PATANYX is a desktop web browser for Windows and Linux, developed and operated by EdgeXene LLC, a limited liability company organized under the laws of the State of Indiana. EdgeXene LLC is the data controller for the limited personal data described in this policy. Your use of PATANYX is also governed by our Terms of Use.
PATANYX has no account system. There is no registration, no sign-in, no profile and no per-install identifier. Nothing you do in the browser is associated with a person by us, because we hold nothing to associate it with.
Little reaches EdgeXene, and most of what does happens only because you chose it: writing to us, donating, or buying and using Premium. Everything else the browser does happens on your computer. This section lists every case in which something reaches EdgeXene. The browser also makes one outbound request that does not come to us: if you have chosen an encrypted resolver, it may check that the resolver is reachable, described in Section 4.4a.
The browser fetches a signed update manifest and a signed blocklist
from patanyx.edgexene.io. Each check is a single
unconditional GET whose address is identical for every installation of
a platform. It carries no version number, no token, no query string
and no cache validator, so nothing in the request distinguishes your
copy from anyone else's. The comparison that decides whether something
newer exists happens on your machine, which means the server is never
told which version you are running.
What the server necessarily receives in the act of answering is your IP address and the time of the request. It is not logged. Failures are recorded so they can be fixed, and such a record can incidentally include an address. No content delivery network sits in front of this host, so no third party observes these requests.
Checks run on a randomised schedule rather than an exact clock, because a precisely repeating interval is itself an identifier. Nothing is ever installed without your explicit acceptance.
If you use the contact form, we receive the category you pick, the subject, your message, and your name and email address if you choose to supply them. Only the subject, category and message are required.
The submission is delivered to an EdgeXene mailbox by email. It is not written to a database or a file. The only server-side state is an in-memory counter, keyed by IP address, that exists to limit automated abuse. It holds no message content, is cleared when the service restarts, and is never retained beyond the day it was created. Access logging is off for this endpoint as well.
The website links to a Stripe payment page where you may donate to EdgeXene's open-source work. The link is an ordinary hyperlink. No Stripe code runs on any PATANYX page, and nothing about you is sent to Stripe unless you click it and leave for their site.
If you do donate, Stripe collects your email address and your payment details and processes the payment. EdgeXene receives a record of the donation, which includes your email address, the amount, the date and the card brand and last four digits. EdgeXene never receives your full card number. Donating is entirely optional, is not required to use PATANYX, and unlocks nothing in the browser.
A donation is separate from Premium, which is covered in 2.4 and in Section 18.
PATANYX Premium unlocks private chat, checking a page against what a contact was served, reading text out of an image, and accent theme packs. The built-in tunnel is free. Buying and using Premium involves EdgeXene in three ways that free use does not.
Buying it. Payment is taken by Stripe, who collect your name, card details, email address, billing address where law requires it, and your IP address, under their own privacy policy. Buying with a card is not anonymous and cannot be made so. EdgeXene receives the payment record, not your card number, and does not collect an email address of its own. Nothing is emailed to you at any point: your license token appears on a page immediately after payment, which you print or save yourself. That page is the only delivery. A lost token cannot be re-sent or recovered by us: we hold no email address of yours and the token is bound to no account or identity we could match you to. You are told this before you pay as well as after.
Your license. EdgeXene's license server issues a signed token and keeps one record of it: a license identifier, the dates of the term, a payment reference, and the token itself. It keeps the token so that a repeated notification from the payment processor cannot mint you a second license for one payment, and so that the page showing your token still works if you reload it. It records no IP address, at purchase or at any other time. You paste the token into the browser's vault once, and it is checked there by your own copy of the browser, offline. There is no account, no sign-in, no activation call and no periodic license check-in, so ordinary use of what you paid for produces no record here.
Using chat. Connecting to the relay at
relay.edgexene.io discloses your IP address and your
license identifier to it for the life of the connection. The relay
keeps aggregate counters only. Section 18 sets out exactly who can see
what, including what this does and does not let us infer.
None of this applies to the free browser. The free build contains no chat or relay code at all, and an automated check on every release fails the build if any appears.
