15% of all profit is donated to Heal Palestine and the Palestine Children's Relief Fund (PCRF)
Platform Research Validation Safety Pricing Company Demo Request access
Privacy

Privacy Policy.

How Provotics collects, uses, retains, and protects account, contact, and research-service data.

Last updated: 20 July 2026

This policy explains how Provotics collects, uses, discloses, retains, and protects personal data. Provotics is a research and educational project operated by Kareem Badran, who is the controller of account, access, support, and website-contact data described here. Questions and privacy requests may be sent to [email protected] or submitted through the privacy request form.

Provotics is not a medical device and is not intended for clinical diagnosis or treatment decisions.

Personal data we collect

When you apply for access or create an account, we collect what you enter: your name, email address, organization, role, use category, and intended use. To create an account we store a one-way cryptographic hash of your password, never the password itself. Product use also requires a passkey (WebAuthn). We store the passkey public key, credential identifier, signature counter, and optional label you choose; the private key stays on your device or with your passkey provider (for example Apple Passwords / iCloud Keychain, Google Password Manager, or Windows Hello). Password sign-in remains available for recovery so you can re-enroll a passkey if you lose every enrolled device.

If you sign in with Google or GitHub, that provider sends us your verified email address and a durable account identifier. We store the provider identifier only as a cryptographic hash so the same identity can be recognized safely on later sign-ins. Provider access tokens are used briefly to retrieve this identity and are not stored. Social sign-in only connects to an existing Provotics account; it does not create or approve one.

When you accept the Access Agreement and Mutual NDA, we record a signing receipt as evidence of consent: your typed signature, the agreement version, a cryptographic hash of the exact text you agreed to, the timestamp, your IP address and country, and your browser's user-agent, sealed so it cannot be altered.

For security, fraud prevention, and abuse control, our server receives your IP address, country, network ASN, user-agent, authentication events, and submission timestamps. Successful and failed sign-ins are recorded in a short-lived login audit. We also remember trusted locations and devices (a fingerprint of your network prefix, country, and ASN, plus a browser device cookie). A sign-in from an unrecognized network and device requires email approval (explicit confirmation on the approval page, or a one-time code) before a session is issued. Passkey sign-in with user verification may proceed without that email step because the authenticator itself proves possession. If you are approved and use the model, we store a securely hashed API key (bound to the network where it was created) and a tamper-evident query audit record containing cryptographic fingerprints of the input and output, the time, the accepted data-boundary version, and a per-response watermark. The audit record does not contain the submitted gene-expression values.

When you choose Run analysis, the parsed gene-expression profile is transmitted to the Provotics gateway and inference service to generate the requested research output. The application does not intentionally write the raw expression values to account storage, browser project history, or the query audit. Network and infrastructure providers necessarily process request data to deliver and secure the service under their applicable terms.

When you contact us or exercise a privacy right, we collect your name, email, message, request type, jurisdiction if supplied, request status, and the response record. If billing is enabled and you choose to purchase, the payment processor handles payment details and returns transaction, customer, subscription, and entitlement identifiers to Provotics. Provotics does not store full card numbers.

We do not request or permit names, patient or sample identifiers, medical record numbers, government identifiers, contact details, clinical notes, or other protected health information through the model. You must be authorized to use the profile, remove direct identifiers, and submit gene-expression values only. Provotics performs a limited identifier-field screen, but it does not certify HIPAA Safe Harbor, Expert Determination, GDPR anonymization, or compliance with another legal de-identification standard. Genetic or expression data may still be personal or sensitive data depending on its context and linkability.

Sources

We obtain personal data directly from you, from your browser and network request, from Google or GitHub when you choose social sign-in, and from a payment provider when you choose a paid transaction. Account approval is manual. Provotics does not make a solely automated decision that produces legal or similarly significant effects.

Purposes and legal bases

  • Contract and pre-contract steps: to review an access application, provide an account, authenticate you, deliver the service, administer a subscription, and respond to support.
  • Legitimate interests: to secure the service, prevent fraud and model extraction, keep audit evidence, troubleshoot incidents, enforce agreements, and understand demand. We balance these interests against the rights of affected people.
  • Consent: where required, for optional communications or another purpose presented at collection. Consent may be withdrawn at any time without affecting earlier lawful processing.
  • Legal obligations and legal claims: to meet applicable accounting, security, regulatory, and dispute-resolution duties.

Provotics does not use personal data for third-party advertising, does not build advertising profiles, and does not sell or share personal information for cross-context behavioral advertising.

Service providers and disclosures

Provotics uses service providers only for defined operational purposes:

  • Cloudflare: website delivery, network security, serverless processing, account records, and key-value storage.
  • Resend: transactional email and delivery metadata.
  • Google or GitHub: identity information only when you choose that social sign-in provider.
  • Stripe: payment processing only when billing is enabled and you choose a paid transaction.

