Privacy

updated 5 october 2026

What this website stores

When you make an account for early access, we store your name, your email address and your password. The password is kept only as a salted hash, never in plain text. If you sign in with GitHub or Google, we store the account id that provider gives us instead of a password.

While you are signed in we keep a session: when it was created, when it expires, and the IP address and browser it came from. We use these to keep you signed in and to slow down repeated sign-in attempts.

What we measure

We use PostHog to see how the site is used: which pages are opened, what is clicked, the browser and device, the rough location the IP address points to, and the errors the site runs into in your browser. PostHog keeps a random id in a cookie and in your browser’s storage to tell one visit from the next. Addresses, wherever they appear (error messages included), reach it without anything after the “?”, so reset links and sign-in codes never do, and the two-step key and backup codes on the Security page are never captured.

What we use it for

To run your account and to email you about early access: confirming your address, resetting your password and sending your invite. What we measure is used only to make the site better. We don’t sell any of it, and this site runs no advertising trackers.

Who handles it

The site is served by Vercel. Accounts are stored in a database on Railway. Emails are sent through Resend. Visits are measured by PostHog, in the United States.

The desktop app

Provenboard itself runs on your computer. Your projects are files in folders you own, and the agent talks to the model provider you choose with your own key.

Deleting your account

Email [email protected] from the address on your account and we’ll delete it and everything above.