Privacy notice
Updated 7 September 2026
This notice describes how Provenance Lab handles information for the Maiastra research project. The project administrator is Nicolas Espinoza, who can be contacted at nicolas@masspredict.io.
Google sign-in and account information
When you use Google sign-in, the app receives your email address, its verification status and a unique Google account identifier. It uses these to verify your identity, match an existing invitation and connect your Google account to your project account. The Google identifier is stored with your account for later sign-ins.
Google sign-in requests only identity and email permissions. It does not request access to Gmail messages, Google Drive files, contacts or calendars. Google access and refresh tokens are not retained by the app.
Your project account also contains the name and email supplied by an administrator, your role and your access status. If you use a project password or personal API key, the app stores a hash rather than the original credential.
Research records and services
Your contributions, comments and research activity are shared within the project. Changes are attributed using your project name and email and retained in the research revision history.
The app runs on Vercel. Account records and research data are stored in the project’s private GitHub data repository; evidence files may also use Vercel Blob storage. These providers process information needed to host and operate the workspace, including technical request information.
If the research assistant is enabled, prompts and project content it retrieves are sent to OpenRouter and the selected model provider to produce responses. Authorized connected research tools can also access project content within their granted permissions. Research assistant transcripts are saved in the project.
Cookies and browser storage
An essential session cookie keeps you signed in for up to 14 days. Google sign-in uses an additional security cookie that lasts up to ten minutes and is cleared when the sign-in attempt returns. Your chosen colour theme may be saved in your browser. The app does not use advertising cookies.
Retention and your choices
Account information is retained while your project access is maintained. Research contributions and previous versions of records can remain in Git history and backups after an account is changed or removed.
Contact the administrator to request access to, correction of or deletion of your account information, or to deactivate your project access. Requests involving research records and revision history are reviewed with you. You can also remove the app’s Google authorization in your Google Account settings; this does not automatically remove records already stored by the project.