Privacy Policy
What we hold, and why.
Effective September 27, 2026. Provenance has no advertising, no third-party analytics, and no tracking pixels. Nothing in the product follows you anywhere else, and the steps we record on the way in are listed in section 2.
1. Who holds your data
James Proctor and Jae Gnazzo, a New York general partnership doing business as Provenance (provenance.space), is the controller of the personal data described here. Contact: support@provenance.space.
2. What we collect
Account
Your email address and a password, held by our authentication provider. Passwords are stored hashed; we never see them. We also record whether your email has been verified and the state of your account.
Profile
What you choose to put in it: name, headline, bio, skills, what you are looking for and pursuing, discipline, what you bring, location, occupation, industry, years of experience, interests and tags, avatar, and GitHub or LinkedIn links. Almost all of this is optional. Someone without an account who opens your page sees only your name and headline; the rest is visible to signed-in members, and you control the remainder through the visibility settings on your profile. Your name also appears on any confirmed Record that names you, wherever that Record is shown.
What you do here
Asks you post, contributions you write, messages you send, discussions and comments, attachments you upload, communities you join, and the Records that result. Messages between two people are private to those two people and to anyone with database-level administrative access. A confirmed Record is public: it names you, it has an address anyone can open without an account, and we may show it on our own public pages, including the front page (Terms, section 4). Ask us to take it off the front page and we will.
Notes we write about you
When we review an account for access we may attach an internal note to it. You cannot see these in the product, but they are your personal data and a request under section 7 reaches them.
Technical
When something breaks we record the error, the page it happened on, and your user ID so we can find it. Our hosting and database providers keep standard server logs including IP addresses. We also record the steps people take to get started: which page they arrived on and the name of the site that linked here, which way in they pick, whether they started a post or an answer, the account form, and whether it went out. A random identifier stored on your device ties those steps together, and it links to your account only once you create one. None of it includes what you write, and none of it follows you anywhere else. We don’t build profiles of what you read or click: this list is all of it. We don’t use third-party analytics or advertising tools.
3. Why we hold it
- To run the service you asked for. Your account, your profile, your work, and the Records that come out of it. This is necessary to perform our agreement with you.
- To tell you things you need to know. That your account was approved, that someone answered your ask, that a Record is waiting on you.
- To keep it safe and working. Preventing abuse and fraudulent Records, fixing errors, enforcing the Terms. These are our legitimate interests, and other members’ interest in Records being trustworthy.
- To meet legal obligations, where one applies.
We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not train machine-learning models on your content.
4. Who else processes it
A small number of providers process data on our behalf, under contract, only on our instructions. As of the effective date they are:
- Supabase: database, authentication, and file storage. Almost everything above lives here.
- Vercel: application hosting and delivery.
- Anthropic: assisted drafting. Only the text you provide when you use a drafting feature is sent, and only at that moment.
- Sentry: error monitoring, including your user ID with each report.
- Resend: delivering email such as verification, password reset, and notifications.
- Cloudflare: the automated check that tells people apart from bots on the sign-up, sign-in, and password-reset forms. It receives your IP address and signals about your browser when one of those pages loads.
We will also disclose data where the law requires it, and to a successor if the service is ever transferred, in which case we will tell you first.
5. Information about other people
Provenance is a record of work done between people, so what you write here often describes someone else. When you name a collaborator, confirm a contribution, or write an account of shared work, you are providing their personal data as well as your own. Write about people the way you would want written about, and only say things you would stand behind.
6. Keeping and deleting
We keep your data while your account exists. You can close your account at any time by writing to support@provenance.space. For now a person does this rather than a button, and we will confirm when it is done.
When you do, we delete your profile, your drafts, your private messages, your uploads, and any work that was never confirmed. Backups are overwritten on their normal cycle.
Confirmed Records are not deleted, but your name stops showing on them. The entry remains as the other person’s account of the work, with your identity removed, and it stops linking to a profile that no longer exists.
A Record is jointly held. It is another person’s account of work you did together and frequently the only evidence they have that it happened, so erasing it would delete their data and destroy their record of their own work. We rely on that interest, and on the integrity of the record as a whole, as the basis for keeping it. We would rather say this plainly here than promise you an erasure we are not going to perform.
If a particular Record is wrong, was obtained improperly, or should not stand, tell us and we will look at it. That process is in Terms, section 7.
7. Your rights
Wherever you are, you can ask us for a copy of what we hold about you, ask us to correct it, ask us to delete it, ask for it in a portable form, or object to a particular use. Depending on where you live you may also have the right to restrict processing, to withdraw consent, and to complain to your data protection authority.
Write to support@provenance.space. We will respond within 30 days. The one limit is section 6: we will explain what we cannot delete and why, rather than quietly not doing it.
8. Cookies and local storage
We store a session in your browser so you stay signed in, and a small amount of local state so the product works. That is all. There are no advertising cookies, no analytics cookies, and no third-party trackers, which is why you are not being asked to accept anything.
9. Where your data lives
Our providers are US-based and your data is processed in the United States. If you are in the UK, EEA, or Switzerland, transfers rely on the standard contractual clauses in our agreements with those providers.
10. Children
Provenance is not for anyone under 18. We do not knowingly collect data from children. If you believe a child has an account here, tell us and we will remove it.
11. Security, honestly stated
Access is restricted, traffic is encrypted, passwords are hashed, and database rules govern who can read what. Provenance is also an early product built by a small team and has not been through an independent security audit. Do not put anything here that would seriously harm you if it were exposed.
12. Changes
We will post changes here with a new effective date, and we will tell you before a material change to how we use your data takes effect.