PATANYX is built so that the sensitive material stays on your computer. The following are stored locally, in your own user profile directory, and are never transmitted to EdgeXene.
| What | Where it lives | Protection |
|---|---|---|
| Saved site passwords | Encrypted vault file on your device | Encrypted with a key derived from your passphrase, which we never receive. Locks itself after a period of inactivity you control |
| Bookmarks and download provenance | Separate encrypted store on your device | Encrypted under a key that is separate from the vault's, so neither can unlock the other. Records are tamper-evident to you |
| Settings | A preferences file on your device | Plain configuration only. No secrets are written here |
| Set-aside tabs (shelves) | On your device | Addresses and titles only. No cookies, no scroll positions, no history |
| Text recognized from images (OCR) | Processed and kept on your device | The recognition engine runs entirely offline and contains no network client |
If you forget the passphrase that protects the vault or the store, EdgeXene cannot recover it. We never receive a copy of the passphrase or of the keys derived from it, so there is no reset we could perform. This is a deliberate design property, not an oversight.
The browser keeps a short record of recent network decisions so you can see why something was blocked or allowed. It is never transmitted. It leaves your machine only if you deliberately export it to a file and then choose to send that file to someone. That export can contain the addresses of sites you visited, so treat it as sensitive and review it before sharing it.
A browser is a tool for reaching other people's servers, so the honest question is not whether third parties are involved but which ones, and on whose initiative. Section 4.1 lists the providers EdgeXene engages to operate the service. The sections after it describe the parties your own browsing brings into the picture.
| Service | Purpose | Data sent |
|---|---|---|
| Hetzner Online GmbH | Hosting of the website, the download service, and the update and blocklist channel | Your IP address and the time of a request, received in the course of answering it. These requests are not logged; a failed request may leave an error record. Servers are in Finland, and under our data processing agreement Hetzner processes data for an EU server location exclusively within the EU or EEA, including its support functions. Its only sub-processor for this location is Hetzner Finland Oy |
| Stripe | Taking payment for donations and for Premium | Only if you choose to pay: your name, email address, card details, billing address where law requires it, and your IP address, collected by Stripe on their own page. EdgeXene receives the payment record, not your card number. Stripe is established in the United States |
| Proton Mail | Delivery of messages sent through the contact form | The contents of your message, its subject and category, and your name and email address if you supplied them. Proton is established in Switzerland, which the European Commission recognizes as providing adequate data protection |
That is the complete list. PATANYX uses no analytics provider, no advertising network, no content delivery network, no crash-reporting service and no customer-relationship platform, because it has no data to put into one. EdgeXene's own license server and chat relay are not third parties; they are ours, and Section 18 states exactly what they see. EdgeXene LLC is not responsible for the independent privacy practices of the providers above, which operate outside our control, though we select for strong security and privacy standards.
On Windows, PATANYX renders pages with Microsoft Edge WebView2. On Linux it uses WebKitGTK. On Windows we ask the engine to reduce what it reports: SmartScreen reputation checking off, so the addresses you open are not sent to Microsoft; crash-dump upload off, so a memory snapshot of a crashed page process is not uploaded; browser sync disabled; hyperlink auditing pings disabled; and tracking prevention enabled explicitly.
Some of those are requests to the runtime rather than guarantees. On an older or unusual WebView2 runtime the settings that suppress crash-dump upload can fail to apply, and the browser falls back to the engine's own defaults, in which case crash reporting to Microsoft remains on. We would rather tell you that than describe a protection as absolute when the code treats it as best effort.
A limit we cannot remove. WebView2 reports a category of component health data to Microsoft, covering matters such as API and SDK usage and component creation failures, that Microsoft classifies as required and that no application embedding it can switch off. It does not include the addresses you visit or page content. Because this cannot be disabled, PATANYX does not and will not claim zero telemetry. On Linux, WebKitGTK has no equivalent reporting channel.
Text typed in the address bar that is not a web address is sent to DuckDuckGo as a search query. It goes to DuckDuckGo, not to EdgeXene, under their privacy policy.
By default PATANYX uses your operating system's DNS resolver, usually your network provider's. You may instead opt in to Mullvad or Quad9 encrypted DNS, sending the domain names you look up to that provider over an encrypted connection rather than in the clear to your network. Whichever resolver you choose sees the domains you visit; encryption changes who can see them, not whether anyone can.
This control is available on Windows only. On Linux the engine offers no encrypted-resolver setting, so PATANYX makes none available and the resolver choice is not shown; name lookups follow your operating system's configuration.
