Privacy Policy
Last updated: August 14, 2026 · Effective: August 14, 2026
The short version
Humanit rewrites text, checks whether text reads as AI-written, paraphrases, summarizes, and fixes grammar. The text you submit is sent to Google's Gemini API to perform the operation you asked for.
If you are signed in, we do store a copy of your recent runs on our servers (your input, the result, and the tool used) so your history page works. You can delete any run, or all of them, at any time from your account page. We do not sell your data, we do not use it to train any AI model, and our session-recording tool masks every text box and result panel so your writing never enters a replay.
The AI detector is free and requires no account. The other four tools require a free account.
1. Who we are
Humanit ("Humanit", "we", "us", or "our") operates the website and web application at https://humanit.app and the Humanit browser extension (together, "the Service").
This policy explains what the Service collects, how it is used, who it is shared with, and what rights you have. By creating an account or using the Service, you agree to the practices described here.
Note on our iOS app. The Humanit iOS app is a separate product with a different data model (it stores history on your device and bills through Apple). It is governed by its own privacy policy at https://humanit-legal.vercel.app/privacy — not by this one.
2. What we collect
2.1 Account information
- Email address, and a securely hashed password if you sign up with email. We never store your password in readable form.
- Google account details if you choose "Continue with Google" — your email address, name, profile picture, and Google account identifier. We do not receive your Google password and we request no access to Gmail, Drive, Contacts, or any other Google service.
- Account state — your word balance, how many of your 300 free monthly words you have used, when your free cycle resets, and your current plan and renewal date.
2.2 Text you submit
- Your input and the result. When you are signed in, each run is saved to our database with the tool used, the mode, your input text, the result, and the word count. See Section 10 for full detail and Section 7 for how long we keep it.
- Writing samples for "Match my style." If you set up a style profile, the writing samples you provide and the resulting style card are stored on your account until you delete them.
2.3 Payment information
Purchases are processed by Dodo Payments, our merchant of record. Your card number, CVC, and billing address are entered on Dodo's hosted checkout and are never sent to or stored on our servers. We receive and store only a record of the transaction: which product was bought, the amount and currency, the payment identifier, and the email address on the purchase.
2.4 Usage and analytics
- Product analytics (PostHog). Page views, clicks, and named events such as starting a run, hitting a limit, viewing a paywall, or starting a checkout. Once you sign in, these are linked to your account identifier and email.
- Session recordings (PostHog). We record on-page interactions to diagnose usability problems. All text inputs and all result panels are masked — the recording captures that you typed in a box, never what you typed or what came back.
- Aggregate counters. Daily per-tool totals of runs, words, and input characters, stored without any user identifier.
- Server and hosting logs. Our host (Vercel) records standard request data including IP address, user agent, and timestamp.
2.5 What we do not collect
- Your card number, CVC, or full billing address — those stay with Dodo Payments.
- Your precise location. Analytics infers only an approximate country from your IP address.
- Your contacts, calendar, photos, camera, microphone, or files.
- Any biometric or face data. We use no camera and no facial-recognition technology.
- Health or financial-account data.
- Your browsing history on other websites. We run no cross-site advertising or tracking pixels, and we do not participate in ad networks.
3. How we use it
- To run the tools. Your text is sent to Google's Gemini API so it can return the humanized, paraphrased, summarized, corrected, or classified output you requested. This is the core purpose of the Service and cannot be switched off while still using it.
- To show your history. Recent runs are stored so your account page can re-display them and hand a past input back to its tool.
- To apply your writing style. If you enable "Match my style", your saved style card is added to the instructions sent to the AI.
- To meter usage. Word balances determine whether a run is allowed and which features are unlocked.
- To take payment and credit your account. Purchase records let us credit words, track subscription state, and produce receipts.
- To send service email. Account emails such as a welcome message, a low-balance or out-of-words notice, purchase receipts, and password resets.
