PATANYX Search is live: The world, connected with purpose. Open Search
← PATANYX

Privacy & Compliance Policy

Effective Date: September 18, 2026 · Last Updated: September 18, 2026 · Applies to the PATANYX Browser, the patanyx.net website, and PATANYX Search at patanyx.com

EdgeXene LLC, Indiana, United States · General: contact form · Privacy & Compliance: compliance@edgexene.io

[ Part A: PATANYX Browser ]

Sections 1 to 19 describe the browser, which runs on your device. Part B describes the PATANYX Search website, which we operate.

[ 1. About PATANYX ]

PATANYX is a desktop web browser for Windows and Linux, developed and operated by EdgeXene LLC, a limited liability company organized under the laws of the State of Indiana. EdgeXene LLC is the data controller for the limited personal data described in this policy. Your use of PATANYX is also governed by our Terms of Use.

PATANYX has no account system. There is no registration, no sign-in and no profile. The one identifier that exists is the random device identifier used to keep Premium within its five-device limit, described in section 2.5; without Premium there is none at all. Nothing you do in the browser is associated with a person by us, because we hold nothing to associate it with.

[ 2. What Data We Collect ]

Little reaches EdgeXene, and most of what does happens only because you chose it: writing to us, donating, or buying and using Premium. Everything else the browser does happens on your computer. This section lists every case in which something reaches EdgeXene. The browser also makes one outbound request that does not come to us: if you have chosen an encrypted resolver, it may check that the resolver is reachable, described in Section 4.4a.

[ 2.1 Update and blocklist checks ]

The browser fetches a signed update manifest, a signed blocklist, and a signed engine-safety advisory from patanyx.edgexene.io. The advisory rides alongside the update check and carries nothing about your copy. Checking asks our server whether a newer version exists. The request is the same for every copy of PATANYX and says nothing about yours. If there is an update, your browser downloads it in the background so it is ready the moment you choose to install it; you can switch that off in the Updates panel. Downloading tells our server which version you are upgrading from, so that it can send only the part that changed.

What the server necessarily receives in the act of answering is your IP address and the time of the request. It is not logged. Failures are recorded so they can be fixed, and such a record can incidentally include an address. No content delivery network sits in front of this host, so no third party observes these requests.

Checks run on a randomised schedule rather than an exact clock, because a precisely repeating interval is itself an identifier. Automatic installation is off by default. While it is off, nothing is installed without your explicit acceptance. If you turn it on, a maintenance or security release installs itself the next time the browser starts; a release that adds new features is announced and waits for you, and installs on its own only after seven days. The setting is in the Updates panel. Neither the check nor an installation sends anything additional to us either way.

[ 2.2 The page a launch opens ]

When you start the browser without handing it a page, its first tab opens PATANYX Search at patanyx.com, a site we operate (Part B). That request looks like any visit to the site: it carries your IP address and your browser's identifying string, and nothing that identifies your copy of PATANYX. Our web server writes no log line for the front page or for the script and images it loads, so an ordinary launch leaves no record on our side. The one exception is a request refused by the site's rate limit, which nginx notes in its error log with the address, as B.2 describes. If you open the browser from a link in another application, that page opens instead and patanyx.com is not contacted.

[ 2.3 Messages you send us ]

If you use the contact form, we receive the category you pick, the subject, your message, and your name and email address if you choose to supply them. Only the subject, category and message are required.

The submission is delivered to an EdgeXene mailbox by email. It is not written to a database or a file. The only server-side state is an in-memory counter, keyed by IP address, that exists to limit automated abuse. It holds no message content, is cleared when the service restarts, and is never retained beyond the day it was created. Access logging is off for this endpoint as well.

Cloudflare sits in front of this website and passes the submission to our server. Because it terminates the encrypted connection, it can see what you sent, not merely that you sent something. Section 4.1 records what it keeps.

[ 2.4 Donations ]

The website links to a Stripe payment page where you may donate to EdgeXene's open-source work. The link is an ordinary hyperlink. No Stripe code runs on any PATANYX page, and nothing about you is sent to Stripe unless you click it and leave for their site.

If you do donate, Stripe collects your email address and your payment details and processes the payment. EdgeXene receives a record of the donation, which includes your email address, the amount, the date and the card brand and last four digits. EdgeXene never receives your full card number. Donating is entirely optional, is not required to use PATANYX, and unlocks nothing in the browser.

A donation is separate from Premium, which is covered in 2.5 and in Section 18.

[ 2.5 Premium and the chat relay ]

PATANYX Premium unlocks checking an image for text before you share it, searching across every open tab, reading the text you drag a box around, and the archive of pages you chose to keep. Reading a written recovery key off a photograph stays free. The built-in tunnel is free, and so is how the browser looks: every accent color and chrome color scheme. Buying and using Premium involves EdgeXene in three ways that free use does not.

