In short
- Every Priorbit tool is read-only. Nothing an agent does through Priorbit changes a record anywhere.
- We log that a call happened, not what you searched for. Query text is not written to the call log; the full list of fields is below.
- Your work in progress (search terms, product description, results) is kept so your agent can resume it, isolated per account, and deleted after 30 days without use.
- We do not use your queries or results to train models, and Priorbit runs no language model of its own on your queries.
- Sign-in is on uselawless.com (Google, or a username and password). AI apps get OAuth tokens that you can revoke on /account.
- Hosted in the United States on Railway (server), Supabase (accounts and database) and Vercel (website).
What happens to a query
- Your AI app (Claude Code, Codex, Cowork, Cursor, …) sends a tool call to
https://patdb-mcp-production.up.railway.app/mcpover HTTPS. The app and its provider see your prompt and the results; that is governed by their terms, not ours. - The Priorbit server (Railway) checks who is calling, applies limits and credits, and runs the query against a Postgres database with a read-only role.
- For status and documents, the server asks the USPTO's public systems live, by patent or mark number.
- Two tools involve another provider: product-page fetching sends the product URL to Oxylabs; FTO ranking can send the product description and candidate claims to Typesafe (see hosting table).
- The result goes back to your app. The server writes one call-log row (below) and, if the call belongs to a task, appends to that task's record.
What we log per call
calls-YYYY-MM-DD.jsonl files on the server's volume, and to a Postgres table ops.call_log through a database role that can only insert.
| Field | What is stored |
|---|---|
| ts | Time of the call (UTC). |
| tenant | Account id as u:<user id> for signed-in accounts; the key name for personal API keys; anon for keyless calls. |
| user_key | The account email (signed-in), the key name, or anon:<IP hash>. Used to show you your own usage on /account. |
| session | First 10 characters of a SHA-1 hash of the MCP session id. |
| client | Name and version the AI app announces, e.g. claude-code/2.x, truncated to 60 characters. |
| tool | Which tool was called (search_patents, get_marks, …). |
| status | ok, error, timeout, invalid_query, … |
| returned | Number of results returned. |
| ms | Latency in milliseconds. |
| args | Not the query. Search text, product descriptions, brand names and owner names are never written. What is stored is the shape of the call: for search_patents / search_trademarks the number of query phrasings and their total character count, the filters (patent_type, CPC or design-class codes, Nice classes, in_force_only, k, how many like_patents or owner names were given); for fetch_product_page only the site domain (e.g. amazon.com), never the path or product id; for get_patents / get_marks / get_drawings the number of items requested and which parts; for get_playbook the playbook name (fto, prior_art, …) so usage can be grouped by kind of work; for every other tool only the parameter names. Filters and result counts are recorded; the search text itself is not. |
| error | The error type only (e.g. OperationalError (timeout)), never the message, because database messages can echo search terms. |
| country | Two-letter country code looked up offline (DB-IP Lite) from the connecting IP at the moment of the call. The IP itself is never written. |
| task | First 10 characters of a SHA-1 hash of the task id, to link the calls of one piece of work. |
| ip_hash | Keyless calls only: first 10 characters of a SHA-1 hash of the IP, to enforce the per-IP daily limit. Signed-in and keyed calls store no IP-derived value other than the country. |
The server has a debugging switch (PATDB_LOG_ARGS) that would record arguments in full, truncated to 200 characters. It is off by default and is not set in production (checked 2026-10-04); it is only turned on temporarily while diagnosing a fault. A key passed in the URL (?key=) is removed from the request before anything is logged.
Retention: call-log rows older than 180 days are removed by a maintenance script. The daily log files on the server volume do not yet have a fixed deletion schedule; we will publish one here once it is in place.
Work in progress (task records)
task_…) and your agent carries it through the rest of that piece of work. The task record holds the queries run, the product description or product page you gave, candidates found and which tools verified them. Values are truncated to 300 characters per field.
- Stored as files on the server's volume under a directory per account; another account cannot read your tasks even with the id.
- Deleted after 30 days without use (checked at start-up and once a day).
- Returned to you through
get_search_log, so you can see exactly what was run.
