Privacy Policy
PRIVACY POLICY (GDPR) — humai.pl
Effective date: 7 July 2026 Last updated: 7 July 2026 Version: 1.0
Governing language and governing law. This document is a courtesy English translation of the Polish original — Polityka Prywatności (RODO) — humai.pl (available at https://humai.pl/polityka-prywatnosci). The Polish version is the legally binding text; in the event of any discrepancy between this translation and the Polish original, the Polish version prevails. The processing of personal data is governed by the GDPR and by Polish law. If you are a consumer, the choice of Polish law for the contract does not deprive you of the protection afforded to you by provisions that cannot be derogated from by agreement under the law of the country of your habitual residence (Article 6(2) of Regulation (EC) No 593/2008 — the "Rome I" Regulation).
1. Introduction
This Privacy Policy describes the rules for the processing of personal data of users of the humai.pl website (the "Service Website", the "Service"), which enables the processing ("humanization") of text with the involvement of artificial intelligence systems.
This document fulfils the information obligation arising from Article 13 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (GDPR).
The data are collected directly from the data subject, which is why Article 13 GDPR applies (and not Article 14).
2. Controller of personal data
The controller of your personal data within the meaning of Article 4(7) GDPR is:
- Name: AutoXCyber Mateusz Grądkowski
- Legal form: sole proprietorship (CEIDG)
- Tax ID (NIP): 1182241134 (VAT-exempt)
- Business Registry No. (REGON) / KRS: 523059876 (no KRS number)
- Registered office address: ul. Wergiliusza 7/69, 01-915 Warsaw, Poland
- E-mail address for personal data matters: [email protected]
In all matters concerning the processing of personal data and the exercise of your rights, you can contact the Controller at the e-mail address indicated above.
3. Data Protection Officer (DPO)
The Controller has not appointed a Data Protection Officer (DPO).
The appointment of a DPO is mandatory only in the cases indicated in Article 37(1) GDPR, i.e. where the core activities consist of regular and systematic monitoring of data subjects on a large scale, or of large-scale processing of special categories of data under Article 9 GDPR. The activity of the Service Website consists in processing text entered by the user at the user's request — the Controller does not carry out systematic monitoring of individuals, and the processing does not take place on a large scale within the meaning of recital 91 GDPR. Appointing a DPO is therefore not mandatory.
In all matters concerning personal data, contact the Controller directly (sections 2 and 16).
4. KEY INFORMATION: the text you paste is transmitted to external AI providers in the USA
This is the most important information in this Policy — please read it carefully.
The essence of the Service is the processing ("humanization") of the text you enter. In order to perform the Service, the content of the text you enter is transmitted to external providers of large language models (LLMs):
- Anthropic (the Claude model) — established in the United States (USA), and/or
- Google (the Gemini model) — established in the United States (USA).
This means that the text you enter leaves the European Economic Area (EEA) and is transferred for processing to the provider's servers in the USA. The rules governing this transfer are described in section 9.
Important warning
Do not paste into the Service Website personal data of third parties, confidential data, secrets (e.g. trade secrets), or special categories of data within the meaning of Article 9 GDPR (including data concerning health, ethnic origin, political opinions, religious beliefs, or data concerning sexuality), unless you have a separate legal basis to do so and are aware that these data will be transmitted to the LLM provider in the USA.
The Controller does not require and does not expect such data to be entered. The user is responsible for the content of the entered text and its lawfulness (see the Terms of Service).
