Privacy policy

Last updated July 6, 2026

Who we are

Patch is a feedback tool for client websites, operated by Sim Studio BV, a Belgian company ("we", "us"). Your clients pin comments on a live site, and Patch turns that feedback into pull requests using a coding agent that runs on your own credentials. Sim Studio BV is the controller of the personal data described in this policy. You can reach us at hello@bysim.studio.

The data we collect

  • Account data. When you create a Patch account we store your name, email address, and sign-in details. For security, sessions record technical details such as your IP address and browser. If you connect GitHub, we store your GitHub username and the installation details needed to access the repositories you link.
  • Client feedback. When someone leaves feedback through the widget, we store the name and email address they enter, their comment, and context about the annotated page: the URL, the selected element, its position, and nearby page details such as visible text. Commenters can also attach images to their feedback, including a screenshot of the part of the page they select. Screenshots are only taken when the commenter chooses to capture one, and are rendered in their own browser from the page as they see it; the widget cannot see other tabs, windows, or anything beyond that page. Attached images are stored with the feedback. Patch does not verify client identities; this information is provided by the person leaving the feedback.
  • Repository data. Patch accesses the repository linked to a project, scoped to that project, so your coding agent can propose changes. Repository contents are cloned into an isolated, short-lived environment for the duration of a run. We keep the run's results, such as the proposed change and run logs, but not a copy of your repository.
  • Agent credentials. If you bring your own coding agent account, we store the credentials you provide and use them only to run the agent on your behalf.
  • Billing data. When a workspace subscribes to a paid plan, payment is handled by Stripe. We do not see or store your full card details; Stripe collects those directly. We keep a Stripe customer reference, your plan and subscription status, and the billing details Stripe returns to us, such as billing name, address, country, and VAT id, to manage your subscription and issue invoices.
  • Usage data. This website uses cookieless analytics (Vercel Analytics) that collect aggregated, anonymous page statistics. They set no cookies and do not track you across sites. Inside the Patch app we use first-party product analytics (PostHog, hosted in the EU) to understand how the app is used, such as signups and key actions, tied to your account and workspace. We do not use it to track you across other websites.

Cookies and local storage

This website sets no cookies. The Patch app uses essential cookies to keep you signed in, plus first-party product analytics cookies (PostHog) to measure how the app is used; these stay first-party to Patch and are never used for advertising or cross-site tracking. On sites where the widget is installed, it remembers a commenter's name and email in the browser's local storage so they don't have to retype them; that information stays in their browser and is not used for tracking. We do not use advertising or cross-site tracking cookies anywhere.

How we use your data

We use the data above to provide and operate Patch: showing feedback to the right project, briefing your coding agent, opening pull requests, keeping accounts secure, responding to support requests, and sending service emails about your account or projects. We do not sell personal data and we do not use it for advertising.

Legal bases

Where the GDPR applies, we process personal data to perform our contract with you (providing Patch), for our legitimate interests (securing and improving the service), and with your consent where the law requires it.

Who we share data with

We share data only with the service providers that run Patch: Vercel (hosting, analytics, and the isolated environments runs execute in), Neon (database hosting), GitHub (repository access and pull requests), Resend (transactional email), Inngest (background job processing), PostHog (first-party product analytics, hosted in the EU), Stripe (subscription billing and payment processing), and your coding agent provider, such as Anthropic, OpenAI, or Anysphere (Cursor), which receives the feedback content needed for a run, including any attached images, under your own account. Each processes data to provide their service, nothing more.

International transfers

Some of these providers process data in the United States. Where they do, transfers rely on safeguards such as the EU-US Data Privacy Framework or standard contractual clauses.

Retention

We keep your data for as long as your account is active. Feedback and run history stay attached to the project they belong to. When you delete your account, or ask us to, we delete the associated personal data within a reasonable period, allowing for residual copies in backups.

Your rights

You can ask us to access, correct, delete, or export your personal data, and you can object to or restrict certain processing. Email hello@bysim.studio and we will respond. You can also lodge a complaint with your local data protection authority.

Children

Patch is not directed at children under 16 and we do not knowingly collect their data.

Changes to this policy

If this policy changes, we will post the new version here and update the date at the top of this page.