Privacy Notice
Last updated: 29 August 2026
This notice states exactly what Provely (provely.app, an Unfussy Labs product) does with your data. It describes the service as it runs today, not as it might run later. Where a feature is not live yet, this notice says so.
You can use Provely without an account
Anonymous use is never gated. You can paste a prompt and run a full check without signing up, without giving a name, and without giving an email. Creating an account is optional, and it exists only to save your checks and read them back later.
The one exception is connecting Provely to another app, such as ChatGPT or Claude. That needs an account, because there is no other way to know whose daily allowance to count or whose prompts to save. See "Using Provely from inside another app" below.
Closed testing: a passcode and a tester email
While Provely is in closed testing, the whole site sits behind a passcode screen. To get in, you enter the current passcode and an email address. That email is recorded on a private tester roster so we know who is testing the product. It is not verified, it is not used to sign you in, and we do not use it to email you or add you to any list.
This gate is temporary. It exists only for the closed-testing period, and this notice will be updated once it is switched off.
If you create an account
You can sign up with an email address and password, or with Google or GitHub. When you do, we store the email address tied to your account, the username you choose, an optional display name and avatar, and which method you signed in with. Email sign-up asks you to verify your email before the account is active, and sign-up is protected by a bot check (Cloudflare Turnstile).
You stay in control of the account. You can change your password and delete the account at any time from your profile. Deleting the account removes your profile and the checks saved to it.
Provely shares its accounts with provely.dev, our Skill Check tool for Claude Agent Skills, because both are the same Provely account system. The same sign-in works on both sites. If you create an account here it works there too, and deleting your account removes it from both sites at once.
What we store, and for how long
When you run a check, we store the prompt you paste and the results the check produces.
- If you are not signed in, an unsaved check is automatically purged after 30 days, unless you save it or share it.
- If you are signed in, or you save a check after signing in, it is kept in your history until you delete it.
- Your browser also keeps a local, on-device record of your recent checks so they are there when you return. When you sign in, you choose whether to sync that local history to your account or clear it.
Saving or sharing keeps the text until you remove it.
How we hold what we store
Your account, your saved checks and your Context live in our database at Supabase, in the EU region. The database is encrypted at rest. Row level security is on, so a row is tied to the account that owns it, and the browser cannot reach another person's rows at all. We store what you need in order to read your own results back, and nothing further.
Some checks store nothing. The hallucination check, which reads one AI answer for claims it cannot back, writes a copy only when you are signed in, so that you can find it again in your history. Run it signed out and nothing is written down. Run it through a connected app and nothing is written down there either, so there is no id, no row and no link to come back to.
Secrets are scrubbed before storage
Before we store or submit your prompt, we scan it for obvious secrets, such as API keys, and strip them out. When that happens, we show you a warning. Please still avoid submitting credentials: automated scrubbing catches common patterns, not everything.
Sharing is explicit, and shared pages are public
Nothing you run is public by default. Sharing is a deliberate act. Before a page goes public, we show you a preview of exactly what will be visible, run a fresh secrets scan, and ask you to confirm with a click. Once shared, the page is public: anyone with the link can read it.
Daily limits and your IP address
On the website, daily limits are keyed to a salted hash of your IP address. We do not store your raw IP address. The hash lets us count usage per day without holding the address itself. When you use Provely through a connected app, limits are keyed to your account instead, for the reason given in "Using Provely from inside another app".
For what today's limits actually are, see the Usage limits page.
The run step uses a bot check
The run step, where we send your prompt to the models, is protected by Cloudflare Turnstile, a bot check. It is there to stop automated abuse of the run button.
