Privacy Policy

Version 2.0 — effective August 23, 2026. All humanizes policies.

In plain language

  • We collect the text you submit, your account and billing identifiers, and usage records. We do not sell your data and we do not share it for advertising.
  • Your text is sent to the AI providers named in the Subprocessor list so the service can run. We do not train our own models on it, and those providers are engaged on terms that do not permit them to train on it either.
  • Content — history, samples and style profiles — is deleted automatically 180 days after it is created. Other categories have their own windows, all listed below.
  • You can export everything we hold and delete your account yourself, at any time, from your account page.
  • We set no advertising or analytics cookies and run no third-party analytics or advertising tags. First-party feature counters are aggregate and do not identify or follow a visitor.
  • Where you live changes what rights you have. Find your region in the annexes and read that one too.

Contents

  1. 1. About this policy
  2. 2. What we collect, and where it comes from
  3. 3. Why we use it, and our lawful basis
  4. 4. How your text is processed by AI
  5. 5. Automated processing and the writing-style profile
  6. 6. Who else sees it
  7. 7. International transfers
  8. 8. How long we keep it
  9. 9. How we protect it
  10. 10. If something goes wrong
  11. 11. Your rights, and how to use them
  12. 12. Children
  13. 13. Cookies and browser storage
  14. 14. Changes to this policy
  15. 15. Contact and complaints
  16. 16. EEA, UK and Switzerland
  17. 17. California
  18. 18. Other US states
  19. 19. Canada
  20. 20. Australia
  21. 21. Brazil

1. About this policy

This policy explains what personal data humanizes, the operator of humanizes.com (humanizes, we, us) collects when you use the humanizes website, applications and APIs (the Service), why we collect it, who else sees it, how long we keep it and what you can do about it. It applies to everyone who uses the Service, whether or not you have an account.

Unless an annex says otherwise, we are the controller of the personal data described here — we decide why and how it is processed. Where a business customer uses the Service to process personal data about other people, that customer is the controller and we act as their processor under the Data Processing Agreement.

Which annex applies to you

The core policy applies to everyone. Then read the annex for where you live — it adds rights and disclosures your law requires:

2. What we collect, and where it comes from

Every category of personal data we hold. Nothing outside this table is collected.
CategoryWhat is in itWhere it comes from
Account and identityEmail address, user id, name if you give one, sign-in method and authentication events, and the roles or entitlements attached to your account.You, and our authentication provider Clerk.
Content you submitThe text you paste or upload, the output we return, writing samples, the writing-style profile derived from them, and AI writer conversations and messages. This is free text — whatever it contains is your choice.You.
Usage and quotaWord and request counts, daily usage rows, plan allowance and entitlement state, feature usage, timestamps, and the outcome of a request (including scores).Automatically, as you use the Service.
BillingPlan purchased, subscription and customer identifiers, payment status, and the country used for tax. We never receive or store your card number — Stripe collects it directly.You, via Stripe.
Support and enquiriesContact-form messages, business and sales enquiries, and email correspondence with us.You.
Privacy requestsYour email address, what you asked for, a hash of the verification token, status, the reason for any refusal, and any appeal.You, through the privacy request form.
Technical and securityA rotating, salted pseudonym derived from your IP address (we do not store raw IP addresses for anonymous visitors), browser user-agent, rate-limit counters, API key metadata (keys themselves are stored only as a one-way hash), and tamper-evident audit records of security-relevant actions.Automatically, from your device and our servers.
Internal cost accountingWhat each request cost us at our AI providers, linked to the account that made it.Automatically.
Referral attributionIf you arrived through an affiliate link, the referral identifier attached to your purchase. See the Affiliate Disclosure.The link you followed.

We do not collect precise geolocation, biometric data, government identifiers, or advertising identifiers, and we run no third-party analytics or advertising tags. First-party feature counters are stored only as aggregate totals without a user, device, IP, text, score, or pseudonym. See the Cookie Policy for the complete list of cookies and browser storage.

Please do not paste sensitive data

The Service is a general-purpose writing tool. Do not submit payment card data, government identification numbers, health or medical records, biometric data, criminal-record data, or anyone else's personal data that you have no lawful basis to share. We are not a HIPAA business associate and not a PCI-DSS service provider. See Sensitive information in the Terms.

