Pentonym®
Home  ·  Privacy Policy
Legal · Privacy

Privacy Policy

Effective 27 July 2026. Controller: Pentonym, Inc., a Delaware corporation, principal office 133 Ray Court, Fremont, CA 94536, USA.

The short version — not legally binding

We collect what we need to run the Service: your account email, a hashed API key, the names/goods you ask us to screen, the verdicts and signed receipts we produce, and request metadata (timing, IP, usage). We use it to deliver the Service, meter and secure it, and — in aggregate, de-identified form — to improve our models. We do not sell or share your personal information, and we do not train third-party models on your data. Every verdict comes with a signed receipt you can verify independently. You can ask for a copy of your data or have it deleted: privacy@pentonym.com.

1 · Scope

What this covers

This Policy covers personal information Pentonym processes as a controller through the Service. It does not cover third parties with their own policies (e.g., our payment processor, or an independent attorney you engage).

2 · What we collect

Data we hold

  • 2.1 Account data — your email address (to issue an API key and for transactional messages).
  • 2.2 Credentials — your API key is stored only as a salted hash, never in the clear.
  • 2.3 Screening inputs — the names, goods/services descriptions, and classes you submit to screen.
  • 2.4 Verdicts & receipts — the verdict we return and its signed receipt (name, decision, timestamp, aspect states), retained as a durable record of what we returned.
  • 2.5 Usage & device data — an install/usage token, request metadata, IP address, and server logs (metering, rate-limiting, security, debugging).
  • 2.6 MCP client info — the client name/version your assistant sends when it connects.
  • 2.7 Billing data — handled by our processor (Stripe); we receive a confirmation and a customer reference, not your full card number.
  • 2.8 Filing matter data (only if you elect to file) — applicant and mark details you provide to open a filing matter.

We do not knowingly collect special-category data and ask you not to submit it in free-text fields.

3 · How we use it

Purposes & legal basis (GDPR)

PurposeData usedLegal basis (GDPR)
Provide the Service (screen, return verdicts, accounts)2.1–2.6, 2.8Contract, Art. 6(1)(b)
Meter, secure, rate-limit, prevent abuse2.2, 2.5Legitimate interests, Art. 6(1)(f)
Take payment2.7Contract, Art. 6(1)(b)
Improve models/calibration (aggregated, de-identified)de-identified 2.3–2.4Legitimate interests, Art. 6(1)(f)
Transactional messages; marketing where permitted2.1Contract / consent, Art. 6(1)(a)–(b)
Comply with lawas neededLegal obligation, Art. 6(1)(c)
4 · What we don’t do

Lines we don’t cross

  • We do not sell your personal information (including under the CCPA definition of “sell” or “share”).
  • We do not train third-party AI models on your screening inputs.
  • We do not use your inputs for anything beyond providing and improving the Service as described.
5 · Sharing

Who we share data with

5.1 Subprocessors — service providers processing on our behalf under contract: hosting/infrastructure (Fly.io), object storage (Cloudflare R2), search/data providers used during screening, register APIs (e.g., USPTO / EUIPO), and the payment processor (Stripe).

5.2 Independent attorney — if you elect a filing, relevant matter details go to the attorney you engage.

5.3 Legal disclosures — where required by law or to protect rights and safety.

5.4 Corporate transactions — in a merger/acquisition, subject to this Policy.

6 · Retention

How long we keep it

We keep personal information as long as needed to provide the Service and meet legal, security, and dispute-resolution needs, then delete or de-identify it. Usage/request metadata is kept for a limited window (target 60–90 days) for security and debugging; hashed API keys persist until you delete the key; signed verdicts/receipts may be retained as a durable record of what was returned.

7 · Your rights

What you can ask for

7.1 Everyone — you can access a copy of your data, correct it, or ask us to delete it: privacy@pentonym.com. We will not discriminate against you for exercising a right.

7.2 EU / EEA / UK (GDPR / UK GDPR) — access, rectification, erasure, restriction, objection, portability, and withdrawal of consent. You may lodge a complaint with your supervisory authority (in the UK, the ICO).

7.3 California (CCPA/CPRA) — the rights to know/access, delete, and correct, and to limit use of sensitive personal information. We do not sell or share personal information, so the opt-out has nothing to act on but remains available. You may use an authorized agent.

7.4 Other US states (Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, etc.) — similar access/deletion/correction/opt-out rights; we honor them on the same channel: privacy@pentonym.com.

8 · International transfers

Data leaving your region

We are US-based; if you are in the EEA/UK, your information is transferred to the US and other countries. Where required we rely on appropriate safeguards (e.g., Standard Contractual Clauses) and maintain data-processing agreements with subprocessors.

9 · Security

How we protect it

Reasonable technical and organizational measures — encryption in transit, hashed API keys, access controls, least-privilege secrets. No system is perfectly secure. We notify affected users and, where required, regulators without undue delay of a personal-data breach (GDPR Art. 33–34).

10 · Children

Not for children

The Service is not directed to children under 16, and we do not knowingly collect their personal information.

11 · Cookies

Storage & cookies

The Pentonym app uses local browser storage (e.g., to keep you signed in) and strictly-necessary/functional cookies only; we do not use advertising or cross-site tracking cookies. See the Cookie Notice for detail.

12 · Changes

Updates to this Policy

We may update this Policy; material changes are notified by email and/or a site banner at least 14 days before they take effect (longer where law requires), and the Effective date above is updated.

13 · Contact

Reach us

privacy@pentonym.com · Pentonym, Inc., 133 Ray Court, Fremont, CA 94536, USA.

See also our Terms of Service and Cookie Notice.

Real verdict · pentonym.app/v1/screen · Ed25519 · signed & independently verifiable a screening signal, not legal advice · US & EU coverage