← onepatch Terms of Service

Privacy Policy

Effective date: July 1, 2026 · Last updated: July 1, 2026

This Privacy Policy explains how OnePatch (“OnePatch,” “we,” “us,” or “our”) collects, uses, discloses, and safeguards personal data when you visit our website, create an account, or use the OnePatch platform (the “Service”). OnePatch is an AI site-reliability platform that analyzes the OpenTelemetry data (logs, metrics, and traces) our customers send us in order to build dashboards, evaluate monitors, and help engineering teams investigate incidents.

1. Who we are

OnePatch is the data controller for personal data about our website visitors and the authorized users of customer accounts. For the telemetry and content our customers submit to the Service (“Customer Data”), OnePatch acts as a data processor and processes that data on our customers’ instructions under our customer agreement and, where applicable, a Data Processing Addendum (“DPA”).

Questions about this policy or our data practices can be sent to privacy@onepatch.dev.

2. Data we collect

Account & identity data

When you sign up or sign in, we collect your name, work email address, organization, and authentication metadata. Authentication and organization membership are managed through our identity provider, WorkOS; we do not store your password.

Customer Data (telemetry)

Customers send us OpenTelemetry logs, metrics, and traces via a per-tenant ingest endpoint. This telemetry may incidentally contain personal data if a customer’s systems include it in their logs or trace attributes. We process this data solely to provide the Service and per the customer’s instructions.

Usage & device data

We collect standard product and website analytics — pages viewed, features used, approximate location derived from IP address, browser and device type, and timestamps — to operate, secure, and improve the Service.

Communications

If you contact us, we keep the content of your message and our reply.

3. How we use data

4. Legal bases (EEA/UK)

Where the GDPR or UK GDPR applies, we rely on: performance of a contract (to provide the Service to account users); legitimate interests (to secure and improve the Service, and for website analytics); consent (where required, e.g. certain cookies); and legal obligation. For Customer Data processed on a customer’s behalf, the customer determines the legal basis.

5. Subprocessors & sharing

We do not sell personal data. We share data with vetted service providers (subprocessors) that help us run the Service, each bound by contractual confidentiality and security obligations:

SubprocessorPurpose
Amazon Web ServicesCloud hosting, compute, storage, and networking
AnthropicAI model inference powering the Service’s analysis features
ClickHouse CloudTelemetry storage and query
WorkOSAuthentication, single sign-on, and organization management

We may also disclose data to comply with law, respond to lawful requests, protect our rights and users’ safety, or in connection with a merger, acquisition, or asset sale (subject to this policy).

6. AI processing

The Service uses AI models (via Anthropic) to analyze telemetry and assist with reliability work. Customer Data submitted to these models is processed to generate outputs for that customer and is not used by us to train foundation models. Our AI subprocessor is contractually restricted from training its models on data submitted through our API.

7. Data retention

We retain account data for as long as your account is active and as needed to provide the Service. Customer telemetry is retained according to the customer’s configuration and agreement. We retain data longer where required for legal, tax, security, or dispute-resolution purposes, then delete or anonymize it.

8. International transfers

We operate primarily in the United States. Where personal data is transferred from the EEA, UK, or Switzerland, we rely on appropriate safeguards such as the Standard Contractual Clauses.

9. Security

We maintain administrative, technical, and organizational measures designed to protect data, including encryption in transit and at rest, least-privilege access controls, network isolation, audit logging, continuous security monitoring, and a signed image supply chain. No method of transmission or storage is perfectly secure, but we work to protect your data and to promptly address vulnerabilities.

10. Your rights

Depending on where you live, you may have rights to access, correct, delete, port, or restrict processing of your personal data, and to object to certain processing. Residents of California and similar jurisdictions may have rights to know, delete, correct, and opt out of “sale” or “sharing” of personal information — we do not sell personal information. To exercise a right, email privacy@onepatch.dev. If your data was submitted to us as Customer Data, we will refer your request to the relevant customer (controller).

11. Cookies

Our website and application use cookies and similar technologies that are strictly necessary to keep you signed in and to secure your session, plus limited analytics. You can control non-essential cookies through your browser settings.

12. Children

The Service is a business tool not directed to individuals under 16, and we do not knowingly collect their personal data.

13. Changes

We may update this policy from time to time. Material changes will be posted here with a new “Last updated” date and, where appropriate, communicated to account administrators.

14. Contact

OnePatch — Privacy
Email: privacy@onepatch.dev


© 2026 OnePatch. See also our Terms of Service.