Privacy
The Services are intended for adults. Under India's Digital Personal Data Protection Act, 2023, a "child" is anyone under the age of 18, and processing a child's personal data requires the verifiable consent of a parent or lawful guardian. We do not knowingly process a child's personal data without that consent. If you believe a child has provided us personal data without the required consent, contact grievance@patternai.in and we will delete it.
13) Third-Party Links and Services
Our Services may contain links to third-party websites or services. Their privacy practices are governed by their own policies, not this Policy.
14) Changes to This Privacy Policy
We may update this Policy from time to time. We will post the updated version and revise the "Last Updated" date. Material changes may be communicated via the Services or by email where appropriate.
15) Contact and Grievance
Privacy Contact: privacy@patternai.in
Support: support@patternai.in
Legal Entity: PatternAI Corporation
Address: 1st Floor, Ashwini Layout, 2nd Main, Ejipura, Bangalore, Karnataka 560047
Grievance Officer (India): Arpit B Lukhi · grievance@patternai.in
Under India's Digital Personal Data Protection Act, 2023 and the Information Technology Rules, 2021, you may raise any privacy or personal-data grievance with our Grievance Officer at grievance@patternai.in. We aim to acknowledge complaints within 24 hours and to resolve them within 15 days.
Appendix A — Data Categories and Purposes
Account & profile — email, name (optional), authentication identifiers — used for account creation, login, and account management.
User Content — prompts, artwork, uploaded images, metadata — used to provide features, generate Output, and store or retrieve your content.
Usage & device data — IP address, device and browser details, events, logs — used for security, abuse prevention, analytics, and service improvement.
Billing data — plan, status, transaction IDs — used for subscriptions, invoicing, and payment support.
Support communications — tickets, messages — used for customer support and troubleshooting.