← Back to Backpatch

Privacy Policy

Last updated June 23, 2026

The short version

We collect the minimum needed to run the service and understand how the site is used. No advertising, no cross-site tracking, and we never sell your data.

Website analytics

When you browse this site, we record anonymous usage events: the page viewed, clicks on a few key buttons, an approximate timestamp, the referring URL, and your IP address (used for coarse geography and abuse prevention). To count returning visits we store a random identifier in your browser's local storage — it isn't a cookie and isn't shared with anyone.

These analytics only run after you accept them in the consent banner. If you decline, no events are sent. You can change your mind by clearing this site's local storage. Traffic events are automatically deleted after 90 days.

API usage

When you call the Backpatch API, we record per-day counts of requests by API key (or, for the free tier, by IP address) and which endpoint was called. This powers your dashboard and our capacity planning. We do not retain the contents of the package.json files you submit beyond the time needed to analyze them.

Account & billing

If you buy a plan, we store your email, your API key (hashed — we can't recover the original), and the Stripe customer and subscription identifiers needed to manage your subscription. Payment details are handled entirely by Stripe; we never see your card number.

Who we share with

We use Stripe for payments and a managed Postgres database to store the data above. We disclose data only as required to operate the service or comply with the law.

Your choices

Decline analytics in the banner, or contact us to access or delete your data. Reach us at [email protected].