Skip to main content

Privacy Policy

Last updated: July 2026

1. Who We Are

HumanKey (“we”, “us”) provides AI traffic intelligence services. This policy explains how we collect, use, and protect personal data in compliance with the GDPR and ePrivacy Directive.

Data Controller: HumanKey · ChainGuard, Poland.
Contact: Contact Form (Privacy Inquiries)

2. Data We Collect

Account Data

  • Email address, name (optional)
  • OAuth provider identifiers (Google) — only if you use social login
  • Hashed password (industry-standard algorithm) — only if using email/password authentication
  • Account metadata: plan tier (Free, Pro, Business, or Enterprise), role (user/admin), registration timestamp, email verification status
  • Stripe customer ID (only if you subscribe to a paid plan)

New accounts receive a 14-day Pro trial. No payment information is required during the trial period.

Traffic Analysis Data

  • IP addresses: Hashed with a cryptographically rotating salt — we never store raw IP addresses
  • User-Agent strings: Truncated to 200 characters for bot classification only
  • Page URLs and referrer URLs (for traffic analysis)
  • Visit timestamps and duration
  • Bot classification results (human/bot, confidence score)
  • Country-level geographic data: Derived from IP address via a geolocation database (stored as country code only — no city or precise location data)
  • Session Pattern Analysis: Aggregated session patterns processed by our proprietary analysis engine. Stored in our EU database. Used exclusively for identifying coordinated bot activity — no individual profiling.
  • ASN Metadata: Autonomous System Number enrichment via Cloudflare Radar public API. Only the ASN number is queried — no personally identifiable information is transmitted to Cloudflare Radar.
  • Interaction metrics: Aggregate measures of pointer movement, typing rhythm and scrolling, together with click coordinates and the type of element clicked, stored linked to the visit that produced them
  • Heatmap data (where the feature is active): Click and scroll coordinates, movement samples and viewport dimensions for the pages visited, stored linked to the visit that produced them and deleted together with it

Device and Browser Signals (read during the visit, not stored)

To classify a request as human or automated, our detection script reads the following categories of information from the visitor’s browser and device. These signals are evaluated for that single decision and are not written to our database:

  • Display characteristics: Screen dimensions and colour depth, as reported by the browser
  • Browser and platform characteristics: The platform string, the number of available plugins, the processor concurrency the browser reports, and preferred languages
  • Rendering characteristics: A value derived from a canvas drawing, and the graphics renderer the device reports. The canvas value is hashed in the browser before transmission — the drawing itself never leaves the device
  • Automated-client indicators: Flags the browser exposes that reveal a remote-controlled or scripted session

Only the outcome of that evaluation — the human/bot classification and its confidence score — is stored, as listed above. Reading information from a visitor’s terminal equipment is governed by Art. 5(3) of Directive 2002/58/EC, implemented in Poland by art. 399 of the Prawo komunikacji elektronicznej. On this website that reading takes place only after you consent through our banner. On our customers’ websites the customer is the controller and is responsible for the lawfulness of that access.

3. Legal Basis (GDPR Art. 6)

  • Contract performance: Processing account data to provide our service
  • Legitimate interest: Bot detection and traffic classification to protect website owners
  • Consent: Optional first-party analytics on this website, including the reading of information from your browser and device that it requires (via the consent banner)

You accept our Terms of Service, and confirm that you have read this Privacy Policy, either (a) via an explicit checkbox during email registration, or (b) on a dedicated acceptance screen shown after OAuth sign-in (Google). That acceptance forms the contract under which we process your account data (Art. 6(1)(b)) — it is not consent, and it is separate from the legitimate interest basis for bot detection (Art. 6(1)(f)). Providing account data is a contractual requirement: without it we cannot create or operate your account (Art. 13(2)(e)). The only processing we base on your consent (Art. 6(1)(a)) is the optional first-party analytics on this website — including the reading of information from your browser and device that it requires — and enquiries you choose to send us through our contact forms.

Automated Processing (Art. 22 GDPR)

Our bot detection uses automated classification of web traffic requests through a proprietary multi-layered analysis methodology. All processing runs on our EU infrastructure — no visitor data is sent to external services. This automated processing does not produce legal effects or similarly significantly affect your website visitors — it classifies network requests, not individuals. Visitors whose requests are classified as non-human traffic are not individually profiled or subjected to consequential automated decisions. Additionally, a proprietary analysis pipeline is used to identify coordinated bot farm activity — this is an informational technique and does not result in automated blocking of any individual visitor.

