Privacy Policy
Last updated: May 17, 2026
1. What we collect
Account information: your name, email, and password hash through Supabase Auth. Usage data: the voice profiles you create, the settings on your account, and basic request logs for operating the service. Billing data: a Stripe customer ID and subscription state. We do not store your payment card; Stripe does.
2. What we don't collect
We do not run third-party advertising trackers. We do not sell or rent your data. We do not use your generated voice profiles to train AI models that other customers use.
3. How we use it
To provide the Service: authenticate you, run the seven-phase synthesis pipeline against the targets you supply, store the output, and bill you correctly. To communicate with you: account emails, completion notifications, occasional product updates.
4. Third parties that process your data
- Supabase for authentication and database storage.
- Stripe for billing and payment processing.
- Anthropic for the language-model analysis steps in the pipeline. Targets and source text are sent through Anthropic to produce the voice profile.
- Public data retrieval for gathering publicly available writing (LinkedIn, Twitter, Reddit, etc.) during Phase 0.
- Resend for transactional email.
- Vercel for hosting and request routing.
5. Public source data and target voice profiles
When you create a target voice profile, ProvenOutreach retrieves publicly available writing under that person's name (LinkedIn posts, public articles, etc.) and analyzes it. We only retrieve content the source platform exposes publicly. We do not bypass authentication, scrape private content, or store the original source text after a profile is built. During synthesis, the parsed source text is sent to Anthropic for analysis. Targets can request removal of a profile by contacting nico@provenlabs.ai.
6. Retention
Account data is kept while your account exists. Voice profiles you delete are kept in a recoverable state for 30 days, then permanently removed. If you close your account we delete account data within a reasonable period unless we are required to retain it for legal, accounting, or fraud-prevention purposes.
7. Your rights
You can access, correct, or delete your account data at any time by contacting nico@provenlabs.ai. EU/UK residents have rights under GDPR/UK-GDPR including the right to lodge a complaint with a supervisory authority. California residents have rights under CCPA; we do not sell personal information.
8. Security
We use TLS for traffic, Postgres row-level security to scope reads and writes to the account that owns them, and rotate credentials when needed. No system is perfectly secure; we will notify affected users in the event of a breach as required by law.
9. Children
The Service is not for users under 18. We do not knowingly collect data from minors.
10. Changes and contact
We may update this policy. Material changes will be announced at the email on your account at least 14 days before they take effect. Questions: nico@provenlabs.ai.