What we collect.
What we don't.
Short version: we do store the text you paste, and we would rather tell you that than pretend otherwise. We keep it for three things, all named below: investigating abuse, checking our own output quality, and training our in-house AI-detection models. We never sell it, never hand it to anyone else to train their models, and run no third-party trackers. One email gets it deleted. The long version is below, with a plain-English translation next to every legal paragraph.
1. What we collect
When you use HumanGPT we receive the text you submit to the tool, the rewritten text we produce from it, the IP address your request comes from, basic browser metadata (user agent, referrer, language), and any account information you provide if you sign up. We store the submitted text and the rewritten output in our database along with a per-account or per-browser identifier and the country the request originated from. That is the entire list.
2. What we do with the text you paste
Your text is sent to our humanizer or detector pipeline and the result is returned to you. Both the submission and the result are then stored in our database. We use them for three things and nothing else. First, to investigate abuse, when a complaint or an anomalous usage pattern points at a specific account. Second, to measure whether our own output quality is improving or degrading between releases, which sometimes involves a member of our team reading a stored submission and involves re-scoring stored submissions through the detection services named in section 4. Third, to improve our own detection and ranking models: stored submissions and their scores are fed into training runs for the in-house classifiers that decide whether a piece of text reads as machine-written. That third use is training, on our own models, on our own infrastructure, and we would rather name it than hide it behind softer language.
What we do not do with it: we do not sell it, we do not rent it, we do not use it for advertising or profiling, we do not publish it, and we do not hand it to a third party to train that third party's models. The external providers in section 4 process your text to return a result to us and are contractually barred under their standard API terms from training their own models on it. If you would rather your text not be part of our training corpus, email us and we will exclude and delete it.
3. Cookies and tracking
We use one essential cookie to maintain your free-tier rate limit per browser session, and, if you sign in, a session cookie issued by our authentication provider so you stay logged in. We do not use Google Analytics, Facebook Pixel, third-party advertising trackers, or any cross-site tracking technology. We do use Cloudflare to keep the site fast and protected from abuse, which involves Cloudflare seeing your request metadata (this is industry-standard for any modern website).
- No Google Analytics. No GA4. No Facebook Pixel. No TikTok Pixel.
- No third-party advertising cookies. We don't run ads.
- No retargeting. If you leave, you leave. We don't follow you around the internet.
- Yes, Cloudflare for DDoS protection. Yes, PayPal for payments (only if you upgrade).
4. Who we share data with
We use the smallest set of processors that lets the product work, and we name all of them. The following receive the text you submit, because rewriting and scoring it is what they do: Google LLC (Gemini API, rewriting and scoring), OpenAI L.L.C. (base-model rewriting, embeddings and detector scoring), Hugging Face, Inc. (hosted detection models), Together AI and DeepInfra, Inc. (open-weight model inference), and GPTZero, Inc. (detection scoring during our own quality evaluation of stored runs). The following handle your data without being sent your text for rewriting: Vercel Inc. (application hosting, your request passes through it in transit), Supabase, Inc. (the database where accounts and stored runs live), Cloudflare, Inc. (DNS, CDN and abuse protection, which sees request metadata), PayPal (payments, only if you buy something), Resend and ZeptoMail (transactional and newsletter email, only if you have an account or subscribed), and Formspree (contact form submissions, only if you use that form). We do not share your data with anyone outside this list.
5. International users and GDPR / CCPA
We comply with GDPR (EU/UK) and CCPA (California) and treat the rights they grant as global rights for every user. You can request access to all data we hold on you, request correction, request deletion, and object to processing at any time. We respond to these requests within 30 days, usually within 48 hours. Email [email protected] with the subject 'Privacy request' and include the email address you used to sign up.
6. Data retention
Submitted text and rewritten output: we retain these until you ask us to delete them, or until we delete your account. We do not currently run an automatic expiry on them, and we would rather say that plainly than publish a retention window we are not enforcing. Account records (email, plan, billing history): kept for as long as the account exists, plus 90 days after closure for legal and accounting purposes, then hard-deleted. Rate-limit counters: reset every 24 hours.
6b. Deleting your data
Deletion is handled by request rather than by a button in the dashboard. Email [email protected] from the address on your account, or, if you never made an account, from any address, with a description of what you need removed. We delete stored submissions and outputs on request, and we confirm in writing once it is done. We aim to complete this within 48 hours and we are bound to 30 days under GDPR. Deleting your submissions does not cancel a subscription and cancelling a subscription does not delete your submissions, so tell us if you want both.
7. Children's privacy
HumanGPT is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe a child has provided us with personal information, contact us and we will delete it within 7 days.
8. Security
We use HTTPS everywhere. Accounts are handled by Supabase Auth, which stores credentials hashed and salted; we never see or store a plaintext password. Stored submissions sit in a Postgres database that is not exposed to the public internet and is reachable only by the application and by an administrator. PayPal handles payment information end-to-end (we never receive your full card number). Our infrastructure runs on Vercel, Supabase and Cloudflare, all of which are SOC 2 certified.
9. Changes to this policy
When we make a material change to this policy we will email all account holders and post a notice on the homepage at least 30 days before the change takes effect. Minor edits (clarifying language, fixing typos) we just push.
10. Contact
Privacy questions: [email protected]. We aim to respond within 24 hours, faster if it's a deletion or access request.