Legal
Effective date: August 16, 2026. This policy describes how Provix collects, uses, and protects information when you use our verified candidate intelligence platform.
When you create an account or complete onboarding, Provix collects account information through Supabase authentication and profile fields you provide — such as your name, email, role, experience level, skills, portfolio links, and employer or candidate profile details.
For candidates, Provix may process GitHub and proof-of-work metrics when you submit repositories or portfolio URLs for screening. This can include repository metadata, commit activity samples, language signals, README excerpts, and derived technical indicators used to generate integrity and execution scores.
We also collect usage data when you interact with the platform, including pages visited, feature usage (such as talent pool browsing, deep screening requests, and job matching), device and browser type, and standard server logs generated during normal operation.
Provix uses collected information to operate the platform and deliver its core services: generating verification and integrity scores, producing employer interview cheat sheets, matching candidates to open roles, and displaying relevant talent pool results.
Profile and screening data help employers evaluate proof-of-work signals before outreach, while candidate data helps personalize job recommendations, application workflows, and visibility settings within the talent pool.
We may use aggregated or de-identified usage data to improve product performance, reliability, and user experience. We do not sell personal information.
Provix relies on trusted infrastructure and service providers to run the product:
Supabase — authentication, database storage, and row-level security for profile and application data.
Vercel — application hosting, edge delivery, and deployment infrastructure.
Google Gemini AI — AI-assisted screening, matching, essay review, college fit analysis, and related structured outputs sent through our API routes.
GitHub API — repository metadata and public code signals used during proof-of-work and deep screening workflows when candidates or employers provide GitHub URLs.
These providers process data only as needed to deliver their services to Provix and are subject to their own privacy and security practices.
Provix applies industry-standard safeguards to protect your information, including encrypted transport (HTTPS/TLS), access controls, and Supabase Row Level Security (RLS) policies that restrict profile access to authorized users and permitted application flows.
Authentication credentials are managed by Supabase Auth; Provix does not store raw passwords in application code.
We retain account and profile data for as long as your account remains active or as needed to provide services, comply with legal obligations, resolve disputes, and enforce our agreements. You may request deletion of your account data subject to applicable law and operational requirements.
Depending on your location, you may have rights to access, correct, export, or delete personal information we hold about you, or to object to certain processing activities.
To exercise these rights or ask questions about this policy, contact us at support@provix.app. We will respond within a reasonable timeframe.
We may update this Privacy Policy from time to time. Material changes will be reflected on this page with an updated effective date.