Legal · Privacy
Privacy Policy
How CrystalMark collects, uses, discloses, and retains personal information, the cookies we set, and the rights available to you.
Effective
June 30, 2026
Last updated
September 14, 2026
1. Who we are
CrystalMark is a USPTO trademark examiner analytics service operated by Schwartz Software Solutions LLC. We provide subscription analytics built on public USPTO records. This policy explains what information we collect when you use our service at crystalmark.app, how we use it, and what rights you have.
Contact for privacy questions: support@crystalmark.app. Our postal address is Schwartz Software Solutions LLC, 6100 Fairview Rd, Ste 1135, Charlotte, NC 28210.
2. Information we collect
We try to collect only what we need to operate the service.
2.1 Information you give us
When you create an account, we collect:
- Name (required at signup)
- Email address (required; used for sign-in and transactional emails)
- Password (stored only as a one-way hash; we never see your plaintext password)
- Firm membership (if your account belongs to a multi-seat firm: the firm name and your role)
When a firm invites you to join, we collect the email address the invitation was sent to (provided by the inviter). If you subscribe to a research newsletter, we collect your email address only. If you write to us through the form on our contact page, we collect the name, email address, and message you type there, plus the IP address the message came from (we rate-limit that form to keep out automated abuse).
As you use the service, you may also choose to give us:
- Docket claims and watches: an attorney-of-record name and the application serial numbers you follow
- Registration watches: registration numbers and the free-text labels you attach to them
- Firm notes: text notes your firm keeps on examiner pages, visible only to your firm
- Email alert preferences: digest frequency and per-alert toggles
None of this feeds the examiner analytics we publish; it exists solely to power your own docket, alerts, and notes.
2.2 Information collected automatically
- Session information: IP address, browser user agent, sign-in timestamps. Used to keep you signed in, to rate-limit abuse-prone endpoints such as sign-in and the contact form, and to detect unauthorized access.
- Examiner viewing history: which examiners you have looked up recently, kept in our cache for 30 days to populate your "recently viewed" list. It stays in our own cache and goes to no one else.
- Error reports: when the service hits an unexpected error, we send the details to our error-tracking provider (Sentry, see §5): the page address, a stack trace, and, if you are signed in, your account ID and email address. Before a report leaves our servers we remove session cookies, authorization headers, request bodies, and query strings from the request data it carries.
- Product analytics: we use PostHog (US-hosted) to understand how the product is used: which pages are visited, which elements are clicked, and the product actions listed below. It sets no cookies and stores nothing on your device, and session recording is disabled. When you are signed in, these events are recorded under an internal account identifier, a random value assigned to your account at signup, so that we can measure use by account; events recorded earlier in the same browsing session are linked to that identifier when you sign in, and because we store nothing on your device the link does not extend to earlier visits. We do not send your name, your email address, or the contents of anything you type to PostHog. Every event is stripped of query strings and URL fragments before it leaves your browser, so the serial numbers and registration numbers that ride those query strings are never sent. The address of a registration page includes that registration's number, and the address of an examiner page includes that examiner's identifier. The product actions recorded are signing in, connecting a docket, undoing a docket connection, adding a registration to your watch list, writing a firm note, and opening a client explainer, each recorded without the matter, registration, or note involved and without any text you typed. A docket connection also records the size band of the docket connected and whether that docket was already connected; a note records whether a serial number was attached. PostHog receives your IP address with each event. PostHog data is not sent to any advertising network, and we do not sell it.
- Advertising conversion measurement: we buy search ads on Google, and some of our pages carry Google's conversion tag so we can tell which ads led to a signup. It reports the address of the page being viewed to Google Ads. Not every page carries it, and the boundary is set out just below this list. It runs in Google's restricted data processing mode with ad personalization and Google signals switched off, which means it does not build remarketing audiences and does not add you to advertising lists. It does set cookies, including cookies on Google-owned domains; §6 names every one of them and explains what they can and cannot do. In the EEA, the UK, and Switzerland the tag is instructed to deny advertising and analytics storage before it runs, which is Google's documented mechanism for measuring without advertising cookies. §8.2 covers your choices.
- Standard server logs: kept by our hosting provider per their standard retention; these include IP address and request path.
Where the advertising tag runs. The tag loads on our public pages, meaning those readable without an account, and on the single onboarding page presented on completion of signup. It does not load on the signed-in product, on account settings, or on the sign-in and signup forms. Accordingly, the examiners you research from your docket and the serial numbers you track are not reported to Google.
Two public pages are an exception and we identify them here. Our public examiner preview carries an examiner identifier in its address, and our example profile does the same. Both retain the tag because our advertisements link to them. If you open either page, that identifier forms part of the page address reported to Google. Such browsing is anonymous, public, and pre-purchase, and is distinct from your signed-in research, but the disclosure is not nil.
