Privacy Policy

Last updated 25 August 2026

The short version: an email address, what you build in the product, and what the payment provider tells us about your subscription. One cookie keeps you signed in, and we measure how the site is used so we can tell which pages help. No advertising, no ad networks, and nothing sold or shared with anyone. You can switch off everything that identifies your browser, and this page has the switch.

Who is responsible

PatternsRadar is operated by «registered legal name, e.g. Bitmask Technologies Private Limited» ("we", "us"), a «private limited company / limited liability partnership» registered in India («CIN or LLPIN»), with its registered office at «registered office, line 1», «line 2», «city, state, PIN», India.

For the purposes of the Digital Personal Data Protection Act, 2023, we are the data fiduciary for the personal data described here.

What we collect

Only what the product needs to work:

  • Account: your email address, your name if you give one, and your password, which is stored only as an argon2id hash and is never recoverable in plain text.
  • What you create: saved scans, alert settings, alert history, and the names and metadata of your API keys. Keys themselves are stored hashed and are shown once, at the moment you create one.
  • What you run: a record of each scan, including the query itself, when you ran it, whether it was your browser or one of your API keys, and how many instruments it matched. It is what shows you your own usage against your plan, and what lets us answer you when you write to us about it.
  • Billing: your plan, its status, the period end, and the reference our payment provider uses for your subscription. We never see or store your card, UPI or bank details — Razorpay collects those directly and holds them.
  • Technical: your IP address, used to apply rate limits and to investigate abuse, and ordinary server logs of requests, which include the address and the path.
  • Usage measurement, if you have not switched it off: which pages you open, which actions you take in the screener, and the anonymous identifier Google Analytics and PostHog set on your device. It is not linked to your name or your email — the only account detail that reaches them is the numeric id of your account, which means nothing outside this service.

Cookies and measurement

One cookie is essential: the session cookie that keeps you signed in. It is HTTP-only, and it is cleared when you sign out. Nothing you can turn off affects it, because without it you cannot stay signed in.

Two more are for measurement, and those are optional. We use Google Analytics and PostHog to understand how the site is used — which pages people arrive on, which scans get run, where people give up. They tell us whether the things we write are worth writing. They set identifiers on your device that let us recognise the same browser across visits, and they are what the switch below turns off.

One more is not optional, because there is nothing to opt out of: Ahrefs Web Analytics counts visits without setting a cookie, without storing anything on your device, and without an identifier that follows you from one visit to the next. It runs on every page.

What none of them is used for: advertising, ad targeting, retargeting, or building a profile of you. We do not run ads, and we do not sell or share this data.

If you are in the EEA, the UK or Switzerland, Google Analytics and PostHog do not read or write anything on your device until you accept, and until then Google receives only an anonymous count with no identifier attached. Elsewhere they run by default, this page is your notice, and the switch below is your off switch — turn it off and the identifiers already set are deleted. The switch changes your mind either way, at any time, and works per browser because that is where the choice is stored.

Why we use it

To run your account and keep you signed in; to save your scans and run your alerts; to send the alert digests you asked for and the occasional message about your account or a change to these documents; to take payment and manage your subscription; to apply rate limits and protect the service; to understand which parts of the site are worth keeping; and to answer you when you write to us.

We do not sell your personal data, we do not share it for advertising, and we do not use it to profile you.

Who else sees it

Only the providers the service runs on, and only what each one needs:

  • Razorpay, our payment provider, for subscriptions and payments.
  • Resend, our email provider, to deliver alert digests and account email.
  • Google (Analytics), PostHog and Ahrefs, our measurement providers, for the usage data described under Cookies — Google and PostHog only if you have not switched them off. PostHog stores it in the European Union and the other two outside India; none of them receives your name or email address.
  • Our hosting and infrastructure providers, which store the data at rest.
  • Anyone we are legally required to disclose to, under a valid legal demand.

How long we keep it

Your account data is kept while your account exists. Delete the account and it goes with it — your saved scans, alerts, alert history, scan history, API keys, notification settings and subscription record are erased at the same time.

The record of scans you run is kept for as long as your plan provides history, which your plan page states and your dashboard shows. After that the queries themselves are deleted and only the daily counts remain.

Two things outlive a deletion. Records of payments, including what our payment provider sent us about them, are kept for as long as tax and company law require us to keep them; the DPDP Act allows retention where another law requires it. Server logs, which contain IP addresses, are kept for a short period for security and then discarded.

Your rights

Under the DPDP Act you may ask for access to your personal data, correction of it, or its erasure, and you may withdraw consent for anything you consented to.

You do not need to ask us for the common ones. Your data is on your account page, alert email has a switch there and an unsubscribe link in every message, and the same page deletes the account outright. For anything else, or if something does not work, write to us and we will act on it.

Complaints go to our Grievance Officer, «name of the grievance officer», at «support@patternsradar.com». If we do not resolve it, you may complain to the Data Protection Board of India.

How it is protected

Traffic is encrypted in transit. Passwords are hashed with argon2id, and session tokens and API keys are stored hashed rather than in the clear, so a leaked backup is not a set of working credentials. Access to production data is limited to those who need it.

No service can promise perfect security. If a breach affects your personal data, we will notify you and the Data Protection Board as the law requires.

Children

This service is not intended for anyone under 18, and we do not knowingly collect personal data from children.

Changes, and reaching us

We will update this policy when the product changes. The date at the top says when it last changed, and a material change will be notified by email.

Questions: «support@patternsradar.com», or «registered legal name, e.g. Bitmask Technologies Private Limited», «registered office, line 1», «line 2», «city, state, PIN», India.