Humanym
Humanym — Privacy Policy
Last updated: August 31, 2026
This Privacy Policy explains how Humanym LLC, a Wyoming limited liability company ("Humanym," "we," "us," "our"), collects, uses, stores, and protects your information when you use the Humanym website (humanym.com) and our iOS and Android apps (together, "the Platform"). We believe in transparency, so this document is written in plain language.
1. The Short Version
- We collect your email address to sign you in. That is the only personal identifier we require.
- We analyze how you write (style, tone, vocabulary) to match you with compatible correspondents. We do not analyze your writing for advertising, and we do not use it to train AI models.
- If you choose to verify your identity, a third-party provider (Veriff) checks a government ID and a selfie. Those images stay with Veriff — we never receive or store them. We keep only your legal name, an 18-or-older indicator, and the decision result.
- Your correspondence is stored encrypted at rest, and your identity is anonymous by default.
- We do not sell your data, we do not show ads, and we do not track you across other apps or websites. On our public web pages (the pages you can see without signing in) we use a cookieless, privacy-configured page-view counter; we never run third-party analytics inside your signed-in account. See Section 8.
- You can deactivate and delete your account yourself, at any time.
2. Information We Collect
2.1 Information You Provide
| Data | When | Why |
|---|---|---|
| Email address | Account creation / sign-in | Authentication (one-time verification code) |
| Letter text | When you write and submit | Delivery to matched recipients; analysis for matching |
| Reply text | When you reply in a conversation | Delivery to your conversation partner |
| Reveal name (verified users) | After verification, optionally edited | Shown to a correspondent only under mutual identity reveal |
| Report reasons | When you report content | Content moderation |
| Appeal text | When you appeal a moderation decision | Appeal review |
| Payment information | Subscription or purchase | Processed by Stripe, Apple, or Google — we never store your card number |
We do not collect or store profile photos. Humanym uses catalog avatar icons only; there is no image upload anywhere on the Platform.
2.2 Information We Generate
| Data | How | Why |
|---|---|---|
| Anonymous aliases | Generated per conversation | Protect your identity — each correspondent sees a unique alias for you |
| Content / voice / intent analysis | AI analysis of your writing | Matching |
| Vector embeddings | Mathematical representation of your writing | Efficient similarity search for matching |
| Writing profile | Aggregated from your writing over time | Improve matching as you write more |
| Entitlements and purchases | When you subscribe, verify, or buy a pack | Unlock the features and items you are entitled to |
2.3 Information Collected Automatically
| Data | How | Why |
|---|---|---|
| IP address | Server logs | Security, abuse prevention |
| Device / browser information | HTTP headers; mobile OS | Rendering, compatibility |
| Usage timestamps | Server-side logging | Service operation, debugging |
| Push notification token (mobile, if you enable notifications) | From Apple Push Notification service / Firebase Cloud Messaging | Deliver the notifications you turn on |
| Store transaction identifiers (mobile) | From Apple / Google at purchase | Validate in-app purchases and grant entitlements |
We do not use tracking cookies or advertising identifiers anywhere on the Platform. On our public web pages only (the landing, about, contact, and legal pages — pages you can view without signing in) we use Google Analytics in a restricted, cookieless configuration to count visits (see Section 8.1). We never run third-party analytics inside the signed-in experience — your account, your letters, and your conversations are not measured by any third party.
3. Identity Verification Data (Veriff)
If you choose to verify your identity, the document and biometric portions of that process are handled entirely by our verification provider, Veriff:
- What Veriff processes: your government-issued ID document image and a selfie/liveness capture. These never touch Humanym's servers. They are processed and retained by Veriff under Veriff's own privacy policy and retention schedule. We do not enable any extended-retention add-on.
- What we receive and store: your legal name, an 18-or-older indicator (we store the indicator, not your date of birth), and the decision result with a Veriff session reference.
- How we use your legal name: to set and validate your reveal name. Your legal name is write-only from Veriff's result and server-read-only for name checks — it is never returned to any app and never shown to another user. The only name another user can ever see is the reveal name you choose, and only under mutual identity reveal.
Verification requires that you are 18 or older. See Section 7 of the Terms of Service for how verification works.
4. How We Use Your Information
We use your information for these purposes and no others:
- Authentication — verify you when you sign in.
