Privacy Policy

This Privacy Policy describes how we handle your educational data with precision and transparency.

Last Updated: September 14, 2026

Our Commitment to Privacy

ProvenanceAI was founded on the belief that transparency isn't optional—it's foundational. This extends to how we handle your data.

This Privacy Policy explains how Exact Rush Multimedia Publishing ("we," "us," or "ProvenanceAI") collects, uses, and protects information when you use the ProvenanceAI platform at provenanceai.app.

1. Information We Collect

1.1 Educational Records (Students and Instructors)

When you use ProvenanceAI for coursework, we collect:

Student Work Data

  • Assignment submissions and drafts
  • Prompts sent to AI systems
  • Source materials and citations
  • Revision history and timestamps
  • Human Distance, Leverage Distance, and Well-Being metrics

Instructor Data

  • Assignment creation and rubrics
  • Feedback and grading information
  • Course structure and settings
  • Usage analytics

1.2 Technical Information

We automatically collect:

  • Browser type and version
  • Device information
  • IP address and location (city/country level)
  • Log data (access times, pages viewed, errors)
  • ProvenanceAI browser extension activity (when installed)

1.3 AI Interaction Data

When you use ProvenanceAI's AI analysis features:

  • Text submitted for analysis
  • AI model responses
  • Anonymized patterns for system improvement

2. How We Use Your Information

2.1 Primary Educational Purposes

We use student educational records to:

  • Track the provenance of academic work
  • Calculate Human Distance, Leverage Distance, and Well-Being metrics
  • Provide feedback to students and instructors
  • Verify academic integrity through process visibility
  • Generate analytics for institutional reporting

2.2 Service Improvement

We use aggregated, de-identified data to improve algorithms, identify usage patterns, and conduct educational research (with institutional approval).

3. AI Analysis and Third-Party Services

3.1 Large Language Model Processing

ProvenanceAI uses AI services from OpenAI, Google (Gemini), and Anthropic (Claude). Personally identifiable information (PII) is removed or tokenized before processing whenever feasible. Our agreements explicitly prohibit using student submissions to train their public models.

3.2 Other Third-Party Services

We use Vercel and AWS for hosting (US regions). All third-party services are bound by Data Processing Agreements requiring FERPA compliance.

3.3 Google Drive (ProvenanceAI Studio)

If you connect Google Drive in ProvenanceAI Studio, you grant ProvenanceAI access to Google user data through Google's OAuth consent screen. Connecting Drive is optional. Coursework on ProvenanceAI does not require it.

We request only the https://www.googleapis.com/auth/drive.file scope. That lets Studio create files and folders you ask it to create, and read or update files you explicitly hand it with Google Picker or that Studio itself created. We do not request access to your full Drive. We cannot list, read, edit, or delete Drive files that were never created by Studio and never imported through the in-product picker.

What we access:

  • The Google account email you use to connect
  • The Studio working folder you create or select (folder id and name)
  • Files Studio creates in that folder (for example Markdown and Word course artifacts)
  • Copies of files you import into the Studio folder through the product UI

How we use, store, and share that Google user data:

  • Use: to provide the Studio Drive workplace (connect a folder, import files you choose, and write course files back into that folder).
  • Store: we store an encrypted OAuth refresh token, the connected Google account email, and the working folder id and name on our servers so the connection can resume on a later visit. File contents stay in your Google Drive. We do not keep a second copy of your Drive as a general archive.
  • Share: we send tokens and file requests to Google's Drive API to perform those actions. We do not sell Google user data. We do not use it for advertising. We do not transfer it to other parties except as needed to operate this feature, to comply with law, or with your instruction.

ProvenanceAI's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. You can disconnect Google Drive from Studio at any time. Disconnecting deletes our stored refresh token and folder binding. It does not delete files already in your Drive.

4. FERPA Compliance

ProvenanceAI acts as a "School Official" with legitimate educational interest under the Family Educational Rights and Privacy Act (20 U.S.C. § 1232g).

Your institution maintains ownership of all student educational records. Students have the right to inspect, review, and request corrections to their records through their institution.

5. Data Retention

Student educational records are retained for the duration of the academic term or according to institutional policy (typically 1-7 years). Aggregated, de-identified research data may be retained indefinitely as it cannot be re-identified.

6. Data Security

We implement industry-standard security measures including TLS 1.3 encryption in transit, AES-256 encryption at rest, and regular security audits. If we detect a breach affecting student records, we notify affected institutions within 72 hours.

Contact Information

Data Protection Officer: Exact Rush Multimedia Publishing

Email: exactrushllc@gmail.com

Effective Date: February 1, 2026