Privacy Notice
Last updated: 27 July 2026
This notice states exactly what Provely (provely.dev, an Unfussy Labs product) does with your data. It describes the service as it runs today, not as it might run later. Where a feature is not live yet, this notice says so.
Provely on provely.dev is a single tool, Skill Check: an evidence-backed review of an AI agent skill.
You can use Provely without an account
Anonymous use is never gated. You can review an AI agent skill without signing up, without giving a name, and without giving an email, by uploading a folder or ZIP, or by linking a public GitHub repository or subfolder. Creating an account is optional, and it exists only to save your reviews so you can read them back later.
Accounts are shared with provely.app
Provely.dev shares its accounts with provely.app, our prompt checker, because both are the same Provely account system. The same sign-in works on both sites. If you already have a Provely account, it works here with no new sign-up, and if you create one here it works there too. Deleting your account removes it from both sites at once.
Closed testing: a passcode and a tester email
While Provely is in closed testing, the whole site sits behind a passcode screen. To get in, you enter the current passcode and an email address. That email is recorded on a private tester roster so we know who is testing the product. It is not verified, it is not used to sign you in, and we do not use it to email you or add you to any list.
This gate is temporary. It exists only for the closed-testing period, and this notice will be updated once it is switched off.
The waitlist
The waitlist is separate from the passcode gate and separate from having an account. Joining it stores one row: your email address, whether you ticked the optional box to hear about other Unfussy Labs products, when you signed up, roughly where the signup came from (which page), and the time we sent your welcome email.
We send you one welcome email and nothing else from the waitlist itself. The optional box is off unless you tick it, and it only governs the wider Unfussy Labs news, not the waitlist.
The row stays until you ask us to remove it. To come off the list, reply to the welcome email and say so, or write to unfussylabs@gmail.com, and we will delete the row.
Joining the waitlist does not create an account, and deleting an account does not remove a waitlist row, because the two are not linked to each other. If you have done both and want both gone, say so and we will remove both.
If you create an account
You can sign up with an email address and password, or with Google or GitHub. When you do, we store the email address tied to your account, the username you choose, an optional display name and avatar, and which method you signed in with. Email sign-up asks you to verify your email before the account is active, and sign-up is protected by a bot check (Cloudflare Turnstile).
You stay in control of the account. You can change your password and delete the account at any time from your profile. Deleting the account removes your profile and the reviews saved to it, across both provely.dev and provely.app. Two things are not covered by it, and they are listed in "What deleting your account does not reach" below.
What deleting your account does not reach
Deleting your account is immediate and permanent. It removes your profile, your saved reviews and their drafts, and your saved checks on provely.app. A few things sit outside it, and we would rather say so here than have you find out later:
- A skill you explicitly submitted to the public skill library stays. It was submitted to a shared collection, so deleting your account does not withdraw it. What we do remove is the link to you: the submission is de-attributed and no longer connected to any account. If you want the skill itself taken down as well, ask us and we will remove it, exactly as described under "The public skill library is opt-in" below.
- Rows keyed on your email address are separate from your account. The waitlist row and the closed-testing tester roster are stored against an email address, not against a user, so account deletion does not touch them. Ask us and we will remove them.
- A one-way fingerprint of a share page we removed stays. If we take down a share page you published because it broke our rules, we keep a content hash of that page so the same content cannot simply be re-published. It is a one-way fingerprint with no readable content and no link to you: no email, no account, nothing that can be turned back into the page or into who you are. It exists only to keep a removed page removed.
For both, one email to unfussylabs@gmail.com is enough, and you do not need an account to send it.
What we store, and for how long
If you are signed in when a review completes, we save that review to your history: the skill name, the source you gave us (a folder label or a public GitHub link and its resolved commit SHA), the review's token counts and estimated cost, when it ran, and the report itself. The report is what you saw on screen, including the findings, the verdict and the short quotes from your own files that each finding is anchored to. We also save the SKILL.md file the review read, with secrets already stripped, so a saved review can be reopened and improved rather than only read. If you then draft an improved version of that file, we save the draft alongside it. This is what lets you reopen a past review. We also save a fingerprint of the files the review read, which is a one-way hash and holds no readable content, so that re-submitting the identical skill can show you the review you already have instead of paying to run it again. Only your own account can read any of it.
How long we keep it: a saved review, and any draft saved with it, is kept until you delete your account. There is no other expiry. We do not age them out, and we do not delete them on a schedule, so a review you saved is still there whenever you come back for it.
Deleting a single review is not built yet, so today the way to remove saved reviews is to delete the account, which deletes every one of them with it. Reviews that completed before 26 July 2026 kept only the summary and not the report, so those cannot be reopened.
If you are not signed in, nothing about the review is saved, with one exception: if you opt the reviewed skill into the public skill library, we store that submission. See "The public skill library is opt-in" below for what an opt-in stores. Otherwise the server reads the selected reviewable text in memory for the duration of the request, returns the report to your browser, and keeps nothing.
Binary assets are excluded from model review. Uploaded scripts are read as text where relevant and are never executed.
Secrets are scrubbed before storage
Before we store or submit reviewable text, we scan the skill files for obvious secrets, such as API keys, and strip them out. When that happens, we show you a warning. Please still avoid submitting credentials: automated scrubbing catches common patterns, not everything. The same scrubbing runs on a skill you add to the public skill library, and on its name, before either is stored.
The public skill library is opt-in
A review is private by default. It is returned to your browser, and, if you are signed in, saved to your own account history. We do not publish it or show it to anyone else.