We also use an AI language model to periodically analyze aggregated, non-personal platform metrics (detection counts, confidence distributions, bot volume trends) and generate advisory recommendations for detection system improvement. Only statistical summaries are processed — no individual visitor data is ever sent to the AI model. All recommendations require manual administrator review.

We may send you periodic email notifications about your site's bot traffic (daily reports, weekly AI-generated insights, new crawler alerts, quota warnings). You can control each notification type independently in Dashboard → Settings → Email Notifications. Both the weekly AI insight emails and the optional AI insight included in the daily report use the same aggregated metrics described above — no personal data is processed by the AI model.

AI Assistant Chatbot:HumanKey provides an AI-powered chatbot assistant on our website and dashboard. Conversations are processed by an AI language model to generate responses. Only the text of your chat messages is sent to the AI model — no personal data, IP addresses, session identifiers, or account information is transmitted. All conversations are ephemeral: they are held in server memory for a maximum of 30 minutes and are never stored in any database. Conversations cannot be recovered after the session ends. The AI assistant provides advisory information only and cannot make binding decisions. In compliance with EU AI Act Article 50, the assistant is clearly marked as AI-powered and a link to human support is always available.

In addition to automated classification, HumanKey administrators may manually review and override borderline bot-detection classifications to improve detection accuracy; in addition, certain automated internal signals may establish a ground-truth bot-classification label. These verification labels are informational only, do not constitute automated decision-making under Art. 22 GDPR, and do not produce legal or similarly significant effects on website visitors. Each label is stored with a hashed identifier — a hashed administrator identifier for manual reviews, or a hashed IP address for automated signals — solely for audit and detection-quality purposes; no additional personal data is collected and no data is transmitted outside HumanKey.

Aggregated Trend Analysis: HumanKey periodically aggregates historical traffic patterns into anonymized daily statistics (visitor counts by category: human, bot, unknown, blocked). This aggregated data contains no personal information and cannot be used to identify individual visitors. Processing basis: legitimate interest (Art. 6(1)(f) GDPR).

4. Data Minimisation

We follow the principle of data minimisation. IP addresses are hashed before storage, User-Agent strings are truncated, and we only retain data necessary for traffic analysis.

5. Your Rights

Under the GDPR, you have the right to:

  • Access: Export your account, site, and traffic data (JSON) from Dashboard → Settings → Export Data
  • Erasure: Delete your account and non-financial data from Dashboard → Settings → Delete Account. When you delete your account, your email address is also scrubbed (replaced with a redacted marker) from audit log entries created by other organizations that interacted with you as a team invitee — preserving the third-party's audit-trail continuity while honouring your right to erasure under Art. 17 GDPR. Financial audit records (invoice events, payment confirmations) are retained for up to 5 years per Art. 17(3)(b) GDPR and Polish Ustawa o rachunkowości art. 74 (legal-obligation exemption), then permanently deleted.
  • Portability: Download your data in JSON format
  • Rectification: Update your profile information in Dashboard → Settings
  • Object: Contact us to opt out of specific processing activities
  • Withdraw consent (Art. 7(3)): Where we rely on your consent, you can withdraw it at any time, as easily as it was given — withdrawal does not affect the lawfulness of processing carried out before you withdrew. For analytics cookies, use the preferences tool on our Cookie Policy page. For an enquiry you sent us through a contact form, use our contact form (Privacy & GDPR). Your account data is not processed on consent — it is processed to perform our contract with you (Art. 6(1)(b)), so this right does not apply to it; see Erasure above.

6. Cookies

  • Essential: Authentication tokens (httpOnly, secure) — required for login
  • Optional: Analytics cookies — only set with your consent

7. Data Retention

Visit data retention depends on your plan:

  • Free plan: 7 days
  • Pro plan: 30 days
  • Business plan: 90 days
  • Enterprise plan: 365 days

Data beyond these periods is automatically and permanently deleted. Account data is retained until you delete your account. After a plan downgrade or a subscription cancellation that keeps your account active, a 7-day grace period applies during which you retain access to your previous plan's features. (Deleting your account is different — it cancels any active subscription immediately; see our Terms of Service.)

