Legal
Version 1.2 · Effective 29 September 2026 · Corvair Pte. Ltd. (UEN 202551453H)
Corvair Pte. Ltd. (UEN 202551453H), 23 Jalan Raja Udang, #11-09, The Arte, Singapore 329216, is the controller of the personal data described in this policy.
Data Protection Officer: Christopher Jackson, reachable at privacy@ipguru.ai. You can contact our DPO about anything in this policy, including a request to exercise your rights.
This policy covers ipguru.ai, invent.sg and any other storefront we operate. It is written to meet the Singapore Personal Data Protection Act 2012 and, where it applies to you, the EU and UK General Data Protection Regulation.
There is one privacy policy, not one per market. IPGuru is a single service operated from Singapore, so there is one controller, one set of processing operations and one set of sub-processors, whichever storefront you arrived through. A separate policy per market would drift, and would mean the same request answered differently depending on which page you had read.
Where a market needs local particulars, they appear in a short market annex at section 15 carrying only the local supervisory authority, the local complaint route and any local representative. Nothing in an annex changes what we collect, why, who we share it with, or how long we keep it.
Schools, employers, events and other institutions. When you take part through an institution's cohort, workplace or licensed deployment, or dedicated platform (Terms clause 5.1), the institution may be the controller of some of your personal data, such as your enrolment and the work its cohort, event or programme makes visible, and we process that data on its behalf under a written agreement. Where that is so, the institution's privacy notice also applies, and you can send a request to either of us. We will pass on a request that belongs to the institution. Where a dedicated platform runs in the institution's own cloud tenancy, the institution controls that platform's infrastructure and data, and its own providers and privacy notice apply as its agreement with us says.
Four things are worth stating before the detail, because they are the questions people actually ask.
We do not sell your personal data. Not to anyone, for any purpose, ever.
We do not use your invention material to train AI models. Your uploads, your generated documents and your project conversations are not used to train, fine-tune or improve any AI model, ours or a third party's. We contract with our model providers on terms that prohibit it. We do analyse chat and generation histories by automated means to improve the service's own software. Nothing from your content is reused for another customer, and you can opt out. Section 3 explains.
We do not read your content as a matter of routine. Our support team sees the shape of your account, not its contents. Staff can see your content only in the cases listed in section 4, and every access is recorded.
We do not use your data for advertising, and we do not build advertising profiles.
Connected apps. A connected client holds a connection token that works only through the connector, never your password. We record the connection, the client's name, its permissions, when it was last used, and its actions as connector activity. You can revoke each connection independently without ending your browser session. When a connected app asks for your content, we send it to that app at your instruction. The app is not our sub-processor, and its own terms and privacy notice govern what it does with that content.
| Category | What it includes | Why we process it | Legal basis (GDPR) |
|---|---|---|---|
| Account data | Name, email address, the identity provider you sign in with, your date of birth or birth year, account settings, verification status | To create and operate your account, authenticate you, and secure it | Performance of a contract |
| Project content | Everything you upload or the service generates for you: invention descriptions, documents, drafts, files, research, conversations | To provide the service you asked for | Performance of a contract |
| Commercial data | Orders, entitlements, membership level, project grades, invoices, refunds, the storefront you bought through | To sell you the service, honour what you bought, and keep accurate records | Performance of a contract; legal obligation for tax records |
| Telemetry | Telemetry as the Terms of Service define it: technical logs, hashes, summary statistics and classifications, metrics and learnings; sign-in, session and presence events; feature use and timings; request rates, errors and provider faults; allowance, cost and model-usage records; safety events and health-check results. It contains none of your content | To run, secure and improve the service, diagnose faults and enforce allowances | Legitimate interests: operating a reliable and secure service |
| Security data | IP address, device and browser information, authentication events, step-up events, audit records | To detect and prevent abuse, fraud and unauthorised access | Legitimate interests: security; legal obligation |
| Safety data | Automated safety flags on requests, uploads and outputs, and the record of any safety review | To prevent prohibited and dangerous uses, protect people, and meet our legal obligations | Legitimate interests: preventing serious harm; legal obligation |
| Support data | Your messages to us, and our record of what we did | To help you, and to keep a record of it | Performance of a contract; legitimate interests |
| Service improvement analytics | Chat and generation histories: your conversations with the service and the outputs it generated for you | Automated analysis to improve the service's filters, safety guardrails, prompts, templates, instructions, guidelines, rubrics, policies and other internal software. Nothing from your content is copied into anything used for another customer | Legitimate interests: improving the quality and safety of the service. You can object at any time (section 9) |
| Cohort and consent data | The cohorts and deployments you join, your role, enrolment dates, what the cohort makes visible, and, for a student under the age of majority, the record of how consent was given | To run the cohort, give the instructor the read-only access its terms allow, and show that consent was given | Performance of a contract; where an institution is controller, its instructions; legal obligation for consent records |
| Marketing data | Your consent, when you gave it, from which page, and under which terms version | To send you material you asked for | Consent |
Service improvement analytics. Our systems, and the sub-processors listed in section 5, analyse chat and generation histories to find where the service falls short and to improve its own software. We never copy your content, or any excerpt, detail or example from it, into a prompt, template, rubric or other part of the service used for another customer. This is not model training, and the promise in section 2 still applies. To opt out, write to privacy@ipguru.ai. We act on it within thirty days, and opting out does not change your service or your price.
