Legal
Version 1.0 · Effective 14 August 2026 · Corvair Pte. Ltd. (UEN 202551453H)
Corvair Pte. Ltd. (UEN 202551453H), 23 Jalan Raja Udang, #11-09, The Arte, Singapore 329216, is the controller of the personal data described in this policy.
Data Protection Officer: Christopher Jackson, reachable at privacy@corvair.ai. You can contact our DPO about anything in this policy, including a request to exercise your rights.
This policy covers ipguru.ai, invent.sg and any other storefront we operate. It is written to meet the Singapore Personal Data Protection Act 2012 and, where it applies to you, the EU and UK General Data Protection Regulation.
There is one privacy policy, not one per market. IPGuru is a single service operated from Singapore, so there is one controller, one set of processing operations and one set of sub-processors, whichever storefront you arrived through. A separate policy per market would drift, and would mean the same request answered differently depending on which page you had read.
Where a market needs local particulars, they appear in a short market annex at section 15 carrying only the local supervisory authority, the local complaint route and any local representative. Nothing in an annex changes what we collect, why, who we share it with, or how long we keep it.
Four things are worth stating before the detail, because they are the questions people actually ask.
We do not sell your personal data. Not to anyone, for any purpose, ever.
We do not use your invention material to train AI models. Your uploads, your generated documents and your project conversations are not used to train, fine-tune or improve any general-purpose model, ours or a third party's. We contract with our model providers on terms that prohibit it.
We do not read your project content as a matter of routine. Our support team sees the shape of your account, not its contents. Access to content requires a declared, time-limited grant that is recorded in your own activity log, so you can see it happened.
We do not use your data for advertising, and we do not build advertising profiles.
| Category | What it includes | Why we process it | Legal basis (GDPR) |
|---|---|---|---|
| Account data | Name, email address, the identity provider you sign in with, account settings, verification status | To create and operate your account, authenticate you, and secure it | Performance of a contract |
| Project content | Everything you upload or the service generates for you: invention descriptions, documents, drafts, files, research, conversations | To provide the service you asked for | Performance of a contract |
| Commercial data | Orders, entitlements, membership level, project grades, invoices, refunds, the storefront you bought through | To sell you the service, honour what you bought, and keep accurate records | Performance of a contract; legal obligation for tax records |
| Usage and operational telemetry | Sign-in events, feature use, performance and error data, request rates, allowance consumption | To run the service, diagnose faults, enforce allowances, and improve reliability | Legitimate interests: operating a reliable and secure service |
| Security data | IP address, device and browser information, authentication events, step-up events, audit records | To detect and prevent abuse, fraud and unauthorised access | Legitimate interests: security; legal obligation |
| Support data | Your messages to us, and our record of what we did | To help you, and to keep a record of it | Performance of a contract; legitimate interests |
| Marketing data | Your consent, when you gave it, from which page, and under which terms version | To send you material you asked for | Consent |
We do not collect payment card details, bank details, health or medical records, or government identification numbers. Payment information goes directly to our merchant of record and never reaches us.
Children. The minimum age for an account is fifteen, and higher in some markets. We do not knowingly collect personal data from anyone below the applicable minimum. If you believe we have, contact our DPO and we will delete it.
Each project is isolated. A project has its own knowledge base, its own working memory and its own file vault. Access is decided per request by a policy engine that denies by default: if it cannot reach a decision, it refuses rather than allowing.
Sharing is yours to control. A project is private until you share it. You can share with named people and revoke each of them individually, or create an unlisted link. An unlisted link can be opened by anyone who has it, so treat it as a key rather than as a secret.
Uploads are scanned for malware and prohibited content before anything enters your knowledge base. Items that fail are quarantined and never enter it.
Sensitive actions require you to re-authenticate. Deleting a project, transferring ownership, exporting your data, changing your credentials, erasing your account and publishing all require a fresh authentication, even if you are already signed in.
Operator access is declared, expiring and logged. If our support team needs to see your content in order to help you, that access is requested explicitly, expires automatically, and appears in your own activity log. There is no standing access and no silent access.
We share personal data only with the following, and only as far as necessary.
| Sub-processor | What it does | Where |
|---|---|---|
| Google Cloud Platform | Application hosting, database and file storage | United States (us-central1) |
| Google Firebase / Identity Platform | Authentication and identity | United States |
| Permit.io | Authorisation decisions. Receives identifiers and entitlement attributes, never content | United States / EU |
| Neo4j Aura | Graph database supporting research features | United States |
| Google Gemini | Generation of drafts, analysis and research output. Contracted on terms that prohibit training on your content | United States |
| Mailgun | Delivery of service email | United States |
We publish changes to this list before a new sub-processor begins processing. If you object to a new sub-processor, contact our DPO.
