Legal
Privacy Policy
Effective date: October 6, 2026 · Version 1.0
Operated by HUMANIZER.COM LLC, a New York limited liability company, PO Box 724, Lynbrook, NY 11563, USA. Prior versions of this policy are available on request from ed@humanizer.com.
Summary
Privacy at a glance
Who we are. HUMANIZER.COM LLC, a New York company, runs the Services: Studio (studio.humanizer.com), the humanizer.com website, the Dreegle desktop application ("Desktop App"), Post-Social (post-social.com), Gravity Press (gravity-press.com and gravitypress.org), our API and MCP server, and related sites (together, the "Services"). This policy covers all of them.
What we collect. Account details, billing identifiers from Stripe (not your card number), order details, Your Content and data derived from it, usage and cost records, technical data such as your IP address for security and rate limiting, and a small number of cookies.
Your Content and AI. In Studio and our other cloud Services, Your Content is stored on our servers and sent to Model Providers to produce Outputs. The Desktop App keeps your archive on your device by default. Its main privacy setting asks for your consent before it sends text-generation requests to a cloud or third-party provider. Some features, described in Section 3.4, are not yet covered by that setting.
We do not train or fine-tune AI models on Your Content.
No sale, no ad tracking on our apps. We do not sell personal information. Studio, Post-Social and Gravity Press use no advertising or analytics cookies or pixels. The humanizer.com website currently uses Google Analytics, which we are removing (Section 7).
How long. Mostly until you delete it or close your account. Some records are kept longer where law or accounting requires (Section 3.5).
Your choices. Ask to access, correct, delete or export your data: email ed@humanizer.com with "Privacy request" in the subject line.
Age and place. You must be 18 or older. We are in the United States. The Services are not offered in the EEA, the UK or Switzerland.
Please be careful. No system is perfectly secure. Avoid submitting sensitive information about yourself or others.
1. Who we are and how to contact us
HUMANIZER.COM LLC ("we", "us", "our") is a New York limited liability company. For the personal information described in this policy, we decide why and how it is processed, which makes us the "controller" or "business" under privacy laws.
- Mail: HUMANIZER.COM LLC, PO Box 724, Lynbrook, NY 11563, USA
- Privacy questions and requests: ed@humanizer.com (please put "Privacy request" in the subject line)
- Phone: (516) 809-8445
- Person responsible for privacy: Edward Bernstein, HUMANIZER.COM LLC
If you use the Services for a business and need service-provider terms for personal information you ask us to process for you, contact us before you rely on the Services for that purpose.
2. What this policy covers
This policy applies to all Services. Capitalized words such as "Services", "Studio", "Desktop App", "Post-Social", "Gravity Press", "API", "Your Content", "Outputs" and "Model Providers" have the same meaning as in our Terms of Service (https://gravitypress.org/terms/). Section 3.4 explains what is different for each Service. If you use more than one Service, each part that applies to you applies together.
This policy does not cover other companies. When you sign in with Google, GitHub or Discord, pay through Stripe, connect your own AI provider account, or follow a link to another website, that company's own policy applies to what it does.
3. What we collect
3.1 Information you give us
- Account information. Your email address, display name, profile picture and the sign-in provider you use. If you have an account that was created through our earlier sign-in system with a password, we store a hashed form of the password, not the password itself.
- Your Content. Anything you upload, import, paste, type, publish or otherwise submit: text, documents, conversation archives you import from other services, images, audio, comments, books and chapters you write, personas and style settings, and your preferences.
- Your own AI provider keys. If you bring your own key ("BYOK"), we store it so that your requests can be sent with it (see Section 3.4).
- Purchases. For Gravity Press purchases, your email address and order details. For sellers, store details, and the information our payment partner collects to verify identity and pay you.
- Rights statements. When you upload material to Gravity Press and confirm that you have the rights to it, we keep that statement together with the IP address it came from.
- Messages to us. Emails and reports you send us, including copyright notices and privacy requests.
3.2 Information collected automatically
- Technical data. Your IP address and request details (such as browser type and the pages or endpoints you call). We use IP addresses to limit abusive traffic and keep the Services secure, and we may use them to restrict access from places where we do not offer the Services. Our network provider, Cloudflare, also sees this information because all traffic to the Services passes through it. Our servers may record the request method and path, which can include any query text in the address.
