Legal

Privacy Policy

Last updated 10 June 2026

This policy covers the website at provenrail.com and its subdomains. It is written to be read, not to hide behind. The short version: the Provenrail software is self-hosted, so the records it produces never reach us, and the website itself collects only what it needs to run.

The software does not send us your data

Provenrail is distributed as open-source software that you run on your own infrastructure. The audit records your agents produce go to a sink you operate. We do not receive, store, or have any access to those records or their contents. When you self-host, you are the data controller for your own data; we are not a processor of it.

What the website collects

When you create an account

If you sign in at /account, we create an account so you can manage a subscription and your commercial license key. For this we store your email address and your plan and subscription status. We do not store passwords: you sign in with GitHub, Google, or a one-time email link. If you choose GitHub or Google, that provider confirms your identity and shares your email address with us; we do not receive your password or post on your behalf. We never store, receive, or have access to the audit records your agents produce. Those remain on infrastructure you operate.

Who processes this data for us

We do not use this data for advertising and do not sell it.

Cookies and local storage

This site sets no cookies, and uses no advertising or cross-site tracking. When you sign in on the account page, your session is kept in your browser's local storage for the single purpose of keeping you signed in. It is never sent to advertisers or third parties, and it is cleared when you sign out. Because we use only this strictly necessary mechanism and no tracking, no cookie consent banner is required.

Site analytics

We count page views and clicks on our own buttons so we can tell which pages are useful. This is first-party and deliberately minimal. For each view we store only: the page path (without any query string), the host of the referring site (never the full referring URL), a utm_source value if one is present in the link you followed, your country as reported by our edge network, whether your screen is phone-sized or larger, and the time.

We do not store your IP address, do not set any cookie or local-storage value for analytics, and do not create any device fingerprint, visitor identifier, or cross-site identifier. There is nothing in this data that identifies you or links two of your visits together, so it does not constitute personal data and no consent banner is required for it. The data is stored on our own infrastructure in the EU and is never sold or shared. We use no third-party analytics provider.

Loading a page on this site makes no request to any third party. Fonts, styles, scripts and images are all served from our own domain: there is no font host, no script CDN and no tag manager, so your IP address is never disclosed to one. The only network calls a page makes beyond fetching itself go to our own backend, which is the Supabase infrastructure listed above, for the account page and for the pageview count described here.

Email you send us

If you email us, we keep that correspondence to reply and for our records. We do not add you to a marketing list without your consent.

Your rights

If you are in the EU/EEA or UK, you have rights to access, correct, or erase personal data we hold about you, and to object to or restrict its processing. To exercise them, email [email protected]. We respond to legitimate requests within the statutory timeframe.

The data controller is the operator of Provenrail, a sole trader registered under individual activity (individuali veikla) in Lithuania. For any data-protection matter, including a request to identify the controller, contact [email protected]. This policy is governed by the laws of the Republic of Lithuania. Your GDPR (or UK GDPR) rights above apply regardless, and you may lodge a complaint with your local data protection authority. In Lithuania this is the State Data Protection Inspectorate (ValstybinÄ— duomenų apsaugos inspekcija), vdai.lrv.lt.

Changes

If this policy changes materially, we will update the date above and, where appropriate, note the change on this page.

Contact

Questions about privacy: [email protected].