We do not collect payment card details, bank details or government identification numbers. Payment information goes directly to our merchant of record and never reaches us.
Health data. Health and medical inventions are welcome, but the service is not for clinical use and we do not want health records. Do not upload identifiable health information about a patient or any other person; use anonymised or synthetic data (Terms clause 2). We are not a healthcare provider, health plan or healthcare clearinghouse, or a business associate of one under HIPAA, and we do not hold health records for anyone. If identifiable patient data reaches us, we may delete it.
Children and students under the age of majority. The minimum age for an account you create yourself is fifteen, and higher in some markets. Younger users can take part with the permission of a parent or guardian, or when a school, education authority or government programme enrols them under a written agreement with us, with consent given by the institution where the law allows it, or by a parent or guardian who opts in (Terms clause 5.2). Apart from that, we do not knowingly collect personal data from anyone below the applicable minimum; if you believe we have, contact our DPO and we will delete it. Where the law requires verifiable parental consent, such as for children under 13 in the United States, we obtain it in the form that law sets. For any user under 18 we send no marketing, keep publishing off by default, accept no purchases from the user, and leave them out of service improvement analytics unless a parent or guardian, or the institution where the law allows it, opts them in. A parent or guardian can exercise the rights in section 9 on the child's behalf.
Each project is isolated. A project has its own knowledge base, its own working memory and its own file vault. Access is decided per request by a policy engine that denies by default: if it cannot reach a decision, it refuses rather than allowing.
Sharing is yours to control. A project is private until you share it. You can share with named people and revoke each of them individually, or create an unlisted link. An unlisted link can be opened by anyone who has it, so treat it as a key rather than as a secret.
Uploads are scanned for malware and prohibited content, including sexual content and material that sexualises or abuses a child, before anything enters your knowledge base. Items that fail are quarantined and never enter it.
Sensitive actions require you to re-authenticate. Deleting a project, transferring ownership, exporting your data, changing your credentials, erasing your account and publishing all require a fresh authentication, even if you are already signed in.
When our staff can see your content. Our support team sees the shape of your account, not its contents, and there is no standing access. Staff can see your content only: when you ask for help and approve a time-limited support access grant; in a safety review of what our automated systems flag; in an investigation of suspect activity; where the law requires it; or to review examples picked out by service improvement analytics, unless you have opted out (Terms clause 7). Every access is recorded. Support access and analytics reviews always appear in your activity log. The others appear there unless telling you would create a risk of harm, prejudice an investigation or is prohibited by law.
Safety review. Automated systems check requests, uploads and outputs for prohibited uses. Where they flag weapons development or a serious risk of harm, such as work towards a weapon capable of mass harm, material that sexualises or abuses a child, or a credible threat to someone's life, a trained member of our team may review what was flagged. The review is limited to what was flagged.