2.3 What we do not collect
- No session replay or screen recording. We do not record playback of how you move through the site. Our error tracker's replay feature has been switched off since May 2026.
- No advertising vendor other than Google. We carry no Meta Pixel, no LinkedIn Insight Tag, and no Google Analytics property. The Google conversion tag in §2.2 is the only advertising tag on the site.
- No cookie that can follow you to another site. The advertising cookies in §6 that sit on Google-owned domains are partitioned, meaning the browser scopes them to CrystalMark: another website cannot read them, and they cannot be used to assemble a profile of your browsing elsewhere. We do not build remarketing audiences, do not upload customer lists to any ad platform, and do not target you with advertisements on other sites.
- No precise geolocation. No biometric data.
- No data about your trademark applications or client work beyond what you explicitly add (docket claims, watches, notes), and none of it feeds our published analytics.
3. How we use your information
We use your information to:
- Authenticate you and keep your account secure
- Deliver the analytics service you signed up for
- Send transactional emails (account verification, password reset, firm invitations, billing receipts) and, if you turn them on, docket digests and alerts
- Answer messages you send us
- Diagnose bugs and improve the service
- Measure which of our advertisements bring people to CrystalMark, as described in §2.2
- Comply with legal obligations
We do not sell your information or disclose it to data brokers, and we do not train machine-learning models against your behavior. We do not target you with advertising on third-party platforms: our advertising use is limited to counting conversions on ads we have already paid for.
4. The USPTO data we publish
The examiner profiles, statistics, and citations on CrystalMark are derived entirely from public USPTO records: bulk trademark XML feeds, the TSDR (Trademark Status & Document Retrieval) API, and TTAB filings. USPTO examiners are federal employees, and their official actions in trademark prosecution are public record under U.S. law.
We do not publish information about you, your client, your firm, or your prosecution history. The data subjects on this site are USPTO examiners in their official capacity, not our users.
5. Service providers
The categories of personal information we hold are: identifiers (your name and email address); account credentials (a hashed password); commercial information (your firm membership, subscription status, and billing records); internet activity information (your IP address, the pages you view, and the internal account identifier described in §2.2); and user-generated content (the cases and registrations you follow, your alert preferences, and any notes you write). We do not collect payment card numbers, postal addresses, telephone numbers, or documents uploaded by you. The examiner analytics we publish are derived from the public USPTO record and are not personal information of yours.
We disclose personal information to service providers that perform functions on our behalf. Each is bound by its own data processing terms and may use the information only to provide the relevant service. We identify a provider by name where your browser contacts it directly, where it is able to store information on your device, or where it processes your information within its own product; our remaining infrastructure providers are identified by function. The advertising tag operates under Google's restricted data processing terms, which limit Google to measuring our own advertisements on our behalf.
The table below sets out the personal information disclosed, the recipient and purpose, and the processing location.
| Personal information disclosed | Recipient and purpose | Location |
|---|---|---|
| Name; email address; billing records | Stripe, for subscription payment processing and receipts | United States |
| Email address; the contents of the message sent, which for the docket digest includes the cases and registrations you follow | Our email delivery provider, for delivery of verification, password reset, billing, and digest email | United States |
| Email address; watched cases and registrations; alert preferences | Our scheduled-jobs provider, for assembly and dispatch of the docket digest | United States |
| Account ID and email address; page address; stack trace; IP address. Disclosed only when the service encounters an error | Sentry, for error diagnosis. Session replay is disabled | United States, or the applicable Sentry region |
| Pageview and interaction events and the product actions listed in §2.2, with query strings removed, carrying an internal account identifier when you are signed in, the size band of a docket you connect, and your IP address | PostHog, for product analytics. No cookies are set | United States |
| Address of the public page viewed (§2.2); IP address | Google, for advertising conversion measurement, under Google's restricted data processing terms | United States; Google global infrastructure |
Except as stated in the table above, we do not disclose your user-generated content to any service provider. Notes are not included in any email we send and are not disclosed to any third party. Our database, hosting, and cache providers store personal information on our behalf in the United States and process it only on our instructions.
Payments. Subscription payments are processed by Stripe. Payment card details are transmitted directly to Stripe; we do not receive or store full card numbers.