- Usage and cost records. For each AI request: which account made it, which model was used, the number of tokens, the cost, the time taken and timestamps. These records do not contain the text of your prompts or the Outputs.
- First-party counters. On Post-Social, a simple counter records that an event happened on a page (for example, a page view) together with the page identifier. It does not store your IP address or any identifier for you.
- Website analytics on humanizer.com. The humanizer.com website currently loads Google Analytics and Google Tag Manager, and Cloudflare's web analytics script. See Section 7.
- Cookies and browser storage. A small number of items, described in our Cookie and Local Storage Notice.
- Security signals on comment forms. Post-Social comment forms use Cloudflare Turnstile to check that a human is submitting the form. Turnstile receives technical signals from your browser.
3.3 Information from other sources
- Sign-in providers. If you sign in with Google, GitHub or Discord, the provider sends us basic profile information such as your email address, name, profile picture and an identifier. Our identity provider (ZITADEL) processes this on our behalf.
- Stripe. Stripe sends us confirmation of payments, a customer identifier, subscription status and related event records. We do not receive or store your full card number.
- Sources you ask us to use. If you ask a feature to fetch or search material (for example, public-domain books, or encyclopedia or paper search), we send the search terms to that source and receive the results.
- Model Providers. We receive Outputs back from the Model Providers we send requests to.
3.4 What is different for each Service
Studio (studio.humanizer.com). Studio is a cloud service. When you import an archive or paste text, Your Content is stored in your account on our servers, converted into numerical representations (embeddings) so it can be searched, and processed by AI models when you use a feature. Media files are kept in private storage. Chat history with the assistant is stored in your account. Section 5 explains what is sent to Model Providers. The detector and other AI features require you to sign in. Hosted curator chats keep up to the last 50 turns of a conversation for up to 90 days. Before you import material, please remember that it will be stored in our cloud, converted to embeddings, and sent to Model Providers when you use AI features, and that it may contain other people's personal information (Section 3.6).
Desktop App. The Desktop App is built to work on your device first.
- Where your data lives. Your archive is kept in a database on your device, with media and backups in folders under your user account. AI provider keys are encrypted using your operating system's secure storage. The Desktop App does not add its own encryption to the local database beyond the encryption of your device, so we encourage you to use full-disk encryption.
- The egress setting. By default, the Desktop App's data-egress setting is "local": text-generation requests use models that run on your device, and the app does not send the content of your archive or your prompts to a cloud or third-party provider for text generation. To change this, you open Settings > Privacy & Data and confirm a consent dialog. The levels are local, trusted cloud and third-party. The app records receipts of what it sent on your device. Requests started by an AI agent or an MCP client to raise this setting are refused. If you set up a cloud or third-party provider for a feature, content for that feature goes to that provider when you use it.
- What the egress setting does not cover yet. Embeddings (the numerical representations used for search) and image generation are not yet controlled by the egress setting. If you configure a cloud or third-party provider for embeddings or image generation, the text or prompts for those features go to that provider whatever the egress setting says. Please do not configure a cloud provider for those features unless you intend to send that content to it.
- When data leaves your device. Your content can leave your device when you link a cloud account, route requests to a cloud or BYOK provider, publish to Post-Social, create a Gravity Press product, push your archive to Studio, or export a bundle and share the file. A "Book+" bundle includes the curator by default; you can turn that off when you export. Anyone who has the file can use what it contains.
- Other network connections. Each time the Desktop App starts, it checks for updates at update.humanizer.com, which receives your IP address and standard request details; this check cannot currently be switched off. When the app refreshes its list of models, it reads a public catalog from models.dev, and, if you have saved provider keys, asks each of those providers for its list of available models using your key. If you choose to download optional models, the download comes from the model host (for example, Hugging Face). Research tools (web, encyclopedia, paper and book lookups, and page fetches you ask for) send your search terms or the page address to the source you use. Images that appear in AI output or in your archive text may be loaded from the web address they point to. The Desktop App does not include third-party analytics or crash-reporting software.
- Logs on your device. The Desktop App keeps operational log files on your device (on a Mac, under ~/Library/Logs/Dreegle/), limited in size and replaced as they fill. If you start the app with optional debug logging switched on, full prompts and answers are also written to log files on your device. Logs stay on your device unless you share them.
