Privacy Policy
Effective date: July 16, 2026
HumAIn ("HumAIn", "we", "us") is an AI email concierge that connects to your mailbox and runs automations you choose. This policy explains what we collect, why, and what we never do with it.
What we collect
- Account information. When you sign in (via our authentication provider, Clerk), we receive your name, email address, and a unique account identifier.
- Mailbox access. When you connect a supported Gmail or Outlook mailbox, you grant HumAIn permission to read and modify mail for the workflows you run (for example to archive messages, file receipts, or unsubscribe) through the provider's official API. We store an encrypted refresh token (AES-256-GCM) so the connection can work when you ask it to; we never see or store your password.
- Workflow data. To power features you use, we store small snapshots: reminder entries (message subject, sender name, and a short snippet you chose to be reminded about), your active workflows, your daily AI-draft usage count, and workflow requests or votes you submit.
- Purchase status. If you subscribe, our billing provider (RevenueCat, on top of Apple App Store or Google Play billing) tells us your subscription tier. We never see your payment card details.
- Beta waitlist. If you join the beta waitlist, we collect the email address you enter and, when you have explicitly chosen one, the optional pathway context already selected in this browser tab (individual, team, company, technology, or unsure).
- Technology partnership applications. If you apply to partner with HumAIn, we collect the company, product, website, target market, use cases, integrations, technical capabilities, security context, geographic availability, pricing context, pilot readiness, collaboration interests, and technical and commercial contact emails you submit.
How we use mailbox data
Mail content is processed only to perform the action you asked for — triaging your inbox, drafting a reply, collecting receipts, unsubscribing, or cleaning up clutter. When you ask HumAIn to draft a reply, the relevant message content is sent to our AI provider (OpenAI) to generate that draft and is not used by us to train models.
HumAIn's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
What we never do
- We do not sell your data. To anyone. Ever.
- We do not use your mail content for advertising.
- We do not use your mail content to train AI models.
- We do not read your mailbox in the background beyond the workflows you explicitly enabled.
Storage & security
Data is stored in a managed PostgreSQL database. Mailbox refresh tokens are encrypted at rest with AES-256-GCM; access tokens are short-lived and minted per request. All traffic uses HTTPS/TLS. On supported devices, the app stores the Clerk session token in the operating system's secure credential storage so you can remain signed in across restarts. Signing out removes the local session.
Beta waitlist records are private. Only authorized HumAIn operations reviewers can access the submitted email, optional pathway context, reference, submission date, and manual review status. We use that information to manage beta invitations and reply by email. There is no public waitlist, member list, or profile, and the public signup route does not provide a read or list endpoint. The intake does not read or store an IP address.
Technology partnership applications are private intake records. Only authorized HumAIn operations reviewers can access them. We use the information to review the application, prevent intake abuse, document the manual decision, and contact the submitted representatives about a possible partnership. Submitting or approving an application does not publish it or create a public partner profile.
While you complete the public partnership journey, your browser may keep the unfinished application fields in session storage for that tab so closing and reopening the journey does not discard your work. The draft is not sent to HumAIn until you submit it, and the tab clears it after a successful submission or an explicit pathway reset.
We retain a partnership application while it is under review and for as long as reasonably needed to manage or document the resulting relationship, resolve disputes, protect the intake from abuse, or meet legal obligations. Applicants can request deletion as described below; we delete the record after verifying the request unless retention is still required for security or legal reasons.
Deleting your data
- Disconnect your mailbox any time in Settings. Disconnecting in Settings asks HumAIn's server to delete its stored mailbox refresh token. For Gmail, the server also attempts to revoke the token at Google, but that provider step is best-effort; for Outlook, Microsoft does not provide a token-revocation endpoint for this flow, so deleting HumAIn's stored token is the disconnect. The app clears its local connection only after the server confirms token deletion; if server deletion fails, the app shows an error so you can retry.
- Delete your account from Settings in the app, or by contacting support@humain.run. A successful deletion removes the account record, connections, reminders, and activity covered by the deletion process.
- Delete a beta waitlist signup by emailing support@humain.run from the address submitted to the waitlist. We use that address to verify the request before deleting the private intake record, subject to any limited security or legal retention requirement. No HumAIn account is required.
- Delete a technology partnership application by emailing support@humain.run from one of the contact addresses submitted with the application. We use that address to verify the request before deleting the private intake record, subject to the limited security and legal retention described above. No HumAIn account is required.
- You can also revoke HumAIn's access directly in your mail provider's account settings. For Google, use your Google Account permissions at any time.
Service providers
We rely on: Clerk (sign-in), Google APIs (Gmail access you authorize), Microsoft APIs (Outlook access you authorize when available), OpenAI (AI draft generation), RevenueCat plus Apple/Google billing (subscriptions), and Replit (hosting). Each receives only what it needs to perform its function.
Changes
If this policy changes materially, we will update this page and the effective date above.
Contact
Questions or requests: support@humain.run