Privacy information
Privacy Policy
This Policy describes the information Provenia handles when providing its international documentary service.
1. Service operator and contact
The international Provenia service is operated by FELIPE PASSOS DE MORAES ALVES LTDA, CNPJ 68.312.415/0001-34, Brazil. Provenia is the product and trade name used for the service.
Privacy questions and requests may be submitted through the Contact page or to contact@provenia.app.
2. Information Provenia handles
Account and profile information
Provenia handles information such as name, display name, email, telephone number where supplied, protected credentials, verification states, account status, and documentary identity level.
Projects, records, and documentary history
This includes project and record titles, descriptions, states, chronological relationships, user declarations, identifiers, audit history, activity events, and generated Dossier or artifact data.
File hashes and declared metadata
SHA-256 hashes are calculated on the user's device. Provenia receives the resulting hash and declared metadata such as file name, extension, and size. Original creative-file contents are not transmitted to Provenia during record creation.
Payment transaction information
For international purchases, Provenia receives transaction details from Paddle that are needed to attribute and reconcile documentary credits, such as transaction identifiers, status, currency, amount, and purchased quantity. Provenia does not receive or store raw payment-card data.
Contact and support submissions
A support submission may include name, email address, subject, message, and technical anti-abuse fields needed to receive and respond to the request.
Logs, security, audit, and activity data
Provenia may handle timestamps, operation results, routes, identifiers, IP addresses, user agents, and security or audit events needed for service operation, diagnosis, abuse prevention, and documentary traceability.
3. Session data in the browser
The current authentication implementation uses browser local storage to maintain session information, including an access token used for authenticated API requests. Users can remove locally stored session data by signing out or clearing browser data.
4. How information is used
Information is used to:
- create, authenticate, secure, and administer accounts;
- operate projects, records, audits, and documentary credits;
- generate PDF, JSON, and package artifacts;
- deliver transactional messages and respond to support requests;
- reconcile transactions and address payment events;
- protect, diagnose, and maintain the service;
- support artifact integrity and independent verifiability.
5. Service providers and technical services
Provenia uses service providers where needed to operate the product. Paddle provides the international payment and Merchant-of-Record layer and supplies relevant transaction information; Paddle does not operate the Provenia service. Resend provides transactional email delivery when configured.
External timestamp services may receive cryptographic material needed to issue or validate timestamp evidence; they do not receive the original creative file through Provenia's record-creation flow. Signing, public-key publication, and verification services process artifact or cryptographic data needed for their technical purpose.
6. International transfers
Providers and technical infrastructure may process information in more than one country. Where applicable, transfers of personal data from the European Economic Area to Brazil may rely on the current European Union adequacy framework. For transfers subject to other requirements, including United Kingdom requirements, appropriate transfer safeguards may be used where required. This Policy does not claim that Brazil has a United Kingdom adequacy decision or that a particular transfer agreement has already been executed.
7. Account closure and retention
Account closure disables normal account access and use under the current account lifecycle. It does not automatically delete every historical record. Provenia may retain data needed for evidentiary integrity and verifiability, audit, security and fraud prevention, payment, fiscal or legal compliance, and the establishment, exercise, or defense of legal claims.
Non-essential personal data should be deleted or anonymized when it is no longer required for those purposes. Retention varies by data category, and Provenia does not promise a single universal retention period or deletion behavior that the current service does not perform.
8. Security
Provenia uses technical and organizational safeguards appropriate to the service, including access controls, password hashing, input validation, protected production connections, secret separation, and operational audit trails. No system can promise absolute security.
9. Requests, choices, and applicable law
Users may contact Provenia to ask about their information or request an available account or data action. Provenia may request reasonable information to authenticate the requester and protect the account and documentary record before acting.
This Policy does not claim that a particular privacy statute applies to every user or that every requested action can be performed on data whose historical or evidentiary role must be preserved.
Privacy rights and obligations may vary according to the jurisdiction applicable to a user, request, or processing activity.
10. Analytics and tracking
Provenia does not currently claim the use of a separate analytics or advertising-tracking platform on this public service. Necessary technical and security logs are described above.
11. Updates
Updated versions will be published with their version and effective date. Material changes may be presented in the product when renewed notice or acceptance is appropriate.
Version 1.0. Effective August 25, 2026.