- Claude Desktop and other AI applications. The Desktop App can run a local MCP server that other applications on your device can call. When it starts, the Desktop App adds itself to the Claude Desktop application's list of MCP servers on your device. You can connect it to other AI applications from Settings. If an AI application uses it, the results it returns (which can include text from your archive) are sent to that application and its provider under their terms.
Post-Social (post-social.com). Post-Social publishes "nodes" (books, essays and similar works) with AI "curators".
- Authors. If you publish a node, it and the information attached to it (your author handle, the license and rights information recorded for it, and your account identifier) are public. To unpublish or delete a node, ask us at ed@humanizer.com.
- Commenters. Comments need an account and a Turnstile check. An automated safety filter reviews a portion of the text of your comment, and the node's curator evaluates it. The text of your comment is not shown publicly. The curator's note about it, which may reflect what you said, is public and is shown with your handle. If the node's author has chosen to read comments directly, the comment form says so, and the author can see your comment. The curator's private reply to you is shown only to you and the node's author. Information derived from every comment, including comments that are not accepted, is used to update that node's curator (for example, so that it can respond to later comments). Your identifiers are removed when you erase your data, but we cannot remove the influence of a comment from the curator's later responses. You can withdraw a comment you wrote, which redacts the words and your name.
- Curators are AI. Curator notes, replies, curator-to-curator exchanges and curated editions on Post-Social are written by AI and may be published automatically after passing a safety check. They are not labeled one by one on the page, so please read them as AI-generated.
- Messages about comments. We do not send emails about comments, and we do not store your email address for that purpose.
- Billing records. Post-Social keeps usage and billing ledger records for accounting. When you erase your Post-Social data, we de-identify your comments and delete your scores, notes and subscriptions, but billing ledger records still identify you for the period in Section 3.5.
Gravity Press (gravity-press.com and gravitypress.org). Gravity Press is a storefront for books and other works.
- Buyers. Gravity Press currently sells digital downloads. We collect your email address and order details. Payment is handled by Stripe. We do not currently print or ship physical items, and we do not collect a shipping address.
- Sellers. Your store name, product listings and the AI-assistance level you declare are public. Stripe collects the identity and bank information needed to pay you through Stripe Connect; Stripe's privacy policy governs that information. When you confirm your rights to material you upload, we keep that statement and the IP address it came from as evidence.
- Support and moderation. Our administrators can view an account in a read-only mode for support and moderation for a limited time (30 minutes per session). These sessions are logged.
- Reports. If you report a product or send a copyright notice, we keep your report and the contact details you provide.
API and MCP (mcp.humanizer.com). Requests are authenticated with a token tied to your account. The content you send is processed as described for Studio. Our MCP server keeps an audit record of each event, with your account identifier, the tool name, the duration and any error, for 7 days. It does not record the content you send or your IP address. Our older API at api.humanizer.com is being retired.
The humanizer.com website and our mailing list. The humanizer.com website loads Google Analytics, Google Tag Manager and Cloudflare's web analytics script (Section 7). We previously ran a mailing list. It is closed to new sign-ups, and we are not sending to it. We keep the names, email addresses and comments that people gave when they signed up.
3.5 Summary table: what we collect, why, on what basis, how long, and who receives it
Some countries' laws ask us to explain the legal reason for processing. The "Basis" column does that. "Contract" means we need the data to provide what you asked for. "Legitimate interests" means our interest in running and securing the Services, balanced against your rights. "Legal obligation" means we must keep it by law. "Consent" means you chose to give it.
Periods marked with an asterisk (*) are targets. We do not yet have automated jobs that enforce every one of them, so until those jobs are in place some data may be kept longer than the target. If you want data deleted sooner, ask us (Section 12).