Cleverbridge GmbH sells to you as our authorised reseller. For the payment transaction it is a separate and independent controller of the personal data it collects from you, not our processor, and its own privacy notice governs that data. We receive from it your order reference, the product bought, and your contact email address. We never receive your payment card details.
We may disclose personal data where we are legally required to, to establish or defend a legal claim, or to protect the safety of a person. In a merger, acquisition or sale of the business, data may transfer to the acquirer under the same protections, and we will tell you.
We never share your project content with anyone for their own purposes.
We are established in Singapore and our infrastructure is currently hosted in the United States. If you are in the EU, the UK or another region with transfer restrictions, your personal data is transferred outside that region.
We rely on Standard Contractual Clauses with our providers, together with the technical measures described in section 4, as the basis for those transfers. You can request a copy of the relevant clauses from our DPO.
We are evaluating regional hosting for other markets. If we introduce it, we will update this policy before any data moves.
| Data | Retention | Trigger for disposal |
|---|---|---|
| Account data | While your account is open | Account closure, then deletion after the erasure process completes |
| Project content | While your account is open, or until you delete the project | Your deletion, or account closure |
| Archived projects | Until you delete them | Your deletion |
| Dormant account, archived | From 180 days without activity | Archiving is automatic and reversible. See section 8 |
| Dormant account, purged | From 18 months without activity, after notice, and only where no paid perpetual entitlement is held | See section 8 |
| Commercial records: orders, invoices, tax | Five years from the end of the relevant financial year | Statutory retention period expiry |
| Security and audit records | Twelve months, or longer where needed for an open investigation | Period expiry, or closure of the investigation |
| Operational telemetry | Thirteen months | Period expiry |
| Support correspondence | Twenty-four months from closure | Period expiry |
| Marketing consent records | While consent stands, and three years after withdrawal as evidence that it was withdrawn | Period expiry |
| Identity record after erasure | Retained in disabled form | See section 8 |
| Backups | Bounded window, currently thirty-five days | Rotation |
You can delete a project at any time from within the service.
You can erase your account. When you do:
What survives an erasure, and why. Your identity record is disabled rather than deleted, retaining your identifier and email address. This is so that the account cannot be silently recreated and so that we can prove the erasure happened if you or a regulator ask. The legal basis is our legitimate interest in the integrity of the erasure, and it is disposed of after twenty-four months. We tell you this before you confirm, not afterwards.
Archiving is not deleting. Archiving preserves your material and frees an active-project slot.
Keeping data forever is not a kindness, so accounts that go quiet are handled on a stated schedule rather than left indefinitely.
| After | What happens | Reversible? |
|---|---|---|
| 180 days with no activity | Your account and its projects may be archived. Everything is preserved. Archiving frees resources and active-project allowance | Yes, immediately. Sign in and it is restored |
| 15 months | We email you to say the account is dormant, what will happen, and how to keep it | — |
| 17 months | We email you again | — |
| 30 days before purge | A final email, with a link to export everything | — |
| 18 months with no activity | The account and its material may be purged, subject to the exception below | No. This is permanent |
Any sign-in resets the clock. Opening the service, exporting, or replying to one of the notices all count as activity.
Accounts holding a paid project grade are never purged. A grade is sold as permanent for its project, and destroying it because nobody signed in for eighteen months would take away something that was paid for and promised without limit. Those accounts are archived and stay archived.
We would rather you kept your work than that we saved the storage. Invention is intermittent by nature, and a year between sessions is normal rather than abandonment, which is why the notices start at fifteen months and why a single sign-in is enough to stop the process.
Whether you are covered by the PDPA, the GDPR or both, you can:
How to exercise them. Most are available directly in the service: export, deletion and correction are self-service. For anything else, contact privacy@corvair.ai. We respond within thirty days and will tell you if we need longer.
Complaints. If you are unhappy with how we have handled your data, tell us first and we will try to fix it. You can also complain to the Personal Data Protection Commission of Singapore, or, if you are in the EU or UK, to your local supervisory authority.
Clause 21 of the Terms of Service sets out every channel we use, what each carries and what you control. This section says what those communications mean for your personal data.
Four kinds of message, kept separate on purpose:
| Kind | Examples | Our legal basis | Your control |
|---|---|---|---|
| Essential | Sign-in and security notices, receipts, entitlement changes, an expiring share, a completed export, material changes to these policies, our answer to a request you made | Performance of our contract with you, and our legal obligations | None while you have an account. You cannot unsubscribe from being told your credentials changed |
| Configured | Activity digests, project and collaborator notifications, allowance warnings, periodic summaries | Performance of our contract, and our legitimate interest in operating a service that tells you what it is doing | Complete. On, off, how often, and by which channel, in your settings |
| Related services | Messages to a customer about IPGuru services similar to what they already have | Our legitimate interests, in markets that permit this. Where your market requires consent first, consent | Off in one click, at any time, and we offer the choice when we take your address |
| Marketing | Product news, launches, education, the notify-me list | Consent where your market requires it, otherwise our legitimate interests | Off in one click, at any time, honoured everywhere |
An essential message never carries marketing. The moment a receipt carries a promotion, the whole receipt becomes marketing, and our ability to send you the receipts you actually need depends on not having done that.
