Privacy Policy

Effective July 4, 2026 · updated September 14, 2026

HumanAuth lets humans approve AI-agent actions from their phone. To do that we collect the minimum we need to route an approval request to you and prove your decision. This page lists exactly what that is.

What we collect
What we don't do

This marketing website (humanauth.ai) uses Google Analytics to measure aggregate site traffic. The mobile app does not.

Who processes your data

We use the service providers below to run HumanAuth. Each processes data only to provide its service to us.

Security

All data in transit is protected with TLS, and our infrastructure encrypts stored data at rest. Approval decisions are signed with an ed25519 key that is generated and stored on your device.

Request content — action labels and descriptions, denial reasons, responses to collect forms, and abuse-report notes — is not end-to-end encrypted. It is encrypted in transit and at rest by our infrastructure, but the platform processes and stores it in plaintext so it can route requests to you and build the audit trail. We treat it as sensitive; do not place secrets in a request payload.

Retention

We keep your account data until you delete your account. Some records are retained beyond deletion for integrity and audit purposes, so that past approvals remain verifiable: signed approval receipts, the request records they refer to (the action label and its description), and security audit events (including the IP address and User-Agent recorded for security-significant actions). After you delete your account these keep only a pseudonymous account reference, and we sever its link to your email and identity by deleting your account record. The account deletion page lists this in full.

Deleting your account

You can delete your account in the app (Settings → Delete account) or by following the steps on our account deletion page, which also covers what to do if you no longer have access to your device.

Changes to this policy

If we change this policy we will update it here and revise the effective date above.

Contact

Questions about this policy or your data: support@humanauth.ai