Legal
Privacy Policy
Effective date: March 28, 2026
Last updated: September 19, 2026
1. Introduction
This Privacy Policy describes how Humanik Technologies Inc. ("HumanikOS," "we," "us," or "our") collects, uses, stores, and protects your information when you use the HumanikOS platform, website, APIs, and all related services (the "Service"). It applies to all users of the Service, regardless of location.
By using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use the Service.
We are committed to transparency about our data practices and to protecting the information you entrust to us.
2. Data We Collect
Account Data
Information you provide when you create an account or manage your profile:
| Data | Purpose |
|---|---|
| Email address | Account creation, authentication, service communications |
| Full name | Account profile, display within workspaces |
| Organization name | Multi-tenant workspace setup |
| Password or OAuth tokens | Authentication via Firebase Auth |
| Billing information | Payment processing via Stripe |
Workspace Data
Content you create, upload, or store through the platform in the course of using the Service:
| Data | Purpose |
|---|---|
| Database records and tables | Core service delivery — your data plane |
| Files and objects | Core service delivery — your storage |
| Code and deployment artifacts | Core service delivery — agent workspaces |
| Agent configurations and prompts | Core service delivery — AI agent setup |
| Task history and logs | Service delivery, debugging, audit trail |
| Integration credentials (encrypted) | Connecting to third-party services you authorize |
AI Interaction Data
Data generated through your use of AI features on the platform:
| Data | Purpose |
|---|---|
| Prompts sent to AI agents | Core service delivery |
| Agent responses and tool calls | Core service delivery |
| Voice interaction audio (if enabled) | Voice synthesis and recognition via ElevenLabs |
| Token usage metrics | Billing and usage tracking |
| Execution data: the sequence of steps an agent took, with values removed at the point of capture | Service delivery and debugging, and the uses in Section 4.2 and Section 4.3, which you control |
Automatically Collected Data
Information collected automatically when you interact with the Service:
| Data | Purpose |
|---|---|
| IP address | Security, rate limiting, fraud prevention |
| Browser type, operating system, device info | Service optimization and debugging |
| Pages visited and feature usage | Product improvement (aggregated) |
| Error logs and crash reports | Service reliability |
3. How We Use Your Data
We use the data we collect for the following purposes:
- Service delivery — operating the platform, processing AI requests, managing workspaces, executing agent tasks
- Billing — processing payments, tracking usage, generating invoices, managing credit balances
- Security — fraud detection, abuse prevention, access logging, threat monitoring
- Communication — account notifications, security alerts, service updates, and transactional emails
- Improvement — aggregated and de-identified analytics to improve the product, and to build the shared templates and baseline configurations described in Section 4.1
- Model improvement — de-identified records of how agents carry out tasks, used to improve the models and systems that run the Service, as described in Section 4.2. You can switch this off.
- Dataset licensing — if, and only if, you turn it on, de-identified records of how agents carry out tasks may be licensed to third parties, as described in Section 4.3. This is off unless you enable it.
- Legal — compliance with legal obligations, responding to lawful requests, enforcing our terms
4. AI, Model Training & Execution Data
We do not train AI models on the contents of your workspace.
The contents of your files, records, tables, emails, calls, chats, and browser sessions, and the text of your prompts as you wrote them, are never used to train or fine-tune any AI model, by us or by anyone else. That is not something you can switch on.
Three narrower uses of operational data are set out below. Each one has its own control and each one is described in full. Section 4.1 covers aggregated analytics and shared templates. Section 4.2 covers de-identified records of how agents carry out tasks, used to improve the models and systems that run the Service. Section 4.3 covers licensing those same de-identified records to third parties, which is off unless you turn it on.
AI features on the platform are powered by Anthropic's Claude models via their API. Anthropic's API data use policy applies to interactions routed through their service. As of this writing, Anthropic does not use API inputs or outputs to train their models. We encourage you to review Anthropic's terms for the most current information.
System prompts — including agent personality, skills, and workspace context — are constructed by our platform to enable service delivery. These prompts do not contain other customers' data.
