Your feedback, your choice.
Patchkind is operated by The Vancouver Agency. It is an early pilot for collecting feedback and preparing owner-approved work. Contact The Vancouver Agency about Patchkind. Updated October 3, 2026.
What is collected
Your message, optional follow-up answer, feedback category, optional name, submission time, and a page address when supplied. Page query strings and fragments are removed. You can optionally attach up to two screenshots or short clips. Nothing is captured until you choose to upload or start capture. Recording can include your microphone only if you select that option and grant permission. Patchkind does not run heatmaps or background session recording.
Opening a feedback form adds one to a daily total for that project, so its owner can tell whether anyone is finding the form. That total is a number and a date. It records nothing about who opened it, no address, no identifier, and no link to anything you go on to send.
Review each attachment before sending. Screenshot marks and covered areas are flattened into the saved image by our feedback form; it uploads that prepared copy, not the original. The form’s image preparation discards image metadata. This is not a guarantee for files submitted by another client. Clips may contain audio or identifying details: preview them and remove any clip you do not want to share. We do not automatically redact clips. Filenames are not stored.
Who can see it
The project owner can read reports. After reviewing and approving a proposal, they may send selected evidence to GitHub or a coding agent. A GitHub issue may be public if the owner chooses a public repository. Do not submit passwords, access tokens, or sensitive personal information.
Connecting an assistant
An owner may connect their assistant to Patchkind using its plugin or an access key. Within that owner’s access, the assistant can read product direction, original feedback, follow-up answers, screenshot annotations and requested private screenshots. The assistant’s provider then processes the returned material under its own policies. This connection does not require built-in Patchkind AI to be enabled.
Connections with plan permissions can also save plans, record the owner’s approval of an exact version, and record implementation results. Read-only keys cannot do that. Connecting an assistant does not give it access to a code repository or start automatic code changes. Revoke a key in the workspace or disconnect the plugin in your assistant. Revocation prevents new access; copies already returned to that provider must be managed there separately.
Connecting a repository
When the GitHub App connection is available, the owner authorizes it separately from their Patchkind sign-in and selects an installed repository they administer. Patchkind stores the repository and installation identifiers, GitHub account identifier and login, connection/check times, run commit and actor logins. The temporary GitHub user token is revoked before repository selection completes; user access and refresh tokens are never stored. Setup links expire after thirty minutes; repository choices expire after fifteen.
The App can start and re-run Actions workflows and read pull requests, checks and commit statuses on selected repositories. It requests no Contents permission. Patchkind cannot inspect the workflow file; review it in GitHub before running. Pull requests and Actions logs or artifacts may themselves contain private information. Short-lived installation tokens stay in server memory, are scoped per operation, and are revoked after use when GitHub confirms the request.
The connection test sends only a random identifier, with no feedback, screenshot or AI key. Disconnecting removes saved connection and setup metadata and stops new requests. GitHub controls uninstalling the App and cancelling an already-running job. Past repository labels and results stay with the project until deletion. Webhook delivery IDs and digests are retained without event payloads to reject duplicate deliveries. Routine completed receipts are removed after thirty days; security-event fingerprints are kept to reject old removal replays. Repository connection does not start a coding worker, merge or deploy.
What built-in AI does, when enabled
Feedback types may be suggested using simple text rules. New reports can become drafts using structured templates, not an AI diagnosis. If AI follow-ups are enabled and you choose “Answer one quick question,” your message and the project’s name are sent to OpenAI to suggest one question and a tentative interpretation. No name, status link, or page address is included in that request. Patchkind requests no stored API response; OpenAI’s API data handling policies still apply. If AI is unavailable, a standard question is used. Original words and answers stay separate from interpretation. If the owner hands it to their coding agent, that provider’s data handling rules also apply.
The owner can separately ask AI to summarize the latest 30 feedback notes against their private product direction. The project name, direction, feedback text, follow-up answers and selected attached screenshots are sent to OpenAI; reporter names, page addresses and private status tokens are excluded. This analysis is visible only in the owner’s workspace. It does not approve work or send replies to reporters. The owner’s private direction is never included in reporter-facing AI questions.
Each owner review includes up to six screenshots within a six MB total limit. The workspace shows how many screenshots were included. Clips and their audio are not sent to AI in this version. Media is not automatically included in GitHub handoffs or notification webhooks. The owner may separately choose to share material outside Patchkind.
Owner notification preferences
Owners can opt into webhook alerts for their own projects and disconnect at any time. Webhook addresses are encrypted. Alerts contain an event identifier and a workspace link, without feedback text, reporter names, contact details or private status links. The receiving service’s data handling rules apply. Failed deliveries may be retried up to three attempts with the same identifier; the receiver should deduplicate it. Reporters receive no automatic email or webhook notification.
Your private status link
The link allows its holder to see the report’s progress, add one optional clarification, attach up to two files during the first hour, and confirm whether a released change helped. Keep it private. Patchkind stores a hash of the link’s secret. No email address is required and no email notifications are sent in this version.