Choosing Mullvad or Quad9 makes name resolution fail closed: if that resolver cannot be reached, PATANYX does not quietly fall back to whatever the network offers, so pages simply stop loading. To tell you why, the browser contacts the resolver you already chose to see whether it is reachable, and only after a navigation has already failed in a way consistent with a dead network. The request goes to that resolver and nowhere else, carries no hostname you were trying to reach, and is not made at all while you are using your operating system's resolver. Nothing about it reaches EdgeXene.
PATANYX includes a WireGuard client, but EdgeXene operates no VPN servers and supplies no endpoints. You import a configuration from a provider you already deal with, and your traffic goes to them under their terms. We are not a party to it.
Pages you open receive whatever your browser sends them in the normal course of loading a page, including your IP address. PATANYX reduces this where it can, by blocking known advertising and tracking hosts from first launch, and because neither engine accepts third-party cookies, an advertiser present on two different sites cannot join them up through a cookie. It cannot eliminate what a site learns, and the About page states those limits in full.
Known tracking parameters are also removed from addresses. On Windows the browser strips them from top-level navigations as you browse; the Linux engine offers no equivalent hook, so it does not. On both platforms the right-click menu offers a copy-link action that removes them from the address you are about to share.
| Data | Retention |
|---|---|
| Update and blocklist check requests | Not retained. Access logging is disabled; the request is answered and nothing is written |
| Server error records | Written only for failed requests, and kept no longer than 30 days |
| Contact form messages | Held in the EdgeXene mailbox for up to 24 months from the close of the exchange, then deleted. Deleted sooner on request |
| Donation records | Kept for as long as United States tax and accounting rules require records of receipts, currently seven years. Held by Stripe and in EdgeXene's Stripe account |
| License records | License identifier, term dates, payment reference and the issued token, kept for as long as tax and accounting rules require records of receipts, currently seven years. No IP address is recorded |
| Chat relay | Nothing per message and no message content at any point. Connection data exists only while you are connected; only aggregate counters are kept afterwards |
| Contact form abuse counters | In memory only, never beyond the day it was created |
| Everything stored by the browser | On your device, for as long as you keep it. Removing the application data directory removes it |
Data held on your device is deleted by you: clear it from within the browser, or delete the PATANYX application data directory. Because we hold no copy, nothing survives that deletion on our side.
For anything you have sent us, which in practice means a message through the contact form, write to compliance@edgexene.io and we will delete it. We aim to act within thirty days and will tell you when it is done.
EdgeXene does not sell personal data, does not share it for cross-context behavioral advertising, and does not transfer it to data brokers, advertisers or analytics providers. We hold almost nothing, and what little we hold is not a product.
Data is disclosed to the service providers listed in Section 4.1 only to the extent they must process it to perform their function, under contractual terms restricting them to that purpose.
Beyond that, we would disclose data only where legally compelled by valid process. The practical consequence of the design is that a demand for your browsing activity could not be satisfied, because we do not have it.
If we receive a legal demand for data relating to you, we will notify you before responding wherever we are permitted to do so and have a means of reaching you.
No security measure is absolute, and pre-1.0 software carries more risk than a mature release. If you believe you have found a vulnerability, please report it to compliance@edgexene.io.
If a breach affecting personal data occurs, EdgeXene will notify affected individuals and the relevant supervisory authorities as required by applicable law, without undue delay and, where GDPR applies, within seventy-two hours of becoming aware of it.
The scope of any such breach is bounded by what we hold. Material kept on your device is not reachable from our infrastructure.
| Processing | Basis (GDPR Article 6) |
|---|---|
| Answering update and blocklist checks, including the transient receipt of an IP address | Legitimate interests: delivering security fixes and malicious domain lists to installed software |
| Rate limiting the contact form | Legitimate interests: protecting the service from automated abuse |
| Replying to a message you send us | Consent, given by choosing to write to us |
| Selling, delivering and supporting a Premium term, and operating the relay for Premium users | Performance of a contract with you; legal obligation for the resulting financial records |
| Processing a donation you choose to make | Performance of a contract for the payment itself; legal obligation for retaining the resulting financial record |
Where we rely on consent, you may withdraw it at any time by writing to compliance@edgexene.io. Withdrawing is as easy as giving it, and it does not affect the lawfulness of anything done before you withdrew.