Private chat, checking a page against what a contact was served, and comparing a downloaded file with a contact ship in PATANYX Nabu-X, a separate build that is not publicly available yet. They are not in the PATANYX Browser you can download today. The chat relay described in this section and in Section 18 serves that build. It is documented here so the practice is on record before the build is released, not because the browser you have contacts it.

Buying it. Payment is taken by Stripe, who collect your name, card details, email address, billing address where law requires it, and your IP address, under their own privacy policy. Buying with a card is not anonymous and cannot be made so. EdgeXene receives the payment record, not your card number, and does not collect an email address of its own. Nothing is emailed to you at any point: your license token appears on a page immediately after payment, which you print or save yourself. That page is the only delivery. A lost token cannot be re-sent or recovered by us: we hold no email address of yours and the token is bound to no account or identity we could match you to. You are told this before you pay as well as after.

Your license. EdgeXene's license server issues a signed token and keeps one record of it: a license identifier, the dates of the term, a payment reference, and the token itself. It keeps the token so that a repeated notification from the payment processor cannot mint you a second license for one payment, and so that the page showing your token still works if you reload it. It records no IP address, at purchase or at any other time. You paste the token into the browser's vault once. There is no account, no sign-in and no periodic license check-in. Each device activates once: the first time your vault opens after you paste the token, the browser asks EdgeXene's license server to activate that device, and it asks again at a later unlock only if that request could not get through. The request carries the license token and a random identifier the browser made for that install, and the server keeps the license identifier, that device identifier and the day; it records no IP address. Releasing a device from its own Vault panel sends the same two things once more. Every unlock after activation is checked by your own copy of the browser, offline, so ordinary use of what you paid for produces no further record here.

Finding contacts on your own network. When you switch Private Chat on, your copy announces itself on the local network so contacts on the same network can reach you directly without going through our relay. That announcement is visible to everyone else on that network — not to us, and not to any company — and it carries the contact addresses you use, so someone watching that network could tell those addresses belong to one machine. It happens only while you are switched on, and stops when you switch off, lock your vault, or quit. Using chat. Connecting to the relay at relay.edgexene.io discloses your address, your Premium token, and the identifiers of the two contacts a message is traveling between -- but never the message itself, which the relay cannot read. If you point Private Chat at a relay you run or trust instead of ours, that relay receives the same things, and it is not on the list of providers in section 4.1. The relay keeps aggregate counters only. Section 18 sets out exactly who can see what, including what this does and does not let us infer.

None of this applies to the PATANYX Browser you can download. That build contains no chat or relay code at all, whether or not you hold a Premium license, and an automated check on every release fails the build if any appears.

[ 2.6 Not collected by EdgeXene ]

[ 2.7 Page translation and language packs ]

Translating a page happens entirely on your machine. The engine ships inside the browser; the text of the page, its address, and the translation itself never leave the device, and translating contacts nobody.

The one network contact is the language pack. The first time you choose a language, the browser downloads that pack from models.patanyx.net, a host we run. That request necessarily tells our server which language pair you chose, along with the connection facts described in the next paragraph. It says nothing about the page you were reading, its address, or anything else you have browsed. The panel states this before you download anything.

That host writes no access log, so the pair you chose is not recorded next to your address on disk. What the server necessarily receives in the act of answering is your IP address and the time of the request. Failures are logged so they can be fixed, and such a record can incidentally include an address. Cloudflare sits in front of this host and absorbs attack traffic. It receives your address and the request in passing, and terminates the encrypted connection; section 4.1 records what it keeps. Our own host still writes no access log. Once a pack is stored, using it contacts nobody, and removing a language deletes it from your machine.

[ 3. How Your Data Is Processed ]

PATANYX is built so that the sensitive material stays on your computer. The following are stored locally, in your own user profile directory, and are never transmitted to EdgeXene.

What Where it lives Protection
Saved site passwords Encrypted vault file on your device Encrypted with a key derived from your passphrase, which we never receive. Locks itself after a period of inactivity you control
Bookmarks and download provenance Separate encrypted store on your device Encrypted under a key that is separate from the vault's, so neither can unlock the other. Records are tamper-evident to you
Settings A preferences file on your device Plain configuration only. No secrets are written here. On Windows, if you name sites to keep across restarts, that list of site names is stored here in plain text, readable by anyone with access to your account on the machine
Set-aside tabs (shelves) On your device Addresses and titles only. No cookies, no scroll positions, no history
A VPN configuration you import Encrypted vault file on your device Includes the keys that configuration contains, encrypted under your passphrase like everything else in the vault
Contacts, chat keys and notes you save (PATANYX Nabu-X only) Encrypted vault file on your device Encrypted under your passphrase
Pages you save, and page snapshots Separate encrypted store on your device Includes the text read from them
Sites where you changed protection settings Separate encrypted store on your device A list of site names, so your choices survive a restart
Text recognized from images (OCR) Processed and kept on your device The recognition engine runs entirely offline and contains no network client

If you forget the passphrase that protects the vault or the store, EdgeXene cannot recover it. We never receive a copy of the passphrase or of the keys derived from it, so there is no reset we could perform. This is a deliberate design property, not an oversight.

