Cookie Policy
Cookie and Device Storage Policy — humai.pl
Effective date: 7 July 2026 Last updated: 7 July 2026 Version: 1.0
Governing language and governing law. This document is a courtesy English translation of the Polish original — Polityka plików cookies i pamięci urządzenia końcowego — humai.pl (available at https://humai.pl/polityka-cookies). The Polish version is the legally binding text; in the event of any discrepancy between this translation and the Polish original, the Polish version prevails. The governing law is Polish law. If you are a consumer, this choice of law does not deprive you of the protection afforded to you by provisions that cannot be derogated from by agreement under the law of the country of your habitual residence (Article 6(2) of Regulation (EC) No 593/2008 — the "Rome I" Regulation).
1. Introductory information
This Cookie Policy (the "Policy") describes how the humai.pl website (the "Service Website") uses cookies and other technologies for storing and reading data on the user's terminal equipment (in particular the browser's localStorage mechanism).
The controller of the Service Website and of the personal data processed in connection with the use of cookies is:
- AutoXCyber Mateusz Grądkowski
- sole proprietorship (CEIDG)
- ul. Wergiliusza 7/69, 01-915 Warsaw, Poland
- Tax ID (NIP): 1182241134 (VAT-exempt)
- Business Registry No. (REGON): 523059876
- Contact: [email protected]
This Policy supplements the Privacy Policy (/polityka-prywatnosci; English translation: /privacy) and the Terms of Service (/regulamin; English translation: /terms) and should be read together with those documents. With respect to the processing of personal data (e.g. logs, session identifiers), the rules described in the Privacy Policy also apply.
2. What cookies and related technologies are
Cookies are small text files saved by a website on the user's terminal equipment (computer, phone), containing, among other things, the name of the website, the storage period and a unique identifier. They can be read on subsequent visits.
Related technologies include, in particular, localStorage — a browser mechanism allowing data to be stored on the user's device without automatically sending it to the server. Under the rules on privacy in electronic communications — Article 399 of the Polish Act of 12 July 2024 — Electronic Communications Law (Journal of Laws 2024, item 1221; in force since 10 November 2024; it replaced Article 173 of the Telecommunications Law) — storing and reading information on terminal equipment, regardless of the technology used (cookie or localStorage), as a rule requires the user's consent meeting the GDPR standard, unless it is strictly necessary to provide a service requested by the user.
Classification by storage period
- Session — deleted when the browser is closed or the session expires.
- Persistent — stored for a defined period or until deleted by the user.
Classification by origin
- First-party — set directly by the humai.pl Service Website.
- Third-party — set by external providers (e.g. the login provider). The current state of use is described in section 4.
3. Legal bases
The use of cookies and terminal-equipment storage relies on the following bases:
- The necessity exception under Article 399 of the Electronic Communications Law — storing and reading information on terminal equipment that is strictly necessary to provide a service expressly requested by the user (e.g. maintaining the session of a logged-in user, enforcing the free usage limit) does not require the user's separate consent.
- Consent under Article 399 of the Electronic Communications Law and the GDPR — for any technologies not covered by the above exception, the user's prior, freely given, informed and unambiguous consent meeting the requirements of Article 4(11) and Article 7 GDPR is required.
- The processing of personal data associated with cookies takes place on the basis of the GDPR (Regulation (EU) 2016/679):
- Article 6(1)(b) GDPR — where processing is necessary for the performance of a contract (e.g. maintaining the session of a logged-in user, providing the text humanization service);
- Article 6(1)(f) GDPR — the controller's legitimate interest (e.g. ensuring security, preventing abuse, enforcing free plan limits);
- Article 6(1)(a) GDPR — the user's consent (for cookies/technologies other than necessary ones, e.g. analytics — if implemented in the future).
Consent to cookies other than necessary ones is voluntary and may be withdrawn at any time (section 7). Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.
4. Technologies actually used on the Service Website
The table below reflects the actual technical state of the Service Website. humai.pl applies the principle of minimisation and does not use cookies to any greater extent than necessary.
4.1. Necessary (technical) — no consent required
These technologies are necessary for the proper operation of the Service Website and for providing the service requested by the user. Without them, logging in and using the account would not be possible.
| Name / mechanism | Type | Purpose | Storage period | Basis |
|---|---|---|---|---|
| Session cookie (Auth.js / NextAuth — JWT session token) | First-party cookie, session/persistent | Maintaining the logged-in user's session, authentication, login security | Duration of the session / validity period of the JWT token | Necessary to provide the service (Article 399 of the Electronic Communications Law — exempt from the consent requirement); GDPR Article 6(1)(b) |
| Security / CSRF cookies (set by Auth.js) | First-party cookie, session | Protection against CSRF attacks, security of login forms | Session | Necessary; GDPR Article 6(1)(f) |
| localStorage — anonymous free-usage counter | localStorage, first-party | Enforcing the Free plan limit (3 humanizations/day) for non-logged-in users on the browser side | Until deleted by the user | Necessary to provide the service requested by the user — the free Free plan in the form offered (a daily limit without registration) cannot be provided without a usage counter, so the counter is an element of the requested service (Article 399 of the Electronic Communications Law — exempt from the consent requirement); additionally GDPR Article 6(1)(f) |
| localStorage — stored cookie-consent choice | localStorage, first-party | Storing information about the user's choice in the consent banner (so the banner is not shown on every visit) | Until deleted by the user | Necessary for operating the consent management mechanism; Article 399 of the Electronic Communications Law — exempt from the consent requirement |
Note: The user session on humai.pl is implemented using the Auth.js (JWT in a cookie) mechanism. The session cookie is strictly necessary to maintain the logged-in state and as such does not require the user's consent. The Service Website does not store the full content of the input or of the humanization result — the history stores only: the tone, the length of the input text (character count), a shortened preview of the result (up to 90 characters), the token count, style indicators and a timestamp.
