humanflow

Security

Your text is transmitted over encrypted connections and processed only to return your result. Account data lives in a managed database with restricted access. We hold no third-party security certifications, and this page says so plainly rather than implying otherwise.

What we collect

  • Account information — when you sign in with Google we receive your email address and name, to create and manage your account.
  • Content you submit — the text you paste to humanize or to check for AI detection. We process it to return your result.
  • Your IP address — to meter free usage and prevent abuse when you are not signed in. Held for 48 hours, then deleted.
  • Basic technical data — the minimum needed to operate the service, such as app version and timestamps.

We do not collect your location, contacts or photos, and we show no ads on any plan including the free one.

In transit and at rest

All data is transmitted over encrypted connections using HTTPS/TLS. Account data is stored in our managed database with restricted access.

No session recording

Error-reporting tools usually offer session replay, which records the page as you use it. We have it switched off deliberately. The page here contains the text you paste in to be rewritten, and recording it would send your private writing to a third party. Our error reporting receives diagnostics only — never your text, and no personally identifying data by default.

Who inside the company can reach your data

Access to production systems is limited to the people who need it to run the service. We do not read submitted text as a matter of course, and we do not use it to train anything. If you need a specific written assurance for an institution or employer, ask and we will answer in writing.

Who processes your text

To generate a result, text you submit is sent to our AI processing providers — including Anthropic and our own detection service — solely to produce your output. They act as our processors. They do not use your text to advertise to you, and we do not sell your personal data. We may disclose data where required by law.

Retention and deletion

We keep your account data for as long as your account is active. You can delete your account and its associated personal data at any time, in the app under Settings → Account → Delete account, or by emailing support@humanflow.pro from your account address. Deletion requests are completed within 30 days. Some records may be retained only where required by law. Full detail on the delete account page.

Age

You must be at least 18 to use HumanFlow, or have your parent or guardian's permission. We apply India's threshold everywhere rather than the lowest one available to us — see our DPDP notice for why. We do not knowingly collect data from children without verifiable parental consent.

What we do not claim

We hold no SOC 2 report, no ISO 27001 certificate, and no third-party penetration test we can publish. Plenty of products in this category display security badges that describe an intention rather than an audit; we would rather tell you where we actually stand.

If your institution or employer requires a specific assurance before you can use a tool like this, email us and we will answer the question directly. That is a more useful answer than a logo.

Reporting a vulnerability

If you believe you have found a security issue, email support@humanflow.pro with enough detail to reproduce it. Please give us a reasonable window to fix it before disclosing publicly. We will confirm receipt and keep you updated. Our machine-readable contact is at /.well-known/security.txt.

We will not pursue legal action against researchers acting in good faith: staying within your own account and test data, avoiding privacy violations and service degradation, and giving us time to fix an issue before publishing it. We run no paid bounty programme and we do not pretend otherwise.

Security questions

Is my text used to train AI models?
Text you submit is sent to our AI processing providers solely to produce your result. They act as our processors and do not use your text to advertise to you. We do not sell personal data.
Is my data encrypted?
Data is transmitted over encrypted connections using HTTPS/TLS, and account data is stored in our managed database with restricted access.
Who can see my text inside the company?
Access to systems and data is restricted. If you need a specific written assurance for an institution or employer, email us and we will answer in writing rather than point you at a badge.
How do I delete my data?
In the app under Settings → Account → Delete account, or by emailing us from your account address. Requests are completed within 30 days. Some records may be retained only where required by law.
Is HumanFlow SOC 2 or ISO 27001 certified?
No. We hold no third-party security certifications today and we will not imply otherwise. If a certification is a requirement for your organisation, contact us and we will tell you honestly where we stand rather than sell you a roadmap.

See also Privacy policy and Terms.