- To improve the product and prevent abuse. Analytics and aggregate counters tell us which parts of the Service are used, where people get stuck, and whether the Service is being abused.
We do not use your text to train any AI model, and we do not sell, rent, or trade your personal information.
4. Legal basis (GDPR)
If you are in the European Economic Area, the United Kingdom, or Switzerland, our legal bases for processing are:
- Performance of a contract — running the tools you request, maintaining your account and word balance, and processing purchases.
- Legitimate interest — product analytics, masked session recordings, abuse prevention, and enforcing fair use, balanced against your privacy by masking all submitted text.
- Legal obligation — keeping transaction records for tax and accounting.
- Consent — where required for non-essential analytics in your jurisdiction. You can withdraw consent at any time by contacting us.
5. Who we share it with
We use the following processors. Each is bound by its own privacy terms.
| Service | Provider | What it receives | Purpose |
|---|---|---|---|
| Gemini API | Google LLC | The text you submit plus a task-specific system prompt | Run the humanizer, detector, paraphraser, summarizer, and grammar tools |
| Sign in with Google | Google LLC | Your email, name, profile picture, Google account id | Optional account creation and sign-in |
| Supabase | Supabase, Inc. | Account details, word balances, run history, style samples | Authentication and database hosting |
| Dodo Payments | Dodo Payments | Name, email, billing and card details entered at checkout | Process purchases as merchant of record |
| PostHog | PostHog, Inc. | Usage events, account id and email, masked session recordings | Product analytics and usability diagnosis |
| Resend | Resend, Inc. | Your email address and the message content | Send account and service email |
| Vercel | Vercel, Inc. | IP address, user agent, request logs | Host and serve the website |
We also disclose information where we are legally compelled to by a valid order, or where necessary to investigate fraud or abuse. If Humanit is ever acquired or merged, account data may transfer to the successor entity, and we will post notice here before that happens.
6. Where it is stored
- Account data, run history, style profiles, and purchase records are stored in our Supabase project, hosted in the United States.
- Submitted text in transit travels over HTTPS to Google's Gemini API endpoints and is processed in Google's data centres.
- Analytics and recordings are stored by PostHog on US infrastructure.
- The site itself is served from Vercel's global edge network.
If you are outside the United States, using the Service involves transferring your data to the United States. Where required, these transfers rely on the European Commission's Standard Contractual Clauses or an equivalent mechanism operated by the provider.
7. How long we keep it
| Data | Retention |
|---|---|
| Run history (input + result) | Only your most recent runs are kept — older entries are pruned automatically. You can delete any entry, or clear all of it, from your account page at any time. |
| Account, balances, style profile | Until you ask us to delete your account. |
| Purchase records | Retained after account deletion for as long as tax and accounting law requires (typically up to 7 years). |
| Text sent to Google | Google may retain API requests briefly for abuse detection under its Gemini API terms, then deletes them. We cannot access, retrieve, or extend that retention. |
| Analytics and session recordings | Kept for a rolling window under PostHog's retention settings, then deleted. |
8. Security
- All traffic is served over HTTPS; the Service makes no unencrypted requests.
- Passwords are hashed by Supabase Auth. Nobody at Humanit can read your password.
- Run history and style profiles are protected by row-level security, so a signed-in user can read and delete only their own rows.
- API keys for Google, Dodo, and Resend are held server-side only and are never shipped to the browser or the extension.
- Card data never reaches our servers — it is entered directly on Dodo's hosted checkout.
No system is perfectly secure. If you believe you have found a vulnerability, please write to us at the address in Section 17 before disclosing it publicly.
9. Your rights and controls
- See your data. Your account page shows your recent runs, your word balance, and your plan.
- Delete your run history. Delete any single run, or clear your whole history, from your account page. Deletion is immediate and irreversible.
- Delete your style profile. Remove it at any time from the style page.
