Privacy Policy
What we collect. What it does. Nothing more.
This policy describes exactly what patkan.in and the official Patkan extension collect, why, and what happens to it. Patkan is open source, so every line here can be checked against the code.
Who we are
Patkan is built and run by Gaurav Sharma, based in India. Patkan, operated by Gaurav Sharma, is the data controller (Data Fiduciary) for personal data under this policy. Also read our Terms of Use at patkan.in/terms.
You can reach him at contact@patkan.in. Our postal address is available on request — write to the same email and it will be sent to you.
This policy covers patkan.in and the official Patkan browser extension published by us. It does not cover copies or forks of the open-source code run by anyone else — those operators are responsible for their own data practices.
The extension
The extension runs only on the AI sites listed in its manifest. It does not watch your browsing, read other tabs, or log your keystrokes anywhere else.
When you finish a sentence with //, the extension reads the text of that input box and sends it to our server to be compiled into a structured prompt. The request carries a device identifier so daily limits can be enforced. If you are signed in, it also carries your sign-in token, so the transform is linked to your account.
A small connector script on patkan.in passes your sign-in session to the extension when you are signed in there. That is how the extension and the website know you are the same person.
The extension sends an event the first time it is installed or updated, so we can count installations. It includes a hashed device identifier and the extension version.
Prompt processing
Your prompt and the compiled output are processed on our server. To make repeated transforms faster, the full prompt text and its output are stored in a cache, in plain text, with no expiry.
The cache is keyed on the exact input text and is not linked to your account. If another person submits the very same input text, they may be served the stored output. Do not enter sensitive personal data — passwords, health details, identity numbers, anything you would not paste into a public search box.
Prompts are also logged as aggregate events (which engine was used, how long it took, whether it succeeded) so we can keep the service reliable.
Saved prompts
If you save a prompt to your library, its text is stored against your account so it is there the next time you sign in. You can delete any saved prompt, and deleting your account removes it.
Usage measurement
On this website, we record page and section views to understand what is useful — a browser identifier kept in your own browser, a session identifier, the page and section viewed, device type, and the site that referred you. No advertising trackers are involved.
In the extension, we record events tied to a hashed device identifier — which AI site a transform happened on, which event occurred, and which version of the extension you run. This tells us what breaks and where to fix.
We keep this measurement deliberately small: counts and coarse events, not your conversations.
Fair-use limits
To stop abuse of the free service, each device gets a daily transform limit. The count is keyed to a shortened hash of your IP address — an irreversible digest, not the address itself — but it can still be linked back to you with effort, so under the law we treat it as personal data.
The counter resets each calendar day at midnight UTC, not on a rolling 24-hour window. The current limit is 50 transforms a day for signed-in use, and we may change that number as the service evolves.
The hashed IP counters have no automatic expiry.
Accounts
Signing in with Google gives us your email address, and the name and photo Google attaches to your profile. Your account record also stores a display name, your usage tier, and a preference flag.
We use your email only to identify your account, for support, and for service notices. We do not sell it and we do not run marketing lists on it.
AI providers
Compiling a prompt is our own code, but we pass your input text to third-party AI model providers whose models generate parts of the compiled prompt. Their handling of that text is governed by their own API terms, including their training and retention terms.
These providers process data in India, the United States and other countries where they operate, so your prompt text may be transferred internationally.
Chrome Web Store Limited Use
Patkan's use of information received, and Patkan's use of other information received from localized applications, will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
In plain terms: the data the extension gathers is used only to run and improve Patkan's single purpose — turning your rough thought into a structured prompt — never for advertising, lending, or selling data.
Security
Everything travels encrypted in transit over HTTPS. The database uses row-level security so an account can only read its own rows.
Patkan's source code is open — you can verify every claim in this policy against the code itself (see the open-source section below).
If a breach of your personal data ever occurs, we will notify the affected users and the Data Protection Board of India within the timelines the law requires.
Legal basis (GDPR)
For users in the EU and UK: we process your prompt text to perform the service you asked for (contract). We count and hash IPs, and keep service telemetry, in our legitimate interest of keeping the service fair, secure and working. Website analytics run on your consent, which you can withdraw by clearing the site's browser identifier from your browser or asking us to do it.
Retention
We keep things simple and honest: most data — cached prompts, hashed-IP counters, telemetry — is kept until you ask us to delete it, because the code currently has no automatic deletion. Write to contact@patkan.in and we will erase what is linked to you. Prompts saved to your library are deleted when you delete them or your account.
Your rights
You can ask to see your data, correct it, delete it, restrict or object to its processing, or withdraw consent for analytics — write to contact@patkan.in and you will get a reply from a person, typically within 30 days.
If you are in India, you may also nominate another person to exercise these rights on your behalf, and you can escalate a complaint to the Data Protection Board of India. If you are in the EU or UK, you can complain to your local supervisory authority.
Children
Patkan is not directed at children under 18, and we do not knowingly collect their personal data. If we learn that we have, we delete it.
Open source
Patkan's code is licensed under the GNU AGPL-3.0 and published at github.com/Gauravrsh/patkan. Anyone can read the code and check this policy against it — that transparency is the point.
The licence covers the code, not the name or brand. And it covers the code only: running a modified copy as your own service makes you the data controller for that service, not us.
Changes and languages
This is version 1.0, last updated on 27 September 2026 — the first published version of this policy. If it changes, we will post the update here and change the date at the top.
You can ask for this policy in any language listed in the Eighth Schedule of India's Constitution by emailing contact@patkan.in.
Questions about any of this — a request to see, correct or delete your data — go to contact@patkan.in. A person answers, not a queue.