Privacy Policy
Version 2026-07-23 · Effective 2026-07-23 · Provider: Pipcast, Inc.
This Privacy Policy explains how Pipcast, Inc. (“Pipcast,” “we,” “us,” or “our”) collects, uses, discloses, and retains personal information in connection with the IP Craft website, hosted service, accounts, billing, support, and business relationship.
Pipcast, Inc. is a Delaware corporation. IP Craft is a product and brand operated by Pipcast.
1. Scope and our roles
This Policy applies to personal information Pipcast processes for its own purposes, including website, signup, account, software purchase, billing, security, support, and business-relationship information (“Customer Account Data”). It applies to both individual and organizational customers.
When a customer submits personal information in Customer Content for software processing, the customer generally determines why and how it is processed. In that context, Pipcast generally acts as processor, subprocessor, service provider, or contractor under the IP Craft DPA, and the customer is the controller/business. An individual who uses the Service principally to process their own information is not required to separately execute the DPA as a “controller”; the DPA applies to the extent Pipcast processes personal data on that individual’s behalf.
A requested “we file” or done-for-you service involves a separate professional relationship. A prospective or engaged Registered Practitioner or Practitioner Provider may act as an independent professional controller/custodian for conflicts information, engagement records, advice, and practitioner-client files under the Professional Engagement and applicable duties. Pipcast does not treat the practitioner as having access to every workspace by default. Matter data is shared only through the approved request, conflict/suitability, engagement, and access flow.
This Policy does not replace the DPA or a Professional Engagement. The DPA controls Customer Personal Data processed by Pipcast on a customer’s behalf. The Professional Engagement controls the identified provider’s professional-service records and duties to the extent stated there.
2. Information we collect
The information we collect depends on how you interact with IP Craft.
2.1 Account and business-contact information
We may collect:
- name;
- work email address;
- organization name and type;
- role, title, and account permissions;
- account and tenant identifiers;
- authentication and identity-provider identifiers;
- verification, password-reset, and multi-factor-authentication status;
- contracting and notice contacts; and
- preferences and notification settings.
2.2 Customer Content
Customers and Authorized Users may submit or generate:
- invention disclosures and technical descriptions;
- inventor, applicant, assignee, client, counsel, and contact information;
- patent applications, claims, amendments, Office actions, responses, figures, and related documents;
- prior-art references and analyses;
- prosecution events, docket information, dates, and deadlines;
- meeting transcripts and support materials;
- communications and instructions;
- AI prompts, context, and generated work products; and
- other patent, legal-workflow, portfolio, or organizational information selected by the customer.
Customer Content may be confidential, privileged, proprietary, technically sensitive, or unpublished. Use of IP Craft does not itself create or guarantee attorney-client privilege or work-product protection. Customers are responsible for determining whether they are authorized to submit information and whether client notice or consent is required.
2.3 Billing and transaction information
We may collect or receive:
- billing-contact name and email;
- Stripe customer, checkout, subscription, invoice, transaction, and payment-status identifiers;
- purchased product, quantity, price, currency, trial, tax, refund, and chargeback information;
- billing address and tax-identification information when enabled or required; and
- fraud-prevention and payment-risk signals provided by Stripe.
Complete payment-card numbers and card security codes are collected on Stripe-hosted pages and are not stored by Pipcast.
2.4 Usage, technical, and security information
We may collect:
- IP address;
- device, browser, operating system, and user-agent information;
- request and response metadata;
- login, access, authentication, and authorization events;
- page, route, feature, and action events necessary to operate the Service;
- timestamps, account identifiers, and event identifiers;
- security, abuse, and fraud signals;
- service performance and availability information;
- application errors, stack traces, and diagnostic telemetry; and
- append-only audit events concerning relevant activity.
We use Sentry for error diagnostics. Session Replay is disabled, default PII collection is disabled, and our application is configured not to include form inputs, cookies, or Customer Content in diagnostic events. Diagnostic systems may nevertheless incidentally receive personal information, so they are treated as disclosed service providers.
When you sign up, we also record basic marketing-attribution information about how you reached us — the campaign parameters in your signup link (UTM values), the page you landed on, and the referring website — with your signup record, so we can understand which channels bring new users; this information is kept with our pre-signup records and is anonymized after a limited period.
