Privacy policy
Last updated: August 14, 2026
Patchlog ("we", "us") is a changelog service operated at patchlog.io. This page explains what data we collect, why we collect it, and what happens to it. We have tried to keep it in plain language, because you should not need a lawyer to understand what a changelog tool does with your data.
What we collect
- Account data. Your name, email address, and a hashed password. If you enable two factor authentication we store the secret needed to verify your codes.
- Content you create. Your projects, changelog entries, and widget settings. Published entries are public by design: they appear on your public changelog page, in your RSS feed, and in your embedded widget.
- Billing data. Payments are processed by Lemon Squeezy. We never see or store your card number. We store your subscription plan and its status so we know which features your account has.
- GitHub push data, only if you enable the integration. Your CI workflow sends us commit messages and diffs so we can draft changelog entries for you. Paths you exclude are stripped inside your own CI runner and never reach us. Diffs are deleted as soon as a draft has been generated from them, and swept if generation never happens. We do not keep your source code.
- Widget analytics. Anonymous counts of widget views and interactions. We do not identify or track individual visitors of your site.
- Technical logs. Standard server logs (IP address, user agent, requested URL) kept for debugging and abuse prevention.
How we use it
- To run the service: hosting your changelog, sending your RSS feed, serving your widget.
- To bill you for a paid plan.
- To draft changelog entries from your commits, if you enabled the GitHub integration.
- To notify our team of operational events such as new signups and feedback, so we can respond quickly.
We do not sell your data, and we do not run third party advertising or ad trackers.
AI processing
If you enable the GitHub integration, your commit messages and diffs are sent to Anthropic's Claude models to generate draft changelog entries. The drafts come back to your account for your review; nothing is published without you. If you do not enable the integration, none of your data is sent to any AI provider.
Service providers
We rely on a small set of providers to run Patchlog:
- Lemon Squeezy for payments and subscription management.
- Anthropic for AI draft generation (GitHub integration only).
- Cloudflare for CDN, caching, and connection security.
- DigitalOcean for hosting.
- Discord for internal operational alerts. A signup alert includes the new account's email address so we can offer help onboarding.
Cookies and local storage
We use first party cookies for signing in (session and CSRF protection) and a small preference cookie for your light or dark mode choice. No advertising or cross site tracking cookies.
The widget on your visitors' browsers
If you embed the Patchlog widget on your site, it stores a small localStorage value in your visitors' browsers to remember which entries they have already seen and whether they dismissed the widget. It contains no personal data and never leaves their browser.
Retention and deletion
Your data is kept for as long as your account exists. You can delete your account yourself from your settings page, which permanently removes your projects, entries, and related data. GitHub diffs are transient, as described above.
Your rights
You can access and correct your account data in your settings at any time. For an export, a correction we do not have a screen for, or a full deletion request, email us and we will sort it out.
Changes
If we change this policy we will update this page and the date at the top. A change that meaningfully affects your rights gets an email to account holders.