El Patron

EL PATRON ASSISTANT

Privacy Policy

El Patron AI Assistant (web app and Chrome extension)

Last updated: July 22, 2026

1. Overview

El Patron AI Assistant (“El Patron”, “we”, “us”) helps developers with AI-powered coding assistance and repository security analysis. You can use El Patron in a web browser or through our Chrome extension side panel.

This policy describes what information is processed when you use El Patron, why it is processed, and which third-party services are involved. We aim to be transparent and keep data collection limited to what the product needs to work.

2. Authentication

You may sign in with GitHub or Google through Supabase Authentication. Supabase processes the basic account information required to authenticate you and associate your activity with your account, such as your user identifier and information provided by your sign-in provider (for example, email address and provider profile details managed by Supabase as part of the OAuth flow).

On the web app, your session is maintained using Supabase session cookies. In the Chrome extension, a Supabase access token is stored locally in chrome.storage.local so the extension can access your synced history.

3. Conversation history

When you are signed in, your chat conversations and messages are stored in our Supabase database so you can access history across the web app and Chrome extension. Stored data includes conversation titles, message text (user and assistant roles), optional model identifiers, and timestamps linked to your account.

We retain at most 10 conversations per user. When you create a new conversation beyond that limit, the oldest saved conversation (and its messages) is automatically deleted. Messages within retained conversations remain stored until that conversation is removed by the limit or your account is deleted.

Signing out clears local session data and locally stored Gemini keys, but it does not delete conversation history already stored in Supabase.

4. Gemini API keys (bring your own key)

El Patron uses a bring-your-own-key model for Google Gemini. You provide your own Gemini API key. The key is used directly from your browser to call Google's Gemini API for AI responses and repository analysis. Your Gemini API key is not sent to our application server for AI generation.

  • Web app:the key is stored in your browser's localStorage with a 24-hour expiry, then removed automatically unless you save it again.
  • Chrome extension: the key is stored in chrome.storage.local until you clear it or sign out.

When you use Gemini, your prompts, chat history sent with a request, and repository content used for analysis are transmitted to Google. Google's terms and privacy practices apply to that processing. See Google's Privacy Policy.

5. Repository security analysis

When you submit a GitHub or Bitbucket repository URL for security analysis, that URL is sent to our application server. Our server retrieves selected public repository files (for example, dependency manifests, CI configuration, README, and other high-risk paths) from GitHub or Bitbucket and returns the fetched content to your browser.

The fetched repository content is then sent from your browser to Google Gemini using your Gemini API key for analysis. El Patron does not permanently store repository file contents or analysis results in our database. Analysis output is shown in your session UI only.

6. Service providers

We rely on the following services to operate El Patron:

  • Supabase — user authentication and conversation database storage.
  • Vercel — hosting for the web application and API routes.
  • Google Gemini — AI processing initiated from your client with your API key.
  • GitHub and Bitbucket — retrieval of repository files when you request an analysis.

These providers process data according to their own terms and privacy policies when you use features that depend on them.

7. Chrome extension data

The Chrome extension may store the following locally on your device: your Gemini API key, Supabase access token, a short-lived extension API token used to call protected endpoints, and optional extension update metadata. The extension requests permissions for local storage, the side panel, periodic update checks, tab/window context to open the side panel, and OAuth sign-in through Chrome's identity API.

The extension communicates with our hosted API and directly with Google's Gemini API. It does not read or collect the content of web pages you browse beyond what you explicitly submit in the assistant UI.

8. Security

Data is transmitted over HTTPS in normal use. Authentication tokens and credentials are handled using industry-standard browser and extension storage mechanisms and server-side session management through Supabase.

No method of transmission or storage is completely secure. We work to protect your information, but we cannot guarantee absolute security.

9. What we do not do

Based on the current El Patron codebase, we do not sell your personal data, use advertising trackers, or operate an ad network. We do not add third-party analytics scripts to the app for behavioral tracking.

10. Data retention and deletion

Conversation history is retained in Supabase subject to the 10-conversation limit described above. Locally stored Gemini keys and extension tokens are removed when you clear them, sign out, or (on the web app) when the 24-hour key expiry elapses.

There is currently no in-app control to delete individual conversations or your entire account. If you want your stored conversation history deleted, please contact us (see Section 12) and we will handle verified requests manually.

11. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date at the top of this page. Continued use of El Patron after changes become effective means you accept the updated policy.

12. Contact

If you have questions about this policy or want to request deletion of stored conversation data, contact us at sergiocortessat@gmail.com.

Public privacy policy URL: /privacy