Skip to content
HUMAPS
Privacy-first by design

Privacy policy

Humaps works with public data. We collect only what is needed to provide and improve the service. We do not sell personal data or use advertising trackers, marketing cookies or third-party profiling.

1. What we collect

  • Account: Firebase Authentication stores the email address and name supplied during sign-in.
  • Conversation history: signed-in users can save and resume conversations. Anonymous conversations remain on the device.
  • Usage events: an opaque session ID, page path, event type and coarse country code may be recorded. We do not store a full IP address, fingerprint or third-party beacon.
  • Query text: prompts may be stored with a submitted-query event to help identify failures and missing sources.
  • Weekly intelligence: subscribers provide an email address and subscription status. Messages contain no tracking pixel.

2. Why we collect it

  • To authenticate users, save conversations, provide exports and enforce organization quotas.
  • To understand aggregate product usage and improve unreliable or missing data connections.
  • To answer access, correction, deletion and portability requests.
  • To send an optional weekly briefing after confirmed consent, with an unsubscribe link in every email.

3. Retention

  • Analytics events: scheduled for deletion after 90 days and removed by bounded server-side cleanup at API startup and every six hours while the service is active.
  • Conversations and authentication records: retained while the account exists or until deletion is requested.
  • Subscriptions: retained while active; after unsubscribe, a minimal suppression record may remain to prevent further mail.
  • Platform logs: retained for 30 days for incident response and do not contain request bodies or query text.

4. Service providers

We do not sell data. Necessary processors include Google Cloud and Firebase for hosting, storage and authentication; OpenAI for generating agent responses; Stripe for paid accounts; and Resend for transactional email and optional briefings. Payment details are processed by Stripe and do not pass through Humaps servers.

5. Your rights

Subject to applicable law, you may request access, correction, deletion, portability or restriction, and object to analytics processing. Email info@humaps.org. We respond within 30 days. EEA users may also complain to their national data protection authority.

6. Changes

Material changes will be announced in advance in the app. This English policy is the governing version and was last updated on July 30, 2026.

Last updated: July 30, 2026Read more about Humaps