3. Why we use it, and our lawful basis

The lawful basis column matters most to readers in the EEA, the UK, Switzerland and Brazil; the purposes themselves apply to everyone.

PurposeCategories usedLawful basis
Running the Service: rewriting, drafting, scoring, style matching, keeping your historyContent, account, usagePerformance of our contract with you
Accounts, authentication and account securityAccount and identity, technicalPerformance of a contract; legitimate interests in securing accounts
Taking payment, managing subscriptions, preventing payment fraudBilling, accountPerformance of a contract; legal obligation (tax and accounting); legitimate interests in preventing fraud
Enforcing allowances, rate limits and fair useUsage, technicalPerformance of a contract; legitimate interests in keeping the Service available to everyone
Preventing, detecting and investigating abuse, including academic-integrity abuseUsage, technical, account, and content only where a report or a security signal makes it necessaryLegitimate interests in protecting the Service, other users and third parties
Answering support, sales and privacy requestsSupport, privacy requests, accountPerformance of a contract; legal obligation (responding to data subject requests)
Service and quality improvement using aggregate, non-identifying measuresUsage, technicalLegitimate interests in improving the Service
Internal cost accounting and capacity planningInternal cost accounting, usageLegitimate interests in running a sustainable service
Complying with law and defending or bringing legal claimsAny category, as strictly necessaryLegal obligation; legitimate interests in establishing, exercising or defending claims

Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights and have limited what we use accordingly. You can object — see Your rights. Where we rely on consent, you can withdraw it at any time without affecting what we did before you withdrew it.

We do not use your content for advertising, profiling for marketing, or any automated decision that has a legal or similarly significant effect on you.

4. How your text is processed by AI

To do what you asked, submitted or generated text is transmitted to the AI providers named in the Subprocessor list — an OpenAI model reached through the Replit AI Integrations proxy; optionally StealthGPT for a secondary rewriting pass on paid plans; and GPTZero, which receives generated candidate text for scoring during paid humanization when enabled and receives submitted text for a provider-backed AI detection request. Each receives only the text needed for the operation and delivery workflow.

  • We do not train our own models on your text.
  • Our AI providers are engaged on terms that do not permit them to train on it either.
  • Providers may retain content briefly for their own abuse monitoring, as their terms allow; we do not control those windows and we do not send them more than the operation requires.
  • How the models work, and what they cannot be relied on for, is set out in the AI Transparency Statement.

5. Automated processing and the writing-style profile

Two parts of the Service analyse your data automatically:

The writing-style profile
If you upload writing samples on a plan that supports style matching, we derive a profile of measurable features of your writing — sentence length distribution, vocabulary range, punctuation habits, tone — and use it to make output read more like you. It is derived only from samples you chose to upload, it is used only for your own requests, it is never shared with other users, and you can delete the samples and the profile at any time from your account page. Deleting the samples deletes the profile.
Scoring
Text is scored automatically for naturalness and, where you ask for it, for AI detection. A score is an estimate about a piece of text, not a judgement about you.
Abuse and rate limits
Automated limits can throttle or block a request. A decision to suspend or terminate an account is reviewed by a person — see Enforcement.

None of this produces a decision with legal or similarly significant effects about you within the meaning of Article 22 of the GDPR, and we do not use it for profiling for marketing.

6. Who else sees it

We do not sell your personal data

WE DO NOT SELL PERSONAL DATA, AND WE DO NOT SHARE IT FOR CROSS-CONTEXT BEHAVIOURAL ADVERTISING OR TARGETED ADVERTISING — NOT FOR MONEY AND NOT FOR ANY OTHER VALUABLE CONSIDERATION. WE HAVE NEVER DONE SO.

We disclose personal data only to:

  • Service providers (processors) who run part of the Service for us, each named — with what it receives and where it processes — in the dated Subprocessor list. They may use it only to provide their service to us.
  • Professional advisers — lawyers, accountants and auditors — under a duty of confidence, where needed.
  • Authorities and other parties, where we are legally required to, or where it is necessary to establish, exercise or defend a legal claim, prevent serious harm, or investigate a breach of the Acceptable Use Policy. We disclose the minimum required, and will tell you unless we are prohibited from doing so.
  • A buyer or successor, if the Service is sold, merged or reorganised. We will tell you before your data becomes subject to a different privacy policy, and the buyer is bound by this one until then.