We share personal data only with the following, and only as far as necessary.
| Sub-processor | What it does | Where |
|---|---|---|
| Google Cloud Platform | Application hosting, database and file storage | United States (us-central1) |
| Google Firebase / Identity Platform | Authentication and identity | United States |
| Permit.io | Authorisation decisions. Receives identifiers and entitlement attributes, never content | United States / EU |
| Neo4j Aura | Graph database supporting research features | United States |
| Google Gemini | Generation of drafts, analysis, research output, images and video, including the Gemini image and Veo video models, and Model Armor safety screening. Contracted on terms that prohibit training on your content | United States |
| TypeSafe AI, Inc. | Jev decision model, used for scoring, grading and classification. Being introduced. Contracted on terms that do not permit training on your content without our consent, which we do not give. TypeSafe may keep Telemetry about our requests, which contains none of your content | United States |
| Exa Labs, Inc. | Web search, grounded search and citations for research. Receives search queries, which may include terms drawn from your content, and the addresses of pages to read | United States |
| GoVeda Pte. Ltd. | Patent database search and retrieval. Receives search queries, which may include terms drawn from your content. Its published terms state that queries are not used to train models | Singapore and other locations |
| Google Analytics | Analytics on the ipguru.ai website, with consent where required. Receives pages visited and device information, never your content | United States |
| Mailgun | Delivery of service email | United States |
We publish changes to this list, and email you at least thirty days before a new sub-processor begins processing your content. If you object, tell our DPO. If we cannot address your objection, you may cancel and receive a refund of the unused part of your membership.
From 29 September 2026, Cleverbridge GmbH sells to you as our authorised reseller and merchant of record. For the payment transaction it is a separate and independent controller of the personal data it collects from you, not our processor, and its own privacy notice governs that data. We receive from it your order reference, the product bought, and your contact email address. We never receive your payment card details.
If you join a cohort or take part in a workplace or licensed deployment, the instructor, organiser, judges, mentors, reviewers and other people the institution names can see, read-only, the work its terms make visible and anything else you choose to share, with your name, enrolment and progress. The institution receives what its agreement with us provides. It does not receive your other work. At the end of a cohort this access ends unless you choose to keep it. In a workplace deployment, the organisation's rules decide what happens to that work when you leave.
We may disclose personal data where we are legally required to, to establish or defend a legal claim, or to protect the safety of a person or the public, including when we report a serious risk to life or public safety, or child sexual abuse material, to the authorities. When an authority asks us for data, we check that the request is lawful, disclose only what it requires, and tell you unless the law forbids it or telling you would create a risk of harm. In a merger, acquisition or sale of the business, data may transfer to the acquirer under the same protections, and we will tell you.
We never share your content with anyone for their own purposes. It leaves us only in the cases listed in clause 7 of the Terms of Service.
We are established in Singapore and our infrastructure is currently hosted in the United States. If you are in the EU, the UK or another region with transfer restrictions, your personal data is transferred outside that region.
We rely on Standard Contractual Clauses with our providers, together with the technical measures described in sections 4 and 11, as the basis for those transfers. You can request a copy of the relevant clauses from our DPO. Where the Singapore PDPA applies, we transfer personal data outside Singapore only to recipients bound, by contract or by law, to protect it to a standard comparable to the PDPA.
We are evaluating regional hosting for other markets. If we introduce it, we will update this policy before any data moves.
| Data | Retention | Trigger for disposal |
|---|---|---|
| Account data | While your account is open | Account closure, then deletion after the erasure process completes |
| Project content | While your account is open, or until you delete the project | Your deletion, or thirty days after account closure, so you can export it |
| Archived projects | Until you delete them | Your deletion |
| Dormant account, archived | From 180 days without activity | Archiving is automatic and reversible. See section 8 |
| Dormant account, purged | From 18 months without activity, after notice, and only where no paid project grade or active paid membership is held | See section 8 |
| Commercial records: orders, invoices, tax | Five years from the end of the relevant financial year | Statutory retention period expiry |
| Security and audit records | Twelve months, or longer where needed for an open investigation | Period expiry, or closure of the investigation |
| Safety review records | Twelve months, or longer where needed for an open investigation or a report to the authorities | Period expiry, or closure of the investigation |
| Telemetry | Up to thirteen months | Period expiry |
| Service improvement analytics | Working copies of chat and generation histories are kept no longer than the project they came from. Findings that contain none of your content may be kept | Deletion of the project or account, or your opt-out |
| Support correspondence | Twenty-four months from closure | Period expiry |
| Marketing consent records | While consent stands, and three years after withdrawal as evidence that it was withdrawn | Period expiry |
| Cohort membership and instructor access | While the cohort runs | End of the cohort, unless you choose to keep it, or your leaving |
| Consent records for users under the age of majority | While the account is open, and afterwards only as long as the law requires us to show that consent was given | Period expiry |
| Identity record after erasure | Retained in disabled form | See section 8 |
| Backups | Bounded window, currently thirty-five days | Rotation |
You can delete a project at any time from within the service.
