Provena is a platform for capturing, preserving, and verifying digital evidence. Handling data carefully is not a compliance afterthought for us — it is the product. This policy explains what we collect, why, and what control you keep.

What we process

Account information. When you create an account we process your name, email address, and organization details, used to operate your account and communicate with you.

Evidence you choose to preserve. When you run a capture session, the platform preserves what you direct it to: screenshots, video recordings, downloaded files, page snapshots, and technical logs of the session. This content is yours. We store it to provide the service — we do not mine it, sell it, or use it for advertising.

Custody and access records. The platform records custody events for preserved evidence — including who accessed a report or package, when, and from which IP address. These records are the product's chain of custody and are retained as part of the evidentiary record.

Contact form submissions. If you write to us, we process what you send — name, email, organization, message — to reply.

What we deliberately don't collect

Files checked publicly never leave your machine. When anyone uses the public check to verify a file, the file's cryptographic fingerprint is computed locally in their browser. Only the fingerprint and the filename are sent to Provena — never the file's content.

External proofs contain hashes, not evidence

When a sealed record is registered with external providers — public blockchain networks or time-stamp authorities — what is registered is a cryptographic fingerprint (hash), never the evidence itself. A hash does not reveal the content it was computed from. Be aware that these external registrations are, by design, public and permanent: that permanence is what makes them useful as proof, and it means they cannot be later withdrawn.

Sharing and revocation

Sharing a report or evidence with someone is controlled access, not publication — unless you explicitly enable a public link, which makes the report readable by anyone holding it. Both are grants you control: you can revoke a recipient's access or disable a public link at any time, which removes the ability to view the material. Revocation does not by itself delete the underlying preserved record, and the fact that access existed remains in the custody chain.

Retention and deletion

Preserved evidence is retained until you delete it or your agreement with us ends. Deletion is a controlled workflow: it removes stored evidence files while preserving the custody records of what occurred — including the deletion itself. This is deliberate: a chain of custody that could be silently truncated would not be a chain of custody.

Security

Capture sessions run in isolated environments created per session and destroyed afterwards. Files are integrity-checked with cryptographic hashes at every transfer. Access to evidence is controlled and itself recorded. We describe our security model honestly and in detail in our methodology — including its limits.

Service providers

We use infrastructure providers to host the platform, external proof providers (public networks and time-stamp authorities) to register hashes, and a form-processing service for our contact form. Providers receive only what their function requires.

Your rights

You can request access to, correction of, or deletion of your personal information by contacting us. Where data protection laws such as the GDPR or LGPD apply to you, you may have additional rights under those laws, and we will honor them.

Changes and contact

If this policy changes, we will update it here with a new date. Questions about privacy at Provena: contact us.