7. How long we keep your information
| Type | Retention |
|---|---|
| Account information (name, email, password hash) | Until you delete your account |
| Sessions (active sign-ins) | 7 days from your last activity, or until you sign out |
| Recently-viewed examiner list | 30 days from last activity |
| Docket claims, watches, notes, alert preferences | Until you remove them or delete your account |
| Messages sent through the contact form | Kept in our support inbox while the conversation is useful; deleted on request |
| Error reports (Sentry) | Per Sentry's standard retention |
| Product analytics events (PostHog) | Per PostHog's standard retention |
| Advertising conversion data (Google Ads) | Per Google's Ads data retention; the _gcl_au cookie expires 90 days after it is set |
| Server access logs | Per our hosting provider's standard retention |
| Database backups | Up to 30 days |
If you delete your account, we remove your personal information from our own systems within 30 days. Backups containing residual references are removed on their normal rotation (within 30 days of deletion). Product analytics events recorded under the internal account identifier (§2.2) remain with PostHog for the retention period above; the identifier is a random value that corresponds to no account once yours is deleted, and on request under §8.1 we delete the analytics profile held under it.
8. Your rights and choices
8.1 Everyone
Regardless of where you live, you may:
- Access the personal information we hold about you
- Correct inaccurate information
- Delete your account and associated personal information
- Export your account data in a portable format
- Object to processing or restrict it
Two of these are self-serve, no email needed: Account → Export my data downloads everything we hold about you as JSON, and Account → Delete account permanently deletes your account and personal information (§7 covers the backup window). For anything else, or if you can no longer sign in, email support@crystalmark.app from the address on your account. We verify every request against the account email and respond within 45 days, or within one month if you are writing to us from the UK or the EU.
We will never charge you, degrade your service, or change your price because you exercised a privacy right.
8.2 Your choices about cookies and advertising
- The advertising cookie. Block or delete
_gcl_auin your browser settings, or browse in a private window. Nothing on CrystalMark depends on it. §6 has the detail. - The notice cookie. You may block or delete
cm_privacy_notice(§6). The notice of a policy revision then appears again the next time you use the signed-in product. - Google ad personalization. You can turn it off for your Google account at myadcenter.google.com. Our tag already tells Google not to use your visit for personalization.
- Email. Every digest and alert email carries a one-click unsubscribe link, and alert preferences live in your account settings. Transactional email (verification, password reset, receipts) is part of the service and cannot be turned off while you hold an account.
- Global Privacy Control. Some browsers and privacy extensions send a Global Privacy Control signal on your behalf. We honor it. If your browser sends one, we deny advertising and analytics storage for your visit wherever you are, which means the advertising tag in §2.2 stores nothing on your device and the advertising cookies in §6 are not set. You do not have to ask us for anything or take our word for it: the signal does the work. If you would rather tell us directly, email support@crystalmark.app and we will leave your visits out of advertising measurement and confirm in writing.
- Do Not Track. Browsers can also send a Do Not Track header. No agreed standard was ever settled for what a website should do when it receives one, so we do not act on it, and you should treat any site that claims otherwise with some caution. California law asks us to tell you how we respond to Do Not Track signals, and this is our answer. The Global Privacy Control signal above is the one with a defined meaning.
- Collection by other parties. California law asks us to tell you whether anyone else may collect information about your online activities across different websites while you use ours. One party can: Google, through the conversion tag described in §2.2. On the pages that carry the tag, and only those, Google receives the address of the page and, if you clicked one of our advertisements, an identifier for that click. §2.2 sets out which pages those are. We have configured the tag so that Google may not use any of it for ad personalization or to build advertising audiences, and the cookies it sets on Google-owned domains are partitioned to CrystalMark (§6). Our two other outside recipients, PostHog and Sentry, receive information about your activity on this site only: neither sets anything on your device from here, and neither can see where else you go. No other outside party collects information about your activity over time or across other websites while you use CrystalMark.
8.3 California
California's requirements as to the content of a privacy policy apply regardless of business size, and this policy is written to meet them. The CCPA and CPRA additionally grant California residents a set of rights, subject to applicability thresholds that we do not meet. Without conceding that those statutes apply to us, we extend the following rights to any California resident on request:
- Right to know what personal information we collect, use, and disclose. §2 lists the categories we collect, §3 the purposes, and §5 every party we disclose it to.
- Right to delete personal information we have collected.
- Right to correct inaccurate personal information.
- Right to limit use of sensitive personal information. We do not collect sensitive personal information as the CPRA defines it, and we do not use or disclose any personal information to infer characteristics about you.
- Right to non-discrimination: we will never degrade your service for exercising a privacy right.
Sale and sharing. We do not sell your personal information. The one advertising disclosure we make is the conversion measurement described in §2.2: on the pages that carry the tag, Google receives the address of the page and the advertising identifiers named in §6, under Google's restricted data processing terms, which limit Google to measuring our own advertisements for us. We do not treat that as a sale or a share, and we do not disclose personal information for cross-context behavioral advertising. If you want your visits left out of advertising measurement, see §8.2.
You may submit a request yourself (§8.1) or through an authorized agent; agents must provide written authorization, and we will still verify with the account holder directly.