4.2. Third-party cookies and technologies — login and payments
| Provider | Purpose | Notes |
|---|---|---|
| Google LLC (login via Google OAuth) | Authenticating a user logging in with a Google account | If the user logs in with Google, the provider may set its own cookies as part of the login process, in accordance with its privacy policy. humai.pl does not control these files. Google LLC holds an active EU-US Data Privacy Framework certification. |
| Stripe, Inc. (card payment handling) | Performing and securing payments for the Pro plan; handling the renewable subscription | During the payment process the provider may use its own cookies, including for security and fraud prevention purposes, in accordance with Stripe's policy. Stripe, Inc. holds an active EU-US Data Privacy Framework certification (including the UK Extension and the Swiss-US DPF). |
4.3. Analytics and marketing — currently not used
As at the effective date of this Policy, the humai.pl Service Website does not use cookies or other technologies for analytics purposes (e.g. Google Analytics) or marketing/advertising purposes (e.g. advertising pixels, remarketing).
If analytics or marketing tools are implemented in the future:
- they will be used only after obtaining the user's prior consent (GDPR Article 6(1)(a) and Article 399 of the Electronic Communications Law),
- this Policy will be updated with the provider's name, the purpose, the storage period and information about any transfer of data outside the EEA,
- the user will be given the ability to manage consent through a banner or a privacy settings panel.
5. Related information: server-side anonymous usage counter (anon_usage)
Independently of browser storage, in order to enforce Free plan limits and prevent abuse, the Service Website stores on the server side a daily hashed identifier based on the IP address (the anon_usage mechanism — a SHA-256 hash of the IP address on a given day), retained for 30 days.
Note: This is not a cookie or localStorage, but server-side processing. A hashed IP address may constitute personal data (pseudonymised) within the meaning of the GDPR. The basis is the controller's legitimate interest — Article 6(1)(f) GDPR (enforcing limits, preventing abuse). A detailed description of this processing can be found in the Privacy Policy (/polityka-prywatnosci; English translation: /privacy).
6. Transfers of data outside the EEA
Some providers connected with the operation of the Service Website process data in countries outside the European Economic Area, including the USA. These transfers take place on the basis of appropriate safeguards provided for in Chapter V of the GDPR (Articles 44–49):
- Google LLC — active EU-US Data Privacy Framework certification (Article 45 GDPR — adequacy decision);
- Stripe, Inc. — active EU-US Data Privacy Framework certification (including the UK Extension and the Swiss-US DPF); Article 45 GDPR;
- Anthropic PBC (provider of the Claude language model) — no DPF certification; transfer on the basis of Standard Contractual Clauses (SCCs), Commission Implementing Decision (EU) 2021/914, Article 46(2)(c) GDPR, included in the data processing agreement (DPA).
The current certification status of providers holding DPF status can be verified at dataprivacyframework.gov. Details of all transfers are described in the Privacy Policy.
7. How to manage cookies and device storage
The user has several ways of controlling cookies and browser storage:
7.1. Settings on the Service Website
The Service Website displays a consent banner on the first visit. In it, the user may give or refuse consent to cookies not covered by the necessity exception. The choice is stored in localStorage (see section 4.1). Consent may be withdrawn at any time by contacting the Controller at [email protected] or by using the browser settings (section 7.2).
7.2. Browser settings
Most browsers allow cookies to be managed and site data (including localStorage) to be cleared. The user may:
- block or restrict the acceptance of cookies,
- delete stored cookies and localStorage data,
- enable notifications when a cookie is set.
Instructions for popular browsers:
- Google Chrome: Settings → Privacy and security → Cookies and other site data
- Mozilla Firefox: Settings → Privacy & Security → Cookies and Site Data
- Safari: Preferences → Privacy
- Microsoft Edge: Settings → Cookies and site permissions
Note: Disabling or deleting necessary cookies (e.g. the Auth.js session cookie) may make it impossible to log in and to use the account and the text humanization service. Deleting localStorage data may reset the free-usage counter and cause the consent banner to be displayed again.
7.3. Withdrawal of consent
With respect to cookies/technologies based on consent, the user may withdraw it at any time — through the browser settings or by contacting [email protected]. Withdrawal of consent does not affect the lawfulness of processing carried out beforehand.
8. User rights (GDPR)
To the extent that data stored or read via cookies/localStorage constitute personal data, the user has the rights described in detail in the Privacy Policy (/polityka-prywatnosci; English translation: /privacy), including: the right of access, rectification, erasure, restriction of processing, objection, data portability (Articles 15–22 GDPR) and the right to lodge a complaint with the President of the Polish Personal Data Protection Office (PUODO) — Article 77 GDPR (ul. Stawki 2, 00-193 Warsaw, Poland).
9. Changes to the Policy
The Controller may update this Policy, in particular if new technologies are implemented (e.g. analytics), providers change or the legal situation changes. The current version is always published on the Service Website together with the date of the last update.
10. Contact
For matters concerning cookies and privacy, please contact:
- E-mail: [email protected]
- Controller: AutoXCyber Mateusz Grądkowski, ul. Wergiliusza 7/69, 01-915 Warsaw, Poland