Consent, where we rely on it, is active and recorded. No pre-ticked boxes, no consent bundled into accepting the terms or into a purchase. We record what you agreed to or declined, when, from which page and under which version. Where we rely on legitimate interests instead, you have the right in section 9 to object, and for direct marketing an objection is absolute: we stop.
Where a market allows us to write to our own customers about related services without asking first, we use it, and we always give you the choice when we take your address and an opt-out in every message. Your Market Schedule states the position for your market.
We do not currently market by telephone call or text message. A text from us is a security code, or an alert you asked to receive that way. If that ever changes we will meet the rules of the market first, including any do-not-call register.
We never pass your contact details to anyone else to market to you, and we do not sell or rent them.
Our merchant of record writes to you as well. Cleverbridge GmbH sends order confirmations, invoices and payment notices as the seller of record for the transaction. For that purpose it is a controller in its own right, under its own privacy notice, and those messages cannot be switched off because they are part of the sale.
If you subscribed to a list without an account, you have given us an email address and nothing else. You have no account and no profile, and the rights in section 9 apply to that record exactly as they would to any other.
We keep a record of what we send you, including support conversations, for the periods in section 7. It is kept so that a question about what you were told has an answer.
The measures we rely on include: encryption of data in transit and at rest; multi-factor authentication; a policy decision point that denies by default; step-up re-authentication for sensitive actions; per-project isolation of storage; short-lived data-plane credentials that can only be narrowed and never widened; keyless deployment credentials; malware scanning of uploads; an append-only audit ledger that is never edited; daily backups replicated to redundant storage; and a documented business continuity and disaster recovery plan.
Breach notification. If a data breach occurs that is likely to result in significant harm, we will notify the PDPC within three calendar days of assessing it as notifiable, and affected individuals as soon as practicable. Where the GDPR applies, we will notify the supervisory authority within seventy-two hours and affected individuals without undue delay where the risk is high. We will tell you what happened, what data was involved, what we have done, and what you should do.
No security is absolute. We will tell you promptly and honestly if something goes wrong.
We use cookies and local storage for three purposes: strictly necessary (keeping you signed in, security, load balancing), preferences (remembering your settings), and analytics (understanding how the service is used so we can improve it).
Strictly necessary cookies do not require consent. Where consent is required for analytics or preferences in your market, we ask for it before setting them and you can change your mind at any time. We do not use advertising cookies or third-party tracking for advertising.
We will publish any new version with a version number and effective date. For a change that materially affects your rights, we will give you at least thirty days' notice by email before it takes effect.
Data Protection Officer, Corvair Pte. Ltd. privacy@corvair.ai 23 Jalan Raja Udang, #11-09, The Arte, Singapore 329216
Local particulars only. Nothing in an annex changes what we collect, why, who we share it with, or how long we keep it. Everything above this section applies to you wherever you are.
Singapore. Corvair Pte. Ltd. is established in Singapore and the Personal Data Protection Act 2012 applies to our handling of your personal data. Supervisory authority: the Personal Data Protection Commission, pdpc.gov.sg. Our Data Protection Officer, named in section 14, is the contact for any access, correction or withdrawal-of-consent request under the Act, and for any complaint. If we do not resolve a complaint to your satisfaction you may take it to the Commission.
European Union. The GDPR applies to our processing of your personal data. Sections 3, 6, 7 and 9 state our legal bases, our retention periods, the rights you hold and the safeguards for transfers. Because we host in the United States, every transfer is made under the European Commission's standard contractual clauses with each recipient, supported by a transfer risk assessment. You may complain to the supervisory authority of the member state where you live, where you work, or where the matter arose, and you may do so without contacting us first, although we would rather you gave us the chance to fix it.
United Kingdom. The UK GDPR and the Data Protection Act 2018 apply on the same terms as the paragraph above, with transfers made under the UK International Data Transfer Addendum to the standard contractual clauses. Supervisory authority: the Information Commissioner's Office, ico.org.uk.
Australia. The Australian Privacy Principles under the Privacy Act 1988 apply to our handling of your personal information. Under the Notifiable Data Breaches scheme we will notify the Commissioner and affected individuals as soon as practicable where a breach is likely to result in serious harm. You may ask us for access to or correction of your information under APP 12 and APP 13, and section 8 tells you how. Supervisory authority: the Office of the Australian Information Commissioner, oaic.gov.au.
Every other market. Where we have not published an annex for your market, this policy applies to you in full and nothing is reduced by the absence. You may complain to your local data protection authority, or to the Personal Data Protection Commission in Singapore, where we are established.