4.1 Aggregated Analytics and Shared Templates
We build template workspaces, template offices, baseline AI employees, and industry-specific configurations so that a new customer starts from something that already works rather than from an empty workspace. To do that we study how the platform is used in aggregate.
| We may use | We never use |
|---|---|
| Which integrations are connected, and which combinations occur together | The contents of any file, record, table, email, call, chat, or browser session |
| How workspaces and offices are structured, and how many employees they hold | Credentials, API keys, secrets, or anything held in a vault |
| Which skills and protocols are used, and how often | Personal data about you, your staff, or your own customers |
| Categories of task attempted, and rates of success, failure, and retry | Anything from inference run on hardware you own |
| The industry a workspace operates in | Anything covered by a signed agreement that says otherwise |
| De-identified structural patterns in customer-written skills and protocols | The text of a skill or protocol as you wrote it |
The rule that protects your work. A pattern may only enter a shared template once it has been observed across multiple unrelated customer workspaces. Anything specific to one customer is by definition not a pattern and never ships. This is the mechanism, not an intention: a method that only your business uses stays yours, because it never clears the threshold.
What comes out. Templates and baseline configurations. Structure, sequence, and defaults. Never text you wrote, never data you hold, and never anything identifying you as its source. Templates are not attributed to any customer and are not shared with any third party for their own purposes.
How to opt out. Use the Data Controls described in Section 4.6. Opting out costs you nothing: it does not change your pricing, your access, or any feature of the Service, and you can opt back in at any time. Templates already built before your request cannot be unbuilt, because no single customer's data is recoverable from them.
4.2 Execution Data and Model Improvement
When an AI employee carries out a task, the platform records how the task was done. We call this execution data. It is the shape of the work rather than the content of it: which tool was called and in what order, what branched, what failed, what was retried, how the agent recovered, where a person approved or corrected the work, how many steps it took, and how long each step ran. It also covers how the workspace was arranged, which systems were connected, and the structure of what those systems returned.
Values are removed at the point of capture. Where a step handled a name, an email address, a record identifier, an amount, or any other value, the record holds a marker showing that a value of that kind was present. The value itself is never written into the record. This is not redaction after the fact. The value does not enter the record in the first place, so there is no version of the record that ever held it.
We use execution data to improve the models, agents, and systems that run the Service, including training and fine-tuning our own models on it. Execution data contains no customer content and no personal data, so this is not training on your workspace.
This is on by default. You can switch it off for your organization at any time using the Data Controls in Section 4.6. Switching it off does not change your pricing, your access, or any feature of the Service. Where a signed agreement between us says otherwise, that agreement governs and this subsection does not apply.
4.3 Dataset Licensing
We may package execution data into datasets and license them to third parties, including developers of AI models. This is a commercial arrangement and we are paid for it. We are telling you plainly because you should not have to infer it.
This is off. It does not happen for your organization unless an owner of your account turns it on. If you turn it on, you receive a credit or discount against your platform fees, set out at the point you enable it, and you can turn it off again at any time. Leaving it off costs you nothing and changes nothing about the Service.
A licensed dataset is built from the same execution data described in Section 4.2 and is subject to the same limits. It carries no customer content, no personal data, and no attribution to any customer. Where a signed agreement between us says otherwise, that agreement governs and this subsection does not apply.
4.4 What Is Never in Execution Data
The following are excluded from execution data, and therefore from everything described in Sections 4.2 and 4.3:
- The contents of any file, record, table, email, call, chat, or browser session
- The text of a prompt as you wrote it, and the text of anything an agent produced for you
- Names, email addresses, phone numbers, postal addresses, account numbers, and amounts tied to an identifiable person or business
- Credentials, API keys, secrets, and anything held in a vault
- Personal data about you, your staff, or your own customers
- The name of your organization, or any field that identifies you as the source
- Anything from inference run on hardware you own
- Anything covered by a signed agreement that says otherwise
The threshold rule applies here too. A sequence of steps may only enter a licensed dataset once the same sequence has been observed across multiple unrelated customer workspaces. A way of working that only your business performs does not clear that threshold and is not included. This is the mechanism, not an intention: a method unique to you stays yours because it never qualifies.
4.5 No Reidentification
We do not attempt to identify any person, business, or customer from a licensed dataset, and we do not permit anyone else to do so. We maintain technical and organizational measures to prevent identification, including removing values at the point of capture and applying the threshold rule above.
Every party that receives a licensed dataset is bound by written contract to those same two obligations, and is prohibited from combining the dataset with any other information in order to identify a person or a business. A recipient that breaches those terms loses access to the dataset.
Because these datasets contain no personal information, licensing them is not a sale or a sharing of personal information under the California Consumer Privacy Act. See Section 8.
