Provenarium
ProductResourcesPlansTalk to us
Try the free demo
Legal

Privacy Policy

This policy explains what Provenarium collects when you visit our site, contact us, or use the workspace—and what we do with that information.

Effective and last updated July 19, 2026hello@provenarium.com
On this pageScope and rolesInformation we collectHow we use informationHow we disclose informationCookies and browser storageRetentionSecurityInternational transfersYour choices and rightsCalifornia disclosuresChildrenChanges and contact
The short version
  • We use Google Analytics automatically to measure visits, product adoption, marketing performance, and a limited set of account and contact events.
  • We do not use customer assay files or workspace content to train artificial-intelligence or machine-learning models.
  • Analytics events do not intentionally include contact-form contents, email addresses, assay files, or scientific workspace content.
  • You can ask about, correct, or request deletion of your personal information by emailing us.

1. Scope and roles

This Privacy Policy applies to the Provenarium website, contact form, individual workspace, and other Provenarium online services that link to it (together, the “Services”). It does not govern a third-party site or service just because we link to it.

Provenarium is responsible for personal information used to operate the website, accounts, contact requests, and our business. If you use an organization workspace, your employer or other organization may control the workspace and direct how information in it is used. In that situation, the organization’s privacy notice and its agreement with Provenarium may also apply. Direct a request about organization-controlled data to the organization first.

A signed customer agreement or data-processing agreement may add to this policy for Team workspaces, integrations, consulting, or custom development. If a signed agreement and this policy address the same processing differently, the signed agreement controls for that customer.

2. Information we collect

We collect information you provide, information provided by your organization or sign-in provider, and limited technical information produced when you use the Services.

CategoryExamplesSource
Account and identityName, email address, account identifier, sign-in provider, workspace membership, role, account timestamps, and first- and latest-touch campaign attribution associated with account creationYou, your organization, your browser, or Google if you choose Google sign-in
Contact and business detailsName, work email, company, role, area of interest, message, correspondence, and first- and latest-touch campaign attribution associated with the requestYou and your browser when you contact us
Scientific and workspace contentCSV or Excel source files, filenames, plate measurements, sheet names, sample names, mappings, dilution settings, model settings, suitability criteria, exclusions and reasons, report text, and other content you submitYou or your organization
Analysis and report informationCalculated values, fitted-model parameters, system-suitability results, SHA-256 fingerprints that identify the source data file and analysis configuration, generated reports, and the name or email attributed to a reportCreated from your inputs when you use the Services
Technical, analytics, and security informationPage views, referring site and campaign parameters, limited interaction and account events, browser and device type, approximate location derived from IP address, user-agent string, IP address and network request information, cookie or device identifiers, authentication and token metadata, timestamps, and error or security eventsYour browser, our infrastructure, Google Analytics, and other service providers

Firebase Authentication manages passwords for email sign-in; Provenarium does not receive a readable copy of your password. If you use Google sign-in, Google processes that sign-in under its own terms and privacy policy.

Do not upload patient data.

Do not submit protected health information, direct patient identifiers, identifiable genetic or biometric information, or other sensitive personal data to the Services. The Terms of Service explain this restriction.

3. How we use information

We use personal information for the following purposes:

  • Provide the Services. Create and authenticate accounts, process source files, run analyses, generate reports, maintain workspaces, and respond to actions you request.
  • Respond to you. Answer contact, support, privacy, security, and commercial requests. We do not add contact-form details to a marketing mailing list unless you ask us to.
  • Protect the Services. Detect misuse, investigate errors, enforce our terms, maintain access controls, and protect users and infrastructure.
  • Maintain reliability. Diagnose problems and improve performance using support reports and limited technical information.
  • Measure adoption and marketing. Understand how visitors reach and use the website and workspace, evaluate campaigns, and measure events such as account creation and completed contact requests.
  • Meet legal obligations. Comply with lawful requests, preserve evidence, and establish, exercise, or defend legal claims.

