AIPTO
Privacy Policy
Effective Date: March 27, 2026 | Last Updated: March 27, 2026
1. Overview
AIPTO is built on a zero-knowledge architecture. We are designed to know as little about your intellectual property as possible. This Privacy Policy explains what information we collect, how we use it, and the protections we have in place. By using AIPTO you agree to the practices described in this policy.
2. What We Do Not Collect
AIPTO never stores the actual text of your registered intellectual property, and never transmits it to any third party. Your submission is processed exclusively on AIPTO-controlled infrastructure to generate a SHA-256 hash, a vector embedding, and a short functional summary — the plaintext is discarded immediately afterward and is not retained anywhere. Only the hash, embedding, and summary are stored. It is mathematically impossible to recover your original content from the hash alone.
3. What We Do Collect
We collect the following information when you use AIPTO: your name and email address for account creation and registration records; SHA-256 hash of your registered intellectual property; AI-generated functional summary describing what your IP does without storing the content itself; payment information processed securely through Stripe — AIPTO does not store card details; registration metadata including dates, filing type, and status; and IP address and browser information for security and fraud prevention purposes.
4. How We Use Your Information
We use the information we collect to provide and operate the AIPTO registration service; send registration confirmations, certificates, and renewal reminders; process payments through Stripe; detect fraud and maintain platform security; respond to legal requests where required by law; and improve the platform and user experience.
5. Stripe Payment Processing
All payments are processed by Stripe, Inc. AIPTO does not store your credit card number, CVV, or full payment details. Stripe's privacy policy governs the handling of your payment information and is available at stripe.com/privacy. We store only the Stripe session ID and amount paid for our records.
6. Data Retention
Registration records including your name, email, SHA-256 hash, functional summary, and registration metadata are retained for the duration of your registration and for 7 years after cancellation or expiration for legal compliance purposes. Account information is retained until you request deletion. Renewal notification logs are retained for 3 years.
7. Data Sharing
AIPTO does not sell your personal information. We do not share your information with third parties for marketing purposes. We may share information with service providers who assist in operating the platform, including Supabase for database services, Resend for email delivery, and Stripe for payment processing. All service providers are bound by confidentiality obligations. We may disclose information if required by law, court order, or to protect the rights and safety of AIPTO and its users.
8. Public Verification
The AIPTO verify page allows anyone to confirm the existence and status of a registration using a certificate ID or SHA-256 hash. The following information is publicly visible on verified registrations: registrant name, asset name, asset type, registration date, registration status, and functional summary. Your email address is not publicly visible. Your actual IP content is never publicly visible.
9. Security
AIPTO uses industry-standard security practices including encrypted connections via HTTPS, secure database storage through Supabase with row-level security policies, and service role key protection for privileged operations. No system is perfectly secure. In the event of a data breach affecting your personal information, we will notify you as required by applicable law.
10. Your Rights
You have the right to access the personal information we hold about you, request correction of inaccurate information, request deletion of your account and associated personal data, and opt out of non-essential communications. To exercise these rights, contact us at support@aipto.io. Note that deletion of your account does not delete registration records required for legal compliance purposes.
11. Cookies
AIPTO uses essential cookies for authentication and session management. We do not use tracking cookies or third-party advertising cookies. You may disable cookies in your browser settings but this may affect your ability to log in to the platform.
12. Children
AIPTO is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from minors. If you believe we have collected information from a minor, contact us immediately at support@aipto.io.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated effective date. Continued use of the platform after changes constitutes acceptance of the revised policy.
14. Contact
For privacy questions or requests, contact AIPTO at support@aipto.io.