You can erase your account. When you do:
What survives an erasure, and why. Your identity record is disabled rather than deleted, retaining your identifier and email address. This is so that the account cannot be silently recreated and so that we can prove the erasure happened if you or a regulator ask. The legal basis is our legitimate interest in the integrity of the erasure, and it is disposed of after twenty-four months. We tell you this before you confirm, not afterwards.
Archiving is not deleting. Archiving preserves your material and frees an active-project slot.
Keeping data forever is not a kindness, so accounts that go quiet are handled on a stated schedule rather than left indefinitely.
| After | What happens | Reversible? |
|---|---|---|
| 180 days with no activity | Your account and its projects may be archived. Everything is preserved. Archiving frees resources and active-project allowance | Yes, immediately. Sign in and it is restored |
| 15 months | We email you to say the account is dormant, what will happen, and how to keep it | — |
| 17 months | We email you again | — |
| 30 days before purge | A final email, with a link to export everything | — |
| 18 months with no activity | The account and its material may be purged, subject to the exception below | No. This is permanent |
Any sign-in resets the clock. Opening the service, exporting, or replying to one of the notices all count as activity.
Accounts holding a paid project grade or an active paid membership are never purged. A grade is sold as permanent for its project, for as long as we operate the service, and purging it for inactivity would take away something that was paid for. Those accounts are archived and stay archived. If we ever close the service, we will give at least ninety days' notice and a way to export everything.
We would rather you kept your work than that we saved the storage. Invention is intermittent by nature, and a year between sessions is normal rather than abandonment, which is why the notices start at fifteen months and why a single sign-in is enough to stop the process.
Whether you are covered by the PDPA, the GDPR or both, you can:
How to exercise them. Most are available directly in the service: export, deletion and correction are self-service. For anything else, contact privacy@ipguru.ai. We respond within thirty days and will tell you if we need longer.
Complaints. If you are unhappy with how we have handled your data, tell us first and we will try to fix it. You can also complain to the Personal Data Protection Commission of Singapore, or, if you are in the EU or UK, to your local supervisory authority.
Clause 21 of the Terms of Service sets out every channel we use, what each carries and what you control. This section says what those communications mean for your personal data.
Four kinds of message, kept separate on purpose:
| Kind | Examples | Our legal basis | Your control |
|---|---|---|---|
| Essential | Sign-in and security notices, receipts, entitlement changes, an expiring share, a completed export, material changes to these policies, our answer to a request you made | Performance of our contract with you, and our legal obligations | None while you have an account. You cannot unsubscribe from being told your credentials changed |
| Configured | Activity digests, project and collaborator notifications, allowance warnings, periodic summaries | Performance of our contract, and our legitimate interest in operating a service that tells you what it is doing | Complete. On, off, how often, and by which channel, in your settings |
| Related services | Messages to a customer about IPGuru services similar to what they already have | Our legitimate interests, in markets that permit this. Where your market requires consent first, consent | Off in one click, at any time, and we offer the choice when we take your address |
| Marketing | Product news, launches, education, the notify-me list | Consent where your market requires it, otherwise our legitimate interests | Off in one click, at any time, honoured everywhere |
No marketing to users under the age of majority. They receive essential and configured messages only, never marketing or messages about our other services.
An essential message never carries marketing. The moment a receipt carries a promotion, the whole receipt becomes marketing, and our ability to send you the receipts you actually need depends on not having done that.
Consent, where we rely on it, is active and recorded. No pre-ticked boxes, no consent bundled into accepting the terms or into a purchase. We record what you agreed to or declined, when, from which page and under which version. Where we rely on legitimate interests instead, you have the right in section 9 to object, and for direct marketing an objection is absolute: we stop.