Storage and removal
Attachments are stored privately in platform-managed object storage. Reading them requires owner authentication or an authorized owner connection. Access expires after 30 days. Expired or removed files are queued for deletion and cleaned up as the service is used; storage failures are retried on later activity. Removing an attachment immediately revokes access. Written feedback is kept separately. Removing or expiring an attachment also invalidates and removes its project’s cached AI summary. Copies already downloaded or sent to a provider are outside that deletion.
Reports remain until the project owner deletes them or the project. Contact the app owner through their website to request removal and provide your submission details. Deletion in Patchkind removes linked local follow-up notes, proposals, approvals and the project’s cached AI summary; copies already sent to GitHub or an agent need to be removed separately with that provider.
Beta requests and contact messages
When you request access or contact Patchkind, we store your email, optional name, product type, optional product website and your message. Contact details and message content are encrypted in storage and are visible only to authorized Patchkind team accounts. A request does not subscribe you to a newsletter or grant a workspace invitation.
Requests stop appearing in team review after 90 days. Expired records are removed when new requests arrive or the team opens its review page. The team can delete a request sooner. Contact Patchkind to ask about or request removal of your access-request information. We may need to confirm ownership before acting.
If you allow optional analytics and arrive through a tagged campaign link, we temporarily keep its source, medium, campaign and creative labels in your browser tab for up to 30 minutes and attach them to your request. Separately, when ad measurement is enabled and you explicitly allow it, we keep an ad click ID in your tab for up to 30 minutes and encrypt it with a saved beta request. The team can export reviewed requests to Google with their click ID, submission time and a random request reference. The export excludes email, name, product website and message. Turning measurement off stops new collection; contact us to remove a saved request. Copies already imported into Google are handled under its policies. We do not save search terms or full referring URLs, load a Google advertising tag or remarketing pixel, or upload hashed email addresses.
Landing-page analytics
The private launch dashboard also shows aggregate product usage from saved projects, feedback and decisions: how many accounts start a project, receive feedback, approve a decision or share an improvement. Internal administrator accounts and installation test messages are excluded. These totals contain no feedback text or account identifiers and are not sent to advertising platforms.
With your permission, a random browser ID is saved on your device so the same browser is counted once. Patchkind records whether that browser viewed the landing page, used the example on it, clicked to request beta access, opened the workspace, created a project, or saved feedback. These records do not include feedback text, names, email addresses, or page contents. Each event counts once per browser. The owner sees grouped totals, not individual activity. Analytics older than 90 days is removed as new events arrive. Turning analytics off below removes the browser ID, saved experiment choices and campaign labels from your device and stops new browser events. Existing server records expire under the same 90-day policy. We honor Global Privacy Control and Do Not Track by keeping these optional features off.
An earlier version of this page compared two product examples and saved which one a browser was shown. That comparison has ended and no new records are created for it. Its existing grouped totals remain visible to the owner until the 90-day removal above reaches them.
Your analytics choice
Optional browser analytics and campaign attribution are off unless you allow them. Feedback, sign-in and access requests work either way. Your choice is saved on this device for six months.
Service providers
This pilot uses OpenAI Sites for hosting and owner sign-in, with platform-managed Cloudflare storage. When enabled, Cloudflare Turnstile processes verification information to reduce spam. GitHub and the owner’s selected coding provider receive information only through the handoff paths described above.
The invited beta is free. If paid billing is enabled later, Stripe hosts checkout and the billing portal. Payment details are entered directly in Stripe; Patchkind stores the customer reference and subscription status, not card details.
Security and data location
Cloudflare documents encryption at rest and in transit for D1 databases and R2 object storage. Attachment files are not served from a public bucket; access requires owner authentication or an authorized owner connection. Application secrets stay on the server. Optional connection tokens, webhook addresses and beta-contact details receive additional application-level encryption. Feedback text is protected by storage encryption, but this service does not provide end-to-end encryption.
This pilot does not offer a Canadian-only storage commitment or a verified recovery-time guarantee. Processing may take place outside your country. Database recovery and retained backup copies depend on the hosting provider; deletion from the active service may precede expiry of a provider’s backups. Do not submit information that needs a particular residency or regulated-data agreement without arranging and verifying those requirements with us first.
Accounts and connections
Your owner profile stores your chosen display name, optional workspace name and preferred dashboard view. These are private workspace settings; they do not change your sign-in identity or the public names of your projects. You can edit them in Account & settings and export your profile, projects, feedback, decisions and attachment metadata there. Media files are downloaded separately from their feedback cards.
Owner accounts use ChatGPT sign-in. The GitHub App never stores user access or refresh tokens; installation tokens stay in server memory for one operation. Older optional project tokens remain encrypted until removed or replaced. The App can start Actions workflows on selected repositories; those workflows may have their own deployment credentials. Patchkind’s connection check does not merge or deploy.