Privacy

What we keep, and how to take it back.

Patina's whole point is that your data stays yours, so the privacy policy had better be short and true. Here it is, in plain English. Last updated 14 August 2026.

What we collect

  • A scrambled fingerprint of your Vana Personal Server, so your score is the same on every computer you connect from. It is a one-way hash: we cannot turn it back into an address, and it is not your email or your name. There is no sign-in to Patina at all.
  • Dates and counts from each source you connect: the month things happened in, how many there were, and the handle that account is known by, plus the score worked out from them. Never your posts, your messages, your captions, your addresses, the names of people you know, or the contents of the account. The full list, source by source.
  • A small cookie, so you can come back and find your own result.

What we never collect

Your passwords. Signing in happens inside Vana Desktop, in a browser window on your own computer, and nothing about it reaches us. Your email or your name. And the actual contents of your accounts: Patina reads the shape of your history, not what is in it. Where a source hands over something we did not ask for, an email address on a YouTube profile, the names of everyone who liked a post, the address a car picked you up from, it is dropped before anything is written down.

Why we keep it

To show you your score and keep it across your devices, and to count eligibility against the underlying account so the same person cannot quietly count twice. That is the whole list.

Who can see it

Patina does not publish a list of who is here. There is nowhere on this site that pairs a set of names with a set of scores. Your shareable card at /u/your-name is public only if you choose a name and share it, and it shows your score and how far your history goes back, never the accounts underneath. We do not sell your data, and we do not hand it to advertisers.

AI assistants, and the public API

Patina has a public API, and an MCP server that lets AI assistants such as Claude and ChatGPT look up a score in the middle of a conversation. Both are open on purpose: no key, no sign-in, so any app or agent can check a score without asking us for permission.

They can only see what is already public: a profile that has claimed a username, its score, how far back its history goes, and the breakdown behind it. The same things on your public card. If you have never chosen a username, your profile is not reachable through any of it.

One of those tools works in the other direction, from a GitHub, Instagram or LinkedIn handle to a score. It returns the score and the number of years, and nothing else. It never returns your Patina name, and it never reveals which other accounts you have connected, because that would let somebody start with one handle and uncover the rest of your accounts. Lookups by email address are refused outright.

When an assistant makes one of these calls, it reaches us from that assistant's own servers rather than from your device, and the answer goes back into that conversation. What happens to it after that is up to whoever runs the assistant, not us.

Revoking access, and deleting your data

Two separate things. Revoking Patina's access inside your Vana account stops any future read, Vana enforces that, not us. To remove what Patina has already stored, use the button below. It deletes everything immediately, no email and no waiting.

Delete my data

Remove everything Patina holds about you, whenever you want.

Questions? Ask in the Vana Discord. See also the terms.