Prosecution Insights
Last updated: October 02, 2026
Application No. 18/936,459

END-TO-END PRIVACY ECOSYSTEM

Non-Final OA §112
Filed
Nov 04, 2024
Priority
Aug 31, 2021 — provisional 63/239,215 +2 more
Examiner
ZOUBAIR, NOURA
Art Unit
2434
Tech Center
2400 — Computer Networks
Assignee
Allstate Insurance Company
OA Round
2 (Non-Final)
73%
Grant Probability
Favorable
2-3
OA Rounds
9m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 73% — above average
73%
Career Allowance Rate
267 granted / 367 resolved
+14.8% vs TC avg
Strong +62% interview lift
Without
With
+62.3%
Interview Lift
resolved cases with interview
Typical timeline
2y 8m
Avg Prosecution
17 currently pending
Career history
383
Total Applications
across all art units

Statute-Specific Performance

§101
8.1%
-31.9% vs TC avg
§103
55.0%
+15.0% vs TC avg
§102
7.2%
-32.8% vs TC avg
§112
17.9%
-22.1% vs TC avg
Black line = Tech Center average estimate • Based on career data from 367 resolved cases

Office Action

§112
DETAILED ACTION A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after allowance or after an Office action under Ex Parte Quayle, 25 USPQ 74, 453 O.G. 213 (Comm'r Pat. 1935). Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, prosecution in this application has been reopened pursuant to 37 CFR 1.114. Applicant's submission filed on 8/28/2026 has been entered. Claims 1-3, 5-10, 12-17 and 19-20 are pending. Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Allowable subject matter Claims 1-3, 5-10, 12-17 and 19-20 would be allowable if the 112(b) rejections below are overcome. The IDS filed on 8/28/2026 had been considered and the references therein, alone or in combination with the existing prior art, do not teach or suggest the features of the independent claims. Therefore, the reasons for allowance are the same as in notice of allowance mailed on 7/22/2026. Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. Claims 1-3, 5-10, 12-17 and 19-20 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. Based on the previously entered allowed claims, additional 112(b) issues were identified as follows: -Claims 1, 8 and 15 recite “content associated with the first user” and further recite “one or more access permission levels to content that are less restrictive” and it is not clear whether the two limitations are referring to the same content or to different contents. The dependent claims inherit this rejection. Amending as suggested in the proposed amendment below would resolve this issue. -Claims 3, 5, 10 and 12 recite “wherein the instruction code that causes the computing system to perform operations comprising” which lack antecedent basis. Amending as suggested in the proposed amendment below would resolve this issue. -Claims 6, 13 and 20 recite “for which a user has defined specific predefined access permission levels” and subsequently recite “suggest predefined access permission levels based on demographic analysis”. It is not clear if the two recitations of predefined access permission levels refer to the same or different permission levels. Amending as suggested in the proposed amendment below would resolve this issue. -Claims 7 and 14 recite “benefits associated with the predefined access permission levels” and subsequently recite “if associated benefits remain unused”. It is not clear if the two recitations of associated benefits refer to the same or different benefits. Amending as suggested in the proposed amendment below would resolve this issue. Proposed Amendments: 1. (Currently Amended) A computing system comprising: a first privacy vault associated with a first user that stores: content associated with the first user; data that specifies one or more predefined access permission levels associated respectively with one or more third-parties, wherein the one or more predefined access permission levels specify respective levels of access that respective third parties have to the content; and data that specifies default access permission levels to be applied to new third-parties; and one or more processors; and one or more instruction storage devices that comprise instruction code, which when executed by the one or more processors, causes the computing system to perform operations comprising: receiving identification of a new third-party; after receiving an indication that the new third-party has a prior agreement with the first user and that specifies one or more access permission levels to the content that are less restrictive than corresponding access permission levels granted by the default access permissions levels, associating with the new third-party, and in the first privacy vault, predefined access permissions that specify the one or more less restrictive access permission levels, rather than the default access permissions levels; after receiving an indication that a second privacy vault, associated with a second user that uses similar services from the new third-party as the first user, stores data that specifies predefined access permission levels associated with the new third-party that are more restrictive than the one or more less restrictive access permission levels, automatically changing the predefined access permission levels stored in the second privacy vault to match the one or more less restrictive access permission levels; determining that at least one type of content covered by the prior agreement is predefined as sensitive data; communicating to a first user device associated with the first user, an alert notification that indicates that sharing of the at least one type of content could result in sharing of sensitive data; and delaying the association of the one or more less restrictive access permission levels until receipt of a response indication from the first user device that indicates consent to share the at least one type of content. 2. (Previously Presented) The computing system of claim 1, wherein the instruction code that causes the computing system to receiving identification of a new third-party comprises instruction code that causes the computing system to perform operations comprising: receiving, with the identification of the new third-party, the prior agreement between the first user and the new third-party. 3. (Currently Amended) The computing system of claim 1, wherein the instruction code [[that]] causes the computing system to perform operations comprising: communicating to the first user device associated with the first user, an alert notification that indicates that the new third-party has accessed content in violation of a policy; and after receiving a response indication from the first user device, associate with the new third-party, and in the first privacy vault, predefined access permissions that specify the default access permission levels rather than the one or more less restrictive access permission levels. 4. (Canceled) 5. (Currently Amended) The computing system of claim 1, wherein the instruction code [[that]] causes the computing system to perform operations comprising: receiving a request indication from the first user device associated with the first user that indicates a request to delete at least a portion of the content accessible by the new third-party via the first privacy vault; determining that at least one term of service for the new third-party indicates a loss of one or more services of the new third-party responsive to the requested deletion; and communicating an indication to the first user device informing the first user of a potential loss of the one or more services. 6. (Currently Amended) The computing system of claim 1, wherein the instruction code causes the computing system to perform operations comprising: determining that the new third-party fits within a demographic group for which the first user has defined specific predefined access permission levels; evaluating existing relationships between the new third-party and other users of similar demographics; and suggesting the specific 7. (Currently Amended) The computing system of claim 1, wherein the instruction code causes the computing system to perform operations comprising: monitoring a frequency of interaction between the first user and the new third-party; determining whether benefits associated with the predefined access permission levels are being utilized; and automaticallysuggesting reverting to the default access permission levels if the associated benefits remain unused for a specified timespan. 