AUTOPULSE / privacy
Less data. A clearer boundary.
Your separate AutoPulse account
When configured, Clerk manages AutoPulse sign-in and credentials in a separate AutoPulse identity. The dedicated AutoPulse account database stores your Clerk user ID, Stripe customer/subscription identifiers and paid-access status. Passwords and full payment-card details are not stored in this application database. Stripe hosts checkout and subscription management.
Paid private workspace
Client promise labels, authorised event metadata, immutable reviews and investigation acknowledgements persist in the dedicated AutoPulse database, scoped to the authenticated account. They are not shared with another customer or the internal Preview workspace. Only submit pseudonymous identifiers, timestamps, counts and statuses. Do not send personal records, message content, payment details or provider credentials. Signing verifies an assertion’s integrity, not the truth of a destination record.
No automatic retention period or self-service deletion control is claimed. Closing the tab does not delete stored account evidence. Contact admin@provhq.com for access or deletion requests; payment records may have separate provider retention requirements. Account deletion in Clerk alone is not represented as automatically erasing retained application records.
The browser-only outcome workbench processes selected metadata files in this browser session. It does not send their contents to an AutoPulse API, a model provider or an analytics service. Customer evidence is not written to localStorage, cookies or server storage by that file-assessment flow.
Separate internal event preview
The internal event surface is different: it explicitly sends contracts and signed metadata to a dedicated Preview database. Contracts, events, evidence reviews and acknowledgement actions persist there and are accessible to authorised internal operators behind hosting protection. Closing its tab does not delete stored metadata. It is not an individual customer account system. Use synthetic or authorised non-personal metadata only; no automatic retention or deletion policy is represented as implemented.
Bring metadata, not customer records
Only opaque event/correlation IDs, timestamps, counts and statuses are needed. Use pseudonyms for client and workflow labels. IDs and filenames can still identify people, so remove personal information before selecting a file. Do not include passwords, API keys, financial details or message bodies.
What clearing means
Clear session removes the app’s in-memory assessment. Reloading or closing the tab also discards it. This does not delete your original files, change your source systems or guarantee forensic erasure from the browser or operating system.
Client-report drafts and downloads
The report preview and optional commentary are prepared in browser memory. Commentary and proposed follow-up are operator-authored, not source evidence or stored database actions. Downloading HTML or JSON deliberately copies the selected assessment, its complete evidence and your notes to your device. It does not email or publish them. Review the draft and identifiers before sharing. Clear/reset cannot delete exported copies, which are outside the app’s retention boundary. Selecting another review or replacing the evidence discards the local draft; closing its preview alone does not.
Hosting and preview access
The hosting provider receives normal page requests and may process IP addresses and access logs. Clerk uses authentication cookies for account sessions. The separate internal Preview remains behind hosting access protection; that is not a customer login. Browser extensions and device software are outside this app’s processing boundary.
Not included
No behavioural analytics, session replay, model calls, connected CRM credentials or marketing email are enabled in this outcome workbench. The account page displays current billing configuration and verified subscription status; the public sample does not create paid access.