5. What data we process
The table below reflects the actual scope of data processed on the Service Website (mapped to the database structure).
| Category / data set | Scope of data |
|---|---|
User account (user) |
First name/display name, e-mail address, password hash, Google identifier (when logging in with Google), photo/avatar (image), selected plan (Free/Pro) |
Subscription and payments (subscription) |
Customer and subscription identifiers in the Stripe system (Stripe customer id / subscription id). The Controller does not store payment card details — they are processed directly by Stripe |
Usage counters (usage_daily, usage_monthly) |
Service usage counters (number of humanizations on a given day, token usage in a given month) for the purpose of enforcing plan limits |
Humanization history (humanizations) |
Tone/style, length of the entered text (character count), shortened preview of the result (up to 90 characters), token count, heuristic style indicators, timestamp. The full content of the input text and the full result are not stored. |
E-mail verification tokens (email_verification_tokens) |
Hash of the token used to confirm the e-mail address |
Password reset tokens (password_reset_tokens) |
Hash of the token used to reset the password |
Anonymous counter (anon_usage) |
SHA-256 hash of the IP address on a daily basis, for the purpose of limits for non-logged-in users and abuse prevention |
| Session | Auth.js (JWT) session token stored in a cookie |
| localStorage (browser storage) | Anonymous usage counter (Free) and the stored cookie-consent choice |
The SHA-256 hash of the IP address constitutes pseudonymised data, but may still be personal data within the meaning of the GDPR.
6. Purposes and legal bases of processing (Article 6 GDPR)
| Purpose of processing | Data | Legal basis |
|---|---|---|
| Creating and maintaining an account, logging in (including via Google OAuth) | account data | Article 6(1)(b) GDPR — performance of the contract (the Terms of Service) |
| Providing the humanization Service, including transmitting the entered text to the LLM provider and returning the result | text content, tone, parameters | Article 6(1)(b) GDPR — performance of the contract |
| Maintaining the humanization history available to the user | humanizations |
Article 6(1)(b) GDPR — performance of the contract |
| Handling subscriptions and payments (Pro) | subscription data, Stripe identifiers | Article 6(1)(b) GDPR (contract) and Article 6(1)(c) GDPR (accounting and tax obligations) |
| Keeping accounting and tax records | billing data | Article 6(1)(c) GDPR — legal obligation (tax and accounting regulations) |
Enforcing plan limits and preventing abuse (Free limits, anon_usage counter = IP hash, usage_* counters) |
counters, IP hash | Article 6(1)(f) GDPR — legitimate interest of the Controller (enforcing plan terms, security, abuse prevention) |
| Account security (e-mail verification, password reset) | password hash, token hashes | Article 6(1)(b) GDPR (contract) and Article 6(1)(f) GDPR (security) |
| Sending transactional messages (password reset, account/subscription notifications) via Mailgun | e-mail address | Article 6(1)(b) GDPR — performance of the contract |
| Handling complaints and defending/pursuing claims | data necessary to handle the matter | Article 6(1)(f) GDPR — legitimate interest |
| Marketing / newsletter (if operated) | e-mail address | Article 6(1)(a) GDPR — consent; with respect to electronic communications, a separate consent is additionally required under Article 399 of the Polish Act of 12 July 2024 — Electronic Communications Law (Journal of Laws 2024, item 1221) and Article 10 of the Polish Electronic Services Act (prohibition of unsolicited commercial information) |
Where processing is based on legitimate interest (Article 6(1)(f) GDPR), the legitimate interest is: the security of the Service Website, prevention of abuse and circumvention of limits, technical statistics, and the pursuit and defence of claims.
Providing data is voluntary but necessary to conclude and perform the contract — without providing account data and processing the entered text, the Service cannot be provided.
7. Recipients of data — processors
In order to provide the Service, the Controller uses the services of trusted providers who process personal data on its behalf under data processing agreements concluded in accordance with Article 28 GDPR.
