# Privacy Policy **Last Updated:** October 8, 2026 Pattern Wave ("we," "us," "our") operates OrionGMV ("the Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service. Pattern Wave determines the purposes and means of processing account, billing, security and service-operation information. Contact support@patternwave.studio for privacy matters. Our hosted service operates in the United States. This notice describes our handling of information. It does not waive your statutory rights or replace consent where applicable law requires separate consent. --- ## 1. Information We Collect ### 1.1 Account Information - Email address (for authentication and communication) - A protected account-passphrase verification record, rather than the plaintext passphrase - Security information needed to protect and open your vault - Stripe customer ID, if you choose a paid subscription (for billing) - Terms acceptance version and server timestamp, and your adult-eligibility confirmation (for account eligibility and agreement records) ### 1.2 Usage Data - HTTP routes, request identifiers, timestamps, outcomes and timings. IP addresses and HTTP connection information are processed to deliver requests, enforce abuse limits and operate the reverse proxy; infrastructure logs can contain network identifiers. Hashing an identifier does not by itself make it anonymous. - Error logs (without payloads or personal content) - Tier usage (read/write counts for quota enforcement) - Vault metadata (size, version, last accessed) - Signed-in app heartbeats, daily first/last activity, heartbeat counts and estimated connected time. - MCP tool names, account/vault/connected-app route identifiers, outcomes, bounded error categories and durations. The operational MCP receipt schema excludes tool arguments, prompts and memory text; information submitted as vault content is processed separately. ### 1.3 Device Information - OS type and version (for compatibility) - App version (for update notifications) - Session security identifiers derived from randomly generated signing public keys, those public keys, session-family identifiers and issuance/expiry/revocation timestamps. They are linked to accounts and are personal data, not hardware serial numbers. A fresh signing identity is generated at sign-in or registration. The private key remains on the device. - Update reporting: account/session identifier, release/version, progress, status, bounded error categories and timestamps, to confirm delivery and recover failed updates. - Support and bug reports you submit, including account/device context and the details you choose to provide. Do not include passwords, keys, or unrelated personal content in a report. - Support reports may include vault and session context, plan/status, app/OS version, architecture, request identifiers and error details. Reports submitted while signed out can be queued locally and sent after the next sign-in. ### 1.4 What We Do NOT Collect - **Routine human review of vault content** — vault content is stored encrypted and temporarily decrypted for authorized memory operations; ordinary administrator interfaces do not expose it. We do not sell it or use it to train shared models or another user's AI. - **Unconnected conversations** — we do not receive conversations simply because you use another AI app. Content that you or a connected app submit to OrionGMV is vault content processed by the Service. - **Model provider credentials** — the consumer switchboard does not require you to provide third-party model API keys to use your vault. - **Complete card numbers and card security codes** — handled by Stripe. We store customer/subscription identifiers, plan/status and trial history. --- ## 2. How We Use Your Information Where GDPR applies, account provision and authorized vault operations rely on performance of the contract only to the extent objectively necessary. Requested billing and support use contract performance or steps you request before entering it. Account authentication, signed-request validation, replay/abuse prevention and security investigation rely on legitimate interests in protecting users and the service. Reliability diagnosis and bounded service-use analytics rely on legitimate interests in maintaining and understanding service operation, separately from contractual necessity. Agreement and adult-eligibility records support our legitimate interests in administering eligibility and evidencing agreements. A legal-obligation basis applies only where a specific applicable law requires the processing. Legitimate interests require necessity and balancing assessments and are subject to your right to object. Accepting the EULA is not blanket privacy consent. A new optional use requiring consent will be explained and separately authorized before that use. We do not use operational records for advertising profiles or to train shared models or another user's AI. Account and session information is required for authenticated access; without it we cannot provide protected service operations. Support descriptions are optional. Previously granted trial eligibility follows account and subscription history, not physical-device tracking. A Free account does not require payment information or contact with Stripe. Account, security and billing gates can operate automatically; contact support to request review of an incorrect restriction. | Purpose | Data Used | |---------|-----------| | Authentication | Email, authentication hash, session public key and signed proofs | | Service provision | Vault metadata, request routing | | Billing | Stripe customer ID, tier status | | Quota enforcement | Read/write counters (Redis, 48h expiry) | | Security | Network information, session proofs, audit metadata | | Support | Email, account status | | Reliability and service-use analysis | Submitted reports, content-free tool receipts, update status and daily activity | --- ## 3. Data Storage and Security ### 3.1 Encryption - **In transit**: The desktop app communicates with the hosted service over HTTPS. - **At rest**: Vault content is encrypted in service-managed storage - **Passphrases**: Vault passphrases are sent in an encrypted envelope to the authorized server and used transiently for authorized operations. They are not persistently stored in plaintext on the server. - **Local credentials**: Local session credentials are encrypted. The app prefers the operating-system credential store, with an app-private key-file fallback when that store is unavailable. Protect access to your device. ### 3.2 Storage Locations - Encrypted vault content is held in service-managed storage. - Account, billing, usage and security records are held separately from vault content. Monthly allowances use durable account records and the server clock; reinstalling an app does not reset them. - Temporary connection, request-security and rate-limit information is held in short-lived caches. ### 3.3 Retention We preserve your account and vaults while you maintain the account, including during