7. International transfers

The Service is hosted in the United States, and the providers who process content for us are principally in the United States. If you use the Service from anywhere else, your personal data is transferred to and processed in the United States and possibly other countries where our providers operate.

Where personal data leaves the EEA, the UK or Switzerland, we rely on the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum for UK transfers and the Swiss adaptations for Swiss transfers, backed by the technical measures described in Security. Australian and Canadian transfers are covered by contractual accountability terms with each recipient. You can ask us for details of the mechanism that applies to a particular transfer at jakemorris@humanizes.com.

8. How long we keep it

An automated sweep enforces these windows — they are not aspirational. Each is measured from when the record was created unless stated otherwise.

WhatHow longThen what
Humanization history, writing samples, style profiles, AI writer conversations and messages180 daysDeleted automatically. You can delete any of it sooner from your account page.
Contact-form messages365 daysDeleted automatically.
Business and sales enquiries730 daysDeleted automatically.
Usage counters and daily word usage400 daysDeleted automatically. Needed for billing disputes and abuse investigation across a full year.
Internal API cost ledger400 daysDeleted automatically.
Privacy requests and appeals730 days after the request is closedDeleted automatically. Open requests are never aged out. Kept as the record that we answered you.
Idempotency recordsAbout 24 hoursExpire per record.
Queued jobsUntil the job lease expiresExpire per record.
Account, API key metadata, quota, plan and credit recordsFor as long as your account existsDeleted when you delete your account.
Security audit logIndefinitelyKept as a tamper-evident hash chain. Erasing it would destroy the integrity guarantee that makes it useful. After an account is erased, all that remains of it is the minimal fact that an identifier was erased, and when.

Where we are required to keep something longer — tax records, or material subject to a legal hold — we keep only that, only for as long as the obligation lasts, and we stop using it for anything else.

9. How we protect it

  • Authentication is managed by Clerk; every user-facing endpoint is scoped to the caller's own account, and administrative surfaces are behind a server-side allowlist.
  • Requests are schema-validated, database access is parameterised, and request bodies are size-limited.
  • HTTPS everywhere in production, with security headers including a content security policy and HSTS, and an explicit origin allowlist rather than a wildcard.
  • API keys are stored only as one-way hashes; secrets are held outside the repository.
  • Rate limits and per-account quotas contain both abuse and runaway cost.
  • Security-relevant actions are written to a tamper-evident, hash-chained audit log.

No system is perfectly secure, and we cannot guarantee that a determined attacker will never succeed. Report a suspected vulnerability to support@humanizes.com — please do not test against other people's accounts.

10. If something goes wrong

If personal data is breached, we contain it, assess the scope using the audit chain, and notify as the law requires: the relevant supervisory authority within 72 hours of becoming aware where the GDPR or UK GDPR applies and the breach is notifiable, affected individuals without undue delay where the risk to them is high, and the equivalent authority and individuals in Canada, Australia, Brazil and the relevant US states under their own tests. We then remediate and record what happened.

11. Your rights, and how to use them

Do it yourself, immediately

  • Export everything. Your account page produces a complete machine-readable copy of every category in the table above. The only things withheld are values that are credentials or ours rather than yours: one-way API-key and verification-token hashes, stored idempotent response bodies, and internal cost figures.
  • Delete your account. Also on your account page. It purges every table that holds your data, cancels billing, and cannot be undone. What survives is described under How long we keep it.
  • Delete individual items. History entries, writing samples and the style profile can each be deleted on their own.

Ask us

Wherever you live, you can ask us to give you access to your data, give you a copy, correct it, or delete it, and you can object to or ask us to restrict a particular use. Use the privacy request form — it works whether or not you have an account — or email jakemorris@humanizes.com. We verify the request by emailing you a link, and we answer within 30 days. If we refuse, we tell you why and you can appeal; appeals are answered within 45 days.

  • We verify by emailing a link to the address the data is held under. We do this because handing someone else's writing to whoever asks would be the worse failure. If we cannot verify you, we will say so rather than guess.
  • It is free. We may charge a reasonable fee, or decline, only for a request that is manifestly unfounded or excessive, or repetitive — and we will explain why.
  • An authorised agent may act for you with written authority, and we may still verify with you directly.
  • Exercising a right never costs you service, price or quality. See non-discrimination.

Your regional annex may give you more rights than this. If it does, they are additional to everything above, not instead of it.

