Privacy Policy
Effective September 14, 20261. Who We Are
Provenience is a data and integration platform that helps businesses organize data from the tools they already use around their projects and customers, and expose it to AI tools.
2. Information We Collect
- Account details — email address, and optionally business name, phone number, and other profile information.
- Business data — customer information, projects, and other content you connect or provide.
- Conversation and tool-use data — text and other content sent to Provenience's AI tools, along with responses and actions taken.
- Billing records — payment information processed through our payment provider; card details are never stored on our servers.
- SMS opt-in data — phone number and consent timestamp, for accounts that enable text notifications.
- Server logs — IP addresses, browser information, and request timestamps, for security purposes.
SMS notifications. Messages are sent based on account activity and frequency may vary. Message and data rates may apply. Your mobile number and opt-in status are used only to deliver these notifications and are never shared with third parties for marketing or sold to any other party.
3. How Information Is Used
We use your data to operate and improve the Service, process requests through Claude, send SMS notifications you have consented to, deliver email, process billing, and provide support.
We do not sell your data, use it for advertising, or use it to train AI models.
4. Third-Party Services
We share data with the vendors that operate the Service on our behalf, including:
- Anthropic — processes conversation and tool-use data through the Claude API.
- Twilio — delivers SMS notifications.
- Our cloud database and payment providers, for storage and billing.
Each of these vendors is bound to use your data only to provide their service to us.
5. Data Retention
Business data is retained while your account is active, against a retention policy you configure for your account. Different categories of data can carry different retention periods, and a legal hold you place on a matter suspends deletion of the data it covers until you release it.
When a retention period ends with no hold in place, the underlying content is destroyed and replaced with a record that something existed there and was removed — we don't silently erase all trace of it, because that record is itself part of your audit history.
When we honor a deletion request, we delete what the request and applicable law require, subject to any active legal hold. A record shared with other parties — a group message or a call involving more than one person, for example — isn't unilaterally erased because one party asked; we narrow who can see it or document an exception instead, resolved by a person rather than an automated process. Deleting your account starts this same process for your data, rather than erasing everything instantly.
Backups are retained separately for up to seven days, so content removed from the primary store may still exist in a backup for that window. Our vendors (Section 4) have their own retention practices; where a vendor's retention differs from ours, we disclose that difference to you.
6. Security
Data is encrypted in transit and at rest. Access controls prevent one tenant's data from being visible to another.
7. Your Rights
You can request a copy of your data, correct it, delete your account, or opt out of SMS communications by emailing zane@bluedataworks.com.
8. Children
Provenience is intended for business use and is not directed at, and does not knowingly collect data from, anyone under 18.
9. Policy Updates
Changes to this policy are reflected in the "Effective" date above. Continued use of the Service after a change takes effect means you accept it.
10. Contact
Questions about this policy can be sent to zane@bluedataworks.com.