- Content delivery — deliver your letters and replies to matched recipients.
- Matching — analyze your writing to find compatible correspondents.
- Content moderation — screen for prohibited content before delivery.
- Identity verification — confirm a verified user is a real adult (via Veriff).
- Payments and entitlements — process purchases and unlock what you are entitled to.
- Notifications — send sign-in codes and, if you enable them, match and conversation notifications (by email and/or push).
- Service operation — maintain, secure, debug, and improve the Platform.
- Audience measurement (public pages only) — count visits to our public marketing pages so we know which pages people find. This never applies to signed-in use.
We do not: sell your personal information; show advertising; use your writing to train AI models; share your email address with other users; build advertising profiles; or track you across other apps or websites.
5. How We Store Your Information
5.1 Infrastructure
Your data is stored on Amazon Web Services (AWS) in the United States:
- DynamoDB — user records, correspondence, conversations, entitlements, delivery records;
- Redis — caching, session data, and real-time state (ephemeral).
All data is encrypted at rest and in transit (TLS).
5.2 Retention
| Data | Retained for |
|---|---|
| Account data (email, alias mappings, settings) | Until you delete your account |
| Correspondence text | Until you delete your account, or indefinitely in a recipient's conversation history |
| Analysis results and writing profile | Same as the correspondence they derive from |
| Vector embeddings | Until the correspondence expires or is removed from circulation |
| Verification record (legal name, 18+ indicator, decision) | Until you delete your account |
| Entitlement / purchase records | Until you delete your account (payment/tax records: see below) |
| Delivery and notification records | Up to 30 days |
| Session / refresh tokens | Up to 30 days (auto-expire) |
| Server logs | 30 days |
| Payment and tax records | As required by law (typically up to 7 years), with personal identifiers minimized |
5.3 Deletion
You can deactivate and delete your account yourself from Settings. Deletion is recoverable for 30 days and then permanent:
- Immediately on request: your account is deactivated — you are signed out everywhere, and matching and sending stop.
- For 30 days: signing back in lets you reactivate with nothing lost.
- After 30 days: we permanently delete the data that belongs only to you — your user record, email marker, entitlements, embeddings, analysis, openings, sessions, and ephemeral Redis state.
- Shared conversations: in a two-party conversation, we remove your identifying information but keep your correspondent's copy of the exchange readable to them, because that content is also theirs.
- Retained where required: payment and tax records are kept for the period the law requires, with personal identifiers minimized. Your identity-document and selfie data are held only by Veriff under their retention policy.
6. Who We Share Your Information With
6.1 Matched Recipients
Your letter text and alias are shared with the recipients the matching system selects. Your email address is never shared with other users. Under mutual identity reveal (verified users only), your chosen reveal name is shared with your correspondent.
6.2 Service Providers
We use the following third parties to operate the Platform. Each receives only what it needs for its function:
| Provider | Purpose | Data shared |
|---|---|---|
| Amazon Web Services (AWS) | Hosting, storage, compute | All Platform data (stored on their infrastructure) |
| OpenAI | Content, voice, and intent analysis | Your letter text (sent for analysis; not used to train their models per our agreement) |
| Veriff | Identity verification | The government-ID and selfie data you submit during verification (held by Veriff, not by us) |
| Stripe | Website payments and tax | Email and payment method (card details go directly to Stripe; we never store them) |
| Google Analytics | Visit counting on public web pages only | Page URL and referrer of the public page, truncated/coarse device and browser info, and your IP address in transit (Google Analytics does not log or store full IP addresses). Configured cookieless — no persistent identifier is set — with Google Signals and ad personalization disabled. Not loaded if your browser sends Global Privacy Control or Do Not Track, and never loaded inside the signed-in app. |
| Apple | iOS in-app purchases and push notifications | Purchase/transaction identifiers; push token (if you enable notifications) |
| Android in-app purchases and push notifications | Purchase/transaction identifiers; push token (if you enable notifications) | |
| AWS SES | Email delivery | Email address (for sign-in and notification emails) |
6.3 Law Enforcement
We may disclose your information if required by law, subpoena, or court order. We will notify you of such requests unless legally prohibited from doing so.
6.4 No One Else
We do not sell, rent, or trade your personal information. We do not share it with data brokers, advertising networks, or marketing companies.