12. Children

The Service is not for anyone under 18, and we do not knowingly collect personal data from anyone under that age. This floor is higher than many comparable services use, and is set deliberately: see Who may use the Service.

If you believe someone under 18 has given us personal data, tell us at jakemorris@humanizes.com and we will delete the account and its data promptly.

13. Cookies and browser storage

We use strictly necessary sign-in cookies and one functional preference cookie. There are no advertising, analytics, profiling or cross-site tracking cookies on this site. The complete list — including what is kept in your browser's local storage and never sent to us — is in the Cookie Policy.

14. Changes to this policy

Every version is published here with a version number, an effective date and a plain-language note of what changed; earlier versions stay listed under Version history. If a change materially affects how we use data we already hold, we will notify account holders by email or in-product notice at least 30 days before it takes effect, and where the law requires your consent we will ask for it rather than assume it.

15. Contact and complaints

Controller
humanizes, the operator of humanizes.com.
Privacy contact
jakemorris@humanizes.com, or the privacy request form.
Data protection officer
We are not required to appoint one at our scale and have not appointed one. Privacy questions go to the privacy contact above.
Security reports
support@humanizes.com

We would like the chance to fix a problem first, but you never have to come to us before complaining to your regulator. Your annex says which one that is.

Regional annexes

16. EEA, UK and Switzerland

This annex applies if you are in the European Economic Area, the United Kingdom or Switzerland. It supplements the core policy under the GDPR, the UK GDPR and the Data Protection Act 2018, and the Swiss FADP.

Controller and representative

The controller is humanizes, the operator of humanizes.com. We have not yet appointed an Article 27 representative in the EEA or the UK. Until we do, contact the controller directly at jakemorris@humanizes.com — we will not use the absence of a representative as a reason to delay a request.

Lawful bases

Set out purpose by purpose in Why we use it. We rely on contract, legitimate interests, legal obligation and — where stated — consent. We do not rely on consent for the core Service, so you do not lose access by withdrawing one.

Your rights

  • Access — confirmation of whether we process your data, a copy of it, and the information in this policy.
  • Rectification — correction of inaccurate data and completion of incomplete data.
  • Erasure — deletion where the data is no longer needed, you withdraw consent we relied on, you successfully object, or processing was unlawful.
  • Restriction — pause processing while accuracy or an objection is being resolved.
  • Portability — the data you gave us, in a structured, commonly used, machine-readable format, for data processed by automated means on the basis of consent or contract. The self-serve export satisfies this.
  • Objection — to processing based on legitimate interests, on grounds relating to your situation. We stop unless we can show compelling legitimate grounds that override your rights, or the processing is for legal claims. To direct marketing, an objection is absolute — but we do not send direct marketing.
  • Withdraw consent — at any time, where we relied on it, without affecting prior processing.
  • Not to be subject to solely automated decisions producing legal or similarly significant effects. We do not make any. See Automated processing.

Use the privacy request form — it works whether or not you have an account — or email jakemorris@humanizes.com. We verify the request by emailing you a link, and we answer within 30 days. If we refuse, we tell you why and you can appeal; appeals are answered within 45 days.

We answer within 30 days, which is inside the one-month statutory deadline. If a request is complex we may extend by up to two further months and will tell you why within the first month.

International transfers

See International transfers. Transfers to the United States rely on the Standard Contractual Clauses, with the UK Addendum and the Swiss adaptations as applicable, plus a transfer risk assessment and the technical measures in Security.

Complaints

You can complain to the supervisory authority in the EEA member state where you live, work, or where the alleged infringement happened; in the UK, to the Information Commissioner's Office; in Switzerland, to the Federal Data Protection and Information Commissioner. You can do this without contacting us first, and you can also go to court.

Other rights that are not privacy rights

Your statutory rights as a consumer sit elsewhere: the 14-day right of withdrawal and how it interacts with immediate access is in the Refund & Cancellation Policy; non-excludable liability and your right to use a national ADR body are in the Terms.

17. California

This annex applies if you are a California resident. It is our notice at collection and our privacy-policy disclosure under the California Consumer Privacy Act as amended by the CPRA. Terms such as *personal information*, *sale*, *share* and *service provider* have the meanings given in that Act.