[ 3.1 Diagnostics ]

The browser keeps a short record of recent network decisions so you can see why something was blocked or allowed. It is never transmitted. It leaves your machine only if you deliberately export it to a file and then choose to send that file to someone. The export carries this session's settings and state: the build, the DNS mode, the automatic lock interval, the update state, the current tab's protection status (including that tab's address, the full address of a plain-HTTP page the browser is holding back for you to confirm, and a username if the browser is mid-offer to save one), how many requests were refused, and that record of recent decisions. It excludes your browsing history, the contents of your vault, and the contents of pages. The record of recent decisions can still name a site you visited in this session, so treat the export as sensitive and review it before sharing it.

[ 4. Third-Party Services ]

A browser is a tool for reaching other people's servers, so the honest question is not whether third parties are involved but which ones, and on whose initiative. Section 4.1 lists the providers EdgeXene engages to operate the service. The sections after it describe the parties your own browsing brings into the picture.

[ 4.1 Service providers EdgeXene engages ]

Hetzner Online GmbH Hosting of the website, the download service, and the update and blocklist channel

Your IP address and the time of a request, received in the course of answering it. These requests are not logged; a failed request may leave an error record. Servers are in Finland, and under our data processing agreement Hetzner processes data for an EU server location exclusively within the EU or EEA, including its support functions. Its only sub-processor for this location is Hetzner Finland Oy

Cloudflare, Inc. Content delivery and denial-of-service protection for patanyx.net and models.patanyx.net

Your IP address, the request, and the time it was made, received in the course of passing the request to our server. Because it terminates the encrypted connection, this includes the contents of anything you submit through a form on this website, such as a contact message or the offline activation form. Cloudflare keeps short-lived security and performance logs under its own retention policy, and it adds headers that ask your browser to report network errors directly to it. On patanyx.net it also passes your address on to our server, where it is used to work out an approximate place, a country, region and city, for the visit count, and to limit abuse. No access log records it, and section 13 and Part B describe what the visit count keeps. A failed or rate-limited request may leave an error record that includes the address, kept no longer than 30 days, as section 5 describes. On models.patanyx.net our server does not use it and writes no access log, though a failed request may leave an error record, as section 2.7 describes. The update and blocklist channel at patanyx.edgexene.io, and the in-browser license activation that uses it, do not pass through Cloudflare at all. Cloudflare is established in the United States, and that transfer relies on the Standard Contractual Clauses in its data processing addendum, which forms part of our agreement with it

Stripe Taking payment for donations and for Premium

Only if you choose to pay: your name, email address, card details, billing address where law requires it, and your IP address, collected by Stripe on their own page. EdgeXene receives the payment record, not your card number. Stripe is established in the United States

Proton Mail Delivery of messages sent through the contact form

The contents of your message, its subject and category, and your name and email address if you supplied them. Proton is established in Switzerland, which the European Commission recognizes as providing adequate data protection

That is the complete list of providers we send data to. PATANYX uses no analytics provider, no crash-reporting service and no customer-relationship platform, because it has no data to put into one. It loads no third-party advertising scripts, no tracking pixels and no advertising SDKs, and it takes no part in behavioral advertising. Section 4.7 describes the affiliate links PATANYX may carry. They make no request when a PATANYX page loads and contain no reader-specific identifier. EdgeXene's own license server, model host and chat relay are not third parties; they are ours, and Section 18 states exactly what they see. EdgeXene LLC is not responsible for the independent privacy practices of the providers above, which operate outside our control, though we select for strong security and privacy standards.

[ 4.2 The rendering engine ]

On Windows, PATANYX renders pages with Microsoft Edge WebView2. On Linux it uses WebKitGTK. On Windows we ask the engine to reduce what it reports: SmartScreen reputation checking off, so the addresses you open are not sent to Microsoft; crash-dump upload off, so a memory snapshot of a crashed page process is not uploaded; browser sync disabled; hyperlink auditing pings disabled; and tracking prevention enabled explicitly.

On Windows, Microsoft may be contacted to update certain WebView2 components, including components used for protected media playback and certificate revocation information. These requests are made to Microsoft services as part of the underlying Windows/WebView2 platform. PATANYX does not control what information Microsoft receives or how Microsoft processes it in connection with those requests. Any information received by Microsoft is handled under Microsoft’s applicable privacy terms and policies. Some of those are requests to the runtime rather than guarantees. On an older or unusual WebView2 runtime the settings that suppress crash-dump upload can fail to apply, and the browser falls back to the engine's own defaults, in which case crash reporting to Microsoft remains on. We would rather tell you that than describe a protection as absolute when the code treats it as best effort.