EdgeXene's servers are located in Finland, European Union. PATANYX is operated by EdgeXene LLC, a company organized under the laws of the State of Indiana, United States. If you are accessing PATANYX from outside the European Union, the limited data described in Section 2 is transferred to and processed in the European Union, and may be accessed from the United States by EdgeXene personnel.
Our hosting provider is bound by a data processing agreement under Article 28 of the GDPR which commits it to processing data for an EU server location exclusively within the EU or EEA. Our mail provider is established in Switzerland, which the European Commission recognizes as providing an adequate level of protection. Payments are processed in the United States, and that transfer relies on the payment provider's Standard Contractual Clauses. Where any other transfer arises we rely on an adequacy decision, Standard Contractual Clauses, or your consent, as applicable.
Where an optional feature sends data elsewhere, it does so to a party you chose: an encrypted DNS provider you selected, or a VPN provider whose configuration you imported. Those transfers are governed by that provider's terms, not ours.
Subject to applicable law you have the right to access the personal data we hold about you, to correct it, to have it deleted, to obtain a copy in a portable form, to object to or restrict processing, and not to be subject to automated decision-making. PATANYX performs no profiling and no automated decision-making.
To exercise any of these, write to compliance@edgexene.io. We respond within thirty days. Because we hold no account and no identifier, an access request will in most cases return only the correspondence you have had with us, and we will say so plainly rather than manufacture a record.
We must be able to verify that a request comes from you. Because there is no account, in many cases the only thing we can verify against is correspondence you have already sent us. Where we cannot reasonably establish that a request is yours, we will say so and decline rather than hand your information to someone else on the strength of an unverified claim.
Exercising any right never degrades how PATANYX works.
Under the California Consumer Privacy Act as amended by the CPRA, California residents have the right to know what personal information is collected, to delete it, to correct it, to opt out of sale or sharing, and not to be discriminated against for exercising those rights.
EdgeXene does not sell personal information and does not share it for cross-context behavioral advertising, so there is no opt-out to operate. We do not use or disclose sensitive personal information for purposes requiring a limitation right.
The statute requires disclosure by its own categories rather than in plain description alone, so the table states them directly.
| CCPA category | Collected | Source, purpose and disclosure |
|---|---|---|
| A. Identifiers (IP address) | Yes, transiently | Received from your device when answering an update or blocklist check, or a contact form submission. Used to deliver the response and to limit abuse. Not logged, not retained, not sold or shared |
| A. Identifiers (name, email address) | Only if you supply them | Provided by you in the contact form, and received from the payment processor in the donation record described in Section 2.3. Used to reply and for accounting records. Disclosed to the mail provider in Section 4.1. Not sold or shared |
| B. Commercial information | Only if you donate or buy a Premium term | A record of a payment you chose to make, and for Premium buyers a license identifier and the dates of the term. Used to deliver Premium and for accounting and tax records. Not sold or shared |
| F. Internet or other network activity | No | Browsing history, search history and interaction data are never transmitted to EdgeXene |
| C. Protected classifications, D. Biometric, E. Geolocation, G. Sensory, H. Professional, I. Education, J. Inferences | No | None collected |
EdgeXene has not sold or shared personal information in the preceding twelve months, and does not knowingly sell or share the personal information of consumers under 16 years of age.
PATANYX sends the Global Privacy Control signal to every site you visit, permanently and with no setting to turn it off. On Windows that means both the request header and the page property; on Linux, the page property alone. Section 15 explains why. In California and in several other states this is a legally recognized opt-out request, which means the browser exercises that right on your behalf without your having to find a link on each site. Section 15 states what the signal does and does not achieve.
EdgeXene LLC is organized in Indiana. Residents of Indiana, Virginia, Colorado, Connecticut and other states with comprehensive consumer privacy statutes have rights to access, correct, delete and port personal data, and to opt out of targeted advertising, sale and profiling. EdgeXene engages in none of those three activities.
Requests go to compliance@edgexene.io. If we decline a request you may appeal by replying to our decision, and we will respond to the appeal in writing.
PATANYX sends Sec-GPC: 1 and exposes the corresponding
Global Privacy Control property to every page. It is always on. There
is no switch, because a privacy signal that most users never find is
not a privacy signal.