| Data | What it includes | Why we use it | Basis | How long we keep it | Who receives it |
|---|---|---|---|---|---|
| Account data | Email, display name, avatar, roles, sign-in provider IDs and sign-in events; for older accounts, hashed password and sign-in provider details | Create and run your account, sign you in, keep it secure, support you | Contract; legitimate interests (security) | While your account is open. Deleted within 30 days after a verified closure or deletion request (Section 12) | ZITADEL (identity); Cloudflare and DigitalOcean (hosting) |
| Plan and billing identifiers | Plan, subscription status, Stripe customer ID, payment amounts and dates, event records. Not your card number | Take payment, manage subscriptions, taxes, refunds, fraud prevention, accounting | Contract; legal obligation; legitimate interests | Up to 7 years after the transaction* | Stripe; Cloudflare (hosting) |
| Order data | Buyer email, order details, reports | Deliver orders, handle refunds and disputes | Contract; legal obligation | Order and tax records: up to 7 years after the order* | Stripe; Cloudflare |
| Rights statements (Gravity Press) | Your statement that you have the rights to uploaded material, the time, and the IP address it came from | Evidence of rights in material offered for sale | Legitimate interests; legal obligation | For as long as the material is offered and for as long as a claim about it could be made | Cloudflare |
| Mailing list (closed) | Name, email, comment, sign-up date | Send news and updates people asked for | Consent | Until you ask us to delete it. We are not sending to this list | Cloudflare |
| Your Content | Imported archives, text, documents, images, audio, books and chapters, personas and style settings, comments, preferences, embeddings derived from them | Provide the features you use: store, search, transform, analyze and publish | Contract | Until you delete it or your account is closed; then within 30 days of a verified request (Section 12) | Cloudflare; DigitalOcean (Studio); Model Providers as described in Section 5 |
| Your AI provider keys (BYOK) | Keys you give us, stored encrypted | Send your requests to your own provider account | Contract | Until you delete the key or close your account | Cloudflare (hosting) |
| Curator and assistant chat history | Your messages and replies | Continue a conversation | Contract | Hosted curator chats: up to 90 days. Assistant history in your account: until you delete it | Cloudflare; Model Providers |
| Post-Social comments and related data | Comment text, author handle, scores, notes, subscriptions, consent records | Run comments, safety checks and curator responses; keep a record of consent | Contract; legitimate interests (safety) | Comment text for comments that are not accepted: 182 days*. Their record: 730 days*. Accepted comments stay and are de-identified on erase | Cloudflare (including Turnstile and safety checks) |
| Published content | Nodes, store pages, product listings you choose to make public | Display your work | Contract; your consent when you publish | Until it is unpublished or deleted. Copies held by search engines or other people are outside our control | The public; Cloudflare |
| Usage and cost records | Account ID, model, tokens, cost, latency, timestamps (no prompt text, no IP address) | Billing and allowances, abuse prevention, troubleshooting, capacity planning | Contract; legitimate interests | Up to 24 months*, then only in aggregate; entries that support billing records are kept as long as those records (up to 7 years)* | Cloudflare; DigitalOcean |
| Technical data | IP address, request path, browser details, rate-limit counters, approximate country from IP | Security, rate limiting, restricting access from places where we do not offer the Services | Legitimate interests; legal obligation (sanctions) | Rate-limit records: about a minute to an hour. Network and server logs: as kept by Cloudflare under our account settings | Cloudflare |
| Website analytics (humanizer.com only) | Pages viewed, browser details, IP address, Google Analytics cookies | Understand use of the humanizer.com website | Legitimate interests | As kept by Google under its own settings; we are removing Google Analytics | Google; Cloudflare |
| First-party counters | Event name and page identifier, no IP, no user ID | Understand which pages are used | Legitimate interests | Kept as aggregate counts | Cloudflare |
| MCP request records | Account ID, event, tool name, duration, error | Security and troubleshooting | Legitimate interests | 7 days | Cloudflare |
| Sign-in and security cookies | See Cookie and Local Storage Notice | Keep you signed in and secure | Contract; legitimate interests | Per cookie; up to 30 days | None (first party) |
| Support and legal records | Emails to us, privacy-request records, copyright notices, law-enforcement requests | Respond to you; comply with law; defend claims | Contract; legal obligation; legitimate interests | Support emails: 2 years after the matter closes*. Privacy-request and copyright records: 3 years after the matter closes*, longer if the law, a dispute or a repeat-infringer decision requires | Our email provider; legal advisers when needed |
| Desktop App local data | Archive database, media, settings, receipts, logs | Run the app on your device | Not applicable: stays on your device unless you send it | On your device until you delete it. The app deletes its own egress receipts after 730 days (180 days for some receipt types) | None unless you choose to send it |
3.6 Information about other people in Your Content
Archives and text you import (for example chat exports, social media downloads or message threads) can include other people's names, messages, contact details and sensitive information. We process this only to provide the features you ask for. We do not know who those people are and cannot notify them. We do not offer a tool that finds or removes other people's personal information for you.