2.5 Communications and support
We collect information you send to hello@ipcraft.co, privacy@ipcraft.co, support channels, demos, surveys, security reports, or other communications. If you send Customer Content by email, it may be processed through our corporate email provider.
2.6 Public patent and government-source information
The Service may retrieve public patent information from the USPTO Open Data Portal, PatentsView, or other public sources. Public availability does not necessarily mean information is outside privacy law, and we use it only for Service functions and related administration.
3. Sources of information
We collect information:
- directly from you;
- from the customer organization that creates or administers your account;
- automatically from your browser, device, and use of the Service;
- from Stripe and other providers supporting transactions, security, email, hosting, and diagnostics;
- from public patent and government databases; and
- from another person who is authorized to invite you, identify you in a matter, or submit information about you.
4. How we use information
We use personal information to:
- provide, operate, secure, and maintain IP Craft;
- create and administer accounts, tenants, roles, permissions, and invitations;
- authenticate users and prevent unauthorized access;
- perform customer-directed drafting, analysis, retrieval, workflow, docketing, document, and AI-assisted functions;
- process subscriptions, purchases, refunds, invoices, taxes, and billing support;
- send transactional communications, including verification, password reset, security, invitation, billing, approval, and deadline-related notices;
- provide support, troubleshoot issues, and communicate about the relationship;
- monitor performance, detect abuse, prevent fraud, investigate incidents, and protect customers and the Service;
- comply with law, legal process, accounting, tax, and regulatory obligations;
- enforce agreements and resolve disputes;
- improve reliability, usability, and security using Usage Data and deidentified or aggregated information that does not contain Customer Content or personal information; and
- evaluate or complete a merger, financing, reorganization, or sale subject to appropriate confidentiality and legal safeguards.
We do not use Customer Content or Customer Personal Data to train, fine-tune, or improve a shared or general-purpose AI model. We do not use Customer Content for unrelated advertising or commercial profiling.
5. Legal bases for EEA, UK, and Swiss processing
Where EU GDPR, UK GDPR, or Swiss law applies to Pipcast’s independent-controller processing, we rely on one or more of the following legal bases:
- Contract: to create and administer an account, provide requested services, process billing, and communicate about the Service.
- Legitimate interests: to secure the Service, prevent fraud and abuse, support customers, maintain records, improve reliability and usability using non-content telemetry, and administer our business, where those interests are not overridden by individual rights.
- Legal obligation: to comply with tax, accounting, regulatory, court, law-enforcement, and other legal requirements.
- Consent: where we expressly request consent for a specific optional activity. You may withdraw consent prospectively where consent is the legal basis.
When Pipcast processes Customer Personal Data on behalf of a customer, the customer determines the applicable legal basis, and Pipcast processes the data under the DPA and the customer’s documented instructions.
6. AI-assisted processing
IP Craft invokes Amazon Bedrock from Pipcast’s U.S. AWS environment to perform customer-requested functions. AWS operates the model deployment environment and states that model providers do not have access to customer prompts and completions. Pipcast does not use Customer Content to train shared or general-purpose models, and does not authorize a model provider to use Customer Content for the provider’s own model training, except under a separate written customer-specific arrangement.
We do not log the content of your AI prompts or the model’s responses. AI-generated drafts are stored in your tenant workspace as work product. The current providers, roles, and processing locations are identified in the DPA and the Subprocessor and Provider List.
AI outputs are drafts for human review. In self-file mode, the customer or its own practitioner reviews and decides. In professional-service mode, the engaged Registered Practitioner independently reviews and is not required to accept the AI output.
If this summary conflicts with the DPA for Customer Personal Data, the DPA controls.
7. How we disclose information
7.1 Customer organization and Authorized Users
Information in an account may be visible to the customer organization, its administrators, and Authorized Users according to configured access. The actual authorization surface must be accurately described and must not overstate unshipped ethical-wall or least-privilege controls.
7.2 Subprocessors for Customer Personal Data
Pipcast uses subprocessors to host and operate customer-directed software processing. The current list, purpose, data type, location, and change process are published at https://ipcraft.co/legal/subprocessors. Categories may include cloud infrastructure, databases, object storage, managed AI inference, transactional email, and diagnostic services to the extent they process Customer Personal Data on Pipcast’s behalf.