A limit we cannot remove. WebView2 reports a category of component health data to Microsoft, covering matters such as API and SDK usage and component creation failures, that Microsoft classifies as required and that no application embedding it can switch off. It does not include the addresses you visit or page content. Because this cannot be disabled, PATANYX does not and will not claim zero telemetry. On Linux, WebKitGTK has no equivalent reporting channel.

Microsoft Edge WebView2 Rendering engine on Windows
WebKitGTK Rendering engine on Linux

[ 4.3 Search ]

Text typed in the address bar that is not a web address is sent to DuckDuckGo as a search query. It goes to DuckDuckGo, not to EdgeXene, under their privacy policy.

DuckDuckGo Search from the address bar

[ 4.4 Encrypted DNS ]

By default PATANYX uses your operating system's DNS resolver, usually your network provider's. You may instead opt in to Quad9 encrypted DNS, sending the domain names you look up to that provider over an encrypted connection rather than in the clear to your network. Whichever resolver you choose sees the domains you visit; encryption changes who can see them, not whether anyone can.

This control is available on Windows only. On Linux the engine offers no encrypted-resolver setting, so PATANYX makes none available and the resolver choice is not shown; name lookups follow your operating system's configuration.

Quad9 Encrypted DNS, only if you choose it

[ 4.4a Checking that your chosen resolver is reachable ]

Choosing Quad9 makes name resolution fail closed: if that resolver cannot be reached, PATANYX does not quietly fall back to whatever the network offers, so pages simply stop loading. To tell you why, the browser contacts the resolver you already chose to see whether it is reachable, and only after a navigation has already failed in a way consistent with a dead network. The request goes to that resolver and nowhere else, carries no hostname you were trying to reach, and is not made at all while you are using your operating system's resolver. Nothing about it reaches EdgeXene.

[ 4.5 The private tunnel ]

PATANYX includes a WireGuard client, but EdgeXene operates no VPN servers and supplies no endpoints. You import a configuration from a provider you already deal with, and your traffic goes to them under their terms. We are not a party to it. We may also point to a VPN service as an alternative to this feature rather than a source of configurations for it. Any such link is an affiliate link and is labeled as one. It changes nothing above: we still operate no VPN servers and supply no endpoints.

WireGuard Tunnel client. EdgeXene operates no VPN servers

[ 4.6 Sites you visit ]

Pages you open receive whatever your browser sends them in the normal course of loading a page, including your IP address. PATANYX reduces this where it can, by blocking known advertising and tracking hosts from first launch, and because neither engine accepts third-party cookies, an advertiser present on two different sites cannot join them up through a cookie. It cannot eliminate what a site learns, and the About page states those limits in full.

Pages we publish, such as the news and AreaGram views, may show images hosted by the publishers whose stories they link to. Your browser fetches those images directly from the publisher, which receives your IP address in the same way any site you open does. We keep no record of which stories or images you loaded.

Some sites are themselves on the tracking list, and navigating straight to one is refused like any other request to it. When that happens the browser shows its own page explaining why, in place of the site. On Windows that page offers to open the site anyway; the exception it grants covers that one host, in that one tab, and ends when the tab leaves the host or closes. It is held in memory, never written to disk, and nothing about it reaches EdgeXene. The list itself ships inside the browser and is consulted on your machine, so choosing to continue tells us nothing, as nothing is sent.

Known tracking parameters are also removed from addresses. On Windows the browser strips them from top-level navigations as you browse; the Linux engine offers no equivalent hook, so it does not. On both platforms the right-click menu offers a copy-link action that removes them from the address you are about to share.

[ 4.7 Affiliate links ]

Some pages we publish, and five places inside the browser, may carry links to products from companies we have an affiliate relationship with. Where one appears it is labeled, and nothing reaches the company until you click it. The current partners are listed below and on our partnerships page, which is the authoritative list.

An affiliate link carries a partner identifier that identifies PATANYX as the referring publisher, so the company can attribute a referral or a commission. That identifier identifies PATANYX, not you. We do not add a user ID, an account ID, a search query, browsing history, a session identifier or any other information about you to the link, and a page carrying one sends nothing when it loads. It is an ordinary link that goes nowhere until chosen.

If you open one, you are on the company's own site. The company may use cookies or other attribution mechanisms on its site to determine whether a later purchase resulted from the referral, under its own privacy and cookie practices.

An affiliate relationship does not affect PATANYX search results, safety warnings, source rankings, blocklists or security decisions. A company being a partner is not a security assessment of it, and if a partner's link ever appears in the malicious-host data PATANYX publishes, the link is withdrawn rather than exempted.

