Privacy Policy
Last updated: August 2026
How Modern Ancients LLC collects, processes, and protects personal information within the SOVEREIGN\\PROVENANCE ecosystem.
TL;DR
- •We collect account data, uploaded content, payment-related billing metadata, and automatically generated provenance metadata
- •We do not sell your personal information or use it for advertising
- •We do not train AI models on your content for unrelated products
- •Immutable provenance records cannot be deleted once created
- •Core processors include authentication, hosting, payments, and email providers
- •You can exercise access, correction, deletion (where feasible), and opt-out rights
1. Who We Are
This Privacy Policy explains how Modern Ancients LLC ("we," "us," or "our") collects, processes, and protects personal information when you use SOVEREIGN\PROVENANCE and its product lines—Mirror (The Provenance Console), Fractal (Artifact Context Layering), Anchor (Core Provenance Protocol)—and related websites, APIs, diligence consoles, and services (the "Service").
For enterprise customers that execute our Data Processing Addendum, roles of Controller and Processor are described in the DPA.
2. Information We Collect
A. Information You Provide
- Account details (name, email, organization, role)
- Profile and workspace settings
- Files, text, images, datasets, artifacts, and other content you upload
- Metadata you supply (titles, tags, authorship statements, questionnaire responses)
- Communications with us (support requests, forms, investor or partner inquiries)
- Billing contact details and plan selections for paid features
B. Authentication & Identity Data
When you sign in with email/password or a third-party identity provider (such as Google, GitHub, Apple, or Facebook), we receive identifiers and profile information those providers share with us (typically name, email, and provider account ID), plus session and security signals needed to maintain your login.
C. Automatically Generated Provenance Metadata
Consistent with provenance workflows, the Service may automatically generate:
- cryptographic hashes and timestamp receipts
- lineage logs, version manifests, and proof bundles
- authorship-intent metadata
- synthetic / AI visibility indicators
- audit and evidence export packages
This metadata is required for the platform to function and may become immutable.
D. Device, Usage & Security Data
- IP address, browser, device, and operating system information
- session logs, request metadata, and approximate location derived from IP
- workflow execution order and feature usage
- security-relevant telemetry (rate limits, abuse signals, authentication events)
- optional first-party analytics events when permitted (see Cookies policy)
E. Payment Information
Paid plans are processed by Stripe (or another designated processor). We receive billing metadata such as subscription status, plan, invoices, and limited payment method descriptors. Full card numbers are handled by the payment processor, not stored on our application servers.
F. Connected Applications
If you authorize OAuth clients, MCP clients, or other integrations, we process the scopes and data necessary to provide that connection, including tokens and access logs.
3. How We Use Information
We use collected data to:
- Operate and improve the Service: accounts, provenance workflows, proof generation, lineage, dashboards, diligence surfaces, and support
- Security, trust, and abuse prevention: detect forged provenance, harmful uploads, fraud, and account compromise
- Compliance & immutable storage: store provenance records (including IPFS / timestamp networks where enabled)
- Assistive AI features: integrity scoring, synthetic detection signals, lineage insights, and similar analysis of content you submit to those features
- Billing & entitlements: process payments, manage subscriptions, and enforce plan limits
- Communication: send operational updates, security notices, and support responses; marketing only where permitted and with opt-out
- Analytics: understand product usage to improve reliability (first-party, non-advertising; subject to consent / signals where required)
We do NOT:
- Sell your personal information
- Use your personal information for third-party advertising or ad profiling
- Train foundation models on your content for unrelated third-party products without explicit agreement
- Distribute your content beyond what is needed to operate provenance workflows and features you enable
4. Legal Bases (EEA/UK and Similar)
Where required, we process personal data under one or more of:
- Contract: to provide the Service you request
- Legitimate interests: security, product improvement, fraud prevention (balanced against your rights)
- Consent: where required for optional analytics, certain cookies, or marketing
- Legal obligation: when we must retain or disclose information under law
5. Sharing & Disclosure
We do not sell or rent personal information. We may share information only:
- With your consent or direction: integrations, external timestamping, archival options, or sharing you enable
- With service providers (processors): vetted providers who help us host, authenticate, process payments, send email, store data, compute, or secure the Service under confidentiality and data-protection terms
- Within your organization: workspace admins and members according to roles you configure
- For legal compliance: court orders, lawful requests, or to protect rights, safety, and provenance integrity
- Business transfers: in connection with a merger, acquisition, or asset sale, subject to continued protection of personal information
Core Categories of Processors
Depending on configuration, processors may include:
- Authentication & database / hosting: Supabase and related cloud infrastructure
- Payments: Stripe
- Transactional email: Resend or equivalent email delivery providers
- Decentralized / public networks you enable: IPFS gateways/nodes and OpenTimestamps (or similar) networks—note that public anchoring may make proofs globally retrievable by design
- Identity providers you choose: Google, GitHub, Apple, Facebook, etc.
