Scope and responsibilities
This policy applies to provon.dev and services operated by Provon, including hosted Workbench, API, Gateway, OpenTelemetry ingest, and related support and billing services (the "Hosted Services"). It does not govern a Provon deployment operated by you or another third party. The operator of a self-hosted deployment decides what that deployment collects, where it stores data, which integrations it enables, and how long it retains data.
Provon is the controller for account, website, billing, security, and support information that we use for our own purposes. For telemetry and other content submitted to the Hosted Services by an organization, Provon generally acts as a processor or service provider on that organization's instructions. The organization is responsible for the data it submits and for notices, permissions, and lawful collection from its users.
Information we collect
Account and workspace information
We collect information used to create and administer accounts, organizations, projects, memberships, and access controls. This can include your name, email address, profile image, authentication provider, email-verification status, role, workspace settings, invitations, and project API-key metadata. We store authentication sessions and security records needed to keep accounts signed in and protected.
Customer Content
The content an organization submits or generates can include OpenTelemetry traces, spans, logs, metrics, prompts, model outputs, tool calls and results, conversation and user identifiers, retrieval context, attachments, usage and cost data, diagnostic Rules and Runs, Findings, workflow definitions and artifacts, evaluation results, comments, and review decisions. What we receive depends on how the organization instruments and configures Provon.
Gateway, provider, and integration information
If an organization uses AI Gateway or integrations, we process routing and policy settings, model-provider requests and responses, provider-key metadata, encrypted provider credentials, connector configuration, OAuth tokens, repository or destination identifiers, and records of actions performed through enabled connectors. Project API-key secrets are stored as hashes; provider and connector credentials are stored in encrypted form.
Billing, communications, and support
For paid Hosted Services, we process plan, subscription, usage, invoice, checkout, and customer identifiers. Payment processors handle payment-card details under their own privacy terms; Provon does not need to store full card numbers. We also collect messages and contact details when you request support, report a security issue, or otherwise communicate with us.
Website and service operation data
When you use the website or Hosted Services, servers may record IP address, request URL, timestamp, response status, browser or user-agent information, referring page, and security or diagnostic events. The Hosted Services use cookies or similar storage that are necessary for authentication, security, theme, and interface preferences. We will describe any optional analytics or advertising technology before using it where consent is required.
How we use information
We use information to:
- Provide the Hosted Services, authenticate users, and administer organizations, projects, memberships, roles, sessions, and API keys.
- Receive, normalize, store, query, and display telemetry and other Customer Content.
- Route configured model requests, apply Gateway policies and guardrails, run diagnostics and workflows, publish Findings, and perform actions through integrations selected by an organization.
- Meter usage, enforce plan limits, process subscriptions, and maintain billing records.
- Secure the Hosted Services, prevent abuse, troubleshoot incidents, and maintain reliability.
- Respond to support requests and send verification, security, service, and billing communications.
- Understand and improve performance and usability using aggregate or deidentified service data.
- Comply with law, enforce agreements, and protect the rights and safety of Provon, customers, and others.
AI providers and integrations
Provon does not send Customer Content to a model provider merely because it is stored as telemetry. Content is sent outside Provon when an organization configures a feature that requires an external model or connector, such as Gateway routing, model-assisted diagnosis, or a repair handoff. The receiving provider processes that content under the organization's account or the applicable provider terms.
Organizations should choose providers, credentials, scopes, capture settings, and retention settings appropriate for their data. A private or self-hosted Provon deployment does not make an external model provider or connector private.
Retention and deletion
We retain account and Customer Content while needed to provide the Hosted Services and for legitimate security, billing, dispute-resolution, and legal purposes. Telemetry retention varies by deployment, plan, organization policy, and, where supported, project settings. Raw payload retention can differ from normalized telemetry retention.
Authorized users can delete supported records or integrations and export data through available product or API features. For other account or organization deletion requests, contact us. Deletion from active systems may not immediately remove information from encrypted backups, security logs, external providers, or connectors; those copies follow their own retention cycles and legal requirements.
Security
We use technical and organizational safeguards designed to protect information, including access controls, scoped credentials, encryption in transit, encrypted storage for provider and connector secrets, monitoring, and secure development practices. No service can guarantee absolute security. Customers remain responsible for limiting the data they send, redacting unnecessary secrets and personal information, granting least-privilege access, and rotating credentials when needed.
Legal bases
Where applicable law requires a legal basis, we process information as needed to perform a contract, based on legitimate interests such as securing and improving the Hosted Services, with consent where requested, and to comply with legal obligations. You may withdraw consent for future processing where consent is the basis, without affecting earlier processing.
Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a copy of your personal information, and to appeal a decision or complain to a supervisory authority. We may request information needed to verify your identity and authority before acting on a request.
If your information is part of Customer Content controlled by a Provon customer, submit the request to that customer first. We will assist the customer as required because it determines how that data is collected and used.
International processing
Provon and its service providers may process information in the United States and other countries. Where required, we use safeguards intended to protect personal information transferred across borders, such as contractual protections.
Children's privacy
The Hosted Services are business services and are not directed to children. We do not knowingly collect personal information directly from anyone under 18. If you believe a child has provided personal information to Provon, contact us so we can review and delete it where appropriate.
Changes to this policy
We may update this policy as the Hosted Services or legal requirements change. We will post the revised policy and update the date above. If a change materially affects how we use personal information, we will provide additional notice where required.
Contact us
For privacy questions or requests, contact Provon, Inc. at [email protected]. If your request concerns Customer Content, include the organization or project that controls the data when possible.