Where your prompts are sent
When you run a test, your prompt is sent to one or more of these three model providers, so we can see what the prompt actually produces. Which of them receive it is decided by the models selected for that test, and only the selected ones are sent anything:
- Anthropic (Claude Sonnet 5)
- OpenAI (GPT-5.6 Luna)
- Google (Gemini 3.6 Flash)
How many of them see it depends on who is running the test and what they picked. Signed out, a test runs on one model, and only that provider receives your prompt. Signed in, you tick which models to run before the test starts; two are ticked by default and the third is opt-in. A test is only ever sent to the providers you selected. Through our MCP server a test starts on the model matching the tool you are calling from, and reaches the others only if you ask for them.
When you rewrite a prompt and run it again, we send it only to the models that missed the first time: a model that already did what you asked has nothing left to prove, and not re-running it means one fewer provider sees your prompt. The result page names any model that was left out.
We pay for those calls ourselves. You never supply an API key, and your prompt is never billed to or run under your own account with them. We test on these models and we say so. We do not test your own model, your own account, or your own setup.
What the model providers do with your prompt
We use commercial API access to these providers, not their consumer chat products. Under those API terms they do not train their models on what we send. They keep a short operational copy so they can investigate abuse, typically up to 30 days, and then it goes. It is held under their data processing terms for us, and it is theirs to protect rather than theirs to use.
To be plain about it, your prompt does leave our servers when a test runs. It has to, because the point of the check is to see what a real model does with your exact wording. This is the same arrangement any company has when it runs on a cloud provider. The providers publish data processing agreements and hold SOC 2 reports, and our calls run under those terms.
Stricter options exist on the provider side, such as endpoints that retain nothing and requests pinned to one region. We do not have those today. They are things we can take up as we grow into larger customers, and this notice will say so when we do.
Using Provely from inside another app
You can connect Provely to an app you already use, such as ChatGPT, Claude, or Claude Code, and check a prompt without leaving it. What that involves:
- Connecting needs your permission, once. The app sends you to a Provely page that names the app asking, says what it will be able to do, and waits for you to allow or cancel. Nothing happens until you allow it. You can disconnect it later in that app's own settings.
- We never see your password. The approval step signs you in to Provely in the normal way, and hands the connected app a limited key that only works with Provely. The app never receives your password, and we never receive it from the app.
- Only the prompt you ask about is sent. The connected app passes us the prompt being checked, not the rest of your conversation. We do not ask for, receive, or store the surrounding chat, your files, or anything else in that app.
- We record which app connected. For each check made this way we store the name of the app and the client it identified itself as, so we can support it and count usage. Nothing else about the app or the conversation is kept.
- Checks are saved to your account, exactly as they are on the website, and they appear in Your Prompts with their results.
- Prompts still go to the model providers named above when a test runs, on the same basis as a check run on the website.
Daily allowances for connected apps are counted against your account rather than an IP address, because a connected app talks to us from its own servers rather than from your device.
Paid plans
There are no payments today, so we hold no payment or billing data about anyone.
When the paid plan launches, Stripe will process payments under its own terms; we never see your card details. This notice will be updated before anyone is charged.
Emails we send
If you sign up with email and password, we send a verification email and, when you ask for one, a password reset email. Those are the only emails the service sends today. They are transactional, not marketing, and you are not added to any list.
Analytics
We count visits anonymously. This means page views only: no cookies, nothing stored on your device, and no profile of you is built. The counting runs through PostHog, in the EU. If we ever want to go further than an anonymous visit count, it will be behind a consent choice, and this notice will be updated before that happens.
Where your data is hosted
Your account and saved prompt-check data are hosted on Supabase (EU region) and Vercel. To run a test, your prompt is also sent to the model providers listed above, and, on the website, to Cloudflare for the bot check.
The closed-testing tester roster is hosted the same way, on Supabase (EU region) and Vercel.
What we never do
- We never sell your data.
- We never use your prompts to train our own models.
- We never let the model providers train on your prompts either. The API terms we run on exclude it.
- We never make sharing a default or a trick. It is always an informed choice, with a preview and a confirmation.
- We never handle your card details. When Pro launches, Stripe will process payments, not us.
Contact
Questions about your data, or a request about it: unfussylabs@gmail.com.