7.3 Other material providers and independent controllers
Pipcast also uses providers that are not necessarily subprocessors for Customer Personal Data. In particular, Stripe processes Customer Account Data for checkout, subscriptions, invoicing, payment, fraud prevention, tax, and related administration and acts as an independent controller for specified payment-network, legal-compliance, fraud, and service-administration purposes under its own terms. Listing Stripe on a transparency page does not classify it as a Customer-Content subprocessor.
Corporate/support email and other providers must be classified by the actual data and role. The public provider page distinguishes “Subprocessors” from “Other Material Providers.”
7.4 Prospective and engaged Practitioner Providers
When a customer intentionally requests Professional Services, Pipcast may disclose limited intake information to a prospective Practitioner Provider for conflicts, jurisdiction, eligibility, and suitability review. If the matter is accepted, Pipcast may provide the matter data authorized by the customer and reasonably necessary for the Professional Engagement. A Practitioner Provider does not receive standing cross-customer access and may use the information only for the professional relationship and permitted platform operations.
7.5 Legal requirements and safety
We may disclose information when reasonably necessary to comply with law or valid process; protect rights, customers, or security; investigate fraud or abuse; or establish, exercise, or defend claims. Where legally permitted, Pipcast follows the DPA for Customer Personal Data.
7.6 Corporate transaction
Information may be disclosed under appropriate safeguards in a financing, merger, acquisition, reorganization, bankruptcy, or asset sale. A successor remains subject to applicable agreements and law.
8. No sale, sharing, or targeted advertising
Pipcast does not sell personal information. Pipcast does not share personal information for cross-context behavioral advertising and does not use Customer Content for targeted advertising.
We use no advertising or third-party analytics trackers on the IP Craft marketing site or Service. If that changes, we will update this Policy and implement legally required choices before enabling the activity.
9. Cookies and browser storage
The website and authenticated Service use strictly-necessary cookies and browser storage for sign-in and session security only. These technologies are used to:
- maintain authentication and session state;
- route traffic and provide security;
- remember accessibility or interface settings; and
- prevent abuse and fraud.
We do not use advertising or cross-site tracking cookies, and our public marketing site sets no cookies. Global Privacy Control is honored to the extent legally applicable to any sale or sharing activity; Pipcast does not sell or share personal information for cross-context behavioral advertising.
Browser settings may block some storage, but strictly-necessary storage may be required for the Service to function.
10. Transactional communications
We send service-related communications such as:
- account verification and password-reset messages;
- multi-factor and security notices;
- invitations;
- billing, trial, payment-failure, refund, and subscription notices;
- approval and workflow notifications;
- deadline reminders configured by the customer; and
- important legal or service notices.
These are not marketing emails. Some non-essential notification categories may be disabled through account settings. Security, billing, legal, and account-administration communications may not be optional while an account remains active.
We will not begin sending promotional marketing emails without providing legally required notice and opt-out controls.
11. Retention
We retain information only for as long as reasonably necessary for the purposes described, subject to the following distinctions.
11.1 Customer Content and Customer Personal Data
During the service term, retention is controlled by customer use, Service functionality, legal holds, and the DPA. After termination or expiry, Pipcast will return or delete Customer Personal Data through an attended offboarding process, consistent with the DPA’s 60-day commitment (DPA Section 11), unless law requires continued retention. Deletion is not an automated, on-request erasure: because backups, audit evidence, legal holds, and append-only records are involved, Pipcast completes deletion through a controlled process and issues a qualified completion confirmation.
Certain prosecution-event and audit records may remain append-only during the term to preserve integrity. Corrections are new records rather than mutation. At termination, personal information in append-only records will be deleted or irreversibly anonymized as required by the DPA, while non-personal cryptographic hashes or integrity digests may be retained if they cannot reasonably identify a person or reconstruct Customer Content.
11.2 Backups
Customer Personal Data in routine backups is overwritten or expires according to the backup-retention cycle. Until expiration, backup data remains protected, is not used for ordinary business purposes, and is restored only for controlled recovery, continuity, testing, or actual restoration. Applicable deletion requests are re-applied where reasonably practicable after restoration.
11.3 Customer Account Data
We retain account, contract, billing, tax, fraud-prevention, security, and relationship records for the life of the relationship and afterward for periods reasonably necessary to:
- comply with accounting, tax, and legal obligations;
- resolve disputes and enforce agreements;
- prevent fraud and abuse;
- maintain security and audit evidence; and
- establish or defend legal claims.
When a specific legal retention period does not apply, we use criteria including the sensitivity, purpose, risk, and practical need for the information.