- Delete your account. Email us and we will delete your account and its associated data, other than the purchase records we must retain for tax purposes. We complete these requests within 30 days.
- Export your data. Ask us and we will send you a machine-readable copy of the data held against your account.
- Opt out of analytics. Enable "Do Not Track" or a global privacy control in your browser, or email us to be excluded. You can also use the AI detector without an account at all.
- Unsubscribe from email. Every non-essential email has an unsubscribe link. Transactional messages such as password resets and receipts cannot be switched off while your account is open.
10. Text you submit
Because Humanit is a text-processing service, this section gives extra detail on how your writing is handled.
10.1 What leaves your browser
When you run a tool, the text in the input box and a short system prompt describing the task are sent over HTTPS to our server, which forwards them to Google's Gemini API together with the model name and generation parameters. Nothing else about your document is transmitted.
10.2 What we store, and why
If you are signed in, we store the input, the result, the tool, the mode, and the word count as a history entry on your account. This exists so your account page can re-display past results and hand an input back to its tool in one click. If you are not signed in, we do not create a history entry — this includes every use of the free AI detector.
10.3 What we never do with it
- We do not use your text to train any AI model, ours or anyone else's.
- We do not sell it, publish it, or share it with advertisers or data brokers.
- We do not read it except where you explicitly ask us to investigate a support issue.
- Our session recordings mask every text box and every result panel, so your writing cannot appear in a replay.
10.4 Your control
Every request is one you initiated — nothing is sent in the background, and the Service never reads text from other tabs or applications. You can delete any stored run at any time from your account page.
11. Cookies and local storage
We use the following, and no advertising cookies of any kind:
- Essential cookies set by Supabase Auth to keep you signed in. Removing them signs you out.
- Analytics cookies set by PostHog to recognise a returning browser and stitch a session together.
- Local storage in your browser for preferences and short-lived state — for example holding the text of a run for up to fifteen minutes across the sign-up step so it can be resumed after you create an account.
12. Browser extension
The Humanit browser extension signs in by reading the session cookie already set on https://humanit.app — it operates no separate backend and asks for no additional account. It requests host permissions only for our own domain and our authentication provider, and it sends text to our API only when you explicitly ask it to run a tool. It does not read, collect, or transmit the content of the pages you browse.
13. Children
The Service is intended for people aged 13 or older. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has given us personal information, contact us and we will delete it. If you are between 13 and the age of majority where you live, use the Service only with the involvement of a parent or guardian.
14. California (CCPA / CPRA)
If you are a California resident, you have the right to:
- Know the categories and specific pieces of personal information we collect and disclose.
- Delete personal information we hold about you.
- Correct inaccurate personal information.
- Opt out of the sale or sharing of personal information. We do not sell or share personal information for cross-context behavioural advertising, and we run no advertising on the Service.
- Not be discriminated against for exercising these rights. We will not deny service, change prices, or degrade quality because you exercised them.
To exercise any of these, email us from the address on your account. We respond within the statutory timeline, typically 45 days, extendable once where the law allows.
15. Europe and the UK (GDPR)
If you are in the EEA, the UK, or Switzerland, you have the rights of access, rectification, erasure, restriction of processing, objection, and data portability, plus the right to lodge a complaint with your local supervisory authority.
Most of these you can exercise yourself: clear your history or delete your style profile from your account, or email us for anything else. We do not use automated decision-making that produces legal or similarly significant effects.
16. Changes
We may update this policy to reflect changes in our practices, our processors, or the law. When we make a material change we will update the "Last updated" date above and, where appropriate, show a notice in the app. The current version always lives at https://humanit.app/privacy. Continuing to use the Service after an update means you accept it.
17. Contact
For privacy questions, deletion or export requests, or to exercise any right above, email adgan.business@gmail.com with "Privacy Request" in the subject line. We reply to general questions within 7 days, and to formal data-subject requests within 30 days as required by law.
See also our Terms of Service.