8. Account Deletion & Data Portability

Deletion

You may delete your account at any time from Settings > Account > Delete Account. Upon deletion, traffic records (visit data), API keys, and non-financial account data are permanently erased within 30 days; site configuration data is deleted immediately. Financial audit log records (invoice events, payment confirmations) are retained for up to 5 years per Art. 17(3)(b) GDPR and Polish Ustawa o rachunkowości art. 74 (legal-obligation exemption), then permanently deleted by our retention cron job. Audit log entries created by other organizations that interacted with you as a team invitee have your email address scrubbed (replaced with a redacted marker) while preserving the third-party's audit-trail continuity.

Data Portability

GDPR data portability (your personal data) is available on all plans. Analytics data export (CSV/JSON) is available on Business plans and above.

9. Sub-Processors & Third-Party Services (GDPR Art. 28)

We use the following vendors to deliver our service. Where a vendor processes personal data on our behalf, a Data Processing Agreement meeting GDPR requirements is in place. Some entries below transfer no personal data at all — we only download a public file they publish — and so are listed for transparency rather than as processors. See our full Sub-Processors list with data locations and DPA links.

ServicePurposeLocationDPA
RailwayApplication compute and request routing for the HumanKey API.🇳🇱 EU (Netherlands — Amsterdam region)View DPA
NeonManaged PostgreSQL hosting for account data, site configuration, and analytics aggregates.🇩🇪 EU (Germany — Frankfurt)View DPA
VercelFrontend hosting, edge routing, and CDN delivery for humankey.io.🇩🇪 EU (Germany) + 🌐 global edge (SCCs)View DPA
StripePayment processing, subscription billing, invoicing, and chargeback management.🇮🇪 Ireland (EEA) + 🇺🇸 US (SCCs + DPF)View DPA
ResendTransactional and service email delivery on HumanKey's behalf, AND receipt of inbound contact-form and email correspondence sent to HumanKey addresses. Outbound categories include: account and authentication messages (address verification, magic-link sign-in, password reset); account, team and site administration (team invitations, domain-claim notices, site disable and deletion notices); billing and subscription notices (receipts, invoices, payment and refund outcomes, plan, quota and downgrade notices); onboarding and installation instructions, including messages sent at the account holder's request to a technical contact whose address the account holder supplies; periodic reports and alerts derived from the customer's own site analytics (AI-crawler and bot digests, new-crawler alerts); and support responses. HumanKey composes every outbound message; Resend transmits it. Inbound: contact-form submissions and any email sent directly to a HumanKey address are received via a signed webhook and delivered to HumanKey's own infrastructure (Neon, EU) — not to any third-party mailbox. These are categories of message, not an exhaustive list.🇺🇸 US (SCCs)View DPA
SentryApplication-error monitoring and diagnostic capture for the HumanKey API and dashboard.🇩🇪 EU (Germany — Sentry EU region)View DPA
MaxMindOne-way geolocation database import. HumanKey downloads the GeoLite2 database file periodically; country-level lookups are performed locally. No visitor data is sent to MaxMind.🇺🇸 US (one-way DB file download — no personal data transfer)View DPA
OpenAI (crawler ranges)One-way import of the public IP-range files OpenAI publishes for its crawlers. HumanKey downloads the files on a fixed schedule and performs range matching locally, to check whether traffic presenting an OpenAI crawler User-Agent actually originated from an address OpenAI publishes. No visitor data is sent to OpenAI.🇺🇸 US (one-way public file download — no personal data transfer)No data transferred
Google (crawler ranges)One-way import of the public IP-range files Google publishes for its crawlers. HumanKey downloads the files on a fixed schedule and performs range matching locally, to check whether traffic presenting a Google crawler User-Agent actually originated from an address Google publishes. No visitor data is sent to Google.🇺🇸 US (one-way public file download — no personal data transfer)No data transferred
Bing (crawler ranges)One-way import of the public IP-range file Microsoft publishes for the Bing crawler. HumanKey downloads the file on a fixed schedule and performs range matching locally, to check whether traffic presenting a Bing crawler User-Agent actually originated from an address Microsoft publishes. No visitor data is sent to Microsoft.🇺🇸 US (one-way public file download — no personal data transfer)No data transferred
Cloudflare RadarNetwork-operator metadata lookup for aggregate benchmark reporting. Queries are keyed by autonomous-system number (ASN), resolved server-side from a pseudonymised visitor context.🇺🇸 US (public API; ASN integer only)View DPA
AnthropicLarge-language-model inference powering: (a) the public AI Assistant chatbot, (b) automated audit summarisation, and (c) admin-only AI Insights advisory analytics. All responses are advisory; no automated decision under GDPR Art. 22.🇺🇸 US (SCCs Module 2; 30-day retention, no model training)View DPA
GoogleOAuth 2.0 authentication when a user chooses Google as the sign-in method. Optional — only invoked at explicit user request.🇮🇪 Ireland (EEA) + 🇺🇸 US (SCCs + DPF)View DPA

