Privacy Policy
Effective 31 July 2026
We collect what you type into Provenly — your story, your challenge answers, your profile — and use it to build and score your proofs. AI (Anthropic's Claude) helps evaluate submissions; a human path always exists. We never sell your data, we delete candidate data on a schedule instead of hoarding it, and you can export or erase everything yourself.
1. Who we are
Provenly (“we”, “us”) operates this website and the skills verification service on it. We are the data controller for the personal data described here. Contact for anything in this policy, including data subject requests: privacy@provenly.dev.
2. What we collect, and why
- Profile data — name, handle, location, the work story you write, and any skill claims produced from it. Basis: performance of our contract with you.
- Challenge submissions and evaluations — the text you submit, time taken, rubric scores, strengths and gaps. Basis: contract. This is the product.
- Employer role specs — role titles, skill requirements, company name. Basis: contract.
- Technical data — IP address (used for abuse prevention and AI spend limits), logs. Basis: legitimate interest in keeping the service available and un-abused.
- Email — if you give us an address, transactional messages (results, account) are sent on the basis of contract. Marketing email is sent only with your separate, unbundled, opt-in consent, which you can withdraw in one click from any message.
We deliberately do not collect: CVs, dates of birth, photos, gender, degrees, or previous employer names. The product exists because those fields are proxies.
3. Automated evaluation — how the AI works
This section is the disclosure required by GDPR Article 13(2)(f) and equivalent US rules, written in plain words:
- When you submit a challenge, your submission text is scored against the published rubric for that challenge — the same rubric you saw before starting — by Anthropic’s Claude model, or by our deterministic offline engine. The engine used is always labelled on your result.
- The model scores each rubric criterion 0–4 and must justify every score with a note referencing your actual text. It is instructed not to score grammar, fluency, length, or formatting — reasoning only. Many of our users do not write in their first language, and the scoring rules say so.
- Significance and consequences: scores become proofs on your profile and feed employer Fit Scores. A score is never shown to an employer without its full per-criterion breakdown, and employers are contractually required to treat scores as one input, not the decision.
- Human review: you can contest any evaluation by emailing review@provenly.dev with your submission id. A human re-reads the submission against the same rubric. No candidate is rejected from an opening on our platform by a solely automated decision.
- Your submissions are not used to train Anthropic’s models (API data is excluded from training by default under Anthropic’s commercial terms), and we do not use your data to train models of our own.
More detail, including our bias posture and what we refuse to build, is on the AI transparency page.
4. Who processes data for us
Subprocessors, each under a data processing agreement:
- Vercel — hosting and edge network (Data Privacy Framework certified).
- Supabase — Postgres database hosting.
- Anthropic — AI evaluation of submissions and experience translation. Inputs are not retained for training.
We do not sell personal data, and we do not share it for cross-context behavioural advertising. If that ever changes, this policy changes first and you will be asked, not told. We honour the Global Privacy Control (GPC) signal.
5. How long we keep things
- Active accounts — for as long as the account exists.
- Candidate data tied to a specific opening — deleted or de-linked 6 months after the opening closes, unless you ask us to keep your profile in play.
- Deleted accounts — profile, proofs, and submissions are erased within 30 days; backups roll off within 90.
- Aggregate statistics (pass rates, score distributions) are retained indefinitely in anonymised form — they contain no personal data.
6. Your rights
Wherever you are, we give you the same set: access your data, export it in machine-readable form, correct it, delete it, object to or restrict processing, and withdraw consent without penalty. EU/EEA and UK users additionally have the right to complain to their supervisory authority; California users have the CCPA/CPRA rights including ADMT access and opt-out; Israeli users have their rights under the Privacy Protection Law as amended.
Requests: privacy@provenly.dev. We respond within 30 days, free of charge, and we do not discriminate against you for exercising rights.
7. Public by choice
Your proof profile at /p/your-handle is public only if you make it public, and you can flip it private at any time. Public profiles are indexable by search engines and readable by AI systems — that reach is the point of a proof, and the toggle is yours.
8. International transfers
Data may be processed in the United States by the subprocessors above, under the EU-US Data Privacy Framework or Standard Contractual Clauses as applicable.
9. Changes
Material changes are announced on this page with a new effective date, and — for anything that expands what we do with your data — by email before it takes effect.