11.4 Support and communications
We retain support and business communications as reasonably necessary to resolve the request, administer the relationship, document decisions, and comply with legal obligations. Customer Content sent through email is subject to the protections and limitations applicable to the email channel and may not be stored in the same tenant-isolated system as in-product Customer Content.
12. Security
Pipcast uses technical and organizational measures designed to protect information, including tenant-scoped access controls, authentication, least-privilege access, append-only audit logging, and provider controls described in the DPA and Security page. Data is encrypted at rest, and data in transit is encrypted with TLS at our public edge; internal traffic runs within a private, access-controlled network.
No system is completely secure. We cannot guarantee that unauthorized access, loss, misuse, or a security incident will never occur. Customers are responsible for endpoint security, credential security, role configuration, and promptly removing unauthorized access.
Security reports may be sent to hello@ipcraft.co.
13. Your choices and rights
13.1 Account information
You may review or update certain account information and notification preferences through the Service. Account administrators may manage organization-level users and settings.
13.2 Customer Content requests
If your information is in Customer Content controlled by a law firm, company, or other IP Craft customer, contact that organization first. We will assist the customer as required by the DPA and applicable law. We ordinarily will not independently fulfill a request concerning Customer Personal Data without the customer’s authorization unless law requires us to do so.
13.3 Requests to Pipcast
For Customer Account Data that Pipcast controls, you may request access, correction, deletion, restriction, objection, or portability where applicable by contacting privacy@ipcraft.co. We fulfill deletion requests through a controlled, attended process as described in Section 11.
We may need to verify identity and authority. We may retain information where permitted or required for security, fraud prevention, legal compliance, accounting, contract enforcement, or legal claims. We will not discriminate against a person for exercising an applicable privacy right.
13.4 California
CalOPPA requires a conspicuous privacy policy for covered commercial websites and online services. This Policy identifies the categories of information collected, the categories of parties with whom it may be shared, the process for reviewing or requesting changes, the effective date, and our treatment of tracking signals.
If Pipcast becomes a “business” subject to the CCPA for a particular processing activity, California residents may have rights to know/access, delete, correct, opt out of sale or sharing, limit certain uses of sensitive personal information, and receive non-discriminatory treatment. Pipcast does not currently sell or share personal information for cross-context behavioral advertising.
The DPA separately imposes CCPA service-provider/contractor obligations where an IP Craft customer is a covered business and Pipcast processes Customer Personal Data on its behalf.
13.5 EEA, UK, and Switzerland
Where applicable, you may have rights to access, correct, erase, restrict, or object to processing; receive portable data; withdraw consent; and complain to a supervisory authority. These rights are subject to legal conditions and exceptions.
If Pipcast’s processing is based on legitimate interests, you may object based on your particular situation. If processing is based on consent, withdrawal does not affect earlier lawful processing.
14. International transfers
Pipcast is located in the United States. Core IP Craft application hosting, primary data storage, and AI inference are configured in AWS’s us-east-1 Region. Other providers and processing locations are identified in our Subprocessor and Provider List.
Where Customer Personal Data is transferred from the EEA, UK, or Switzerland and a transfer mechanism is required, the DPA incorporates the EU Standard Contractual Clauses, UK Addendum, and Swiss adaptations as applicable.
For Pipcast’s independent-controller processing of Customer Account Data, we use legally available transfer safeguards where required and can provide additional information upon request.
15. Children
IP Craft is not directed to children under 18, and the self-service Service may be used only by adults with legal capacity. We do not knowingly collect personal information directly from a child for the child’s own account. Customer Content may contain information about inventors or other individuals who are minors when submitted by an authorized customer; the customer is responsible for the legal basis and required notices or permissions.
Contact privacy@ipcraft.co if you believe a child created an account or submitted information without authorization.
16. Changes to this Policy
We may update this Policy prospectively to reflect legal, operational, provider, or Service changes. We will post the updated version and effective date. We will provide additional notice of a material change through email or the Service where appropriate or legally required.
If a change would materially expand a use of personal information in a manner requiring consent, we will obtain the required consent before applying the new use.
Historical versions will be retained or archived so that the version applicable to a period can be identified.
17. Contact
Pipcast, Inc.
5889 Fleet St
San Jose, CA 95120
United States
Privacy inquiries and requests: privacy@ipcraft.co
General inquiries: hello@ipcraft.co