You are responsible for having the right to import and process what you upload. Please remove or avoid importing other people's private or sensitive information. Please do not import material you are not allowed to share. If you are not a user and think your information is in someone's content, email ed@humanizer.com with "Privacy request" in the subject line. We will delete it if we can locate it.
3.7 Sensitive information
We do not ask for sensitive information. Your content may still include it, such as health information, information about sexual orientation, racial or ethnic origin, religion, or private messages. Please do not submit it unless you need to. If Your Content includes it, we process it only to provide the feature you asked for. We do not use it to infer characteristics about you or anyone else, to build advertising profiles, or to make decisions about people. The safeguards in Section 9 apply to it, but no system is perfectly secure.
4. How we use personal information
We use personal information to:
- provide, operate and maintain the Services, including storing and processing Your Content, running features and returning Outputs;
- create and manage accounts, sign you in and authenticate API requests;
- take payments, manage subscriptions and allowances, deliver orders, and keep financial records;
- keep the Services secure and prevent fraud, abuse and misuse, apply rate limits, and restrict use from places where we do not offer the Services;
- review published content and comments for safety and rights issues, and handle reports and copyright notices;
- respond to your questions and requests;
- send service messages (such as security notices, changes to our terms and policies, and billing messages);
- understand how the Services are used and fix problems, using usage and cost records and aggregate counters (not Your Content), and, on the humanizer.com website only, Google Analytics;
- meet legal obligations, enforce our Terms and protect rights, safety and property; and
- evaluate or carry out a merger, acquisition or sale of our business (see Section 6).
We do not use personal information for advertising, to sell to others, or to build profiles about you for others.
5. AI processing
5.1 What is sent to Model Providers, and when
Features that use AI send the content they need to a Model Provider so that it can produce the Output. That is the text, images or audio you submit, our instructions to the model, and for features that work with your archive, the parts of it that the feature uses. In Studio and the other cloud Services this happens whenever you use such a feature. We also send comments and published content to an automated safety filter, and we send text from your archive to an embedding model so that it can be searched.
Model Providers may keep inputs and outputs for a limited period under their own terms, for example for safety and abuse monitoring. We do not control their practices.
5.2 Who runs the models
- In our cloud Services, models run on Cloudflare (Workers AI) and, for Studio, on DigitalOcean.
- If you bring your own key, requests go to your own provider account (for example OpenAI, Anthropic, Google, Groq, Together or others) under your agreement with that provider. In cloud Services, we relay the request with your key. In the Desktop App, requests go from your device directly.
- The current list is on the Subprocessor List.
5.3 No training
We do not train or fine-tune AI models on Your Content. We do not authorize our Model Providers to use Your Content or Outputs to train their models for our account. Each Model Provider's own terms govern what it does with the content it receives, and we cannot control a provider's later changes to its terms. If you use your own key, your provider's terms apply.
Features that analyze your own writing, such as detection scores or curators, work from your own content and are stored in your account or on your device.
5.4 Human review
We do not routinely read Your Content. We may access specific content to investigate abuse or a security incident, to help with a support request you send us, to review a report or copyright notice, to review products and published works, or to meet a legal obligation.
5.5 Outputs and accuracy
Outputs are generated by AI and can be wrong, incomplete or similar to existing material. Please check them before relying on them. The Services are writing refinement and voice tools. We do not promise that any Output will be scored a particular way by any AI detector, and you are responsible for following the rules of your school, employer, publisher or platform about AI use.
Our AI detector gives a probabilistic estimate about a piece of text. It can be wrong in both directions, including on text written by a person. It is not a statement about a person and should not be the sole basis for decisions about someone, such as academic, employment or similar decisions.
5.6 Automated decisions
We do not make decisions with legal or similarly significant effects about people using automated processing. Automated safety checks may stop a comment or published work from appearing.
5.7 AI-generated public content
Curator notes, replies, exchanges and curated editions on Post-Social are generated by AI. On Gravity Press, we ask sellers to declare how much AI assistance a work had, and we show that label.
6. Who we share information with
We share personal information only as follows.
- Service providers (processors). Companies that host and operate the Services or perform tasks for us, bound to use the information only for us: for example Cloudflare (hosting, network, AI, bot checks), DigitalOcean (Studio hosting and AI), ZITADEL (identity) and Stripe (payments). The full list is on the Subprocessor List.
- Model Providers, as described in Section 5.