Private Internet Access Labeled affiliate link. Sends nothing until you click it
NordVPN Labeled affiliate link. Sends nothing until you click it
Saily Labeled affiliate link. Sends nothing until you click it
NordPass Labeled affiliate link. Sends nothing until you click it
Coveron Labeled affiliate link. Sends nothing until you click it

[ 5. Data Retention ]

Data Retention
Update, blocklist and engine-advisory check requests Not retained. Access logging is disabled; the request is answered and nothing is written
Server error records Written only for failed requests, and kept no longer than 30 days
Contact form messages Held in the EdgeXene mailbox for up to 24 months from the close of the exchange, then deleted. Deleted sooner on request
Donation records Kept for as long as United States tax and accounting rules require records of receipts, currently seven years. Held by Stripe and in EdgeXene's Stripe account
License records License identifier, term dates, payment reference and the issued token, kept for as long as tax and accounting rules require records of receipts, currently seven years. No IP address is recorded
Chat relay (PATANYX Nabu-X only) Nothing per message and no message content at any point. Connection data exists only while you are connected; only aggregate counters are kept afterwards
Contact form abuse counters In memory only, never beyond the day it was created
Cloudflare edge logs Held by Cloudflare, not by EdgeXene, under its own retention policy for security and performance logging. The address it passes on to our server is used and discarded within the same request, and no access log records it. A failed or rate-limited request may leave an error record that includes the address, kept no longer than 30 days, as the row above describes
Everything stored by the browser On your device, for as long as you keep it. Removing the application data directory removes it

[ 6. Data Deletion ]

Data held on your device is deleted by you: clear it from within the browser, or delete the PATANYX application data directory. That removes what is on your device. A few records live with us and are not affected: a donation receipt, and if you bought Premium, your license record and which devices you activated. Sections 2.4 and 2.5 describe both, and you can ask us to delete them.

For anything you have sent us, which in practice means a message through the contact form, write to compliance@edgexene.io and we will delete it. We aim to act within thirty days and will tell you when it is done.

[ 7. Data Sharing ]

EdgeXene does not sell personal data, does not share it for cross-context behavioral advertising, and does not transfer it to data brokers, advertisers or analytics providers. We hold almost nothing, and what little we hold is not a product.

Data is disclosed to the service providers listed in Section 4.1 only to the extent they must process it to perform their function, under contractual terms restricting them to that purpose.

Beyond that, we would disclose data only where legally compelled by valid process. The practical consequence of the design is that a demand for your browsing activity could not be satisfied, because we do not have it.

If we receive a legal demand for data relating to you, we will notify you before responding wherever we are permitted to do so and have a means of reaching you.

[ 8. Security ]

No security measure is absolute, and a first release carries more risk than a mature one. If you believe you have found a vulnerability, please report it to compliance@edgexene.io.

[ 9. Breach Notification ]

If a breach affecting personal data occurs, EdgeXene will tell the relevant regulator within seventy-two hours of becoming aware of it, where the law requires that, and will tell affected people without undue delay where there is a high risk to them.

The scope of any such breach is bounded by what we hold. Material kept on your device is not reachable from our infrastructure.

[ 10. Lawful Basis for Processing ]

Processing Basis (GDPR Article 6)
Answering update, blocklist and engine-advisory checks, including the transient receipt of an IP address Legitimate interests: delivering browser updates, including security fixes, and malicious domain lists to installed software
Rate limiting the contact form Legitimate interests: protecting the service from automated abuse
Replying to a message you send us Consent, given by choosing to write to us
Selling, delivering and supporting a Premium term, and operating the relay for PATANYX Nabu-X users Performance of a contract with you; legal obligation for the resulting financial records
Processing a donation you choose to make Our legitimate interest in keeping a record of money received; legal obligation for retaining the resulting financial record

Where we rely on consent, you may withdraw it at any time by writing to compliance@edgexene.io. Withdrawing is as easy as giving it, and it does not affect the lawfulness of anything done before you withdrew.

[ 11. International Data Transfers ]

EdgeXene's servers are located in Finland, European Union. PATANYX is operated by EdgeXene LLC, a company organized under the laws of the State of Indiana, United States. If you are accessing PATANYX from outside the European Union, the limited data described in Section 2 is transferred to and processed in the European Union, and may be accessed from the United States by EdgeXene personnel.

Our hosting provider is bound by a data processing agreement under Article 28 of the GDPR which commits it to processing data for an EU server location exclusively within the EU or EEA. Our mail provider is established in Switzerland, which the European Commission recognizes as providing an adequate level of protection. Payments are processed in the United States, and that transfer relies on the payment provider's Standard Contractual Clauses. Our content delivery and denial-of-service provider is also established in the United States, and that transfer relies on the Standard Contractual Clauses in its data processing addendum, which forms part of our agreement with it. Where any other transfer arises we rely on an adequacy decision, Standard Contractual Clauses, or your consent, as applicable.

