Privacy

What we keep, and how to take it back.

Patina's whole point is that your data stays yours, so the privacy policy had better be short and true. Here it is, in plain English. Last updated 25 September 2026.

What we collect

  • A scrambled fingerprint of your Vana Personal Server, so your score is the same on every computer you connect from. It is a one-way hash: we cannot turn it back into an address, and it is not your email or your name. There is no sign-in to Patina at all.
  • Dates and counts from each source you connect: the month things happened in, how many there were, and the handle that account is known by, plus the score worked out from them. Never your posts, your messages, your captions, your addresses, the names of people you know, or the contents of the account. The full list, source by source.
  • A small cookie, so you can come back and find your own result.
  • Instagram is paused. Patina cannot yet prove an Instagram account belongs to the person connecting it, so it is not offered. Instagram data already held is not used in any score, and you can remove it on your data page.

What we never collect

Your passwords. Signing in happens inside Vana Desktop, in a browser window on your own computer, and nothing about it reaches us. Your email or your name. And the actual contents of your accounts: Patina reads the shape of your history, not what is in it. Where a source hands over something we did not ask for, an email address on a YouTube profile, the names of everyone who liked a post, the address a car picked you up from, it is dropped before anything is written down.

Why we keep it

To show you your score and keep it across your devices, and to count eligibility against the underlying account so the same person cannot quietly count twice. That is the whole list.

Who can see it

Patina does not publish a list of who is here. There is nowhere on this site that pairs a set of names with a set of scores. Your shareable card at /u/your-name is public only if you choose a name and share it, and it shows your score and how far your history goes back, never the accounts underneath. We do not sell your data, and we do not hand it to advertisers.

AI assistants, and the public API

Patina has a public API, and an MCP server that lets AI assistants such as Claude and ChatGPT look up a score in the middle of a conversation. Both are open on purpose: no key, no sign-in, so any app or agent can check a score without asking us for permission.

They can only see what is already public: a profile that has claimed a username, its score, how far back its history goes, and the breakdown behind it. The same things on your public card. If you have never chosen a username, your profile is not reachable through any of it.

One of those tools works in the other direction, from a GitHub or LinkedIn handle to a score. It returns the score and the number of years, and nothing else. It never returns your Patina name, and it never reveals which other accounts you have connected, because that would let somebody start with one handle and uncover the rest of your accounts. Lookups by email address are refused outright.

When an assistant makes one of these calls, it reaches us from that assistant's own servers rather than from your device, and the answer goes back into that conversation. What happens to it after that is up to whoever runs the assistant, not us.

Revoking access, and deleting your data

Two separate things. Revoking Patina's access inside your Vana account stops any future read, Vana enforces that, not us. To remove what Patina has already stored, use the button below. It deletes everything immediately, no email and no waiting.

See, download, or delete your data

Everything above is checkable rather than a promise. Your data page lists every row Patina stores, hands you a copy of it, and lets you remove one source or all of them.

Open your data page

Questions? Ask in the Vana Discord. See also the terms.