I Am Human

Privacy Policy

Privacy Policy

This policy explains how the IAMHUMAN website and Android APP process and protect personal information when issuing and checking Human ID and providing account, community, friend, and chat features.

Effective date: August 10, 2026

1. Scope of application and information processor

This policy applies to the iamhuman.group website, the I AM HUMAN Android APP, and the IAMHUMAN services they use. The entity listed below is the personal information processor and service operator. Do not submit identity documents, financial account numbers, health information, or other sensitive information unrelated to the product's features.

  • Operator name in Chinese: 南京定义未来科技有限公司
  • Operator name in English: Nanjing Define the Future Technology Co., Ltd
  • Registered and contact address: Building T2, Tianji Industrial Park, No. 2 Huachuang Road, Jiangbei New Area
  • Contact email: panda@deffuture.com

2. Information we process

  • Human challenges and Human ID: your display name, plus the choices, text, reaction times, and drawing coordinates submitted during a challenge. Original challenge answers are used for immediate scoring. The service database stores the Human ID, display name, issue time, derived score and traits, status, and digest values used for replay prevention and holder verification; it does not store the app's private holder credential in plain text.
  • Community account: username, community display name, bio, password salt and irreversible password verifier, the link between the account and Human ID, session digests, and expiry times. We do not store plaintext passwords.
  • Community and communication: posts, comments, likes, friend relationships, reports, one-to-one messages, message read times, and related activity times. Private-chat content is stored as plaintext in the server database and is not currently end-to-end encrypted.
  • Operational and security information: IP address, request time, request path and query parameters, response status, Referer, User-Agent, rate-limit status, and error logs. A one-time pairing code is used only during the short-lived process of linking a Human ID to a community account.

3. Public scope and visible objects

  • Human ID verification is public. Anyone or any third-party system that knows a Human ID can query its ID, display name, issue date, score, derived traits, and current status. Do not use a real name or other sensitive information as your display name if you do not want it to be public.
  • Posts, comments, display names, and interaction status are visible to signed-in community members; report information is used only for community governance.
  • Friend relationships and one-to-one messages are shown only to the relevant participants through signed-in account interfaces, but the server processes this information for transmission, storage, troubleshooting, and legally required governance. Do not send passwords, payment details, identity documents, or other highly sensitive information in chat.

4. Purpose of processing

  • To score challenges, issue and publicly verify Human ID, and verify possession through the APP.
  • To create community accounts, support username-and-password login, maintain sessions, and prevent account abuse.
  • To provide community, friend, private-chat, read-status, and content-reporting features, with community content shown in chronological order.
  • To limit automated abuse, maintain service stability, troubleshoot failures, handle disputes, and comply with applicable legal obligations.

5. Cookies, local storage and device permissions

The website uses a necessary Secure, HttpOnly session cookie to keep you signed in. Browser local storage may hold the complete local public Human ID record and cross-tab sign-in state; sessionStorage may hold the intended message recipient, message digest, and client message ID; the service worker caches only public static assets. The APP uses secure device storage for Human ID credentials, login sessions, pending session revocations, and pending-message summaries, while public identity records use ordinary local storage. APP camera access is used only to scan QR codes; QR scanning does not upload camera images to the server. Disabling required storage or permissions may make related features unavailable.

The website also uses a one-year, non-HttpOnly, SameSite=Lax IAMHUMAN_LOCALE cookie to remember your language preference; the app stores that preference in AsyncStorage. When switching to or from a right-to-left language, the app may reload its interface, but this does not clear account, identity, or message data.

6. Third-party services, processing locations and cross-border transfers

The website and database are currently deployed in the Amazon Web Services (AWS) Sydney, Australia region, where accounts, Human IDs, community content, messages, and operational information are processed and stored. You can review the AWS Privacy Statement.

Web fonts are provided by Google Fonts. When you browse the website, your browser may send request metadata such as your IP address, User-Agent, and Referer to that service. Review the Google Privacy Policy. Google is not involved in IAMHUMAN account verification.

When users in China use registration, identity, community, or chat features, relevant personal information may be transferred overseas. Read this section in full before submitting information. If you do not agree to the processing locations and transfer arrangements, do not register or use these features. Publishing this policy does not replace any separate notice, separate consent, impact assessment, or other data-export procedure required by applicable law.

7. Retention periods

  • The login session is valid for up to 30 days by default; the one-time pairing code expires in 5 minutes by default, and the invalid record will be deleted in the subsequent cleanup process.
  • Human ID, accounts, posts, comments, friend relationships, reports, and messages are retained for as long as needed to provide the service, resolve disputes, and meet legal obligations. The current version does not yet offer self-service account deletion. Clearing the local identity in the APP deletes only device data; it does not automatically revoke the server-side Human ID or delete the community account.
  • Access and error logs are kept short-term according to the server log rotation policy. Restricted access logs may contain complete request paths and query parameters, and are only used for operation and maintenance, troubleshooting, and legal governance.
  • Backups are retained for as long as required for disaster recovery; after production data is deleted, copies in the backup may continue to exist until the backup rotation is complete.

8. Security measures

We use HTTPS, database TLS, password and credential digests, least-privilege database accounts, access controls, request rate limiting, and restricted operational logs. No online service can guarantee absolute security. If information is or may be leaked, altered, or lost, we will assess the incident, take remedial action, and provide any notice required by applicable law.

9. Your rights

Where provided by law, you may request access to, a copy of, correction of, or deletion of personal information; withdraw consent where it can be withdrawn; and ask about our processing rules. You can sign out from the account page. Account deletion, deletion of historical content, and other rights requests currently require manual verification. Submit such requests to the contact email published in Section 1: panda@deffuture.com

10. Minors

The service is not intended for children under 14, who should not register on their own. Users under 18 should use the service only after a guardian has read and accepted this policy and the Terms of Service. If a guardian discovers that a child submitted personal information without consent, send a deletion request to the contact email published in Section 1: panda@deffuture.com

11. Policy updates

If features, processing purposes, data types, processing locations, or third-party services change materially, we will update this policy and provide reasonable notice on the website or APP. Where the law requires renewed consent, merely updating this page will not replace that process.