Legal

Privacy Policy

last updated · July 26, 2026

This Privacy Policy describes how ProvenText ("ProvenText", "we", "us", or "our") collects, uses, and discloses information when you use the ProvenText control plane and related services (the "Service"). ProvenText is a human-in-the-loop content operations platform. Auto-generate and auto-post are off by default; every public action requires an authorized operator.

This page is maintained by ProvenText to answer common questions about the Service. It is a starting template and should not be relied on as legal advice. Please review with counsel before public launch.

1. Information we collect

Account information

When you sign up we collect your email address, display name, avatar (if provided by your identity provider), and authentication metadata such as email-verification timestamps.

Brand and workspace information

Operators associate themselves with one or more brands. For each brand we store the brand name, timezone, roles, invitations, and configuration you provide.

Connected-source data

With your explicit authorization, ProvenText connects to third-party services (YouTube, Meta / Facebook / Instagram, X, TikTok, Google Analytics 4, Google AdSense, WordPress, Postmark inbound email, and others). For those connections we store:

  • OAuth access and refresh tokens, encrypted at rest.
  • Account identifiers, handles, and granted scopes.
  • Content and metrics you asked us to ingest (videos, transcripts, comments, posts, analytics, emails, uploaded documents).

Usage and diagnostics

We record limited diagnostic information (request timestamps, error logs, feature usage) to operate, secure, and improve the Service.

2. How we use information

  • To provide the Service, including brand voice ingestion, content generation, analytics, and human-approved publishing.
  • To authenticate operators and enforce role-based access.
  • To send transactional messages (verification, invitations, security notices).
  • To detect abuse and secure the Service.
  • To improve the Service, always subject to your instructions and applicable law.

3. Sharing and disclosure

We do not sell personal information. We share information only:

  • With subprocessors that operate the Service under contract (cloud hosting, database, AI inference, transactional email, and analytics providers).
  • With third-party platforms you have explicitly connected, only as needed to fulfil your requested action (for example, publishing an approved post).
  • When required by law, subpoena, or lawful government request.
  • In connection with a merger, acquisition, or sale of assets, with notice to affected users.

4. Facebook / Meta Platform data

When you connect a Meta account, ProvenText requests only the permissions needed to operate the features you enable (for example, pages_show_list, pages_read_engagement,pages_manage_posts, instagram_basic, and instagram_content_publish). Platform data received from Meta is used only to provide the Service to you, is not sold or transferred to data brokers, and is stored subject to the retention rules in this policy. To request deletion of your Meta-derived data, see our User Data Deletion page.

5. Data retention

We retain account and brand data for as long as your account is active. Connected-source content is retained until you disconnect the source or request deletion. Encrypted OAuth tokens are deleted when a connection is removed. Backups are rotated on a rolling window.

6. Security

We use industry-standard controls including TLS in transit, encryption at rest, role-based access control, row-level security in our database, and encryption of sensitive credentials (OAuth tokens, WordPress application passwords) using a per-workspace key. No system is perfectly secure; we encourage strong passwords and email verification.

7. Your choices

  • You may disconnect any third-party integration from Brand → Integrations at any time.
  • You may request access, correction, or deletion of your data by contacting us (see below).
  • Depending on your jurisdiction you may have additional rights under GDPR, UK GDPR, CCPA/CPRA, or similar laws.

8. Children

The Service is not directed to children under 13, and we do not knowingly collect information from them. If you believe we have, please contact us and we will delete the data.

9. International transfers

ProvenText is operated from the United States. If you access the Service from outside the United States, you consent to the transfer of your information to the United States and other jurisdictions where our subprocessors operate.

10. Changes

We may update this Privacy Policy from time to time. Material changes will be announced in the control plane and reflected in the "last updated" date above.

11. Contact

Questions or requests about this policy can be sent to privacy@proventext.com.