Where applicable law requires a legal basis, we process information to perform our contract with you, take steps you request before a contract, pursue legitimate interests in operating and securing the Services, comply with law, or act with your consent. You may withdraw consent for future processing when consent is the basis.

We process customer assay files and workspace content only to provide, secure, support, or maintain the Services; comply with law; or follow the customer’s instructions. We do not use that content for advertising or to train AI or machine-learning models.

4. How we disclose information

We disclose information only as needed for the purposes above:

  • Infrastructure, authentication, and analytics providers. Google Firebase and Google Cloud provide authentication, database, file-storage, and related infrastructure. Google also provides Google sign-in when you select it and Google Analytics for usage and advertising measurement.
  • Your organization. Workspace owners and authorized administrators may access and manage organization accounts, members, and workspace content.
  • Professional advisers. Lawyers, accountants, auditors, insurers, and security advisers may receive information subject to appropriate duties of confidentiality.
  • Legal and safety recipients. We may disclose information when reasonably necessary to comply with law, respond to valid legal process, protect rights or safety, investigate abuse, or enforce agreements.
  • Business transactions. Information may transfer as part of a merger, financing, acquisition, reorganization, bankruptcy, or sale of all or part of the business, subject to this policy and applicable law.

We do not sell personal information for money or currently display third-party advertisements in the Services. Google Analytics receives the analytics and device information described above and is currently configured with advertising measurement and personalization signals enabled. Depending on the law that applies, this disclosure may be treated as “sharing” for targeted or cross-context behavioral advertising.

5. Cookies and browser storage

Google Analytics loads automatically on the marketing site and workspace. It uses cookies and similar browser or device signals to measure page views, referring campaigns, account creation and sign-in methods, completed contact requests, and product-usage events such as file-format categories, workflow steps, analysis execution, configuration import or export, and report preview or export. Google advertising storage, advertising user-data, Google signals, and advertising-personalization signals are currently enabled. We do not intentionally send Google Analytics the contents of contact forms, email addresses, names, assay files, filenames, workspace or run identifiers, measurements, sample information, analysis results, report contents, or other assay-specific scientific inputs or outputs.

Provenarium also uses local storage and a cookie shared across Provenarium subdomains to maintain a 90-day first- and latest-touch campaign-attribution window. This record is limited to UTM parameters, Google advertising click identifiers, the landing-page path, the referring origin and path, and capture time. Unrelated landing-page and referrer query parameters are removed. We save this attribution in Firestore with a completed contact request or newly created account so we can evaluate which inbound campaigns result in leads and signups.

The workspace also uses browser storage needed for authentication, to keep you signed in, and to remember which account-access form to show when you return. This preference does not contain your password or assay data. If you choose Google sign-in, Google may use cookies or similar technologies on its own pages to complete authentication. Blocking browser storage may prevent analytics collection, sign-in, or other workspace functions.

Provenarium does not yet provide an in-product analytics or advertising-cookie preference control and does not currently respond differently to “Do Not Track” or Global Privacy Control signals. You can block or delete cookies through your browser and can use the Google Analytics opt-out browser add-on. We plan to add consent and preference controls as the Services develop.

6. Retention

Retention periods differ by category. Current retention works as follows:

  • Account profiles, workspace membership, signup method, and signup attribution remain stored while the account is open and until a verified closure or deletion request is processed.
  • A private, write-once copy of each uploaded source file is retained for no longer than three months after upload so Provenarium can investigate file-import problems and provide support. This includes a file that cannot later be parsed. At the end of the retention period, Provenarium currently deletes the copy through a manual retention review. Clearing a file from the analysis screen does not immediately delete that retained copy.
  • Contact requests and their associated attribution remain stored until they are manually removed after the response and related business need have ended.
  • Google Analytics event-level data is retained according to the retention settings of our Google Analytics property. Google may retain aggregated reporting information for longer periods under its service settings.
  • Technical and security records are retained under the operational settings of Provenarium and its infrastructure providers.