8. (Currently Amended) A non-transitory computer-readable medium having stored thereon instruction code, which when executed by one or processors of a computing system cause the computing system to perform operations comprising: implementing a first privacy vault associated with a first user that stores: content associated with the first user; data that specifies one or more predefined access permission levels associated respectively with one or more third-parties, wherein the one or more predefined access permission levels specify respective levels of access that respective third parties have to the content; and data that specifies default access permission levels to be applied to new third-parties; receiving identification of a new third-party; after receiving an indication that the new third-party has a prior agreement with the first user and that specifies one or more access permission levels to the content that are less restrictive than corresponding access permission levels granted by the default access permissions levels, associating with the new third-party, and in the first privacy vault, predefined access permissions that specify the one or more less restrictive access permission levels, rather than the default access permissions levels; after receiving an indication that a second privacy vault, associated with a second user that uses similar services from the new third-party as the first user, stores data that specifies predefined access permission levels associated with the new third-party that are more restrictive than the one or more less restrictive access permission levels, automatically changing the predefined access permission levels stored in the second privacy vault to match the one or more less restrictive access permission levels; determining that at least one type of content covered by the prior agreement is predefined as sensitive data; communicating to a first user device associated with the first user, an alert notification that indicates that sharing of the at least one type of content could result in sharing of sensitive data; and delaying the association of the one or more less restrictive access permission levels until receipt of a response indication from the first user device that indicates consent to share the at least one type of content. 9. (Previously Presented) The non-transitory computer-readable medium of claim 8, wherein the instruction code that causes the computing system to receiving identification of a new third-party comprises instruction code that causes the computing system to perform operations comprising: receiving, with the identification of the new third-party, the prior agreement between the first user and the new third-party. 10. (Currently Amended) The non-transitory computer-readable medium of claim 8, wherein the instruction code[[that]] causes the computing system to perform operations comprising: communicating to the first user device associated with the first user, an alert notification that indicates that the new third-party has accessed content in violation of a policy; and after receiving a response indication from the first user device, associating with the new third-party, and in the first privacy vault, predefined access permissions that specify the default access permission levels rather than the one or more less restrictive access permission levels. 11. (Canceled) 12. (Currently Amended) The non-transitory computer-readable medium of claim 8, wherein the instruction code[[that]] causes the computing system to perform operations comprising: receiving a request indication from the first user device associated with the first user that indicates a request to delete at least a portion of the content accessible by the new third-party via the first privacy vault; determining that at least one term of service for the new third-party indicates a loss of one or more services of the new third-party responsive to the requested deletion; and communicating an indication to the first user device informing the first user of a potential loss of the one or more services. 13. (Currently Amended) The non-transitory computer-readable medium of claim 8, wherein the instruction code causes the computing system to perform operations comprising: determining that the new third-party fits within a demographic group for which the first user has defined specific predefined access permission levels; evaluating existing relationships between the new third-party and other users of similar demographics; and suggesting the specific predefined access permission levels based on a demographic analysis. 14. (Currently Amended) The non-transitory computer-readable medium of claim 8, wherein the instruction code causes the computing system to perform operations comprising: monitoring a frequency of interaction between the first user and the new third-party; determining whether benefits associated with the predefined access permission levels are being utilized; and automatically suggesting reverting to the default access permission levels if the associated benefits remain unused for a specified timespan. 15. (Currently Amended) A computer-implemented method comprising: implementing a first privacy vault associated with a first user that stores: content associated with the first user; data that specifies one or more predefined access permission levels associated respectively with one or more third-parties, wherein the one or more predefined access permission levels specify respective levels of access that respective third parties have to the content; and data that specifies default access permission levels to be applied to new third-parties; receiving identification of a new third-party; after receiving an indication that the new third-party has a prior agreement with the first user and that specifies one or more access permission levels to the content that are less restrictive than corresponding access permission levels granted by the default access permissions levels, associating with the new third-party, and in the first privacy vault, predefined access permissions that specify the one or more less restrictive access permission levels, rather than the default access permissions levels; after receiving an indication that a second privacy vault, associated with a second user that uses similar services from the new third-party as the first user, stores data that specifies predefined access permission levels associated with the new third-party that are more restrictive than the one or more less restrictive access permission levels, automatically changing the predefined access permission levels stored in the second privacy vault to match the one or more less restrictive access permission levels; determining that at least one type of content covered by the prior agreement is predefined as sensitive data; communicating to a first user device associated with the first user, an alert notification that indicates that sharing of the at least one type of content could result in sharing of sensitive data; and delaying the association of the one or more less restrictive access permission levels until receipt of a response indication from the first user device that indicates consent to share the at least one type of content. 16. (Previously Presented) The computer-implemented method of claim 15, wherein receiving identification of a new third-party further comprises: receiving, with the identification of the new third-party, the prior agreement between the first user and the new third-party. 17. (Currently Amended) The computer-implemented method of claim 15, further comprising: communicating to the first user device associated with the first user, an alert notification that indicates that the new third-party has accessed content in violation of a policy; and after receiving a response indication from the first user device, associating with the new third-party, and in the first privacy vault, predefined access permissions that specify the default access permission levels rather than the one or more less restrictive access permission levels. 18. (Canceled) 19. (Previously Presented) The computer-implemented method of claim 15, further comprising: receiving a request indication from the first user device associated with the first user that indicates a request to delete at least a portion of the content accessible by the new third-party via the first privacy vault; determining that at least one term of service for the new third-party indicates a loss of one or more services of the new third-party responsive to the requested deletion; and communicating an indication to the first user device informing the first user of a potential loss of the one or more services. 20. (Currently Amended) The computer-implemented method of claim 15, further comprising: determining that the new third-party fits within a demographic group for which the first user has defined specific predefined access permission levels; evaluating existing relationships between the new third-party and other users of similar demographics; and suggesting the specific predefined access permission levels based on a demographic analysis. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to NOURA ZOUBAIR whose telephone number is (571)270-7285. The examiner can normally be reached Monday - Friday. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, ALI SHAYANFAR can be reached at 571-270-1050. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /NOURA ZOUBAIR/Primary Examiner, Art Unit 2434
Read full office action