7. Your Rights
7.1 Access and Portability
You may request a copy of the personal data we hold about you. Contact support@humanym.com and we will respond within 30 days.
7.2 Correction
You may update your email address and reveal name through the Platform at any time.
7.3 Deletion
You may deactivate and delete your account yourself from Settings, at any time. See Section 5.3 for what is deleted, anonymized, and retained.
7.4 AI Analysis
The AI analysis of your writing is essential to the matching service and cannot be turned off while you use the Platform. If you do not want your writing analyzed for matching, please do not use Humanym. This analysis is inference-only and is never used to train AI models.
8. Cookies and Tracking
8.1 On the Website
We use a single functional session cookie to keep you signed in. It holds your authentication token and expires when your session ends (or after up to 30 days). We do not use analytics cookies, advertising cookies, tracking pixels, or fingerprinting.
On our public pages only (landing, about, contact, and legal pages), we use Google Analytics in a restricted configuration to count page views: it stores no cookies and no identifiers on your device, Google Signals and ad-personalization features are off, and it is not loaded at all if your browser sends a Global Privacy Control or Do Not Track signal. It never runs inside your signed-in account — nothing you do while signed in (your home, letters, conversations, or settings) is sent to any analytics provider.
8.2 In the Mobile Apps
The apps do not use advertising identifiers. If you enable notifications, we store a push token to deliver them. In-app purchases use transaction identifiers provided by Apple or Google to validate your purchase and grant entitlements.
8.3 Social Login
If you sign in with Google or Apple, those providers may set their own cookies or use their own identifiers during the authentication flow, governed by their respective privacy policies.
9. Children's Privacy
Humanym is not intended for anyone under 18. We do not knowingly collect personal information from children. If you believe a child under 18 is using the Platform, contact support@humanym.com and we will remove the account.
10. International Data Transfers
Your data is processed and stored in the United States on AWS infrastructure. If you are located outside the United States, your data will be transferred to the US. By using the Platform, you consent to this transfer.
For users in the European Economic Area (EEA) or United Kingdom, we rely on Standard Contractual Clauses and our data-processing agreements with our service providers (including AWS, OpenAI, Veriff, Stripe, Apple, and Google) as the legal basis for these transfers.
11. Security
We implement reasonable measures to protect your data:
- All data encrypted at rest (AES-256) and in transit (TLS 1.2+);
- Short-lived authentication tokens (minutes-long access tokens; refresh tokens up to 30 days), with immediate revocation support;
- Identity-document and biometric data handled entirely by Veriff — never stored on our servers;
- Payment card data handled by Stripe, Apple, and Google (PCI-compliant) — we never see or store card numbers;
- API keys and secrets stored in encrypted secret storage.
No system is perfectly secure. If we become aware of a data breach affecting your personal information, we will notify you and the relevant authorities as required by law.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date and notify you by email or an in-app notice. Continued use of the Platform after changes take effect constitutes acceptance of the updated policy.
13. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have the right to:
- Know what personal information we collect and how we use it (see Sections 2–4);
- Access a copy of your personal information (Section 7.1);
- Delete your personal information (Section 7.3);
- Correct inaccurate personal information (Section 7.2);
- Opt out of "sale" or "sharing" of personal information — we do not sell your personal information and do not share it for cross-context behavioral advertising; and
- Non-discrimination — we will not treat you differently for exercising your rights.
- Our website honors the Global Privacy Control browser signal.
To exercise these rights, contact support@humanym.com.
14. GDPR Rights (EEA/UK)
If you are in the EEA or UK, your rights include:
- Legal bases for processing: performance of our contract with you (delivering the service you signed up for), your consent (e.g., enabling notifications, completing verification), legitimate interests (operating, securing, and improving the Platform, and cookieless measurement of visits to our public web pages), and legal obligation (tax and compliance records).
- Access, rectification, and erasure of your personal data;
- Restriction of and objection to certain processing;
- Data portability in a machine-readable format; and
- Withdrawal of consent at any time, including by deleting your account.
To exercise these rights, contact support@humanym.com. If you are in the EEA or UK and believe we have not adequately addressed your concerns, you may lodge a complaint with your local Data Protection Authority.
15. Contact
For privacy questions, data-access requests, or concerns:
Email: support@humanym.com
Humanym LLC — a Wyoming limited liability company.