Legal · Privacy
Privacy Policy
What we collect, how we use it, who we share it with, and the rights you have. We run no third-party advertising or analytics trackers.
Effective
June 30, 2026
Last updated
July 22, 2026
1. Who we are
CrystalMark is a USPTO trademark examiner analytics service operated by Schwartz Software Solutions LLC. We provide subscription analytics built on public USPTO records. This policy explains what information we collect when you use our service at crystalmark.app, how we use it, and what rights you have.
Contact for privacy questions: support@crystalmark.app.
2. Information we collect
We try to collect only what we need to operate the service.
2.1 Information you give us
When you create an account, we collect:
- Name (required at signup)
- Email address (required; used for sign-in and transactional emails)
- Password (stored only as a one-way hash — we never see your plaintext password)
- Firm membership (if your account belongs to a multi-seat firm — the firm name and your role)
When a firm invites you to join, we collect the email address the invitation was sent to (provided by the inviter). If you subscribe to a research newsletter, we collect your email address only.
2.2 Information we collect automatically
- Session information — IP address, browser user agent, sign-in timestamps. Used to keep you signed in and detect unauthorized access.
- Examiner viewing history— which examiners you have looked up recently, kept in our cache for 30 days to populate your "recently viewed" list. Not sold, not shared.
- Error reports — when the service hits an unexpected error, we send the details (URL, your user ID if signed in, and a stack trace) to our error-tracking provider (Sentry, see §5).
- Session replays — for a sample of sessions, and sessions where an error occurs, we record a privacy-filtered playback of how you interacted with the page to diagnose UI bugs. Replays mask text inputs and sensitive fields by default.
- Standard server logs — kept by our hosting provider (Vercel) per their standard retention; these include IP address and request path.
2.3 What we do NOT collect
- No third-party advertising trackers (no Google Ads, Meta Pixel, LinkedIn Insight Tag).
- No third-party analytics platforms (no Google Analytics, PostHog, Mixpanel, Segment, or similar).
- No precise geolocation. No biometric data.
- No data about your trademark applications or client work — only which USPTO examiner pages you have looked up.
3. How we use your information
We use your information to:
- Authenticate you and keep your account secure
- Deliver the analytics service you signed up for
- Send transactional emails (account verification, password reset, firm invitations, billing receipts)
- Diagnose bugs and improve the service
- Comply with legal obligations
We do not sell or share your information with data brokers, use it for targeted advertising on third-party platforms, or train machine-learning models against your behavior.
4. The USPTO data we publish
The examiner profiles, statistics, and citations on CrystalMark are derived entirely from public USPTO records: bulk trademark XML feeds, the TSDR (Trademark Status & Document Retrieval) API, and TTAB filings. USPTO examiners are federal employees, and their official actions in trademark prosecution are public record under U.S. law.
We do not publish information about you, your client, your firm, or your prosecution history. The data subjects on this site are USPTO examiners in their official capacity, not our users.
5. Service providers we share data with
We use a small number of vendors ("sub-processors") to operate CrystalMark, and share with each only the data it needs to perform its function. We do not share your data with any third party for marketing, advertising, or independent commercial use.
| Vendor | What they handle | Where |
|---|---|---|
| Neon | Primary database (account, sessions, firm membership) | US (AWS us-east-1) |
| Vercel | Web hosting, edge serving | Global edge; primary US |
| Upstash | Redis cache (sessions, "recently viewed") | US |
| Stripe | Subscription payment processing | US |
| Sentry | Error tracking and session replay | US (or per Sentry region) |
| Resend | Transactional email delivery | US |
| Doppler | Secret/configuration management (no user data) | US |
Payments. Subscription payments are processed by Stripe. Your payment card details are transmitted directly to Stripe; we never see or store full card numbers.
7. How long we keep your information
| Type | Retention |
|---|---|
| Account information (name, email, password hash) | Until you delete your account |
| Sessions (active sign-ins) | 30 days, or until you sign out |
| Recently-viewed examiner list | 30 days from last activity |
| Error reports / session replays (Sentry) | Per Sentry's standard retention |
| Server access logs (Vercel) | Per Vercel's standard retention |
| Database backups | Up to 30 days |
If you delete your account, we remove your personal information from our active systems within 30 days. Backups containing residual references are removed on their normal rotation (within 30 days of deletion).
8. Your rights
8.1 Everyone
Regardless of where you live, you may:
- Access the personal information we hold about you
- Correct inaccurate information
- Delete your account and associated personal information
- Export your account data in a portable format
- Object to processing or restrict it
To exercise any of these, email support@crystalmark.app.
8.2 California residents (CCPA / CPRA)
California residents have additional rights:
- Right to know what personal information we collect, use, and disclose.
- Right to delete personal information we have collected.
- Right to correct inaccurate personal information.
- Right to opt out of "sale" or "sharing." We do not sell or share your personal information as those terms are defined under the CCPA.
We do not process sensitive personal information for purposes other than providing the service you signed up for.
8.3 EEA, UK, and Switzerland (GDPR / UK GDPR)
Our service is aimed at U.S.-based trademark attorneys. If you are in the EEA, UK, or Switzerland and use CrystalMark, the lawful basis for our processing is performance of contract (delivering the service you signed up for) and our legitimate interests (security, fraud prevention, service improvement). You may exercise the rights granted by the GDPR by contacting support@crystalmark.app.
9. Security
We protect your account information with standard safeguards:
- Passwords are stored as one-way hashes (scrypt)
- All connections to our service use HTTPS
- Database access is restricted to authenticated application code
- Secrets and API keys are managed through a secrets manager (no plaintext credentials in code)
- We monitor for errors and unauthorized access
No system is perfectly secure. If we discover a security incident affecting your data, we will notify affected users in accordance with applicable law.
10. Children's privacy
CrystalMark is a B2B service for trademark attorneys. We do not knowingly collect personal information from anyone under 18. If you believe a minor has created an account, contact us at support@crystalmark.app and we will delete it.
11. International data transfers
Our primary infrastructure is hosted in the United States. If you access CrystalMark from outside the U.S., your data will be transferred to and processed in the United States.
12. Changes to this policy
We may update this policy from time to time. The "Last updated" date reflects the most recent revision. Material changes will be announced via email or in-app notice before they take effect.
13. Contact
For privacy questions, requests, or complaints: support@crystalmark.app.
Questions about this policy? support@crystalmark.app.