Categories of personal information

Statutory categories, whether we collect them, and for what. Sources are listed in What we collect; business and commercial purposes are listed in Why we use it.
Statutory categoryCollectedWhat it is hereDisclosed to
A. IdentifiersYesEmail address, account id, a rotating pseudonym derived from IP address, referral identifierAuthentication, hosting, payment and email providers
B. Customer records (Civ. Code § 1798.80(e))YesName if given, email, billing identifiers. No card number, which Stripe collects directlyPayment and email providers
C. Protected classificationsNoNot collected
D. Commercial informationYesPlans and credits purchased, transaction records, usage against allowancePayment provider
E. Biometric informationNoNot collected
F. Internet or network activityYesRequest and usage records, rate-limit counters, feature usage, user-agent. No browsing history across other sites, and no advertising or analytics trackersHosting provider
G. Geolocation dataNoNo precise geolocation. Stripe derives a country for tax
H. Audio, visual or similarNoNot collected
I. Professional or employment informationOnly if you type itWe do not ask for it; free text you submit may contain anything you put in itAI processors, as part of the text
J. Non-public education informationOnly if you type itAs aboveAI processors, as part of the text
K. InferencesYes, narrowlyThe writing-style profile derived from samples you upload, used only to style your own outputAI processors, to produce your output
L. Sensitive personal informationLimitedAccount log-in credentials, handled by our authentication provider. We do not collect other sensitive categories, and we do not use any of it to infer characteristics about youAuthentication provider

Sale and sharing

We do not sell or share personal information

WE HAVE NOT SOLD PERSONAL INFORMATION, AND HAVE NOT SHARED IT FOR CROSS-CONTEXT BEHAVIOURAL ADVERTISING, IN THE PRECEDING 12 MONTHS OR AT ANY TIME. WE DO NOT DO SO NOW AND HAVE NO PLANS TO. WE DO NOT SELL OR SHARE THE PERSONAL INFORMATION OF CONSUMERS UNDER 16 — THE SERVICE IS NOT OFFERED TO ANYONE UNDER 18 AT ALL.

Sensitive personal information

We use the limited sensitive personal information described above only for purposes permitted without a right to limit — providing the Service you asked for, security, and preventing fraud — and never to infer characteristics about you. The right to limit the use of sensitive personal information therefore has nothing to bite on here, but you may still send us a limitation request and we will confirm the position in writing.

Retention

We do not keep personal information for longer than reasonably necessary. The specific period for each category is in How long we keep it, which is the per-category retention disclosure the CPRA requires.

Your California rights

  • Right to know — the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of recipient, for the 12-month period and beyond on request where it is not disproportionate.
  • Right to delete, subject to the statutory exceptions (for example completing a transaction, security, and legal compliance — see How long we keep it).
  • Right to correct inaccurate personal information.
  • Right to opt out of sale or sharing — there is none to opt out of, and we honour an opt-out signal anyway (below).
  • Right to limit the use of sensitive personal information, as described above.
  • Right to non-discrimination — we will not deny you the Service, charge you a different price, or give you a lower quality of service because you exercised a right. We offer no financial incentives for personal information.

Global Privacy Control

We set no cross-context advertising cookies, so there is no sale or share for a preference signal to stop. Where a browser sends Global Privacy Control or another recognised opt-out preference signal, we treat it as a valid opt-out request for any processing it applies to, and we will not start selling or sharing in the face of one.

How to exercise, agents, and appeals

Use the privacy request form — it works whether or not you have an account — or email jakemorris@humanizes.com. We verify the request by emailing you a link, and we answer within 30 days. If we refuse, we tell you why and you can appeal; appeals are answered within 45 days.

An authorised agent may submit a request with your written permission; we may ask you to verify your own identity and to confirm the agent's authority. We are not required to publish request metrics at our scale and do not do so.

18. Other US states

This annex applies if you live in a US state other than California that has a comprehensive consumer privacy law in force. During 2026 that includes Virginia, Colorado, Connecticut, Utah, Iowa, Indiana, Tennessee, Montana, Texas, Oregon, Florida, Delaware, New Hampshire, New Jersey, Nebraska, Kentucky, Rhode Island, Minnesota and Maryland, alongside California. The rights below track what those laws have in common; where your state gives more, your state wins.