Hosting and providers
| Provider | What runs there / what it receives |
|---|---|
| Railway | MCP server (patdb-mcp), task records and daily log files on its attached volume. Single instance on Railway in the United States (requests enter through the sjc1 edge). |
| Supabase | Accounts and sign-in (Supabase Auth, OAuth 2.1 server for AI apps). The patent and trademark database and the call log are Postgres databases on Supabase; the server reads them with a read-only role (patdb_ro) and writes the log with an insert-only role (patdb_log). Both Supabase projects run in AWS us-west-1 (Northern California). |
| Vercel | The website uselawless.com, including the sign-in, consent and account pages. |
| Only if you choose "Sign in with Google": Google sends us your name and email. | |
| USPTO | Live status checks and document/drawing fetches go to the USPTO's public systems at query time. Those requests carry the patent or mark number, not your identity. |
| Oxylabs | When a tool fetches an e-commerce product page (fetch_product_page), the product URL is sent to Oxylabs, which retrieves the page. |
| Typesafe | For FTO-style ranking, the server can send the product description you gave plus the candidate patents' titles and claim text to Typesafe's ranking API (api.typesafe.ai). This is active in production. Typesafe receives the product text and patent text only, never your account or any identifier. |
| Stripe | Payments for Plus and Professional. Card, WeChat Pay and Alipay details are entered on Stripe's own pages; we store Stripe's customer and subscription identifiers and your plan, never payment details. |
Country lookups use an offline copy of DB-IP Lite inside the server; no IP leaves the server for geolocation.
Sign-in, tokens and keys
- Sign in at uselawless.com with Google, or with a username and password. Passwords are stored by Supabase Auth in hashed form; Lawless never sees them.
- AI apps connect through OAuth: the app sends you to uselawless.com, you approve it on a consent screen (scopes: confirm who you are, see your email, see your name), and the app receives a short-lived access token. Tokens are signed JWTs; the server verifies them against Supabase's published keys and accepts only tokens issued through OAuth to an app. A website session token cannot call tools.
- Revoke an app on /account → Disconnect. The app can no longer renew; access it already holds ends within an hour.
- Personal API keys (for firms and pre-account users) are 32 random bytes with a
lwp_prefix. The server stores only a SHA-256 hash and compares in constant time; the plaintext is shown once and kept nowhere. To revoke a key, email zhiyuanren@uselawless.com; it is removed from the server configuration. - Keyless use was switched off on 2026-10-03: every tool call now needs a signed-in account or a personal key. The landing page's brand lookup is the one exception (3 a day per network, logged only with a hashed IP).
- Rate limits, concurrency caps and daily or monthly credits apply per account, so one user cannot degrade the service for others.
Read-only by design
- All ten tools read. The database role the server uses has
SELECTonly; the log role hasINSERTonly on the log table. - The server never writes to the USPTO or to any third party on your behalf; the only things it writes are its own logs and task records.
- The operations dashboard and statistics endpoints require an administrator key; they show counts and hashed identifiers, never IPs.
- Secrets (database credentials, provider keys) live in the hosting provider's environment, not in the repository or the deployed image.
No training on your data
For law firms
- Confidentiality of searches. What you search for is not written to the call log. The task record that holds your search terms is readable only through your own account's token or key and is deleted 30 days after last use.
- No sharing between accounts. Task records are stored per account; the usage API returns only the data of the token's owner; keys and tokens are never shown in logs.
- Deletion on request. Email zhiyuanren@uselawless.com to have an account, its task records and its call-log rows deleted sooner than the default retention. We answer within 30 days, usually within a few business days.
- What we cannot promise. Your AI app's provider sees your prompts. Requests from Cowork and claude.ai reach us from Anthropic's cloud, so the logged country is Anthropic's data-centre location, not yours. A search that finds nothing is not proof that nothing exists.
- Paperwork. Firms that need a DPA, seat management or invoicing: write to zhiyuanren@uselawless.com.
Report a vulnerability
- We reply to every report and tell you what we did once it is fixed.
- Good-faith research that avoids reading other users' data, degrading the service or exceeding what is needed to show the issue will not be the subject of legal action by Lawless.
- There is no paid bounty programme at present.