Be clear about what this is worth. GPC is a legally binding opt-out request in California and several other jurisdictions, and sites subject to those laws are obliged to honor it. Elsewhere it is a request that a site may ignore. It does not block anything by itself, and it does not make you anonymous.
Platform difference. On Windows the browser sends the
Sec-GPC request header and sets the page property. On
Linux the engine we use provides no way for an application to add a
request header, so only the page property is set. We would rather
state that than let the two look the same.
PATANYX does not send the older Do Not Track header, which was never standardised in a way that obliged anyone to act on it, and does not act on a DNT header received from anywhere.
In addition to Section 12, residents of the European Economic Area and the United Kingdom may restrict processing while a dispute is resolved, object to processing on grounds relating to their particular situation, and lodge a complaint with their local supervisory authority.
PATANYX carries out no marketing, no profiling and no automated decision-making. Contact compliance@edgexene.io to exercise any of these.
EdgeXene LLC does not currently have an EU representative. EU users may contact compliance@edgexene.io directly or lodge a complaint with their local supervisory authority.
PATANYX is a general-purpose web browser intended for adults. We do not knowingly collect personal data from children under 13, or under the age of digital consent in their country where that age is higher, and the product is built so that we collect almost nothing from anyone. If you believe a child has sent us information through the contact form, write to compliance@edgexene.io and we will delete it promptly.
A browser can reach any site on the web. PATANYX does not filter content by age and is not a substitute for parental supervision.
Premium unlocks private chat, checking a page against what a contact was served, reading text out of an image, and accent theme packs. Everything else stays free, including the built-in tunnel, all the blocking, the vault, the update channel, and light and dark following your system setting. Paying changes what the browser can do. It does not change what it collects about your browsing, which remains nothing.
PATANYX ships as two binaries. The free build contains no chat code and no relay code whatsoever, and an automated check runs on every release that fails the build if any is found. That is a stronger statement than a setting being switched off: if you run the free build, the code that could talk to our relay is not present in the file. The Premium build contains everything the free build has, plus the paid features.
Stated as a table because it is the only honest way to answer it.
| Party | What they can see |
|---|---|
| The payment processor | Your full payment identity: name, card, email address, billing address where law requires it, IP address, the amount, the date, and that you paid EdgeXene. Buying with a card is not anonymous and cannot be made so |
| EdgeXene's license server | A license identifier, the dates of your term, a payment reference, and the token it issued you. It records no IP address. Your browser never contacts it: the only contact is the page you are sent to after paying, which you may reload |
| EdgeXene's chat relay | While you are connected: your IP address and your license identifier. It cannot read your messages, holds no keys, and stores no message and no queue. Afterwards it keeps aggregate counters only |
| Anyone watching the network | That your computer holds encrypted connections to the payment page, the license server and the relay, with their timing and volume. Not their contents |
| EdgeXene, about your browsing | Nothing. Paying does not change this |
A license identifier is stable across renewals. The relay sees it alongside an IP address for the duration of a chat connection. So a relay operator who chose to keep records it currently does not keep could, in principle, learn that a particular license was online at particular times and from particular addresses. It could not learn who you spoke to by name, or anything you said, because it never holds the keys. We keep aggregate counters instead, and we would rather write this paragraph than let you assume a property the architecture does not provide.
The relay cannot be removed from the path for relayed chat. On a local network, chat can connect directly between two machines and the relay is not involved at all.
Premium is a prepaid term, not a subscription. There is nothing to cancel and nothing renews on its own: a term simply runs out on the date the token carries.
When it runs out, the Premium features stop until you buy another term. All of them. We do not operate a partial or reduced Premium tier, and we would rather state that here than have the browser surprise you. Nothing phones home to switch anything off: your own copy of the browser reads the date in your token and stops honoring it after that date, offline, with no check-in.
Free features are never affected. Nothing you created is deleted or held back; it is on your device and stays yours. We do not need to delete anything at our end, because we hold no copy of it. There is no account to close.
EdgeXene LLC may update this policy as PATANYX develops. Material changes will be announced in the release that introduces them and recorded in the changelog below, with the effective date updated. Continued use after a change constitutes acceptance.
While PATANYX remains pre-1.0, expect this policy to change more often than it would for a finished product. Every change will be recorded rather than made quietly.
For privacy-related questions, data rights requests, or compliance matters: compliance@edgexene.io
For all other questions, use the contact form.
EdgeXene LLC