- Payment partners. Stripe processes payments and payouts and uses some information for its own legal and fraud-prevention purposes under its own privacy policy.
- Google, for website analytics on the humanizer.com website only, until we remove it (Section 7).
- At your direction. For example, publishing a node (it becomes public), sending content to your own AI provider account, signing in with a provider, or connecting an AI application to the local MCP server.
- Other users and the public, for content you publish.
- Legal and safety. Authorities, courts or other parties where we believe disclosure is required by law, to respond to a copyright notice, to enforce our Terms, or to protect rights, safety and property. Where we are allowed to, we will tell you first.
- Business transfers. If we are involved in a merger, acquisition or sale of assets, personal information may be transferred. We will give notice before it becomes subject to a different privacy policy.
- With your consent.
We do not disclose personal information to third parties for their own direct marketing.
Subprocessor changes
We post changes to the Subprocessor List and update its date.
7. Sale and sharing of personal information
We do not sell personal information for money. Studio, Post-Social, Gravity Press, the API and the Desktop App do not use advertising or analytics cookies or pixels, and we do not share personal information from them for cross-context behavioral advertising.
The humanizer.com website currently loads Google Analytics and Google Tag Manager. They set cookies and send Google information about your visit, such as the pages you view, your browser and your IP address. We use this only to understand use of that website, and we are removing it. Until it is removed, you can block it with your browser's privacy settings or an extension, and you can ask us to confirm what we hold about you. We do not knowingly sell or share the personal information of anyone under 18.
8. How long we keep information
We keep personal information for the periods in the table in Section 3.5. Where no fixed period is given, we keep it for as long as it is needed for the purpose described, and then delete or de-identify it.
- Your Content and account data. We keep these until you delete them or close your account. We then delete them within 30 days of a verified request (Section 12).
- Backups. Our hosting providers keep backup copies for disaster recovery. Deleted data can remain in a backup copy until that copy expires under the provider's backup schedule.
- Records we must keep. We keep financial, tax, accounting, copyright, sanctions and export-compliance and legal-request records for as long as the law or a dispute requires, even after you delete your account.
- What others hold. Providers and recipients may keep information under their own terms (for example, Stripe's payment records, or a Model Provider's safety logs). Once content is public, copies may exist that we cannot remove.
- The Desktop App. Data on your device stays there until you delete it. Uninstalling the app may leave your archive in the application data folder, which you can delete yourself.
9. Security
We use measures that are reasonable for our size and the type of data. These include encrypted connections (HTTPS) to the Services, storage provided by infrastructure providers that encrypts data at rest, access to production systems limited to authorized personnel, session cookies that scripts on the page cannot read, and encryption of AI provider keys that you give us. In the Desktop App, keys are encrypted using your operating system's secure storage. Our Security and Vulnerability Disclosure Policy has more detail.
No system is perfectly secure, and we cannot promise that information will never be accessed without permission. You can help by keeping your device up to date and protecting your sign-in provider account, including by turning on its multi-factor authentication. Email ed@humanizer.com with "Security" in the subject line if you think an account or the Services has been compromised.
10. Your rights and choices
10.1 Everyone
Whatever country you live in, you can ask us to tell you what personal information we hold about you, to correct it, to delete it, or to give you a copy in a common format. You can also:
- delete items, media, keys and projects yourself in the Services, where the Service offers it;
- change the Desktop App's data-egress setting and remove cloud or BYOK provider settings (Settings > Privacy & Data);
- use a Global Privacy Control signal in your browser (Section 16); and
- close your account (Section 12).
10.2 US state privacy rights (one notice for all US users)
Some US states, including California, Colorado, Connecticut, Virginia, Texas, Oregon and Montana, give residents privacy rights. We may not be legally required to apply every one of these laws, but we offer the rights below voluntarily to all US users.
You can ask us to:
- Know and access the personal information we have about you, the categories, sources, purposes and recipients, and receive a copy;
- Delete your personal information, subject to the exceptions in Section 8;
- Correct inaccurate personal information;
- Port your data in a portable, commonly used format;
- Opt out of the sale of personal information, sharing for cross-context behavioral advertising, targeted advertising, and profiling that produces legal or similarly significant effects. Section 7 explains what we do and do not do; you can ask and we will confirm;
- Limit the use of sensitive personal information. We use it only to provide the Services you asked for and do not use it in ways that trigger a right to limit; and
- Appeal a decision on a request (Section 11).