We are building a public skill library. When a review finishes, we offer to add the reviewed skill to it. This is opt-in and off unless you turn it on. We ask once per review, and nothing is stored for the library unless you turn it on and confirm.
If you opt in, we store:
- the reviewed SKILL.md, with obvious secrets stripped out;
- the skill's name, with obvious secrets stripped out;
- the review's verdict and a small summary of its findings, which is counts only, not the full report and no skill content beyond the SKILL.md itself;
- the time you opted in;
- if you are signed in, a link to your account, so that a reward can reach you if your skill is featured.
If you opt in without an account, the submission is not linked to you. It is stored on its own, with no account behind it.
Every submission is stored as pending. Nothing you opt in is shown to anyone else at that point. A submission becomes visible to other people only after we review it and publish it. The public browse and download library is still being built. Once it exists, a published skill can be viewed, used, and downloaded by other people.
We keep a submission until it is removed. You can ask us to remove a submitted skill at any time by emailing unfussylabs@gmail.com, and we will remove it. We may also decline, reject, or remove a submission ourselves. We do not sell submitted skills, and we do not use them to train our own models.
Sharing a result is opt-in
Separately from the library, you can publish a result as a public page with its own link. This is opt-in too, it takes an explicit click, and nothing is published until you make it.
A share page holds a deliberately narrow snapshot of the review, and it is not the report:
- the skill's name;
- the verdict and its one-line reason;
- how many findings there were, at each severity, and their titles;
- the routing score, and which guideline version the review used;
- the date, and the display name you chose to sign it with, if you chose one.
Before anything is published, we show you the page exactly as it will read, including every finding title, and publishing is a second, separate click after that. Finding titles are written by the model about your skill, so read them: if one says more than you want public, do not publish.
It does not hold your skill files, any quote from them, your SKILL.md, the inferred purpose of your skill, the file inventory, the recommended fixes, the source you gave us, or anything from your account. If you do not type a display name, the page carries no name at all. A display name can only be attached when you are signed in.
A share page is public and meant to be found: search engines may index it, and anyone with the link can open it without an account.
Only a passing result can be published. A result that did not pass has no share page.
You can take a page down. If you were signed in when you published it, do that from the same share menu on the review; either way, emailing unfussylabs@gmail.com is enough. A page you take down stops working immediately, and its link is never reused. You can publish that same result again later if you change your mind, and it gets a new link. A page we remove cannot be republished. Deleting your account also removes the pages you published while signed in.
Daily limits and your IP address
Daily limits are keyed to a salted hash of your IP address. We do not store your raw IP address. The hash lets us count usage per day without holding the address itself.
For what today's limits actually are, and how they can rise, see the Usage limits page.
The review step uses a bot check
The review step, where we send skill text to the model, is protected by Cloudflare Turnstile, a bot check. It is there to stop automated abuse.
Where your skill files are sent
When you run a review, the reviewable skill text is sent only to Anthropic (Claude Sonnet 5), which processes it under its own API terms to return the review. A separate trigger-routing simulation sends only the skill's name and description, along with generated test prompts, to Anthropic's Claude Haiku. Everything goes to Anthropic and to no other model provider, under Anthropic's API terms. We test on these Anthropic models and we say so.
Donations and the community pool
Provely is free, and donations do not change that: they are voluntary, and they do not buy anyone extra usage. If Provely has been useful to you, you can choose to chip in through Ko-fi. Payments are handled by Ko-fi and Stripe, under their own terms; we never see your card details and never process the payment ourselves.
What we keep is a single, minimal record for each confirmed donation: the transaction ID, the amount, the currency, and when it was received. We do not store your name, email or any message, even though Ko-fi's own form may ask for them; that information stays with Ko-fi and Stripe, not with us.
Everything given goes into a shared community pool. When the pool covers a month's model costs, we raise the daily usage limits for everyone, not just for people who gave. Provely is free today; see the Terms of Use for how that could change in future. See the Support page for how the pool works.
Emails we send
Here is every email the service can send you today:
- a verification email, when you sign up with email and password;
- a password reset email, when you ask for one;
- one welcome email, if you join the waitlist. It is sent once and there is no second one.
That is the whole list. All three are transactional, not marketing, and none of them adds you to a mailing list. If you tick the optional box on the waitlist form, you are also telling us we may send you occasional news about other Unfussy Labs products; that box is off unless you tick it, and you can ask us to stop at any time.
We also send ourselves operational alerts, such as a note when the day's model costs cross a threshold we set. Those go to us, not to you, and they contain no information about you or your skills.
If you make a donation through Ko-fi, any receipt comes from Ko-fi or Stripe, not from us: we do not hold an email address to send you anything, because we do not store one.
Analytics
We count visits anonymously. This means page views only: no cookies, nothing stored on your device, and no profile of you is built. The counting runs through PostHog, in the EU. If we ever want to go further than an anonymous visit count, it will be behind a consent choice, and this notice will be updated before that happens.
Where your data is hosted
Your account and saved review data are hosted on Supabase (EU region) and Vercel, the same shared account store used by provely.app. To run a review, the reviewable skill text is also sent to Anthropic, and to Cloudflare for the bot check. Community pool donation records, public skill library submissions, and the closed-testing tester roster are hosted the same way, on Supabase (EU region) and Vercel.
What we never do
- We never sell your data.
- We never use your skill files to train our own models.
- We never add a skill to the public library unless you opt in. It is off by default and asked for each review.
- We never publish a result. A result becomes a public page only when you choose to publish it, and even then it never carries your files or your account.
- We never let a donation buy extra usage. Support goes to a shared pool, not to a personal limit.
Contact
Questions about your data, or a request about it: unfussylabs@gmail.com.