What we collect
When you sign up, we collect your name, company name, and email address. When you use the HUMA API, we record each verification (the result, the confidence score, the summary signal numbers described below, and the user ID you send us) tied to your API key. That user ID is whatever identifier you choose to pass. We never ask for, receive, or store your end users' names, emails, or addresses.
Behavioral signals
HUMA's JavaScript snippet (huma.js) measures anonymous behavioral signals in the browser: mouse movement patterns, keyboard timing intervals, scroll behavior, click and touch patterns, and signals used to detect automated browsers and AI agents.
The raw input traces never leave the visitor's device. Pointer coordinates and the content of anything typed are reduced to summary statistics (timings, counts, and variability measures) inside the browser itself, and the traces are discarded. Only those summary numbers reach our servers, where they are scored and stored with the result so we can support your integration and improve detection.
The snippet sets no cookies, writes nothing to local storage, and does not fingerprint the device: no canvas, no WebGL, no user-agent profiling. It creates no identifier that follows a person from your site to any other site. You can confirm all of this in your browser devtools.
How we use your data
We use your email address to send your API key, account notifications, and usage alerts. We use verification data to calculate and display your dashboard statistics. We do not sell, rent, or share your data with third parties except as required by law.
Data retention
Verification records (result, confidence score, and the summary signal numbers) are retained for 12 months and then automatically deleted. Your account data is retained until you request deletion. To delete your account, email team@humaverify.com.
Third-party services
We use Supabase for data storage, Stripe for payment processing, and Resend for transactional emails. Each service has its own privacy policy. We do not use advertising trackers or analytics pixels.
Security
All data is transmitted over HTTPS. API keys are stored as plaintext identifiers (not passwords). We recommend rotating your API key periodically from your dashboard.
To stop abuse of our own signup, login, and integration pages, we record the IP address of requests to those pages, and delete those records daily. This is about protecting this site. Verification calls made through the API do not record IP addresses at all.
Contact
Questions about this policy? Email team@humaverify.com and you will get a reply within one business day.