Privacy Policy
Last updated: December 7, 2025
1. Introduction
nextX AG ("Company", "we", "us", or "our") operates the PatentFiller platform. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.
We are committed to protecting your privacy and ensuring compliance with the Swiss Federal Act on Data Protection (FADP), the EU General Data Protection Regulation (GDPR), and other applicable privacy laws.
2. Data Controller
nextX AG
Hauptstrasse 20
6418 Rothenthurm
Switzerland
Email: info@nextx.ch
3. Information We Collect
3.1 Account Information
When you create an account, we collect:
- Email address
- Name (optional)
- Profile picture (optional, via OAuth providers)
- Authentication credentials
3.2 Patent-Related Data
When you use our Service, we process:
- Invention disclosures and descriptions
- Patent drafts and documents
- Inventor and assignee information
- Uploaded files and references
- AI chat conversations
3.3 Technical Data
We automatically collect:
- IP address
- Browser type and version
- Device information
- Usage patterns and analytics
- Cookies and similar technologies
3.4 Payment Information
Payment processing is handled by Lemon Squeezy. We do not store credit card numbers or full payment details. We only receive:
- Transaction IDs
- Subscription status
- Billing address (for tax purposes)
4. How We Use Your Information
We use your information to:
- Provide and maintain the Service
- Process your patent documents
- Authenticate your account
- Process payments and manage subscriptions
- Send important updates and notifications
- Respond to customer support requests
- Improve our Service based on usage analytics
- Detect and prevent fraud or abuse
- Comply with legal obligations
5. AI Processing
🤖 We use AI (Claude by Anthropic) to process your patent content.
When you use AI-powered features (patent generation, quality review, chat), your content is sent to our AI provider. We have data processing agreements in place to ensure your data is:
- Not used to train AI models
- Processed securely and confidentially
- Deleted after processing
6. Data Sharing
We share your data only with:
6.1 Service Providers
- Supabase: Database and authentication
- Anthropic: AI processing (Claude)
- Perplexity: Prior art search
- Lemon Squeezy: Payment processing
- Vercel: Hosting and CDN
6.2 Legal Requirements
We may disclose your information if required by law, court order, or government request.
6.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, your data may be transferred to the new owner.
7. Data Retention
| Account Type | Retention Period |
|---|---|
| Free accounts | 3 months after last activity |
| Pro/Professional | While active + 3 months after cancellation |
| Paused subscriptions | 6 months |
| Exported projects | Immediately available for deletion |
8. Your Rights
Under GDPR, FADP, and other applicable laws, you have the right to:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate or incomplete data
- Erasure: Request deletion of your data ("right to be forgotten")
- Portability: Receive your data in a structured format
- Restriction: Limit how we process your data
- Objection: Object to certain types of processing
- Withdraw consent: Revoke previously given consent
To exercise these rights, contact us at info@nextx.ch. We will respond within 30 days.
9. Data Security
We implement appropriate security measures including:
- TLS encryption for data in transit
- Encryption at rest for stored data
- Access controls and authentication
- Regular security audits
- Secure development practices
While we strive to protect your data, no system is 100% secure. You are responsible for maintaining the security of your account credentials.
10. International Data Transfers
Your data may be processed in countries outside Switzerland and the EU, including the United States (where our service providers are located). We ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs)
- Data Processing Agreements with all providers
- Compliance with Swiss-U.S. Data Privacy Framework where applicable
11. Cookies
We use cookies for:
- Essential cookies: Authentication and security
- Functional cookies: Remembering preferences
- Analytics cookies: Understanding usage patterns
You can control cookies through your browser settings. Disabling essential cookies may affect Service functionality.
12. Children's Privacy
Our Service is not intended for users under 18 years of age. We do not knowingly collect data from children. If you believe we have collected data from a child, please contact us immediately.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or in-app notification. The "Last updated" date at the top indicates when changes were made.
14. Contact Us
For privacy-related questions or to exercise your rights, contact us at:
Email: info@nextx.ch
Address: nextX AG, Hauptstrasse 20, 6418 Rothenthurm, Switzerland
You also have the right to lodge a complaint with a data protection authority, such as the Swiss Federal Data Protection and Information Commissioner (FDPIC).