The rights you have

  • Confirm and access the personal data we process about you.
  • Correct inaccuracies, taking account of the nature of the data and the purpose.
  • Delete personal data you provided or that we obtained about you.
  • Portability — a copy in a portable, readily usable format, where processing is automated. The self-serve export satisfies this.
  • Opt out of targeted advertising, of the sale of personal data, and of profiling with legal or similarly significant effects. We do none of the three, so there is nothing to opt out of — but the route stays open and we will confirm in writing.
  • Consent before processing sensitive data — we do not ask for sensitive data and do not process it for these purposes.

Your right to appeal a refusal

Most of these laws — Virginia, Colorado, Connecticut, Texas, Oregon, Montana and others — require us to give you a way to appeal if we refuse a request. If we refuse, our answer will tell you why and how to appeal. We answer appeals within 45 days, in writing, with the reasons. If we refuse the appeal, we will also tell you how to contact your state Attorney General to complain.

State-specific points

Universal opt-out mechanisms
Colorado, Connecticut, Montana, Texas, Oregon, New Jersey, Delaware, Minnesota, Nebraska, New Hampshire and Maryland require recognised opt-out preference signals to be honoured. We honour Global Privacy Control as an opt-out request. As there is no sale, share or targeted advertising here, honouring it changes nothing about what we do — which is the point.
Maryland
Maryland's Online Data Privacy Act imposes strict data minimisation — collection limited to what is reasonably necessary for the requested product — and bans the sale of sensitive data outright. We collect only the categories in What we collect and sell nothing.
Minnesota
You additionally have the right to ask us to explain the result of profiling, to review the personal data used, and to have it corrected and the profiling redone. We do not profile in a way that produces such decisions; ask and we will confirm that in writing.
Oregon
You may request a list of the specific third parties to which we have disclosed personal data. The Subprocessor list is that list, and we will confirm it for your account on request.
Texas and Utah
You have been given notice that we do not sell personal data. Texas also requires disclosure that a user is interacting with an AI system — see the AI Transparency Statement.
Nevada, Washington and health data
We are not a covered entity under the Washington My Health My Data Act or the Nevada consumer health data law and we do not knowingly collect consumer health data. Do not submit health information — see Sensitive information.

Use the privacy request form — it works whether or not you have an account — or email jakemorris@humanizes.com. We verify the request by emailing you a link, and we answer within 30 days. If we refuse, we tell you why and you can appeal; appeals are answered within 45 days.

19. Canada

This annex applies if you are in Canada. It supplements the core policy under PIPEDA, and under provincial law where it applies — Quebec's Law 25, and the personal information protection Acts of Alberta and British Columbia.

Accountability and consent

  • The person accountable for personal information, including for Quebec purposes, can be reached at jakemorris@humanizes.com.
  • We collect, use and disclose personal information for the purposes identified in Why we use it and no others without your consent. Creating an account and submitting text is express consent to the processing needed to run the Service; security, fraud prevention and legal compliance rely on implied consent or a statutory exception.
  • You may withdraw consent at any time, subject to legal and contractual restrictions and reasonable notice. Withdrawing consent to the processing the Service requires means ending your account.

Your rights

  • Access the personal information we hold about you and be told how it has been used and to whom it has been disclosed.
  • Correct inaccurate or incomplete information.
  • Portability (Quebec) — a computerised copy in a structured, commonly used technological format. The self-serve export satisfies this.
  • Automated decision transparency (Quebec) — to be told when a decision is based exclusively on automated processing and to make representations about it. We do not make such decisions; see Automated processing.
  • De-indexing or cessation of dissemination (Quebec), in the limited circumstances the law provides.

Transfers outside Canada

Personal information is processed in the United States and may be accessible to courts and authorities there under their law. We use contractual and security measures to give it a comparable level of protection, and we remain accountable for it. See International transfers and the Subprocessor list.

Breaches and complaints

We report a breach of security safeguards to the Office of the Privacy Commissioner of Canada — and to the Commission d'accès à l'information in Quebec — and notify affected individuals where it creates a real risk of significant harm, and we keep records of breaches as required. You can complain to us first at jakemorris@humanizes.com, and to the OPC, the CAI or your provincial commissioner at any time.

Use the privacy request form — it works whether or not you have an account — or email jakemorris@humanizes.com. We verify the request by emailing you a link, and we answer within 30 days. If we refuse, we tell you why and you can appeal; appeals are answered within 45 days.

20. Australia

This annex applies if you are in Australia. It supplements the core policy under the Privacy Act 1988 (Cth) and the Australian Privacy Principles.

