What we collect, and why.
The short version: we read your Search Console data only to measure your site, we never write to it, we never sell it or train on it, and you can disconnect or have everything deleted whenever you like.
Who we are
Provenplot is operated by Silk Creative Labs LLC. Questions about this policy, or requests about your data, go to privacy@provenplot.com.
The free check
When you run the free check, we read the public pages of the site you entered: its sitemap and a sample of its pages, the same way any visitor or search engine would. We keep a count of how many checks have been run and nothing about the site itself. We do not ask for an email address, and we do not set up an account.
Your account
To sign in we ask for your email address, and send a sign-in link to it. Your account holds the sites you add and everything measured about them. Sign-in is provided by Supabase, which is also where our database lives.
We use one cookie to keep you signed in, a short-lived cookie while you connect Google, and, if someone referred you, a cookie that remembers which site sent you so they can be credited. We do not use advertising or analytics cookies.
Google Search Console
With your permission, we request read-only access to the Search Console properties you choose, and your Google email address so the site page can show which account is connected. Read-only is the only Search Console access we ever ask for. We never change anything in your Search Console.
What we read: for each page, the clicks, impressions, average position and search queries Google reports, for as far back as Google keeps it, which is sixteen months, and then every night after that. We use it for one purpose: to measure your site, build the baseline an experiment is compared against, and report how the pages we rewrote did against the pages we left alone.
To keep reading after you close the page, Google gives us a refresh token. It is stored in our database, is never sent to your browser, and is used only by our background jobs. You can disconnect Google from your site page at any time, or revoke access from your Google account's security settings. Either one stops all reading immediately; the measurements already taken stay in your account until you ask us to delete them.
Provenplot's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In practice that means: we do not sell Google user data, we do not use it for advertising, and we do not use it to train artificial intelligence models, ours or anyone else's. When our agent drafts a rewrite, the instruction sent to our AI provider can include a short reason drawn from your traffic, for example that a page received about half as many visits in the last four weeks as the four before, so the rewrite addresses the right problem. The provider processes it only to produce that rewrite and does not train on it.
Your pages and the rewrites
To decide what needs refreshing, we read the pages on your site, using Firecrawl. To draft a rewrite, we send the text of that one page to our AI provider, Anthropic, along with the reason it was chosen. These are pages you have already published. Nothing changes on your site until you approve a rewrite.
If you connect a code repository, we store the access token you give us and use it only to open a pull request for each rewrite you approve, and to check whether it has been merged.
Payments and email
Payments are handled by Stripe. We store your subscription's status, price and renewal date. We never see or store card numbers.
We send two kinds of email, through Resend: a note when rewrites are waiting for your approval, and the result when an experiment reaches day ninety. We do not add you to a mailing list.
Published reports
An experiment's report becomes public only if you choose to publish it. A published report shows your domain, the pages that were rewritten and left alone, and the measured result. You can ask us to unpublish it.
Who processes data for us
Vercel hosts the site. Supabase provides the database and sign-in. Google provides Search Console data, at your request. Firecrawl reads pages. Anthropic drafts rewrites. Trigger.dev runs our background jobs. Stripe handles payments. Resend sends email. GitHub is used only if you connect a repository. Each receives only what it needs to do that one job.
How long we keep it, and your choices
We keep your account and your sites' data for as long as your account is open. You can ask for a copy of your data, ask us to correct it, or ask us to delete your account. Write to us at the address above and we will do it within 30 days, and confirm when it is done.
If this policy changes in a way that matters, we will change the date below and email account holders before it takes effect. Last updated 11 September 2026.