Skip to content

Public beta · 21 September 2026

Privacy notice

This notice explains what the Ma’atara Provenance beta processes. It distinguishes your source work from the fingerprints and signed records the service needs in order to provide provenance.

Files you protect or search

Image, video and writing source data is processed in your browser. Protect publishes signed capsules for images and video; writing uses a separate fingerprint registration authorized by your identity. Registration exposes fingerprints, identity references and record metadata. Detect sends image fingerprints and, when enabled, a semantic descriptor to the search service. These fingerprints are not the original file, but they should not be treated as anonymous: they can be compared with candidate material.

Identity and account data

Private key material and recovery data are encrypted in browser storage on each paired origin. The services process public keys, public Ma’atara identifiers, signed authorization records and device-registration metadata. During identity onboarding, the authentication service processes a Google or Microsoft account and retains a keyed email hash and redacted display value for accountability and recovery workflows.

Operational and payment data

When you contact an owner, the message and sender details are encrypted for that recipient, who can read your reply email. The service also processes your email to deliver a verification code and holds it temporarily during that flow. We process request timing, security events, coarse network information and rate-limit keys to operate and protect the beta. If you buy a plan, the payment provider processes payment details; Ma’atara receives transaction, subscription and entitlement records rather than your full card details.

Public and append-only records

A provenance claim is designed to be independently verifiable. Its public identifier, capsule, signature and chain metadata may therefore remain available after you stop using the service. Corrections and revocations are normally expressed by a later signed record rather than silently rewriting earlier evidence.

Service providers and retention

The beta uses infrastructure, identity and payment providers, including Cloudflare and, when you choose them, Google, Microsoft or Stripe. Records are retained for as long as needed to operate, secure and account for the service, subject to the integrity constraints described above. We do not promise that similarity fingerprints are confidential or impossible to correlate.

Your choices and contact

You can use public verification without creating an identity, decline an authorization request, and remove local browser data through your browser controls. Before removing it, follow the portal recovery guidance and secure your current recovery material; deletion can remove your only working signing identity. For access, correction, deletion or privacy questions, email trust@parable.social. Some public integrity records cannot be erased without invalidating the evidence they provide; we will explain any such limitation when responding.