| Processor / recipient | Role | Location | Transfer basis |
|---|---|---|---|
| Anthropic PBC (Claude) | LLM provider — processes the entered text | USA | Standard Contractual Clauses (SCCs) — Commission Decision 2021/914; Anthropic is not on the EU-US DPF list |
| Google LLC (Gemini) | LLM provider — processes the entered text | USA | EU-US Data Privacy Framework (active certification); additionally Standard Contractual Clauses (SCCs, Commission Decision 2021/914) included in Google's terms of service; a paid API is used (data are not used to train models) |
| Stripe, Inc. | Card payment handling (renewable subscription) | USA | EU-US Data Privacy Framework (active certification; the certification also covers the UK and Switzerland) |
| Google LLC (OAuth) | Login with a Google account | USA | EU-US Data Privacy Framework (active certification) |
| Mailgun Technologies, Inc. | Sending transactional messages (e-mail) | USA (company); infrastructure in the EU region (api.eu.mailgun.net) | EU-US Data Privacy Framework (active certification); e-mail data processed on EU servers |
| Application and database hosting provider | Hosting | EEA | No transfer to a third country |
The current DPF certification status of each provider can be verified at dataprivacyframework.gov.
Data may also be disclosed to entities authorised under provisions of law (e.g. public authorities) — solely to the extent required by the applicable regulations.
8. Data retention periods
The Controller applies automatic data clean-up (a scheduled task run cyclically, as a rule daily), which deletes data after the technical periods indicated below have elapsed. Periods arising from provisions of law take precedence.
| Data | Retention period |
|---|---|
Account data (user) |
For as long as the account exists; deleted after account deletion or upon request, subject to data that must be retained under provisions of law |
| Billing data and accounting documents | 5 years from the end of the financial year in which the transaction took place (Article 70 §1 and Article 86 §1 of the Polish Tax Ordinance; where accounting books are kept — Article 74 of the Polish Accounting Act) |
Humanization history (humanizations — result preview ≤90 characters, tone, input length, tokens, style indicators, timestamp) |
Up to 12 months from creation — automatic deletion; the user can delete the entire history themselves from the dashboard on the Service Website |
E-mail verification tokens (email_verification_tokens) |
Until used or expired (valid for 24 h); deleted automatically after expiry/use |
Password reset tokens (password_reset_tokens) |
Until used or expired (valid for 1 h); deleted automatically after expiry/use |
Daily usage counters (usage_daily) |
Up to 90 days — automatic deletion |
Monthly token budgets (usage_monthly) |
Up to 13 months — automatic deletion |
Anonymous counter (anon_usage — IP hash) |
30 days — automatic deletion |
Security / rate-limit counters (rate_limits) |
Up to 2 days — automatic deletion |
Payment event log (idempotency, processed_stripe_events) |
90 days — automatic deletion |
Evidence of purchase consents (consent_events) |
Up to 6 years — until the general limitation period for claims expires (Article 118 of the Polish Civil Code); constitutes evidence of the conclusion of the contract and of the consumer's consents |
| Session (Auth.js JWT cookie) | For the duration of the session / validity period of the cookie |
| Data processed on the basis of consent (e.g. marketing) | Until consent is withdrawn |
| Data necessary to pursue/defend claims | Until the applicable limitation periods for claims expire |
9. Transfers of data outside the European Economic Area (USA)
As indicated in section 4, in connection with the use of LLM providers and other services, data (including the content of the text you enter) are transferred to a third country — the United States (USA).
The transfer takes place in accordance with Chapter V of the GDPR (Articles 44–49), in particular:
- Article 45 GDPR — on the basis of the European Commission's implementing decision of 10 July 2023 finding an adequate level of protection under the EU-US Data Privacy Framework (DPF) — with respect to providers holding an active DPF certification (Google LLC, Stripe, Inc., Mailgun Technologies, Inc.); the current certification status can be verified at dataprivacyframework.gov;
- Article 46(2)(c) GDPR — on the basis of Standard Contractual Clauses (SCCs) adopted by the European Commission (Implementing Decision (EU) 2021/914) — with respect to Anthropic PBC, which is not listed in the DPF register; the SCCs are included in the DPA concluded with Anthropic.
The application and database are hosted on servers located in the European Economic Area (EEA) — no transfer outside the EEA takes place in this respect.
The Controller does not rely on the derogations of Article 49 GDPR (intended for occasional transfers), because the transfers are of a regular nature.
You have the right to obtain a copy of the safeguards applied (see Article 13(1)(f) and Article 15(2) GDPR) — to do so, contact the Controller at [email protected].
