Privacy Policy
This Privacy Policy explains how OnePatch (“OnePatch,” “we,” “us,” or “our”) collects, uses, discloses, and safeguards personal data when you visit our website, create an account, or use the OnePatch platform (the “Service”). OnePatch is an AI site-reliability platform that analyzes the OpenTelemetry data (logs, metrics, and traces) our customers send us in order to build dashboards, evaluate monitors, and help engineering teams investigate incidents.
1. Who we are
OnePatch is the data controller for personal data about our website visitors and the authorized users of customer accounts. For the telemetry and content our customers submit to the Service (“Customer Data”), OnePatch acts as a data processor and processes that data on our customers’ instructions under our customer agreement and, where applicable, a Data Processing Addendum (“DPA”).
Questions about this policy or our data practices can be sent to privacy@onepatch.dev.
2. Data we collect
Account & identity data
When you sign up or sign in, we collect your name, work email address, organization, and authentication metadata. Authentication and organization membership are managed through our identity provider, WorkOS; we do not store your password.
Customer Data (telemetry)
Customers send us OpenTelemetry logs, metrics, and traces via a per-tenant ingest endpoint. This telemetry may incidentally contain personal data if a customer’s systems include it in their logs or trace attributes. We process this data solely to provide the Service and per the customer’s instructions.
Usage & device data
We collect standard product and website analytics — pages viewed, features used, approximate location derived from IP address, browser and device type, and timestamps — to operate, secure, and improve the Service.
Communications
If you contact us, we keep the content of your message and our reply.
3. How we use data
- To provide, maintain, and secure the Service, including authentication, dashboards, monitor evaluation, and incident investigation.
- To operate the AI features of the Service, which analyze Customer Data to produce reliability insights.
- To communicate with you about your account, security, and product updates.
- To monitor, debug, and improve performance and reliability.
- To detect, prevent, and respond to fraud, abuse, and security incidents.
- To comply with legal obligations and enforce our agreements.
4. Legal bases (EEA/UK)
Where the GDPR or UK GDPR applies, we rely on: performance of a contract (to provide the Service to account users); legitimate interests (to secure and improve the Service, and for website analytics); consent (where required, e.g. certain cookies); and legal obligation. For Customer Data processed on a customer’s behalf, the customer determines the legal basis.
5. Subprocessors & sharing
We do not sell personal data. We share data with vetted service providers (subprocessors) that help us run the Service, each bound by contractual confidentiality and security obligations:
| Subprocessor | Purpose |
|---|---|
| Amazon Web Services | Cloud hosting, compute, storage, and networking |
| Anthropic | AI model inference powering the Service’s analysis features |
| OpenAI | AI model inference for incident summaries and select analysis features |
| ClickHouse Cloud | Telemetry storage and query |
| WorkOS | Authentication, single sign-on, and organization management |
| Stripe | Billing and payment processing |
Integrations you connect to your account (for example GitHub, Slack, or Linear) receive data under your own agreements with those providers and at your direction; they are not our subprocessors.
We may also disclose data to comply with law, respond to lawful requests, protect our rights and users’ safety, or in connection with a merger, acquisition, or asset sale (subject to this policy).
6. AI processing
The Service uses AI models (via Anthropic and OpenAI) to analyze telemetry and assist with reliability work. Customer Data submitted to these models is processed to generate outputs for that customer and is not used by us to train foundation models. Our AI subprocessors are contractually restricted from training their models on data submitted through our API.
7. Data retention
We retain account data for as long as your account is active and as needed to provide the Service. Customer telemetry is retained according to the customer’s configuration and agreement. We retain data longer where required for legal, tax, security, or dispute-resolution purposes, then delete or anonymize it.
8. International transfers
We operate primarily in the United States. Where personal data is transferred from the EEA, UK, or Switzerland, we rely on appropriate safeguards such as the Standard Contractual Clauses.
9. Security
We maintain administrative, technical, and organizational measures designed to protect data, including encryption in transit and at rest, least-privilege access controls, network isolation, audit logging, continuous security monitoring, and a signed image supply chain. No method of transmission or storage is perfectly secure, but we work to protect your data and to promptly address vulnerabilities.
10. Your rights
Depending on where you live, you may have rights to access, correct, delete, port, or restrict processing of your personal data, and to object to certain processing. Residents of California and similar jurisdictions may have rights to know, delete, correct, and opt out of “sale” or “sharing” of personal information — we do not sell personal information. To exercise a right, email privacy@onepatch.dev. If your data was submitted to us as Customer Data, we will refer your request to the relevant customer (controller).
11. Cookies
Our website and application use cookies and similar technologies that are strictly necessary to keep you signed in and to secure your session, plus limited analytics. You can control non-essential cookies through your browser settings.
12. Children
The Service is a business tool not directed to individuals under 16, and we do not knowingly collect their personal data.
13. Changes
We may update this policy from time to time. Material changes will be posted here with a new “Last updated” date and, where appropriate, communicated to account administrators.
14. Contact
OnePatch — Privacy
Email: privacy@onepatch.dev
© 2026 OnePatch. See also our Terms of Service.