Privacy Policy

Last Updated: June 26, 2026

Introduction

Welcome to HumanixOS. We respect your privacy and are committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.

Most of the information processed through HumanixOS is data that an organization enters about the people it serves. For that data, your organization is the controller and HumanixOS acts as a service provider (processor) — we process it only on your behalf and on your documented instructions to provide the service, and not for our own independent purposes. Your organization is responsible for obtaining any consents and providing any notices required for the data it uploads.

1. How We Share Your Information

We do not sell your personal information. We may share your information with:

  • Service Providers: Trusted third parties who help us operate our service (Supabase for database hosting, Stripe for payment processing)
  • Legal Requirements: Only when compelled by valid legal process, and subject to the protections described in "Law Enforcement and Government Requests" below
  • Business Transfers: In connection with a merger, acquisition, or sale of assets
  • With Your Consent: When you explicitly authorize us to share your information

Funding Partner Data Sharing

HumanixOS allows organizations to link their account to a funding partner (for example, a foundation, grantmaker, or sponsor) by entering a partner code. Linking to a funding partner may provide a sponsored or modified subscription as described in your account settings.

When your organization is linked to a funding partner, that funding partner is granted ongoing access to a limited view of your organization's operational data for the duration of the link. Specifically, the funding partner can see:

  • Anonymized, aggregate information about the clients and services your organization records, such as total counts, activity over time, and aggregate demographic and geographic summaries (for example, breakdowns by city, gender, or age range). This information is presented in aggregate and does not include any individual client's personal information. Client names, contact information, addresses, dates of birth, case notes, and other individual client details are never shared with a funding partner.
  • Your organization's own contact information, including the name and email address of your organization's owner or administrator, so the funding partner can identify and contact the grantee organization.

Funding partners do not have access to your billing details, your donor or volunteer records beyond aggregate activity, or any individual client's personal information. This access continues for as long as your organization remains linked to the funding partner and ends when the link is removed.

By entering a funding partner code, you consent to this data sharing on behalf of your organization. You are responsible for ensuring you have the authority to share this information and for complying with any obligations you owe to your own clients and funders regarding their data.

2. Law Enforcement and Government Requests

Many organizations use HumanixOS to serve vulnerable communities, and the confidentiality of an individual's record can directly affect that person's safety. We handle requests for your data from law enforcement, government agencies, and other third parties with that responsibility in mind.

  • No voluntary disclosure. We do not voluntarily disclose your organization's data — including any individual client or student record — to law enforcement or government agencies. We disclose such data only when compelled by a valid, legally binding request (such as a properly issued subpoena, court order, or warrant), and only to the minimum extent required.
  • We scrutinize requests. We review each request for legal validity and scope, and we object to, or seek to narrow, requests that are overbroad, improper, or legally deficient.
  • Advance notice where permitted. Unless we are legally prohibited from doing so (for example, by a court-ordered nondisclosure) or believe there is a risk of imminent harm to a person, we will notify the affected organization before disclosing its data, so the organization has an opportunity to seek to limit or challenge the request.
  • No sale, no enforcement collaboration. We do not sell personal information, and we do not share individual client or student records with — or use them in collaboration with — any external entity for marketing, data-brokerage, enforcement, or any purpose unrelated to providing the service.

Questions about how we handle government or law enforcement requests can be sent to info@humanixos.com.

3. Student and Sensitive Data Protection

Organizations use HumanixOS to record sensitive information about the people they serve, which may include students and their families. We recognize the heightened sensitivity of this information and apply the following commitments to it.

  • You remain in control; we are a service provider. When your organization uploads student or client records, your organization remains the controller of that data. HumanixOS processes it solely on your behalf and under your direction to provide the service. Where your organization is subject to the Family Educational Rights and Privacy Act (FERPA) or similar student-privacy laws, we act as a service provider acting on your instructions, and we use student data only to perform the services you have requested.
  • No secondary use. We do not use individual student or client records for advertising or any purpose other than providing and securing the service. Our AI providers process this data only to return results to your organization and do not use it to train their models. (See "Third-Party Services" for the providers involved.)
  • Never shared with external entities. Individual student and client records are never sold, rented, shared with, or used in collaboration with any external entity — commercial or governmental — except (a) with the sub-processors strictly necessary to operate the service, who are contractually bound to protect the data and may not use it for their own purposes, or (b) as compelled by valid legal process, subject to the "Law Enforcement and Government Requests" section above.
  • Data Processing Agreement available. Organizations handling student or other regulated data may request a Data Processing Agreement (DPA) covering these commitments by contacting info@humanixos.com.