Where an optional feature sends data elsewhere, it does so to a party you chose: an encrypted DNS provider you selected, or a VPN provider whose configuration you imported. Those transfers are governed by that provider's terms, not ours.

[ 12. Your Rights ]

Subject to applicable law you have the right to access the personal data we hold about you, to correct it, to have it deleted, to obtain a copy in a portable form, to object to or restrict processing, and not to be subject to automated decision-making. PATANYX performs no profiling and no automated decision-making.

To exercise any of these, write to compliance@edgexene.io. We respond within thirty days. Because we hold no account and no identifier, an access request will in most cases return only the correspondence you have had with us, and we will say so plainly rather than manufacture a record.

We must be able to verify that a request comes from you. Because there is no account, in many cases the only thing we can verify against is correspondence you have already sent us. Where we cannot reasonably establish that a request is yours, we will say so and decline rather than hand your information to someone else on the strength of an unverified claim.

Exercising any right never degrades how PATANYX works.

[ 13. California Privacy Rights ]

Under the California Consumer Privacy Act as amended by the CPRA, California residents have the right to know what personal information is collected, to delete it, to correct it, to opt out of sale or sharing, and not to be discriminated against for exercising those rights.

EdgeXene does not sell personal information and does not share it for cross-context behavioral advertising, so there is no opt-out to operate. We do not use or disclose sensitive personal information for purposes requiring a limitation right.

The statute requires disclosure by its own categories rather than in plain description alone, so the table states them directly.

CCPA category Collected Source, purpose and disclosure
A. Identifiers (IP address) Yes, transiently Received from your device when answering an update or blocklist check, a language pack download, or a contact form submission. Used to deliver the response and to limit abuse. Not logged or retained by EdgeXene. Disclosed to Cloudflare for requests to this website, though not for update or blocklist checks, which do not pass through it. Cloudflare keeps short-lived security logs of its own. Not sold or shared
A. Identifiers (name, email address) Only if you supply them Provided by you in the contact form, and received from the payment processor in the donation record described in Section 2.3. Used to reply and for accounting records. Disclosed to the mail provider in Section 4.1. Not sold or shared
D. Commercial information Only if you donate or buy a Premium term A record of a payment you chose to make, and for Premium buyers a license identifier and the dates of the term. Used to deliver Premium and for accounting and tax records. Not sold or shared
F. Internet or other network activity Yes, on our websites only Our web server records which page was requested, as Part B describes. Nothing about your browsing in PATANYX reaches EdgeXene: browsing history, search history and what you do in the browser are never transmitted to us
G. Geolocation data Yes, approximate only A country, region and city worked out from the address a request came from, for visit counts on our websites, as Part B describes. Never a precise location, and never from the browser
B. Customer records, C. Protected classifications, E. Biometric, H. Sensory, I. Professional, J. Education, K. Inferences, L. Sensitive personal information No None collected

EdgeXene has not sold or shared personal information in the preceding twelve months, and does not knowingly sell or share the personal information of consumers under 16 years of age.

PATANYX sends the Global Privacy Control signal to every site you visit, permanently and with no setting to turn it off. On Windows that means both the request header and the page property; on Linux, the page property alone. Section 15 explains why. In California and in several other states this is a legally recognized opt-out request, which means the browser exercises that right on your behalf without your having to find a link on each site. Section 15 states what the signal does and does not achieve.

[ 14. Indiana, Virginia and Other State Privacy Laws ]

EdgeXene LLC is organized in Indiana. Residents of Indiana, Virginia, Colorado, Connecticut and other states with comprehensive consumer privacy statutes have rights to access, correct, delete and port personal data, and to opt out of targeted advertising, sale and profiling. EdgeXene engages in none of those three activities.

Requests go to compliance@edgexene.io. If we decline a request you may appeal by replying to our decision, and we will respond to the appeal in writing.

[ 15. Do Not Track and Global Privacy Control ]

PATANYX sends Sec-GPC: 1 and exposes the corresponding Global Privacy Control property to every page. It is always on. There is no switch, because a privacy signal that most users never find is not a privacy signal.

Be clear about what this is worth. GPC is a legally binding opt-out request in California and several other jurisdictions, and sites subject to those laws are obliged to honor it. Elsewhere it is a request that a site may ignore. It does not block anything by itself, and it does not make you anonymous.

Platform difference. On Windows the browser sends the Sec-GPC request header and sets the page property. On Linux the engine we use provides no way for an application to add a request header, so only the page property is set. We would rather state that than let the two look the same.

PATANYX does not send the older Do Not Track header, which was never standardised in a way that obliged anyone to act on it, and does not act on a DNT header received from anywhere.

[ 16. EU and UK Users ]

In addition to Section 12, residents of the European Economic Area and the United Kingdom may restrict processing while a dispute is resolved, object to processing on grounds relating to their particular situation, and lodge a complaint with their local supervisory authority.