Not yet in place
一句话
- Priorbit 的每个工具都是只读的。智能体通过 Priorbit 做的任何事都不会改动任何地方的记录。
- 我们记录发生了一次调用,不记录你检索了什么。检索内容不写入调用日志;完整字段见下。
- 你的进行中的工作(检索条件、产品描述、结果)会保存,以便智能体接着做;按账号隔离,30 天不用自动删除。
- 我们不用你的检索或结果训练模型;Priorbit 自己也不在你的查询上运行任何语言模型。
- 登录在 uselawless.com(Google,或用户名加密码)。AI 应用拿到的是 OAuth 令牌,可在账号页撤销。
- 托管在美国:Railway(服务器)、Supabase(账号与数据库)、Vercel(网站)。
一次查询经过哪里
- 你的 AI 应用(Claude Code、Codex、Cowork、Cursor…)通过 HTTPS 把工具调用发到
https://patdb-mcp-production.up.railway.app/mcp。该应用及其提供方能看到你的提示词和结果,受它们的条款约束,不受我们的。 - Priorbit 服务器(Railway)确认调用者身份,执行限额和积分,然后用只读角色查询 Postgres 数据库。
- 法律状态和文件按专利号或商标号实时向 USPTO 公开系统核对。
- 有两个工具会经过其他服务商:商品页抓取把商品网址发给 Oxylabs;FTO 排序可能把产品描述和候选专利的权利要求发给 Typesafe(见托管表)。
- 结果回到你的应用。服务器写一行调用日志(见下);若该调用属于某个任务,再追加到该任务的记录。
每次调用记什么
calls-YYYY-MM-DD.jsonl 文件、以及只允许插入的数据库角色写入的 Postgres 表 ops.call_log。
| 字段 | 存什么 |
|---|---|
| ts | 调用时间(UTC)。 |
| tenant | 登录账号记为 u:<用户 id>;个人钥匙记钥匙名;免钥匙调用记 anon。 |
| user_key | 账号邮箱(已登录)、钥匙名,或 anon:<IP 哈希>。用于在账号页给你看自己的用量。 |
| session | MCP 会话 id 的 SHA-1 哈希前 10 位。 |
| client | AI 应用自报的名称和版本,如 claude-code/2.x,截到 60 字符。 |
| tool | 调用了哪个工具(search_patents、get_marks…)。 |
| status | ok、error、timeout、invalid_query… |
| returned | 返回的结果条数。 |
| ms | 耗时(毫秒)。 |
| args | 不是检索内容。检索词、产品描述、品牌名、权利人名字一律不写入。存的是这次调用的形状:search_patents / search_trademarks 记查询说法的条数与总字数、过滤条件(patent_type、CPC 或外观类号、尼斯分类、in_force_only、k、给了几件 like_patents 或几个权利人名);fetch_product_page 只记网站域名(如 amazon.com),不记路径和商品号;get_patents / get_marks / get_drawings 记请求了几件和哪些部分;get_playbook 记手册名(fto、prior_art…),用于按工作类型汇总;其他工具只记参数名。过滤条件与结果条数会记录,检索原文不记。 |
| error | 只记错误类型(如 OperationalError (timeout)),不记错误消息,因为数据库消息可能带出检索词。 |
| country | 由连接 IP 当场离线查出(DB-IP Lite)的两位国家代码。IP 本身不写入。 |
| task | 任务 id 的 SHA-1 哈希前 10 位,用来串起同一件工作的调用。 |
| ip_hash | 仅免钥匙调用:IP 的 SHA-1 哈希前 10 位,用于按 IP 的每日限额。登录和带钥匙的调用除国家外不存任何 IP 衍生值。 |
服务器有一个排障开关(PATDB_LOG_ARGS),打开后会记录完整参数(截到 200 字符)。默认关闭,生产环境没有设置这个开关(2026-10-04 核对);只在排查故障时临时打开。 写在网址里的钥匙(?key=)在记录任何东西之前就被从请求中去掉。
保留期:超过 180 天的调用日志行由维护脚本清理。服务器卷上的按天日志文件暂时没有固定删除周期;定下来后会在这里公布。
进行中的工作(任务记录)
task_…),你的智能体在这件工作的后续调用中带着它。任务记录包含跑过的检索、你给的产品描述或商品页、找到的候选以及哪些工具核验过它们。每个字段截到 300 字符。
- 以文件形式存在服务器卷上,每个账号一个目录;别的账号即使拿到 id 也读不到你的任务。