Prosecution Timeline

Nov 04, 2024
Application Filed
Mar 27, 2025
Response after Non-Final Action
Mar 27, 2026
Non-Final Rejection mailed — §112
Jun 29, 2026
Response Filed
Jul 14, 2026
Examiner Interview (Telephonic)
Aug 28, 2026
Request for Continued Examination
Sep 01, 2026
Response after Non-Final Action
Sep 09, 2026
Non-Final Rejection mailed — §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12749126
USER INTERFACE LOG VALIDATION VIA BLOCKCHAIN SYSTEM AND METHODS
2y 0m to grant Granted Sep 29, 2026
Patent 12726333
HARDWARE-BASED KEY GENERATION AND STORAGE FOR CRYPTOGRAPHIC FUNCTION
4y 1m to grant Granted Sep 01, 2026
Patent 12682022
SYSTEM, METHOD, AND COMPUTER PROGRAM PRODUCT FOR WORKSPACE CREATION IN EMBEDDED APPLICATIONS
3y 6m to grant Granted Jul 14, 2026
Patent 12682389
SECURE EMAIL AUTHENTICATION SYSTEM FOR COMPLETING E-COMMERCE TRANSACTIONS
1y 7m to grant Granted Jul 14, 2026
Patent 12665934
CYBERSECURITY AI-DRIVEN WORKFLOW GENERATION USING POLICIES
2y 0m to grant Granted Jun 23, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

2-3
Expected OA Rounds
73%
Grant Probability
99%
With Interview (+62.3%)
2y 8m (~9m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 367 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month