PATANYX carries out no marketing, no profiling and no automated decision-making. Contact compliance@edgexene.io to exercise any of these.

EdgeXene LLC does not currently have an EU representative. EU users may contact compliance@edgexene.io directly or lodge a complaint with their local supervisory authority.

[ 17. Children's Privacy ]

PATANYX is a general-purpose web browser intended for adults. We do not knowingly collect personal data from children under 13, or under the age of digital consent in their country where that age is higher, and the product is built so that we collect almost nothing from anyone. If you believe a child has sent us information through the contact form, write to compliance@edgexene.io and we will delete it promptly.

A browser can reach any site on the web. PATANYX does not filter content by age and is not a substitute for parental supervision.

[ 18. PATANYX Premium ]

Premium unlocks checking an image for text before you share it, searching across every open tab together with the tab switcher and batch tab actions, reading the text you drag a box around, and the archive of pages you chose to keep. Reading a written recovery key off a photograph stays free, because Premium lives inside the vault a locked-out person cannot open. Private chat, checking a page against what a contact was served, and comparing a downloaded file with a contact ship in PATANYX Nabu-X, a separate build that is not publicly available yet. They are not in the PATANYX Browser you can download today. Everything else stays free, including every accent color and chrome color scheme, the built-in tunnel, all the blocking, the vault, the update channel, and light and dark following your system setting. Paying changes what the browser can do. It does not change what it collects about your browsing, which remains nothing.

[ 18.1 Two builds, and why that matters ]

PATANYX ships as two builds. The PATANYX Browser is the one you can download today; it contains no chat code and no relay code whatsoever, and an automated check runs on every release that fails the build if any is found. That is a stronger statement than a setting being switched off: buying Premium does not add that code, because the code that could talk to our relay is not present in the file. PATANYX Nabu-X is the separate build that contains everything the PATANYX Browser has, plus the chat stack and the relay client. It is not publicly available yet, and it will also be a free download, licensed by the same Premium token.

[ 18.2 Who can see what ]

Stated as a table because it is the only honest way to answer it.

Party What they can see
The payment processor Your full payment identity: name, card, email address, billing address where law requires it, IP address, the amount, the date, and that you paid EdgeXene. Buying with a card is not anonymous and cannot be made so
EdgeXene's license server A license identifier, the dates of your term, a payment reference, the token it issued you, and, per activated device, a random per-install identifier and the day it activated. It records no IP address. Your browser contacts it once per device, to activate (and once more if you release that device); the other contact is the page you are sent to after paying, which you may reload
EdgeXene's chat relay (PATANYX Nabu-X only) While you are connected: your IP address and your license identifier. It cannot read your messages, holds no keys, and stores no message and no queue. Afterwards it keeps aggregate counters only
Cloudflare Your IP address and the request, for the purchase page and the offline activation form on this website, in the course of passing them to our server. It terminates the encrypted connection, so it sees their contents, and it keeps short-lived security logs of its own. Activating from inside the browser does NOT pass through it: that call goes to patanyx.edgexene.io, which Cloudflare does not sit in front of
Anyone watching the network That your computer holds encrypted connections to the payment page, the license server and, in PATANYX Nabu-X, the relay, with their timing and volume. Not their contents. Cloudflare is the exception described in the row above: it is in the path, not merely watching it
EdgeXene, about your browsing Nothing. Paying does not change this

[ 18.3 What this lets us infer, stated rather than fudged ]

A license identifier is stable across renewals. The relay sees it alongside an IP address for the duration of a chat connection. So a relay operator who chose to keep records it currently does not keep could, in principle, learn that a particular license was online at particular times and from particular addresses. It could not learn who you spoke to by name, or anything you said, because it never holds the keys. We keep aggregate counters instead, and we would rather write this paragraph than let you assume a property the architecture does not provide.

The relay cannot be removed from the path for relayed chat. On a local network, chat can connect directly between two machines and the relay is not involved at all.

[ 18.4 What we deliberately do not do ]

[ 18.5 When a Premium term ends ]

Premium is a prepaid term, not a subscription. There is nothing to cancel and nothing renews on its own: a term simply runs out on the date the token carries.

When it runs out, the Premium features stop until you buy another term. All of them. We do not operate a partial or reduced Premium tier, and we would rather state that here than have the browser surprise you. Nothing phones home to switch anything off: your own copy of the browser reads the date in your token and stops honoring it after that date, offline, with no check-in.

Free features are never affected. Nothing you created is deleted or held back; it is on your device and stays yours. We do not need to delete anything at our end, because we hold no copy of it. There is no account to close.

[ 19. Changes to This Policy ]

EdgeXene LLC may update this policy as PATANYX develops. Material changes will be announced in the release that introduces them and recorded in the changelog below, with the effective date updated. Continued use after a change constitutes acceptance.

