Privacy Policy
HumanAuth lets humans approve AI-agent actions from their phone. To do that we collect the minimum we need to route an approval request to you and prove your decision. This page lists exactly what that is.
- Email address
You sign in with WorkOS AuthKit. WorkOS handles the sign-in itself; the HumanAuth platform stores the email address associated with your account.
- Account and device identifiers
A HumanAuth account identifier (human_id), a device identifier (device_id), and your device's model name, which is used as a human-readable label when your device is registered.
- Push notification tokens
A push token for your device so we can deliver approval requests to your phone. Delivery goes through the Expo push service, which hands off to Apple (APNs) on iPhone and iPad and Google (FCM) on Android.
- User content
Your approval and denial decisions, optional reasons you attach to a denial, responses you submit to collect forms sent by an agent, and notes you include when reporting abuse.
- Server logs
Our servers record standard request metadata — your IP address and User-Agent string — in server logs.
- Contact details you send us
If you submit a form on humanauth.ai asking for access or support, we store the email address you enter, anything you type into the optional segment and message fields, which page you submitted from, the referring URL, and your User-Agent. We keep a one-way hash of your IP address to spot repeated abuse, never the address itself. The longer form on /access is hosted by Tally, so what you type there reaches Tally first and then us — including your organisation, your role, and what you write about your agent. We use all of this only to reply to you and to set up an account if you asked for one. It is not sold, and it does not go into a marketing list you did not ask for. Ask us and we will delete it.
- The HumanAuth mobile app contains no analytics or tracking SDKs.
- We show no ads.
- We do not sell your data.
- We do not use your data to track you across other companies' apps or websites.
This marketing website (humanauth.ai) uses Google Analytics to measure aggregate site traffic. The mobile app does not.
We use the service providers below to run HumanAuth. Each processes data only to provide its service to us.
- WorkOS
Authentication (sign-in)
- Cloudflare
Hosting and infrastructure
- Tally
Hosting the access-request form on humanauth.ai/access
- Cal.com
Hosting the demo-booking page linked from the site
- Resend
Delivering the internal alert that tells us you asked
- Expo push service
Routing approval notifications to Apple and Google
- Apple Push Notification service (APNs)
Delivering notifications on iPhone and iPad
- Google Firebase Cloud Messaging (FCM)
Delivering notifications on Android
All data in transit is protected with TLS, and our infrastructure encrypts stored data at rest. Approval decisions are signed with an ed25519 key that is generated and stored on your device.
Request content — action labels and descriptions, denial reasons, responses to collect forms, and abuse-report notes — is not end-to-end encrypted. It is encrypted in transit and at rest by our infrastructure, but the platform processes and stores it in plaintext so it can route requests to you and build the audit trail. We treat it as sensitive; do not place secrets in a request payload.
We keep your account data until you delete your account. Some records are retained beyond deletion for integrity and audit purposes, so that past approvals remain verifiable: signed approval receipts, the request records they refer to (the action label and its description), and security audit events (including the IP address and User-Agent recorded for security-significant actions). After you delete your account these keep only a pseudonymous account reference, and we sever its link to your email and identity by deleting your account record. The account deletion page lists this in full.
You can delete your account in the app (Settings → Delete account) or by following the steps on our account deletion page, which also covers what to do if you no longer have access to your device.
If we change this policy we will update it here and revise the effective date above.
Questions about this policy or your data: support@humanauth.ai