← Back to Humanlike AI

Privacy Policy

Last updated: October 8, 2026

1. Introduction

Humanlike AI ("we", "us", "our") operates the platform at humanlike.co (also available through tryhumanlike.com) and its associated products, including AI Visibility, Humanlike Agents, Coworker, LoveForm, and related services (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service. The data controller is HUMANLIKE ΜΟΝΟΠΡΟΣΩΠΗ Ι Κ Ε, VAT ID 802695454, at ΕΛΕΥΘΕΡΙΟΥ ΒΕΝΙΖΕΛΟΥ 1, ΦΙΛΙΑΤΕΣ 46300, Greece. This policy describes our processing; where consent is required, we ask for it separately.

2. Information We Collect

Account information: When you sign up, we collect your name, email address, and authentication credentials. We support sign-in via email, Google, Microsoft, and LinkedIn.

Company & workspace data: If you create or join a company workspace, we store your company name, team members, roles, and associated configurations.

Product data: Depending on which products you use, we store AI agent configurations, conversation logs, form data and responses, calendar integrations, voice commands, and workflow automations.

Interactive email data: Some of our emails use dynamic ("AMP") content that lets you respond, RSVP, or submit inputs directly from your inbox. When you interact with these emails, we collect your responses, selections, and the time of your interaction in order to process your request.

Usage data: We collect information about how you interact with the Service, including pages visited, features used, and timestamps.

Payment information: Payment processing is handled by our PCI-DSS-compliant payment providers, Stripe and Viva.com (Viva Payments). We do not collect or store full card numbers: card data is entered directly on the provider's secure checkout. We receive only billing details such as plan type, subscription status, the transaction result, and the last four digits of the card.

Device & browser data: We automatically collect IP address, browser type, operating system, and device identifiers for security and analytics purposes.

3. How We Use Your Information

  • To provide, maintain, and improve the Service and its products
  • To process your transactions and manage your subscription
  • To send transactional emails (verification, receipts, notifications)
  • To power AI features such as agent conversations, HR automation, and form analysis
  • To connect with third-party integrations you authorize (Google Calendar, Outlook, Slack, etc.)
  • To detect, prevent, and address security issues and abuse
  • To comply with legal obligations
  • To provide customer support

4. Data Sharing & Third Parties

We do not sell your personal information. We share data only with:

  • Supabase: database hosting and authentication
  • Stripe: subscription & card payment processing
  • Viva.com (Viva Payments): card payment processing for checkout transactions
  • Amazon SES: transactional and inbound email delivery
  • Cloudflare: application delivery, backend processing and storage for uploaded media
  • Vercel: application hosting and analytics
  • Google AI / OpenAI: AI-powered features (conversations, scoring, analysis). We send information to AI providers when you use an AI feature. The provider and information sent depend on that feature and your settings.
  • Integration providers: When you connect third-party services (Google Calendar, Outlook, Slack, Discord, etc.), data is shared as necessary to provide the integration. You can disconnect integrations at any time.

Connected LinkedIn Pages: When you connect a LinkedIn Company Page, we access only the organizations you administer, so we can publish and manage posts, comments, and reactions and read page and post analytics on your behalf. We use this data only to provide the Service. We do not sell or share it, and our use complies with the LinkedIn API Terms of Use. You can disconnect in Humanlike and revoke authorization in the provider account settings. Disconnecting does not automatically delete previously stored content.

We assess requests from public authorities individually. We verify the authority and legal instrument, obtain human legal review, assess whether a request should be challenged or narrowed, and disclose only the information lawfully required. A request from an authority outside the EEA does not by itself establish a lawful basis or a valid international transfer mechanism. We document decisions and any disclosure. We notify the relevant customer or individual unless law prohibits notice or a documented lawful exception applies.

5. Connected social accounts

When you connect Facebook, Instagram, WhatsApp, TikTok, YouTube or LinkedIn, we receive the account identifiers, profile information, access tokens and permissions needed for the features you authorize. Depending on those permissions, this can include Pages and professional accounts you manage, posts and uploaded media, captions, comments, messages, follower totals, and engagement or performance statistics. We do not receive your social account password.

We use this information to display your connected accounts and analytics, prepare and publish content you approve, and provide the messaging, comment management or automation features you enable. For WhatsApp, enabled business messaging features may process contact phone numbers, message contents and delivery status. We do not sell connected account data or use it for advertising targeting.

Content you approve for publishing is sent to the selected platform. Authorized workspace members may access shared connections and content according to their roles. Connecting an account does not by itself instruct us to publish a post or send a message.

Workspace roles: For our own account, billing, security and support records, Humanlike is the controller. For messages, contacts and other personal data a customer processes through its workspace, the customer usually determines the purpose and is the controller, while Humanlike acts as a processor under the applicable agreement. We assist that customer with rights requests and seek its instructions unless applicable law requires otherwise.