Data Transfer Safeguards

  • EU Storage: All primary data (accounts, visits, analytics) is stored in EU regions (Germany, Netherlands)
  • Standard Contractual Clauses: processors whose transfers rely on SCCs (Vercel, Resend, Anthropic) have executed EU SCCs per GDPR Chapter V
  • EU-US Data Privacy Framework: Vercel is certified under the EU-US DPF (2024), providing additional adequacy safeguards
  • PII Minimisation: Sentry receives NO personal identifiers — all email addresses and IP addresses are stripped before transmission
  • Stripe Data Retention: Payment data retained by Stripe for 7 years per EU tax law. You can request deletion after the legal retention period expires.
  • Transfer Impact Assessment: We publish a detailed Transfer Impact Assessment (TIA) covering our analysis of transfers to the United States under EDPB Recommendations 01/2020 (Schrems II).

Right to Object: If you object to data transfers outside the EU, contact us via our contact form. Note that certain services (billing, OAuth) require US processors — opting out may limit functionality.

10. Security

We implement industry-standard encryption in transit and at rest, password hashing, token-based authentication, rate limiting, and access controls to protect your data.

Account isolation:Each dashboard session is fully isolated from other sessions in the same browser. Logging out triggers a full client-state purge (session storage, query cache, per-user settings) and a hard page reload, so no account ever inherits another account's data — consistent with GDPR Article 32 (security of processing).

Browser security headers: HumanKey enforces industry-standard browser security policies including Content Security Policy, cross-origin resource protection, and referrer policy. These headers prevent unauthorized script injection, resource theft, and data leakage across origins. Our Content Security Policy is strict by design — we do not permit dynamic code evaluation, and we never embed third-party scripts that we cannot audit. If your browser reports console warnings from installed extensions while visiting a HumanKey-enabled site, those warnings come from the extension, not from our service. See our troubleshooting guide for common browser warnings and their causes.

11. Data Protection Impact Assessment

Our systematic bot monitoring processing has been assessed under GDPR Article 35. View the full Data Protection Impact Assessment (DPIA) for details on risk assessment, safeguards, and compliance measures.

11A. Embeddable Verified Badge

Customers on Pro+ plans may opt in to embed our HumanKey Verified Badge on their websites. When a visitor loads a page containing the badge, the visitor's browser fetches an SVG image from api.humankey.io. This HTTP request includes the visitor's IP address (hashed with a daily rotating salt before any storage per GDPR Art. 32), User-Agent (truncated to 200 characters), and optionally a Referer header. The recommended embed snippet includes Referrer-Policy: no-referrer to suppress the Referer header. Legal basis: GDPR Art. 6(1)(f) legitimate interest — trust signaling for our customers and visitor transparency about AI traffic monitoring. The Legitimate Interest Assessment (LIA) is documented in our DPIA.

12. Children's Data

HumanKey is a business-to-business (B2B) service intended for website owners and operators. We do not knowingly collect data from individuals under 18 years of age. If you become aware of a minor using the Service, please contact us via our contact form.

13. Contact

For privacy-related inquiries, contact us via our contact form or write to the Polish supervisory authority: Urząd Ochrony Danych Osobowych (UODO), ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl

This Privacy Policy complies with the GDPR (Regulation (EU) 2016/679), the ePrivacy Directive, and Polish data protection law.