10. Your rights (Articles 15–22 and Article 7(3) GDPR)
In connection with the processing of your data, you have the following rights:
- the right of access to the data and to obtain a copy of them (Article 15 GDPR),
- the right to rectification of the data (Article 16 GDPR),
- the right to erasure of the data ("right to be forgotten", Article 17 GDPR),
- the right to restriction of processing (Article 18 GDPR),
- the right to data portability (Article 20 GDPR) — with respect to data processed on the basis of a contract or consent, by automated means,
- the right to object to processing based on legitimate interest (Article 21 GDPR),
- the right to withdraw consent at any time, without affecting the lawfulness of processing carried out before the withdrawal (Article 7(3) GDPR) — where consent is the basis.
Some of these rights can be exercised directly from the dashboard on the Service Website:
- deleting the entire humanization history — a button available directly in the user dashboard;
- deleting the account — a button available in the dashboard; deleting the account simultaneously cancels an active Pro subscription.
In all other matters, contact the Controller at [email protected].
Right to lodge a complaint
If you believe that the processing of your data infringes the GDPR, you have the right to lodge a complaint with the supervisory authority — the President of the Polish Personal Data Protection Office (PUODO) (Article 77 GDPR):
Urząd Ochrony Danych Osobowych (Personal Data Protection Office) ul. Stawki 2, 00-193 Warsaw, Poland uodo.gov.pl
If your habitual residence, place of work or the place of the alleged infringement is in another EU/EEA country, you may also lodge a complaint with the supervisory authority of that country.
11. Automated decision-making and profiling (Article 22 GDPR)
The Controller uses automated data processing to enforce plan limits and to calculate the heuristic style indicator of the entered text.
The Controller does not make decisions concerning you based solely on automated processing (including profiling) that would produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 GDPR.
The displayed style indicator is an internal, estimated heuristic, not the output of an external, independent AI detector. It is for illustrative purposes only and does not constitute an assurance as to the score in any AI content detection tool.
12. Data security (Article 32 GDPR)
The Controller applies appropriate technical and organisational measures ensuring data security adequate to the risk, in accordance with Article 32 GDPR, in particular:
- storing passwords exclusively as a hash (bcrypt) — the Controller does not store passwords in plain text,
- storing e-mail verification and password reset tokens in hashed form,
- pseudonymisation of IP addresses (SHA-256 hash) for counters,
- encryption of connections (TLS/HTTPS),
- access control and the principle of least privilege,
- concluding data processing agreements (Article 28 GDPR) with processors.
13. Cookies and device storage
The Service Website uses cookies and browser storage (localStorage). Detailed rules concerning cookies are described in the Cookie Policy — see /polityka-cookies (English translation: /cookies).
In brief:
- Session cookie (Auth.js / JWT) — strictly necessary for logging in and maintaining the user session; storing this file does not require consent under Article 399 of the Polish Act of 12 July 2024 — Electronic Communications Law (Journal of Laws 2024, item 1221), which provides an exception for storage that is technically necessary to provide a service requested by the user;
- localStorage — used to store the anonymous usage counter (Free plan) and to remember the cookie-consent choice; consent to storage is given in accordance with the requirements of the GDPR and the Electronic Communications Law.
You can change your cookie settings in your browser or using the consent management tool available on the Service Website.
14. Related documents
- Terms of Service — see /regulamin (English translation: /terms)
- Cookie Policy — see /polityka-cookies (English translation: /cookies)
This Policy and the Terms of Service complement each other.
15. Changes to the Privacy Policy
The Controller may update this Policy. Users will be informed of material changes with appropriate advance notice (e.g. by a notice on the Service Website or by e-mail). The current version, together with its date, applies from the date indicated as the "Last updated" date.
16. Contact
In all matters concerning personal data:
- Controller: AutoXCyber Mateusz Grądkowski
- E-mail: [email protected]
- Address: ul. Wergiliusza 7/69, 01-915 Warsaw, Poland