Google and YouTube

Humanlike uses YouTube API Services. By connecting a YouTube channel you agree to the YouTube Terms of Service, and the Google Privacy Policy applies to that data.

What we access: your channel's name, ID, thumbnail and subscriber and video counts; your videos with their titles, descriptions, visibility and thumbnails; live broadcast and live chat data for streams you run in Humanlike; and YouTube Analytics reports for your own channel.

How we use it: only to provide the features you start in Humanlike: publishing, editing and deleting your videos, running your live streams, and showing your channel's analytics. We do not sell it, use it for advertising, or use it to train general AI models, and we share it only with the service providers that host Humanlike and only to run these features. Our use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements. We do not place or read cookies on your device through YouTube API Services.

Storage and deletion: we store the connection (access tokens and the channel details above), and for live streams the broadcast details and live chat. Analytics reports and video lists are fetched from YouTube when you open them and are not stored. Stored channel details are refreshed daily, live chat and live stream records are deleted after 30 days, and all of the channel's stored YouTube data is deleted immediately when you disconnect it in Humanlike, or within 7 days after you revoke access at Google. Disconnecting also revokes Humanlike's YouTube access at Google, unless another Humanlike connection still uses the same Google authorization. You can revoke access at any time in your Google security settings. Content you create in Humanlike, such as drafts, uploaded videos and the record of a post you published, stays in your workspace until you delete it.

6. Data Retention

We retain your account data for as long as your account is active. Product data (agent configurations, conversation logs, form responses) is retained until you delete it or your account. Deletion requests are reviewed without undue delay. We normally respond within one calendar month of receiving a request. Where GDPR permits an extension for complexity or volume, we notify you within that first month with the reasons and the extended deadline, which may be up to two additional months. Information that must be retained under an applicable legal obligation or for a specific legal claim is restricted and reviewed separately. Disconnecting a social account stops its use as an active connection. For YouTube, see Google and YouTube above: disconnecting or revoking access deletes the channel's stored YouTube data. Other stored reports, workspace content and uploaded media require a separate deletion request. Disconnecting other platforms does not automatically erase their stored tokens or content. To request removal of stored integration data, follow our data-deletion instructions. Posts already published on another platform must be managed there.

7. Data Security

We implement industry-standard security measures including encryption in transit (TLS), provider storage protections, row-level security policies on our database, and access controls for operational and compliance records. However, no method of transmission over the Internet is 100% secure.

8. Your Rights (GDPR & CCPA)

For our controller activities, our legal bases are performance of a contract (Article 6(1)(b)) for accounts and requested services, legal obligations (Article 6(1)(c)) for applicable accounting and lawful disclosure duties, legitimate interests (Article 6(1)(f)) for proportionate security, fraud prevention and support, and consent (Article 6(1)(a)) where an optional feature or communication requires it. We assess the interests and rights involved when relying on legitimate interests. Where a feature requires consent, you can withdraw it. Depending on your jurisdiction, you may have the right to:

  • Access your personal data we hold
  • Rectify inaccurate data
  • Delete your personal data ("right to be forgotten")
  • Port your data to another service
  • Object to or restrict processing
  • Withdraw consent at any time

To manage your request, we may keep your contact details, account or workspace reference, requested scope, original receipt date, identity-verification outcome, review decisions, deletion tasks and response evidence in a restricted compliance register. We ask for additional identity information only where reasonably necessary. Do not send passwords or access tokens. Request records and legal-hold evidence are kept only as necessary for handling the request, demonstrating compliance or a specific legal obligation or claim, with access limited to authorized personnel. Legal holds are reviewed and released when no longer justified. Live storage, uploaded files, copied workflow records, service providers and backups are checked separately before a deletion request is closed.

Requests to access or delete data are not automatically forwarded to public authorities. For customer workspace data, you can also contact the business that controls that workspace.

You may also complain to your local data-protection authority, including the Hellenic Data Protection Authority. To exercise these rights, contact us at minas@humanlike.co.

9. Cookies & Local Storage

We use essential cookies for authentication and session management. We use local storage to remember your preferences. We use Vercel Analytics for aggregate usage data. You can control cookies through your browser settings.

10. Children's Privacy

The Service is not directed to children under 16. We do not knowingly collect personal information from children. If we learn that we have collected data from a child under 16, we will delete it promptly.

11. International Data Transfers

Your data may be processed in the United States and other countries where our service providers operate. A transfer outside the EEA requires a valid GDPR transfer mechanism, such as an applicable adequacy decision or appropriate contractual safeguards with any necessary supplementary measures. The mechanism and processing location depend on the provider and feature. Contact us for information about the providers and safeguards relevant to your service.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or through the Service. The date above identifies the latest version. Where required, we will ask for new consent before using data for a new purpose.

13. Contact Us

If you have questions about this Privacy Policy or your data, contact us at minas@humanlike.co.