Privacy Policy
This policy explains what HumDay (“HumDay”, “we”, “us”) collects when you use humday.com, why we collect it, who touches it, and what control you keep. The short version: we collect what running your automations requires, your credentials are encrypted before anything stores them, and we do not sell personal data or use your content to train models.
1. What we collect
- Account details. Your name, email address, and sign-in method (email and password, or a Google or GitHub account), plus a session cookie that keeps you signed in.
- Automation content. What you write in the build conversation, the Contracts you approve, automation settings, and the reports and evidence each run produces.
- Connected account credentials. API keys and OAuth grants for the outside services your automations use. They are encrypted before storage and used only to make the calls your approved automations require.
- Billing records. Which plan or credit packs you bought and your credit balance. Card details go to our payment provider and never reach our systems.
- Technical logs. Standard operational records — requests, errors, and aggregate usage — kept to run and secure the Service.
2. What we use it for
- Building, testing, and running the automations you approve — the Service’s only job.
- Telling you what your automations did: run evidence in the product, and email alerts when something needs you.
- Billing, fraud prevention, and keeping the Service secure.
- Measuring, in aggregate, how the product performs so we can improve it.
3. AI processing
Text you write while building — your descriptions, answers, and approved Contracts — is processed by AI model providers under contract with us to draft plans and generate the programs you approve. That processing serves your request and nothing else: we do not use your content to train models, and we do not permit our providers to.
4. Who else touches your data
The Service runs on a short list of processors, each doing one job:
- hosting and network infrastructure, which serves humday.com and executes runs;
- a managed database and encrypted object storage, which hold the records described above;
- AI model providers, for the processing described in section 3;
- a payment provider, which handles checkout and card details;
- an email delivery provider, for sign-in and alert emails.
Beyond processors: the providers you connect receive exactly the calls your approved automations make — that is the product working as designed, on your instruction. We disclose data when the law properly requires it, and if HumDay is ever part of a merger or acquisition, this policy travels with the data. We do not sell personal data, full stop.
5. How credentials are protected
Credentials are encrypted the moment they arrive — each one under its own data key, wrapped by a master key held separately from the database — and decrypted only to make the calls your automations require. They are never shown back to you or anyone else in full, and deleting a connection destroys the stored secret.
6. Cookies and analytics
Signed in, you carry one essential session cookie. Our marketing pages use limited, aggregate measurement to understand how people find HumDay; your automation content is never part of any advertising or analytics signal.
7. How long we keep things
- Account details, automations, and their evidence: for as long as your account exists.
- Connected credentials: until you delete the connection or your account, whichever comes first.
- Billing records: as long as bookkeeping law requires.
- When you delete your account, personal data is deleted or anonymised within 30 days, except where the law requires longer.
8. Your rights
Wherever you are, you can ask us for a copy of your personal data, ask us to correct or delete it, or object to a use of it. Write to privacy@humday.com and we will answer within 30 days. If you are in a jurisdiction with a data protection authority, you also have the right to complain to it.
9. Children
The Service is not directed at children and may not be used by anyone under 16. If you believe a child has given us personal data, contact us and we will delete it.
10. Changes to this policy
When this policy changes materially we will tell you — by email or in the product — before the change takes effect. The date at the top is always the version you are reading.
11. Contact
Privacy questions and requests: privacy@humday.com. Anything else: support@humday.com. See also the Terms of Use.