4.6 Your Controls
Each of the three uses above has its own setting, held at the organization level and changed by an account owner:
| Setting | What it covers | Default |
|---|---|---|
| Shared templates | Aggregated analytics and template building (Section 4.1) | On |
| Model improvement | Execution data used to improve our own models (Section 4.2) | On |
| Dataset licensing | Execution data licensed to third parties (Section 4.3) | Off |
The settings live in your workspace settings, under Data Controls. You can also change them by emailing info@humanik.io with the subject line “Data Controls” and naming the workspace or organization, and we will confirm in writing when the change is done.
A change takes effect for new data immediately. Data already collected is removed from our working set within 30 days. Two things cannot be undone: a template already built, and a dataset already licensed and delivered. Neither can be unbuilt or recalled, because no single customer's contribution is recoverable from them.
5. Data Sharing & Third Parties
Service Providers
We share data with third-party service providers solely as necessary to operate the Service. These providers process data on our behalf under contractual obligations to protect your data:
| Provider | Purpose | Data Shared |
|---|---|---|
| Anthropic | AI model inference (Claude) | Prompts and context via API |
| Firebase (Google) | Authentication | Auth tokens, user profiles |
| Supabase | Database infrastructure | Workspace structured data |
| Fly.io | Compute infrastructure | Office runtime data, code, files |
| Cloudflare (R2) | Object storage | Files, snapshots, uploaded objects |
| Stripe | Payment processing | Billing data, payment methods |
| ElevenLabs | Voice synthesis (if enabled) | Voice text input, audio output |
A complete list of our subprocessors is available at humanik.io/legal/subprocessors. We will provide at least 14 days' advance notice before adding new subprocessors.
What We Do Not Do
- We do not sell your personal data
- We do not share your data with advertisers
- We do not provide your personal data to data brokers
- We do not sell, license, or otherwise disclose Customer Data to any third party for that party's own purposes, including AI model training, other than through the dataset licensing described in Section 4.3, which is off unless you turn it on and which contains no customer content and no personal data
Legal & Safety Disclosures
We may disclose your data when we believe in good faith that disclosure is necessary to:
- Comply with applicable law, regulation, or valid legal process
- Protect the safety of any person or the public
- Protect against fraud, abuse, or security threats
- Protect our rights, property, or the integrity of the Service
In the event of a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction. We will notify you before your data becomes subject to a different privacy policy.
6. Data Storage & Security
We implement technical and organizational measures designed to protect your data:
- Encryption at rest — AES-256-GCM for credentials and secrets; standard encryption for other stored data
- Encryption in transit — TLS 1.2 or higher for all connections
- Credential isolation — BYOK API keys are encrypted in per-office vaults, never logged, and injected via a localhost proxy at runtime
- Tenant isolation — each office runs in a dedicated VM with IAM-enforced access boundaries
- Access controls — role-based access with scoped policies; 34 granular permissions across 13 roles
- Inter-service authentication — HMAC-based verification between internal services
No method of storage or transmission is completely secure. While we strive to protect your data, we cannot guarantee absolute security. If you discover a security vulnerability, please report it to info@humanik.io.
7. Data Retention
We retain your data only for as long as necessary to fulfill the purposes described in this policy:
| Data Category | Retention Period |
|---|---|
| Account profile data | While your account is active, plus 90 days after deletion |
| Workspace data (databases, files, code) | While your workspace is active, plus 30 days after deletion |
| AI interaction logs (prompts, responses) | 90 days rolling, then purged |
| Voice interaction audio | Not stored — processed in real time and not persisted by HumanikOS |
| Billing records and invoices | 7 years, as required by tax and legal obligations |
| Access and audit logs | 1 year |
| Server and application logs | 30 days |
| BYOK API keys | While active; securely wiped immediately upon removal or office deletion |
| Backup snapshots | 30 days rolling |
| Execution data (Section 4.2) | Held while the setting is on; removed from our working set within 30 days of it being switched off |
| Licensed datasets (Section 4.3) | Once delivered to a recipient, held by that recipient under contract and not recallable |
When you delete your account or workspace, we initiate deletion of your data across all systems. Some data may persist in encrypted backups for the retention periods listed above before being permanently removed.
8. Your Rights
All Users
Regardless of your location, you may:
- Request access to the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Export your workspace data in machine-readable format (JSON, CSV, SQL)
- Switch off shared templates and model improvement, and leave dataset licensing off, using the Data Controls in Section 4.6, at any time, without affecting your pricing or access
European Economic Area & United Kingdom (GDPR)
If you are located in the EEA or UK, you have additional rights under the General Data Protection Regulation, including:
- Right to restrict processing of your data
- Right to data portability
- Right to object to processing based on legitimate interest
- Right to withdraw consent at any time for consent-based processing
- Right to lodge a complaint with your local supervisory authority
Our lawful bases for processing your data under GDPR are: contract performance (account and service delivery), legitimate interest (security, product improvement), and consent (voice features, marketing).
