← HumAIn

Privacy Policy

Effective date: July 16, 2026

HumAIn ("HumAIn", "we", "us") is an AI email concierge that connects to your mailbox and runs automations you choose. This policy explains what we collect, why, and what we never do with it.

What we collect

How we use mailbox data

Mail content is processed only to perform the action you asked for — triaging your inbox, drafting a reply, collecting receipts, unsubscribing, or cleaning up clutter. When you ask HumAIn to draft a reply, the relevant message content is sent to our AI provider (OpenAI) to generate that draft and is not used by us to train models.

HumAIn's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

What we never do

Storage & security

Data is stored in a managed PostgreSQL database. Mailbox refresh tokens are encrypted at rest with AES-256-GCM; access tokens are short-lived and minted per request. All traffic uses HTTPS/TLS. On supported devices, the app stores the Clerk session token in the operating system's secure credential storage so you can remain signed in across restarts. Signing out removes the local session.

Beta waitlist records are private. Only authorized HumAIn operations reviewers can access the submitted email, optional pathway context, reference, submission date, and manual review status. We use that information to manage beta invitations and reply by email. There is no public waitlist, member list, or profile, and the public signup route does not provide a read or list endpoint. The intake does not read or store an IP address.

Technology partnership applications are private intake records. Only authorized HumAIn operations reviewers can access them. We use the information to review the application, prevent intake abuse, document the manual decision, and contact the submitted representatives about a possible partnership. Submitting or approving an application does not publish it or create a public partner profile.

While you complete the public partnership journey, your browser may keep the unfinished application fields in session storage for that tab so closing and reopening the journey does not discard your work. The draft is not sent to HumAIn until you submit it, and the tab clears it after a successful submission or an explicit pathway reset.

We retain a partnership application while it is under review and for as long as reasonably needed to manage or document the resulting relationship, resolve disputes, protect the intake from abuse, or meet legal obligations. Applicants can request deletion as described below; we delete the record after verifying the request unless retention is still required for security or legal reasons.

Deleting your data

Service providers

We rely on: Clerk (sign-in), Google APIs (Gmail access you authorize), Microsoft APIs (Outlook access you authorize when available), OpenAI (AI draft generation), RevenueCat plus Apple/Google billing (subscriptions), and Replit (hosting). Each receives only what it needs to perform its function.

Changes

If this policy changes materially, we will update this page and the effective date above.

Contact

Questions or requests: support@humain.run