Last updated: 23 August 2026
The principle
Patinae collects the minimum needed to run the service, encrypts journal content entry by entry, and refuses to record certain information even where that would be technically convenient. The technical detail is on the Security page.
Account data
First name, last name, email address, interface language, an optional profile photo, and a notification preference. The email address is the means of signing in: without it, access to the account is impossible.
Object data
Type, brand, model, serial number and an optional reference. The serial number is also kept in a normalised form used solely to guarantee its uniqueness.
Journal content
Texts, photos and voice messages are encrypted with a key specific to each entry. Only the ciphertext, the encrypted data key, its reference and its version are kept. Media are stored in a private space, outside the public web.
Invitations and access
The email address of a recipient who has no account yet is kept in encrypted form, together with a digest computed with a dedicated key, used solely to find the matching invitation. Invitation tokens are never kept in plaintext: only their digest is.
Access log
Invitations, responses, revocations and views are recorded append-only, so that you can see what happened to an object.
Never recorded: message contents, serial numbers, invitation tokens, raw IP addresses and media contents. This exclusion applies equally to the application's technical logs.
What partner brands see
None of the above. A partner space gives access to the brands and models linked to the partnership, the sheets published by that partner, and the count of coupons issued and redeemed. No journal, no owner name, no serial number, no inventory.
Cookies
The public site sets no analytics cookie and no advertising tracker. The authenticated application uses a session cookie that is strictly necessary for signing in; sessions are encrypted server-side.
Processors
Hosting and email delivery are handled by providers whose list is to be completed before going live. Emails carrying a secret link are encrypted in the queue until they are sent.
Retention
Account and journal data are kept for as long as the account exists. Expired invitations and consumed tokens are purged. After an account is deleted, access-log records remain in a form with no content, no serial number and no direct identification.
Your rights
You have rights of access, rectification, erasure, restriction, objection and portability. Write to legal@patinae.com. Do not include journal content or invitation links in your request.