We will not discriminate against you for using these rights. We will not deny you the Services, charge you different prices or give you a different quality of service because you made a request, except to the extent a request makes it impossible to provide a feature (for example, we cannot run your account after deleting it).
Nevada. We do not sell covered information as Nevada law defines it. You may still send a request to ed@humanizer.com.
California "Shine the Light." We do not disclose personal information to third parties for their own direct marketing purposes.
Authorized agents. You can use an authorized agent. We may ask for your written permission and, where needed, confirm directly with you.
10.3 California categories of personal information
In the 12 months before the date of this policy, we have collected the following categories, using the statutory names. We collect them from you, from your sign-in provider, from Stripe and automatically from your use of the Services. We use them for the purposes in Section 4 and disclose them to the recipients in Section 6. We have not sold them. Section 7 describes Google Analytics on the humanizer.com website. Retention periods are in Section 3.5.
| Statutory category | What we collect | Disclosed to |
|---|---|---|
| Identifiers | Name, email address, account name, display name, IP address, online identifiers, account and customer IDs | Service providers; Stripe; Google (humanizer.com website analytics only); the public (for author handles you publish) |
| Personal information categories listed in the California Customer Records statute (Cal. Civ. Code 1798.80(e)) | Name, email. We do not hold card numbers; Stripe handles them | Stripe; service providers |
| Characteristics of protected classifications under California or federal law | We do not ask for these. They may appear in Your Content if you submit them | Service providers and Model Providers, only as part of processing Your Content |
| Commercial information, including records of products or services purchased, obtained or considered | Plan, purchases, subscription status, order history | Stripe; service providers |
| Biometric information | None | Not applicable |
| Internet or other electronic network activity information | Request records, usage and cost records, interactions with the Services, first-party page counters, and website analytics on humanizer.com | Service providers; Google (humanizer.com website analytics only) |
| Geolocation data | Approximate location (country or region) derived from IP address, used for security and legal restrictions. No precise location | Service providers |
| Audio, electronic, visual, thermal, olfactory or similar information | Audio files and images you upload to features that process them | Service providers and Model Providers, only to process your request |
| Professional or employment-related information | Only if it appears in Your Content | As for Your Content |
| Education information (non-public, as defined in FERPA) | Only if it appears in Your Content | As for Your Content |
| Inferences drawn from the information above to create a profile | We do not create profiles about you. Detection scores describe a piece of text, not you | Not applicable |
| Sensitive personal information | Account log-in details (including provider keys you store with us); and the content of messages and documents you submit, which may include sensitive information. We are the intended recipient of what you submit to us | Service providers and Model Providers, only as needed to provide the features you use |
We do not use sensitive personal information to infer characteristics about you. We use it only to provide the Services you ask for and for the security and legal purposes the law permits.
11. How to exercise your rights
How to ask. Email ed@humanizer.com from the address on your account, with "Privacy request" in the subject line, or write to HUMANIZER.COM LLC, PO Box 724, Lynbrook, NY 11563, USA. Tell us who you are, which Service you use and what you want us to do. We do not charge a fee for reasonable requests.
Verification. For account-related requests, we confirm that the request comes from your account email or by signing in. We may ask for more information only if we need it to be sure it is you. We will not ask for more than we need.
Our timing. We confirm we received your request within 10 business days. We respond within 45 days. If we need more time, we may extend by another 45 days and will tell you why before the first 45 days end.
If we say no. We will tell you why. We may refuse a request that is repeated or manifestly unfounded, that we cannot verify, or where an exception in the law applies.
Appeals. If you disagree with our decision, email ed@humanizer.com with "Privacy appeal" in the subject line and tell us why. We respond within 45 days, and can extend by up to 15 more days where reasonably necessary (telling you if we do). If we deny your appeal, you may contact your state attorney general. In New York, that is the Office of the Attorney General (ag.ny.gov).
12. Account deletion and export
Deleting your account. Email ed@humanizer.com with "Delete my account" in the subject line and ask us to close and delete your account. After we verify your request, we delete your account data and Your Content from our systems within 30 days, apart from the records described in Section 8, and we let you know when it is done. Account deletion is not yet available as a button in the Services.
Post-Social. Post-Social has an erase option in Settings > Your data. It de-identifies your comments and deletes your scores, notes and subscriptions. Billing ledger records are kept as described in Section 3.4. Nodes you published are not removed by the erase option; ask us to remove them.