  • What we collect and why (APP 1, 3 and 5) — set out in What we collect and Why we use it. We collect only what we need to provide the Service, and we collect it from you unless it is unreasonable or impracticable to do so.
  • Anonymity and pseudonymity (APP 2) — anonymous visitors are identified only by a rotating pseudonym, never a stored raw IP address. An account cannot be anonymous, because it must be paid for and secured.
  • Use and disclosure (APP 6) — only for the purposes described, a directly related purpose you would reasonably expect, or where the law requires it.
  • Direct marketing (APP 7) — we do not use your personal information for direct marketing. Emails we send are transactional.
  • Cross-border disclosure (APP 8) — we disclose personal information to overseas recipients, principally in the United States, listed in the Subprocessor list. We take reasonable steps to ensure they handle it consistently with the APPs, and we remain accountable for an act or practice that would breach the APPs.
  • Government identifiers (APP 9) — we do not collect or use them. Do not submit them.
  • Quality and security (APP 10 and 11) — see Security and How long we keep it; we destroy or de-identify personal information we no longer need.
  • Access and correction (APP 12 and 13) — self-serve, or through the routes below. We respond within 30 days and give written reasons if we refuse.

Notifiable data breaches — where a breach is likely to result in serious harm we notify affected individuals and the Office of the Australian Information Commissioner as the scheme requires.

Complain to us at jakemorris@humanizes.com first if you can; we will respond within 30 days. If you are not satisfied you can complain to the OAIC. Your non-excludable rights under the Australian Consumer Law are addressed in the Terms and the Refund & Cancellation Policy.

21. Brazil

This annex applies if you are in Brazil. It supplements the core policy under the Lei Geral de Proteção de Dados (Law 13.709/2018, LGPD).

Legal bases (Article 7)

  • Execution of a contract (Art. 7, V) — providing the Service, your account, billing and allowances.
  • Compliance with a legal or regulatory obligation (Art. 7, II) — tax records, responding to requests, breach reporting.
  • Legitimate interests (Art. 7, IX) — security, abuse prevention, and aggregate service improvement, balanced against your rights and limited to what is necessary.
  • Exercise of rights in proceedings (Art. 7, VI) — establishing or defending claims.
  • Consent (Art. 7, I) — only where stated, and revocable at any time.

Your rights (Article 18)

  • Confirmation that we process your data, and access to it.
  • Correction of incomplete, inaccurate or out-of-date data.
  • Anonymisation, blocking or deletion of unnecessary or excessive data, or data processed other than as the LGPD allows.
  • Portability to another provider, on request.
  • Deletion of data processed on the basis of consent, subject to the retention the law requires.
  • Information about the public and private bodies with which we have shared data.
  • Information about the possibility of refusing consent and the consequences of doing so.
  • Revocation of consent.
  • Review of decisions taken solely by automated processing — we do not take any; see Automated processing.

International transfer

Personal data is transferred to and processed in the United States, relying on contractual guarantees with each recipient — including standard contractual clauses where they apply — that reproduce the level of protection the LGPD requires, together with the measures in Security.

Person in charge and complaints

Requests and questions go to the person in charge of personal data processing (*encarregado*) at jakemorris@humanizes.com. We answer within 30 days. You may also petition the Autoridade Nacional de Proteção de Dados (ANPD) or a consumer protection body.

Use the privacy request form — it works whether or not you have an account — or email jakemorris@humanizes.com. We verify the request by emailing you a link, and we answer within 30 days. If we refuse, we tell you why and you can appeal; appeals are answered within 45 days.

Version history

  • v2.0 — August 23, 2026: Rewritten as a global core with regional annexes for the EEA/UK, California, other US states, Canada, Australia and Brazil. Removed an inaccurate disclosure of Google Ads measurement cookies — no Google Ads tag, advertising pixel, or third-party analytics tag exists on this site. Replaced the single 180-day claim with the full per-category retention table the automated sweep actually enforces. Added lawful bases, the recipient list, international transfer mechanisms, breach notification, automated-processing and writing-style-profile disclosures, and the appeal route for refused requests. Raised the age floor from 13 to 18 to match the Terms. Moved cookie detail into a standalone Cookie Policy and the vendor list into a dated Subprocessor list.
  • v1.0 — August 21, 2026: First published Privacy Policy: what we collect, how it is used, third-party processors, a 180-day content retention statement, security, user rights and a 13 age floor.