- 30 天不用即删除(启动时和每天各检查一次)。
- 通过
get_search_log原样返回给你,你能看到到底跑了什么。
托管与服务商
| 服务商 | 跑什么 / 收到什么 |
|---|---|
| Railway | MCP 服务器(patdb-mcp)、任务记录和按天的日志文件(挂载卷)。单实例,部署在 Railway 美国区(请求经 sjc1 边缘节点进入)。 |
| Supabase | 账号与登录(Supabase Auth,兼作 AI 应用的 OAuth 2.1 授权服务器)。专利商标数据库和调用日志是 Supabase 上的 Postgres;服务用只读角色(patdb_ro)读、用只能插入的角色(patdb_log)写日志。两个 Supabase 项目都在 AWS us-west-1(北加州)。 |
| Vercel | 网站 uselawless.com,包括登录、授权确认和账号页。 |
| 仅当你选择"用 Google 登录":Google 向我们提供姓名和邮箱。 | |
| USPTO | 实时状态核验和文件/附图获取在查询时访问 USPTO 公开系统。这些请求带的是专利号或商标号,不带你的身份。 |
| Oxylabs | 当工具抓取电商商品页(fetch_product_page)时,商品网址会发给 Oxylabs 由其抓取页面。 |
| Typesafe | FTO 类排序时,服务可以把你给的产品描述和候选专利的标题、权利要求文本发给 Typesafe 的排序接口(api.typesafe.ai)。生产环境已启用这一步。Typesafe 只收到产品文字和专利文字,不收到你的账号或任何标识。 |
| Stripe | Plus 和 Professional 的收款。银行卡、微信、支付宝信息都在 Stripe 自己的页面填写;我们只保存 Stripe 的客户号、订阅号和你的方案,不保存付款信息。 |
国家查询用服务器内置的 DB-IP Lite 离线库;没有任何 IP 为了定位离开服务器。
登录、令牌与钥匙
- 登录在 uselawless.com,用 Google,或用户名加密码。密码由 Supabase Auth 以哈希形式保存,Lawless 看不到。
- AI 应用通过 OAuth 接入:应用把你带到 uselawless.com,你在授权确认页同意(范围:确认你是谁、查看邮箱、查看名称),应用获得一个短期访问令牌。令牌是签名的 JWT;服务器用 Supabase 公布的公钥验证,且只接受经 OAuth 发给应用的令牌。网站的登录会话令牌不能调用工具。
- 撤销:账号页 → 断开。该应用不能再续期,已持有的访问权限最长一小时内失效。
- 个人 API 钥匙(给机构和尚无账号的用户)是带
lwp_前缀的 32 字节随机值。服务器只保存 SHA-256 哈希并做恒定时间比较;明文只显示一次,任何地方都不保存。要吊销钥匙,写信到 zhiyuanren@uselawless.com,我们从服务器配置中删除它。 - 免钥匙使用已于 2026-10-03 关闭:每次工具调用都需要已登录账号或个人钥匙。唯一例外是落地页的品牌试查(每个网络每天 3 次,只记录 IP 哈希)。
- 频率限制、并发上限和每日/每月积分按账号执行,一个用户不会拖慢其他人。
天生只读
- 全部十个工具都是读。服务器用的数据库角色只有
SELECT;日志角色只对日志表有INSERT。 - 服务器从不代表你向 USPTO 或任何第三方写入任何东西;它写的只有自己的日志和任务记录。
- 运营看板和统计接口需要管理员钥匙;只显示计数和哈希后的标识,不显示 IP。
- 密钥(数据库凭据、服务商密钥)放在托管服务商的环境变量里,不在代码仓库或部署镜像中。
不用你的数据训练
给律师事务所
- 检索保密。你检索的内容不写入调用日志。保存检索条件的任务记录只能通过你自己账号的令牌或钥匙读取,最后一次使用 30 天后删除。
- 账号之间不共享。任务记录按账号存放;用量接口只返回令牌持有人自己的数据;钥匙和令牌不出现在任何日志里。
- 按请求删除。写信到 zhiyuanren@uselawless.com,可以提前删除账号、其任务记录和调用日志行。我们在 30 天内答复,通常几个工作日内完成。
- 我们不能承诺的。你的 AI 应用提供方能看到你的提示词。来自 Cowork 和 claude.ai 的请求经 Anthropic 云端到达我们,所以记录的国家是 Anthropic 机房所在地,不是你的位置。检索不到不等于不存在。
- 文件。需要 DPA、席位管理或开票的事务所:写信到 zhiyuanren@uselawless.com。
报告安全漏洞
- 每一份报告我们都会回复,修复后告知你处理结果。
- 善意研究(不读取其他用户数据、不影响服务、不超出证明问题所需的范围)不会受到 Lawless 的法律追究。
- 目前没有付费漏洞奖励计划。