4. Information We Collect

Information You Provide

  • Account information (name, email address) when you register
  • Profile information you choose to provide
  • Organization and client data you enter into the system
  • Communications with us

Information from Third-Party Services

  • When you sign in with Google, we receive your name, email address, and profile picture from Google
  • Payment information processed through Stripe (we do not store credit card details)

Automatically Collected Information

  • Device information (browser type, operating system)
  • Usage data (pages visited, features used)
  • Log data (IP address, access times)

5. How We Use Your Information

We use your information to:

  • Provide, maintain, and improve our services
  • Create and manage your account
  • Process your transactions and subscriptions
  • Send you technical notices, updates, and support messages
  • Respond to your comments and questions
  • Monitor and analyze usage patterns and trends
  • Detect, prevent, and address technical issues and security threats

Artificial Intelligence and Automated Processing

Some HumanixOS features use artificial intelligence (for example, search, data analysis, and import assistance). When you use these features, the relevant content is sent to our AI providers solely to return a result to your organization. Our AI providers do not use your data to train their models, and we do not use individual client or student records to train AI models or for advertising.

We do not use these features to make decisions that produce legal or similarly significant effects about an individual without human involvement. AI output is provided to assist your staff, who remain responsible for reviewing it and making decisions.

6. Data Storage and Security

Your data is stored securely using industry-standard encryption and security practices:

  • Data is hosted on Supabase in the United States (US-East region)
  • Data is encrypted in transit using HTTPS/TLS (1.2 or higher) and at rest using AES-256
  • Especially sensitive fields — such as Social Security numbers and the access tokens for any third-party integrations you connect — are protected with an additional layer of application-level AES-256-GCM encryption before they are stored, so they are not readable in plaintext even within the database
  • We enforce role-based access controls and database-level Row Level Security to keep each organization's data logically isolated from every other organization
  • Encrypted backups are performed automatically to support recovery and business continuity
  • We conduct regular security monitoring and reviews

Security Incident Notification

If we become aware of a security breach that compromises the security, confidentiality, or integrity of your personal information, we will notify the affected organization without undue delay after confirming the incident, and in any event consistent with applicable breach-notification laws. Our notice will describe, to the extent known, the nature of the incident, the data involved, and the steps we are taking in response.

7. Your Rights and Choices

You have the right to:

  • Access: Request a copy of your personal information
  • Correction: Update or correct your information
  • Deletion: Request deletion of your account and data
  • Portability: Export your data in a standard format
  • Opt-out: Unsubscribe from marketing communications

To exercise these rights, please contact us at info@humanixos.com. Where the data belongs to your organization (for example, client or student records), we will refer requests we receive to your organization, which controls that data, and assist your organization in responding.

U.S. State Privacy Rights

Depending on where you live, you may have additional rights under state privacy laws (such as the California Consumer Privacy Act, as amended, and similar laws in other states), including the rights to know, access, correct, delete, and obtain a portable copy of your personal information, and to be free from discrimination for exercising those rights. We do not sell your personal information, and we do not share it for cross-context behavioral advertising. To exercise any of these rights, contact us at info@humanixos.com; we will not discriminate against you for doing so.

8. Cookies and Tracking

We use cookies and similar tracking technologies to enhance your experience, maintain your session, and analyze usage patterns. You can control cookies through your browser settings.

9. Third-Party Services

Our service integrates with third-party services that have their own privacy policies:

We engage these providers as sub-processors who handle data only to perform services for us. They are bound by contract to protect your information and may not use it for their own purposes. We maintain the list above and will update this Privacy Policy before engaging a new sub-processor that processes personal information, so you have the opportunity to review the change.

10. SMS Messaging Program

Organizations using HumanixOS may send SMS text messages to recipients who have explicitly opted in. Message and data rates may apply. Message frequency varies. Reply STOP to any message to unsubscribe, or reply HELP for help. We do not sell, rent, or share your phone number or SMS consent data with third parties for marketing purposes.

Full program terms, opt-in methods, supported keywords, and supported carriers are available at SMS Terms & Consent.

11. Children's Privacy

HumanixOS account holders must be adults — the service is not intended for use by children under 13, and we do not knowingly let children under 13 create accounts or provide us with their own personal information as users of the service.

We recognize, however, that organizations use HumanixOS to keep records about the people they serve, who may include minors and students. When your organization uploads records about a minor, your organization is the controller of that data and is responsible for obtaining any parental or guardian consent required by law. We process that data only on your organization's behalf, and we handle it under the protections described in the "Student and Sensitive Data Protection" section above.

12. Data Retention

We retain your information for as long as your account is active or as needed to provide you services. If you request deletion of your account, we will delete your information within 30 days, except where we are required to retain it for legal purposes.

13. Data Residency and International Transfers

HumanixOS stores your organization's data — including your client and student records, files, and backups — in the United States (Supabase US-East region). We do not store these records outside the United States.

A limited number of our sub-processors may process certain data outside the United States in the course of providing their service (for example, when content you submit to an AI feature is processed, or when email or SMS is delivered). Where that occurs, we rely on appropriate safeguards to protect your information in accordance with this Privacy Policy.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. We encourage you to review this Privacy Policy periodically.

15. Contact Us

If you have any questions about this Privacy Policy or our privacy practices, please contact us:

Email: info@humanixos.com

Website: www.humanixos.com

Mailing Address: 225 Dyer Street, Providence, Rhode Island 02907