Gravity Press. To delete a Gravity Press account, email us. We keep order, financial and rights-statement records as described in Section 8.
Plans that end. If a paid plan ends, Your Content is not deleted automatically. You can ask us at any time to export or delete it. If we introduce a deletion period for accounts whose plan has ended, we will update this policy before it applies.
Desktop App. Your local data stays on your device after you close a cloud account. Delete the application data folders to remove it.
Exporting your data. Post-Social has an export option in Settings > Your data. Your Desktop App archive is stored in files on your device and can be exported to portable bundles. For Studio and Gravity Press, email us and we will send a copy of your data in a common machine-readable format (such as JSON) within 30 days.
13. Children
The Services are for people who are 18 or older. By using the Services you confirm that you are. The Services are not directed to children, and we do not knowingly collect personal information from anyone under 18. We do not market to children.
If we learn that someone under 18 has given us personal information, we will delete the account and the associated information, which we aim to do within 30 days. If you believe a child has given us information, email ed@humanizer.com with "Under 18" in the subject line. This also covers our obligations under the Children's Online Privacy Protection Act.
14. International users and hosting
14.1 Where we process information
We are based in the United States. Our main data stores are hosted by Cloudflare and by DigitalOcean in its New York region. Some of our providers run global networks, and we have not restricted where Cloudflare stores data, so some processing and storage (for example, delivering pages, blocking attacks, caching, or running AI models) can happen in other countries. If you use the Services from outside the United States, your information is transferred to and processed in the United States and those other countries, where privacy laws may differ from yours.
14.2 EEA, United Kingdom and Switzerland
The Services are not offered in the European Economic Area, the United Kingdom or Switzerland. Please do not use them from there. We do not knowingly accept accounts from those places.
14.3 Other countries
The Services are offered in some other countries, and not in the places listed in our Terms of Service and our Sanctions and Export Statement. Wherever you live, you may use the process in Sections 10 and 11. If a local law gives you additional rights that apply to us, we will respect them. If you are in Canada (outside Quebec), Australia or another country with a privacy regulator, you may also contact it. Contact our person responsible for privacy (Section 1) with questions.
15. Security incidents
If a security incident affects your personal information, we will notify you and the authorities as required by law, without undue delay. We may notify you by email or by a notice on the Services.
16. Do Not Track and Global Privacy Control
We do not track you across other websites or over time to serve advertising. Because of this, the Services do not change how they work in response to "Do Not Track" browser settings. We treat a Global Privacy Control signal as a valid request to opt out of sale, sharing and targeted advertising.
Other companies that may collect information when you use the Services: Cloudflare (as our network and bot-protection provider, including Turnstile on comment forms and web analytics on the humanizer.com website), ZITADEL and your sign-in provider (when you sign in), Stripe (when you pay), and Google (Google Analytics on the humanizer.com website, until we remove it).
17. Cookies and local storage
Studio, Post-Social and Gravity Press use first-party cookies and browser storage that are needed to keep you signed in, keep the Services secure and remember your settings. They do not use advertising cookies. The humanizer.com website currently also sets Google Analytics cookies (Section 7). See the Cookie and Local Storage Notice for the list and how to control them.
18. Marketing email
We do not currently send marketing email. If we start, each message will identify HUMANIZER.COM LLC, PO Box 724, Lynbrook, NY 11563, USA as the sender and include a way to unsubscribe, and we will honor an unsubscribe request within 10 business days. We may still send you service messages that are not marketing, such as security notices and billing messages.
19. Changes to this policy
We may change this policy. If we make a material change, we will post the new version on this page at least 30 days before it takes effect, and we may also tell you by email or by a notice in the Services. We update the date at the top for any change. We do not apply a change that loosens how we use personal information we have already collected without getting your consent first.
20. Contact and complaints
Questions, requests or complaints about privacy: ed@humanizer.com (subject line "Privacy request"), (516) 809-8445, or HUMANIZER.COM LLC, PO Box 724, Lynbrook, NY 11563, USA. We aim to answer within 45 days. If you are not satisfied, you may contact your state attorney general or another regulator that has authority where you live.
The same address, ed@humanizer.com, handles support, legal notices, copyright notices, content and abuse reports, and security reports. Please put the topic in the subject line.