inactivity or on the Free plan. Inactivity, a missed payment or cancellation does not trigger automatic deletion. You can request account deletion in Settings. Access is revoked when the request is accepted, and a durable receipt tracks removal of account records, vault data, associated support records, and service-managed backup copies. Deletion is completed only after the required checks pass. Failures are retried; acceptance is not a statement that erasure has finished. A specific legal obligation or documented dispute may require restricted retention of particular records. Stripe and other independent providers may retain records under their own legal obligations and policies. - Operational MCP receipts/rollups, HTTP audit records and daily activity have a **90-day default** retention policy. The server supports configured periods between 7 and 730 days. Any different production period must be disclosed before taking effect. - Retired session-identity bindings are removed after that retention period measured from revocation or the last refresh-session expiry, once no usable refresh session remains. Live session bindings are preserved. - Update history expires after the same retention period without progress. Recently progressing updates are preserved; abandoned update records also expire. - Short-lived replay, rate-limit and presence caches expire independently of durable audit/activity records. - Account deletion removes associated installation bindings, update history, operational receipts and daily activity from the active database. The deletion workflow also handles vault/storage versions, support records and billing-system actions. A content-free completion receipt is retained for 90 days. - Support and billing records remain while needed for the request, account administration, a specific legal obligation or a documented dispute. Longer retention must be restricted to that purpose. Cancellation alone is not immediate account deletion. Cleanup jobs are bounded and may take time to complete. Contact us for the applicable configured period, backup expiry and any specific legal-retention exception. --- ## 4. Data Sharing and Disclosure ### 4.1 Third-Party Services We use the following third-party services: | Service | Purpose | Data Shared | |---------|---------|-------------| | Stripe | Payment processing | Account and subscription information needed for billing; payment details provided directly to Stripe | | Hosting and storage providers | Operation of the hosted service | Encrypted stored vault content and operational information needed to host the service | | Apps you connect | Your authorized memory operations | Content and results you authorize through those apps; their own privacy notices apply | ### 4.2 Legal Disclosure We may disclose information if required by: - Valid court order or subpoena - Law enforcement request with proper legal process - Emergency involving imminent harm ### 4.3 Business Transfers If Pattern Wave is acquired or merges, user data may transfer to the successor entity under the same privacy protections. --- ## 5. Your Rights Depending on your jurisdiction, you may have the right to: - **Access**: Request a copy of your account data - **Correction**: Update your email or other account details - **Deletion**: Request account and vault deletion, subject to lawful retention requirements - **Access and export**: Request access to or a portable copy of your information as provided by applicable law - **Restriction**: Limit certain processing activities - **Object**: Object to processing based on legitimate interests, including operational analytics. We assess the request and stop the processing unless applicable law permits continuation on demonstrated grounds. - **Withdraw consent**: Withdraw consent for any processing actually based on consent, without affecting prior lawful processing. - **Complain**: Lodge a complaint with a competent supervisory authority, including in the EU country of habitual residence, work or the alleged infringement. You can export account information and readable vault memories, or request deletion, in the desktop app's Settings. Exported files contain readable personal content; store them securely. You may also request a copy by emailing support@patternwave.studio from your account email. These requests are handled manually, and we may need to verify your identity securely. Never email account passwords or vault passphrases. The app can open a draft request; you review and send it yourself. For correction, restriction, objection, or assistance with any right, contact support@patternwave.studio. We verify identity proportionately, normally through your existing account, and respond within applicable statutory deadlines. Statutory access/export rights are not limited by the absence of a particular UI feature. Essential account-security processing may remain necessary for protected service access. EULA acceptance does not waive these rights. --- ## 6. Children's Privacy OrionGMV is a general-purpose memory and storage service intended exclusively for adults who are at least 18 and have reached the age of legal majority where they reside. Registration requires an affirmative eligibility confirmation and acceptance of the current EULA. We do not knowingly permit minors to create accounts or use the Service, including with parental permission or through another person's account. We rely on the confirmation unless we receive information indicating that it is inaccurate; we do not routinely inspect vault content to determine a user's age. If you believe an account belongs to a minor, contact support@patternwave.studio. If we learn that a user is ineligible, we will suspend access and handle associated personal information as required by applicable law, including deletion where required. An eligibility confirmation does not remove our obligations under applicable law. --- ## 7. International Data Transfers The hosted service processes information in the United States. Your connected apps may process information in other locations under their own policies. Where applicable law requires a transfer mechanism or additional safeguards, those requirements must be satisfied; this notice does not itself establish such a mechanism or waive those requirements. Contact support@patternwave.studio for relevant recipients, processing locations and safeguards, or a copy of applicable safeguards. Accepting the EULA is not consent to otherwise unlawful transfers. --- ## 8. Changes to This Policy We may update this Privacy Policy. Material changes will be communicated via email or in-app notice. Where required by law, we will obtain consent for a new use of information rather than relying solely on continued use. --- ## 9. Contact - **Privacy inquiries**: support@patternwave.studio - **Underage-use reports**: support@patternwave.studio - **Location**: Pattern Wave is based in Texas, United States. The hosted service runs in the United States. --- *© 2026 Pattern Wave. All rights reserved.*