We may disclose information where required by law, to protect rights and service security, or as part of a properly documented business transfer. We do not disclose it to third parties for their own marketing.

International transfers

Provotics is operated in the United States and its service providers may process data in the United States and other countries. Where European data-transfer law applies, the applicable provider agreement must supply a lawful transfer mechanism, such as an adequacy decision or Standard Contractual Clauses, before the transfer is relied upon. Contact us to request information about the mechanism applicable to a specific provider.

Retention

  • Application and account records that remain approved or otherwise active currently have no automatic expiry. They are kept while access is reviewed or provided and are deleted through the verified request process unless a legal, security, fraud, contract, or dispute-related exception requires limited retention.
  • Rejected access applications and accounts are retained for up to 180 days after the rejection decision, then removed by an automated retention job.
  • Agreement signing receipts currently have no automatic expiry. They are retained as contract and legal-claims evidence while reasonably necessary; a final limitation-period schedule remains to be approved.
  • Newsletter or update-subscription records are kept until opt-out, a verified deletion request, or removal of the list.
  • Raw gene-expression values are processed to answer the model request and are not intentionally persisted by the application in account storage, project history, or query audits.
  • Query and administrative audit records expire after no more than 12 months.
  • General contact messages expire after no more than 12 months.
  • Privacy-request and response records are retained for 24 months where needed to demonstrate handling under California law, and are not used for another purpose.
  • Short-lived verification, reset, rate-limit, and OAuth-state records expire automatically, generally within minutes, hours, or days.
  • Billing and payment records, if billing is enabled, follow applicable provider, tax, accounting, contract, and legal-claims retention requirements; a final internal schedule remains to be approved.
  • Local project history, display preferences, and motion preferences remain on your device until you clear browser storage or use the product's deletion control.

Provotics does not currently run a scheduled secondary application backup. If backup storage is activated, this notice and the applicable retention, access, and erasure process must be updated before personal data is copied there.

Cookies, local storage, and analytics

Provotics does not load third-party advertising or analytics scripts. Essential signed cookies are used for account sessions, OAuth state, and security. Browser-local storage remembers display theme, motion preference, the one-time home intro, signup drafts during the current session, and locally stored project history. These browser-local values are not used for advertising.

Security

Safeguards include HTTPS, secure and HttpOnly session cookies, password hashing, mandatory passkeys for product access, access controls, rate limits, origin checks, bounded inputs, limited identifier-field screening, tamper-evident audit records, provider-managed storage encryption, application-layer field encryption for supported PII and network fields (where DATA_ENC_KEY is configured), trusted-location and device checks on sign-in, and documented incident and recovery procedures. A scheduled secondary KV backup to object storage is not active until the backup bucket binding is enabled. No system is perfectly secure. Report suspected vulnerabilities through the security contact.

Your privacy rights

Depending on where you live and which law applies, you may have rights to know or access personal data, correct it, delete it, receive a portable copy, restrict or object to processing, withdraw consent, opt out of sale or sharing, limit use of sensitive personal information, and appeal a denied request. You will not be discriminated against for exercising a privacy right.

Use the privacy request form or email [email protected]. Requests are handled manually; submitting the form records the request but does not itself export, correct, or delete other records. We may verify your identity or an authorized agent's authority before disclosing, correcting, or deleting records. Requests are free except where applicable law permits a reasonable response to requests that are manifestly unfounded or excessive.

If the GDPR applies, you may complain to the data-protection authority in the EU or EEA country where you live, work, or believe an infringement occurred. If California law applies, the rights described above include the rights to know, delete, correct, opt out, limit, and receive equal service. Provotics has not sold or shared personal information in the preceding 12 months. Because there is no sale or sharing, there is currently no separate sale or sharing opt-out to apply when a Global Privacy Control signal is received.

HIPAA and health information

Under its current role and intended use, Provotics is not a HIPAA covered entity or business associate, has no Business Associate Agreement in force, and is not designed to receive protected health information (PHI). Do not submit PHI. If your organization requires PHI processing, Provotics is not available for that workflow unless a BAA and the required HIPAA privacy, security, and breach program are completed before any PHI is exchanged.

If identifiable health information is submitted despite this prohibition, we will contain and delete it where legally permitted, preserve only the minimum incident evidence, notify the submitter as appropriate, and assess applicable breach-notification duties.

Children

The service is intended for adults acting in a research, educational, or organizational capacity. Provotics does not knowingly collect personal data from children. Contact us to request deletion if you believe a child submitted personal data.

Changes

We may update this policy as the project evolves. Material changes will be reflected by the "last updated" date above and, where required, communicated through an additional notice.

← Back to Provotics