8.4 Other U.S. states
Several states, including Virginia, Colorado, Connecticut, Texas, Oregon, Montana, Delaware, New Jersey, and others, have comprehensive privacy laws granting rights to access, correct, delete, and obtain a copy of personal data, and to opt out of targeted advertising, sale, and profiling with legal effects. Most of those laws exempt information collected in a purely business-to-business context, and CrystalMark is sold only to professionals for their work. We do not depend on that exemption: we extend the rights in §8.1 and the choices in §8.2 to everyone who asks, whatever state they live in.
Appeals. If we decline a privacy request, we will tell you why in writing. You may appeal by replying to that decision or emailing support@crystalmark.app with "privacy appeal" in the subject line. We will review and respond within 45 days, and if we deny the appeal we will tell you how to contact your state attorney general.
Nevada. Nevada asks operators to publish a designated address for requests not to sell covered information. Ours is support@crystalmark.app. We do not sell covered information. Send a request there and we will verify it against your account and respond within 60 days, as Nevada requires.
8.5 EEA, UK, and Switzerland
CrystalMark is a research tool for United States federal trademark prosecution. It is sold in U.S. dollars, offered in English, and directed at the United States market; we do not advertise or solicit customers in Europe. On that basis we do not consider our processing to fall under the EU or UK GDPR. The service is nonetheless reachable from the EEA, the UK, and Switzerland since August 28, 2026, so rather than rest on that position we set out plainly where you stand if you use it from there.
Who holds your data. Schwartz Software Solutions LLC, 6100 Fairview Rd, Ste 1135, Charlotte, NC 28210, United States, reachable at support@crystalmark.app.
Why we process it. Your account information is processed to deliver the subscription you signed up for, including the optional email digests you can switch off at any time. Security logs and error reports are processed to keep the service running and to keep accounts from being taken over. Our product analytics are first-party: they set nothing on your device and they are not used to follow you to other sites. When you are signed in, the events are recorded under an internal account identifier so that we can measure use by account rather than by page alone. You can object to any of it under §8.1.
Advertising. The tag in §2.2 is instructed to deny advertising and analytics storage for visitors in the EEA, the UK, and Switzerland before it runs, which is Google's documented mechanism for measuring conversions without setting advertising cookies. If we ever want to set a non-essential cookie for you, we will ask for your consent first and you will see the request before anything is stored.
Your rights. Access, rectification, erasure, restriction, portability, and objection. We make no decisions about you by automated means. Use the paths in §8.1; we answer within one month. If you believe we have handled your data badly, you may complain to your national data protection authority, or to the UK Information Commissioner's Office if you are in the UK.
Transfers. Our infrastructure and every vendor in §5 are in the United States, so using CrystalMark from Europe means your information is processed there. §11 explains the basis.
9. Security
We protect your account information with standard safeguards:
- Passwords are stored as one-way hashes (scrypt)
- All connections to our service use HTTPS
- Database access is restricted to authenticated application code
- Secrets and API keys are managed through a secrets manager (no plaintext credentials in code)
- We monitor for errors and unauthorized access
No system is perfectly secure. If we discover a security incident affecting your data, we will notify affected users in accordance with applicable law.
10. Children's privacy
CrystalMark is a B2B service for trademark attorneys. We do not knowingly collect personal information from anyone under 18. If you believe a minor has created an account, contact us at support@crystalmark.app and we will delete it.
11. International data transfers
Our infrastructure is hosted in the United States, and every vendor in §5 processes data in the United States. If you access CrystalMark from outside the U.S., your information is transferred to and processed in the United States.
Two different things happen when you use CrystalMark from the EEA, the UK, or Switzerland, and they are worth separating.
What you type, you send to us. When you fill in the signup form or write to us, you are handing your information directly to a United States company. Nobody exports it on your behalf.
What our tags transmit, we transmit. That is our doing, not yours, so we hold it to a tighter line: advertising and analytics storage are denied by default for visitors in those regions, so the advertising tag stores nothing on your device there. A request still reaches Google carrying your IP address and the address of the page, which is how measurement works without a cookie.
Our arrangements with the service providers described in §5 are governed by each provider's own published data processing terms. Where those terms provide a transfer mechanism for European personal data, such as the European Commission's standard contractual clauses or the UK international data transfer addendum, we rely on that mechanism. We have not audited each provider's terms against the others and make no representation that they are uniform. On request, we will identify the terms applicable to a particular provider.
12. Changes to this policy
We may update this policy from time to time. The "Last updated" date reflects the most recent revision. Material changes will be announced via email or in-app notice before they take effect.
13. Contact
For privacy questions, requests, or complaints: support@crystalmark.app.
Questions about this policy? support@crystalmark.app.