Expect this policy to change as the product develops. Every change from the Stable Release onward is recorded here rather than made quietly. Entries from the prerelease period were withdrawn at the 1.0.0 release.

[ B.1 What it is ]

PATANYX Search is a website at patanyx.com, operated by EdgeXene LLC. It has five parts: Weather, which answers a place name with a forecast; Earthquakes, which shows recent earthquakes worldwide from the US Geological Survey; AreaGram, which shows which publishers in which countries carried the same news story; Travel, which answers a destination you name with the weather there, the travel advice published separately by the United States, the United Kingdom and Canada, recent earthquakes nearby, news stories that crossed borders about it, and for a United States city, alerts from the National Park Service; and Recall, which answers a product, brand, food, medicine or vehicle you name with the official recall notices published by the United States Consumer Product Safety Commission, the National Highway Traffic Safety Administration, the Food and Drug Administration, and Health Canada. There are no accounts, PATANYX Search sets no cookies, and there is no analytics beyond the page-view totals described in B.2. The pages load no advertising scripts, tracking pixels or advertising SDKs. Some may carry a labeled affiliate link, described in Section 4.7. The pages contain no scripts except the small one that offers place-name suggestions as you type on the weather, earthquake and travel pages.

[ B.2 What our web server records ]

Like most web servers, ours writes one line per request to a log: your IP address, the time, the page you asked for, the response, and your browser's identifying string. The front page, and the script and images it loads on its own, are the exception: no line is written for them, because the PATANYX browser opens that page every time it starts and a record of those requests would be a record of when you started your browser. A request the rate limit refuses is noted in the server's error log with the address; that log is kept on the same 14-day schedule. It does not record what you typed into the weather search, and it does not record the address of the page you came from; the log format is set so those two fields are never written. These logs are rotated daily and deleted after 14 days. They are used to keep the site running and to notice abuse; they are not used to build profiles, are not combined with any other data, and are not shared. We use them for analytics: counting visits and downloads, and seeing which country and city a visit came from. We keep no personal information about you — no name, no email, no account — and the only address we hold is the one in the log described above, kept to deal with abuse and deleted after 14 days.

[ B.3 Weather ]

The place you type is matched to a coordinate on our own server, from a copy of the GeoNames gazetteer we hold. That coordinate, rounded to one tenth of a degree (about 11 kilometers), is sent to the forecast provider: MET Norway for most of the world, the United States National Weather Service for the United States. Nothing about you goes with it: the request carries our own identifying string, not your IP address or browser. Forecasts are cached on our server for five minutes, so a place that several people ask about is looked up once. Radar and satellite images are fetched by our server on a schedule and re-served to you; the image providers see our server, not you. The providers are listed on the Sources page.

[ B.4 AreaGram ]

AreaGram is built from publishers' public news feeds, which our server polls. From each item we keep the headline, the outlet's name, the time the publisher gave, and the link. We never keep the article. Nothing about readers is recorded by AreaGram: it does not know who looked at which story. Every headline is a link to the publisher's own page; opening one takes you there, and the publisher receives your IP address as any site you open does. What we may show from publishers is stated in section 4.6. Every publisher we poll is listed on the Sources page. We do not poll publishers whose feed terms limit use to personal or non-commercial readers, or require permission.

[ B.5 Retention and your rights ]

The only data about you that PATANYX Search holds is the server log in B.2, kept for 14 days. The visit counts kept for two years are totals only: they carry no address and nothing that identifies you. Sections 5 through 17 of Part A apply to it in the same way: you may ask what we hold and ask us to delete it, using the contact below, and the lawful basis is our legitimate interest in running and protecting the site.

[ Contact ]

For privacy-related questions, data rights requests, or compliance matters: compliance@edgexene.io

For all other questions, use the contact form.

EdgeXene LLC
15442 Ventura Blvd., Ste 201-2525
Sherman Oaks, CA 91403

[ Changelog ]

September 18, 2026
Cloudflare was placed in front of patanyx.net and models.patanyx.net to absorb denial-of-service traffic and filter malicious requests. Cloudflare is now listed as a service provider in section 4.1, and the statement that no content delivery network sits in front of the language-pack host has been corrected in section 2.7. The update and blocklist channel at patanyx.edgexene.io is unchanged and still answers directly, so the statement in section 2.1 that no content delivery network sits in front of that host is unchanged. Section 2.1 was edited the same day for a separate reason: it now also names the signed engine-safety advisory that rides alongside the update check. Section 4.1 is now a set of blocks rather than a table, and each third party named in section 4 carries a link to its own site or policy. Nothing new is collected by EdgeXene.
September 17, 2026
The Stable Release. This policy now applies to the PATANYX Browser as released; the prerelease notices are withdrawn and the effective date is the release date. No change to what is collected, stored or sent.