LEGAL AND TRUST
Privacy policy
Version 1 · updated 2026-10-06
Written in plain language and updated as the service grows. Questions: [email protected]
Provetale turns the data you upload into a written report whose every number you can check. This page says what that involves for your data, in plain words.
1. What we keep
- Your account: your name and email address, how you signed in (a password stored only as a salted hash, or Google or GitHub), your industry if you chose one, the language you picked, and the version of these texts you accepted.
- Your files: the spreadsheets you upload, a prepared copy of each, and the PDF, Word or PowerPoint files you export. They sit in private storage under your workspace; nobody else can open them.
- What we compute from them: dataset metadata (column names and meanings, row counts), the analysis's results and evidence (figures, groups, how each was calculated), and the written reports.
- Your feedback: a rating and an optional comment on a report. A comment is private unless you separately say we may quote it.
- Usage and billing facts: counts (how many reports, how large an upload), your plan, and billing status. We never see card numbers.
- Product analytics, first-party only: a short list of steps your workspace has reached (for example “uploaded a dataset”), with when, how often, your plan and your language. It holds no file name, no column, no figure, no report text, no email and no IP address, and it is not shared with anyone.
- Security logs: an audit trail of important actions (an upload, an export, a setting changed), kept with identifiers and never with the content of your data. They are kept for about 13 months and cannot be edited afterwards; if you delete your account they stay, without your name attached.
2. What we do not do
- We do not sell your data and we do not use it for advertising.
- We do not use third-party advertising or analytics scripts, and we set no tracking, analytics, marketing or preference cookies. The only cookies are the ones that sign you in and protect signing in (see Cookies and browser storage below). Our typefaces are served by Provetale itself, so a visit does not tell Google or anyone else that you were here.
- We do not train AI models on your data, and we do not send your uploaded file, or its rows, to the AI service.
Cookies and browser storage
Provetale stores only what it needs to sign you in and keep that safe, so there is no cookie banner to answer: these are strictly necessary, and they are not used for anything else. We store nothing else in your browser (no local storage, no tracking identifiers). If we ever add anything that is not strictly necessary, it will stay off until you say yes, and you will be able to change your mind as easily.
__Secure-authjs.session-token: Keeps you signed in. Signed and encrypted; not readable by page scripts. Lasts: 30 days, or until you sign out.__Host-authjs.csrf-token: Protects the sign-in form against forged requests. Lasts: Session.__Secure-authjs.callback-url: Remembers the page you were going to while you sign in. Lasts: Session.__Secure-authjs.pkce.code_verifier: Protects signing in with Google or GitHub; exists only for the few minutes that takes. Lasts: 15 minutes.__Secure-authjs.state: Protects signing in with Google or GitHub against forged requests; only during sign-in. Lasts: 15 minutes.__Secure-authjs.nonce: Protects signing in with Google or GitHub against replay; only during sign-in. Lasts: 15 minutes.
The only other sites a page contacts are the picture hosts of the account you signed in with, to show your own profile picture: lh3.googleusercontent.com, avatars.githubusercontent.com, cdn.paddle.com, buy.paddle.com, checkout-service.paddle.com, sandbox-buy.paddle.com, sandbox-checkout-service.paddle.com.
3. How the AI is involved
Provetale computes its findings with ordinary statistics, in its own code. A language model (Mistral AI) is then given the results (the figures, the column and group names they involve, and any focus question you wrote) and asked to explain them. Every figure, date and name in the written report is then checked by code against the computed evidence, and a statement that fails is rewritten or dropped. Because group names and column names can come from your data, they can appear in what the model receives. If your column or group names are themselves sensitive, remove them before uploading.
4. How long we keep it
You choose, per workspace, in Settings: keep your files until you delete them, or have Provetale remove the uploaded file, its prepared copy and its exports one hour after analysis, or after 24 hours, 7 days or 30 days. Removing the files does not remove the findings and reports already computed from them: those stay readable until you delete the dataset or the report. Correcting a column or analysing again then needs the file again. You can delete a dataset or a report yourself at any time, which removes it and its stored files immediately.
5. Who handles it
A small number of services handle data for us: the database, private file storage, hosting, email, background-job orchestration and the AI service, and, once paid plans open, payments. The database and the application server are in Singapore. Each is listed, with what it receives and whether it is in use today, on Where your data goes.
6. Your choices and rights
- See, correct and delete your datasets and reports in the app.
- Pick how long your files are kept (Settings).
- Keep your account safe with two-step verification and sign out of every device (Security and privacy).
- Withdraw permission to quote a comment at any time, on the report where you gave it.
- Download a copy of your data (your account, datasets, reports, feedback and activity, as a JSON file) from Settings → Security and privacy. Your uploaded files are not repeated in it: download those from Datasets while they are stored.
- Delete your account yourself, from the same page. That deletes your account and the workspaces only you belong to, including their stored files, datasets, reports and exports, immediately and permanently. In a workspace you share, you leave it and what you made there stays with it. If you pay for a plan, cancel it first. The payment provider keeps the records the law requires it to keep.
- For anything the page does not cover, write to [email protected].
Depending on where you live you may have further legal rights (for example under the GDPR or similar laws); write to the same address to use them.
7. Security
Your workspace is isolated from every other at the database and the storage level, files are private and are downloaded only through links that expire within minutes, and access is checked on every request. The details, and what we do not yet have (such as a security certification), are on Security and trust.
8. Children, changes, contact
Provetale is run from Dhaka, Bangladesh, and its operator is responsible for the data described on this page; the operator's full legal details are available on request. Provetale is for people aged 16 and over. If this text changes in a way that matters, we will ask you to accept the new version. Questions: [email protected].