To request account, contact, or file deletion, follow the process in “Your choices and rights” below. We will verify and assess the request, remove information where required by law or reasonably practicable, and explain any information we must retain for security, legal compliance, or legal claims. Deletion from active systems may not immediately remove copies already present in provider backups or security records.

7. Security

The Services use authenticated access and access-control rules intended to restrict access to workspace records and uploaded files. We also rely on security controls provided by our infrastructure providers. No internet service or storage system is completely secure, so we cannot guarantee that information will never be lost, accessed, or disclosed without authorization.

You are responsible for protecting your credentials, using an appropriate device and network, and promptly telling us if you suspect unauthorized account access.

8. International transfers

Provenarium operates the Services from the United States. We and our service providers may process information in the United States and other countries where they operate. Those countries may have data-protection laws different from the laws where you live.

Where applicable law requires a transfer mechanism, we rely on contractual protections and transfer mechanisms made available through our service-provider agreements. An organization that needs a data-processing agreement, data-residency commitment, or customer-specific transfer terms should contact us before uploading personal data.

9. Your choices and rights

Depending on your location and the law that applies, you may have the right to:

  • ask whether we process your personal information and receive a copy;
  • correct inaccurate or incomplete information;
  • request deletion of information;
  • restrict or object to certain processing;
  • receive information you provided in a portable format;
  • withdraw consent for future processing; and
  • appeal a denied request or complain to your local data-protection authority.

Email hello@provenarium.com with the subject “Privacy request” and describe what you want us to do. We may ask for information needed to verify your identity, authority, account, or organization. An authorized agent may submit a request where law permits, but we may require proof of authorization and direct identity confirmation. We will not discriminate against you for exercising a privacy right.

You can also limit Google Analytics through browser cookie controls or the Google Analytics opt-out browser add-on linked above. These controls may not affect information already collected.

Some rights have legal exceptions. For example, we may retain information needed for security, legal compliance, a transaction you requested, or legal claims. If we deny a request, we will explain why when required by law. You may appeal by replying to the decision.

10. California disclosures

The table in “Information we collect” describes the categories of personal information collected, the sources, and representative examples. We use those categories for the purposes described in “How we use information” and disclose them to the recipient categories described in “How we disclose information.”

We have not sold personal information for money in the preceding 12 months and do not offer a financial incentive for personal information. We use Google Analytics with advertising measurement and personalization signals enabled. Depending on how California law applies to this use, it may constitute “sharing” for cross-context behavioral advertising. “Cookies and browser storage” describes the available browser and Google controls.

If the California Consumer Privacy Act applies to Provenarium or a particular request, California residents may have rights to know, access, correct, or delete personal information; opt out of sale or sharing; limit certain uses of sensitive personal information; and receive equal service when exercising those rights. Use the request process above to submit a request, including an opt-out request.

11. Children

The Services are designed for professional scientific work and are not directed to children. You must be at least 18 years old, or the age of legal majority where you live, to create an account. We do not knowingly collect personal information from children. If you believe a child provided personal information, contact us so we can investigate and take appropriate action.

12. Changes and contact

We may update this policy when the Services, vendors, or legal requirements change. We will post the revised policy with a new effective date. If a change materially affects how we use information already collected, we will provide additional notice when required.

Questions or requests may be sent to hello@provenarium.com. Provenarium operates from the United States. Organization customers that need formal privacy, security, or data-processing terms should contact Provenarium.

Provenarium

Dose-response and relative-potency analysis from plate-reader data through review and reporting.

Product

Product overviewPlansPotency assay software

Learn

All resources4PL and 5PL curve fittingRelative-potency analysisPlate-reader data analysisComputerized system validation

Get started

Try the free workspaceDiscuss a Team workspaceDiscuss custom developmentContact Provenarium
© 2026 Provenarium
Privacy PolicyTerms of Servicehello@provenarium.com