Execution data as described in Section 4.2 is captured without personal data and is anonymous in the sense used by the GDPR, so the Regulation does not apply to it once captured. If you are in the EEA or the UK and you turn on dataset licensing under Section 4.3, we rely on your consent for that activity rather than on legitimate interest, and you may withdraw it at any time by switching the setting off.
California (CCPA/CPRA)
If you are a California resident, you have the right to:
- Know what personal information we collect and how it is used
- Request deletion of your personal information
- Opt out of the sale or sharing of personal information
- Non-discrimination for exercising your privacy rights
We do not sell or share your personal information as defined by the CCPA. The datasets described in Section 4.3 are licensed for money, but they are deidentified information rather than personal information, so that licensing is not a sale or a sharing under the Act. We hold that position on the basis of the three commitments in Section 4.5: we publicly commit not to reidentify anyone from those datasets, we maintain measures to prevent reidentification, and every recipient is bound by contract to do the same.
Exercising Your Rights
To exercise any of these rights, contact us at info@humanik.io. We will verify your identity and respond within 30 days (GDPR) or 45 days (CCPA). We will not charge a fee for processing your request unless it is manifestly unfounded or excessive.
9. International Data Transfers
Your data may be transferred to and processed in countries other than your own, including the United States and Canada, where our infrastructure providers operate.
For transfers of personal data from the EEA or UK to countries without an adequacy decision, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission. We ensure that all subprocessors handling EEA/UK personal data are bound by equivalent protections.
If you have questions about how your data is transferred, contact us at info@humanik.io.
10. Cookies
We use a minimal set of cookies to operate the Service:
| Cookie | Type | Purpose | Duration |
|---|---|---|---|
| Session | Strictly necessary | Authentication state | Session |
| CSRF token | Strictly necessary | Prevent cross-site request forgery | Session |
| Cookie preferences | Strictly necessary | Remember your cookie choices | 1 year |
We do not use advertising or marketing cookies. We do not use third-party tracking cookies. If we introduce analytics cookies in the future, we will update this policy and obtain your consent where required.
11. SMS & Text Messaging
Where you give us your mobile number and tick the consent box on one of our forms, we may send you text messages. This section describes what we do with that number. It applies in addition to the rest of this policy.
How we obtain consent
We only text people who have asked us to. Consent is collected through a checkbox that is never pre-selected and must be actively ticked by you, shown alongside a description of the messages, their frequency, and how to stop. The wording you were shown, and the date and time you agreed to it, are recorded with your number. Our opt-in form is published at humanik.io/sms.
Consent to receive text messages is never a condition of buying anything from us or of using the Service.
What we send
- Confirmations and reminders for calls and appointments you book with us
- Replies from a member of our team about an inquiry you made
- Service and account notifications
- Occasional marketing and promotional messages
Message frequency varies, and is typically 2 to 6 messages per month. Message and data rates may apply under your own carrier plan; we do not charge you for the messages themselves.
How we use the number
We use your mobile number to send the messages described above, to record and honour your opt-out, and to keep proof of your consent for as long as we are required to. We share it only with the telecommunications providers that deliver the messages on our behalf, who act under contract and may not use it for their own purposes.
- We do not sell, rent, or share mobile numbers or SMS consent data with third parties or affiliates for their own marketing purposes. No mobile opt-in information is disclosed to anyone other than the messaging providers needed to deliver the message.
- We do not add your number to any list you did not opt into
- We do not use your number to build advertising audiences
Stopping messages
Reply STOP to any message to opt out. You will receive one confirmation and nothing afterwards. Reply HELP for help, or contact us at info@humanik.io.
After you opt out we retain your number on a suppression list. That record exists so we do not text you again and is not used for any other purpose. You may still receive non-marketing messages where we are permitted to send them, such as confirming an appointment you booked afterwards.
12. Children's Privacy
The Service is not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child under 16, we will take steps to delete it promptly. If you believe a child has provided us with personal data, please contact us at info@humanik.io.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. We will notify you of material changes at least 30 days in advance via email or a notice within the platform.
Your continued use of the Service after the updated policy takes effect constitutes your acceptance of the changes. We encourage you to review this policy periodically. Prior versions are available upon request.
Prior versions of this policy are available on request from info@humanik.io.
14. Contact
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, contact us at:
Humanik Technologies Inc.
Email: info@humanik.io
Website: humanik.io