Where a market allows us to write to our own customers about related services without asking first, we use it, and we always give you the choice when we take your address and an opt-out in every message. Your Market Schedule states the position for your market.
We do not currently market by telephone call or text message. A text from us is a security code, or an alert you asked to receive that way. If that ever changes we will meet the rules of the market first, including any do-not-call register.
We never pass your contact details to anyone else to market to you, and we do not sell or rent them.
Our merchant of record writes to you as well. Cleverbridge GmbH sends order confirmations, invoices and payment notices as the seller of record for the transaction. For that purpose it is a controller in its own right, under its own privacy notice, and those messages cannot be switched off because they are part of the sale.
If you subscribed to a list without an account, you have given us an email address and nothing else. You have no account and no profile, and the rights in section 9 apply to that record exactly as they would to any other.
We keep a record of what we send you, including support conversations, for the periods in section 7. It is kept so that a question about what you were told has an answer.
The measures we rely on include: encryption of data in transit and at rest; multi-factor authentication; a policy decision point that denies by default; step-up re-authentication for sensitive actions; per-project isolation of storage; short-lived data-plane credentials that can only be narrowed and never widened; keyless deployment credentials; malware scanning of uploads; an append-only audit ledger that is never edited; daily backups replicated to redundant storage; and a documented business continuity and disaster recovery plan.
Breach notification. If a data breach occurs that is likely to result in significant harm to the people affected, or that affects 500 or more people, we will notify the PDPC within three calendar days of assessing it as notifiable, and affected individuals as soon as practicable where significant harm is likely. Where the GDPR applies, we will notify the supervisory authority within seventy-two hours and affected individuals without undue delay where the risk is high. We will tell you what happened, what data was involved, what we have done, and what you should do.
No security is absolute. We will tell you promptly and honestly if something goes wrong.
We use cookies and local storage for three purposes: strictly necessary (keeping you signed in, security, load balancing), preferences (remembering your settings), and analytics (understanding how the service is used so we can improve it).
Strictly necessary cookies do not require consent. Where consent is required for analytics or preferences in your market, we ask for it before setting them and you can change your mind at any time. We do not use advertising cookies or third-party tracking for advertising.
We will publish any new version with a version number and effective date. For a change that materially affects your rights, we will give you at least thirty days' notice by email before it takes effect.
Data Protection Officer, Corvair Pte. Ltd. privacy@ipguru.ai 23 Jalan Raja Udang, #11-09, The Arte, Singapore 329216
Local particulars only. Nothing in an annex changes what we collect, why, who we share it with, or how long we keep it. Everything above this section applies to you wherever you are.
Singapore. Corvair Pte. Ltd. is established in Singapore and the Personal Data Protection Act 2012 applies to our handling of your personal data. Supervisory authority: the Personal Data Protection Commission, pdpc.gov.sg. Our Data Protection Officer, named in section 1, is the contact for any access, correction or withdrawal-of-consent request under the Act, and for any complaint. If we do not resolve a complaint to your satisfaction you may take it to the Commission.
European Union. The GDPR applies to our processing of your personal data. Sections 3, 6, 7 and 9 state our legal bases, our retention periods, the rights you hold and the safeguards for transfers. Because we host in the United States, every transfer is made under the European Commission's standard contractual clauses with each recipient, supported by a transfer risk assessment. You may complain to the supervisory authority of the member state where you live, where you work, or where the matter arose, and you may do so without contacting us first, although we would rather you gave us the chance to fix it.
United Kingdom. The UK GDPR and the Data Protection Act 2018 apply on the same terms as the paragraph above, with transfers made under the UK International Data Transfer Addendum to the standard contractual clauses. Supervisory authority: the Information Commissioner's Office, ico.org.uk.
Australia. The Australian Privacy Principles under the Privacy Act 1988 apply to our handling of your personal information. Under the Notifiable Data Breaches scheme we will notify the Commissioner and affected individuals as soon as practicable where a breach is likely to result in serious harm. You may ask us for access to or correction of your information under APP 12 and APP 13, and section 9 tells you how. Supervisory authority: the Office of the Australian Information Commissioner, oaic.gov.au.
Every other market. Where we have not published an annex for your market, this policy applies to you in full and nothing is reduced by the absence. You may complain to your local data protection authority, or to the Personal Data Protection Commission in Singapore, where we are established.