A current subprocessor list for enterprise customers is available upon request and as described in the DPA.
6. Cookies, Local Storage & Analytics
We use cookies and local storage for authentication, session integrity, security, preferences, and—where permitted—optional first-party analytics. We respect browser Do Not Track and Global Privacy Control signals for optional analytics where technically feasible.
We do not use advertising cookies or sell personal information for cross-context behavioral advertising. Details and preference controls are in our Cookies, Tracking & Local Storage Policy.
7. Data Security
We employ technical and organizational controls aligned with provenance principles, including:
- encryption in transit and at rest where applicable
- cryptographic hashing and tamper-evident logs
- access controls, monitoring, and rate limiting
- isolation of sensitive processes
No system is perfectly secure. Additional detail is in our Security Policy.
8. Data Retention
Account data: retained until your account is deleted, subject to legal holds and backup cycles.
Content you provide: deleted when requested or when your account is closed, unless incorporated into immutable provenance records or required for legal/security reasons.
Provenance-specific artifacts: hashes, timestamp receipts, manifests, lineage logs, proof bundles, and archived objects written to immutable or public networks cannot be deleted once created. This is a core function of the Service.
Billing records: retained as required for tax, accounting, and dispute resolution.
See the Data Retention & Deletion Policy and Immutable Data Policy.
9. Your Rights
Depending on your jurisdiction (including GDPR, UK GDPR, CCPA/CPRA, and similar laws), you may request:
- Access to your personal data
- Correction of inaccurate data
- Deletion of non-immutable data
- Export or portability of data
- Restriction or objection to certain processing
- Withdrawal of consent where processing is based on consent
- Appeal or complaint to a supervisory authority
California residents: We do not sell personal information or share it for cross-context behavioral advertising as those terms are commonly defined. You may request know/access, delete, and correct rights. We will not discriminate against you for exercising privacy rights. Authorized agents may submit requests as permitted by law with verification.
Immutable provenance artifacts cannot be deleted, including hashed digests, timestamp receipts, manifests, lineage logs, proof bundles, and archived IPFS/OTS objects. We will still delete or de-identify associated personal content in mutable systems where feasible.
To exercise rights, email legal@modernancients.com. We may need to verify your identity. See also the Consent & User Rights Policy.
10. International Data Transfers
We may process information in the United States and other countries where we or our processors operate. Where required, we use appropriate safeguards (such as Standard Contractual Clauses) for cross-border transfers.
Sovereign zones and jurisdictional proof boundaries (if enabled) may limit where certain proofs or metadata propagate. Public decentralized timestamping or archival may still make proofs globally retrievable by design.
11. Children's Privacy
The Service is not intended for individuals under 18. We do not knowingly collect personal data from children. If you believe a child has provided personal information, contact us and we will take appropriate steps.
12. Third-Party Links & Services
The Service may link to third-party sites or rely on networks you enable (identity providers, payment pages, IPFS/OTS). Their privacy practices are governed by their own policies.
13. Policy Changes
We may update this policy periodically. The "Last updated" date reflects the most recent changes. Material changes will be posted on this page; where required, we will provide additional notice.