Privacy policy
What we process, why, and what we deliberately refuse to collect, under the GDPR (EU) 2016/679.
Last updated: 11 August 2026
1. Data controller
AIGiner, S.L., tax ID B93819753, Gran Via de Carles III, 98 · 08028 Barcelona · España. Privacy contact:privacy@thehumanbehind.com.
2. What this policy covers
This policy covers this website (thehumanbehind.com) and the registry platform where accounts and records are managed. Registering is private: your record is a private record of standing until you request verification. Onlyverified records are published. This policy explains exactly what becomes public, when, and what stays private, always.
3. Purpose of processing
We process your data to run the registry of self-declarationsof AI identities: to create your record, generate its cryptographic hash and date, manage identity verification where you request it, publish your record and allow its public consultation (including through the public API) once it is verified, and communicate with you about your account.
4. Legal bases
- Consent (Art. 6(1)(a) GDPR): by requesting verification you accept the publication of your record's data in the public registry.
- Performance of a contract (Art. 6(1)(b) GDPR): providing the service you signed up for, including paid verification.
- Legitimate interest (Art. 6(1)(f) GDPR): maintaining the integrity of the registry and preventing fraud and abuse.
5. Data we process
- Record data (public only once verified): avatar name, type, scope, where it operates, responsible person's name, registration number and date, and the record's hash. This data stays private while your record is only Registered, and is published only once the record is Verified.
- Contact data (private): your email address, which is never published and is used only to manage your account and communicate with you. If you sign in with Google or Microsoft, we receive the name and email address associated with that account from the provider to create or link your account; we never receive your password with either provider.
- Verification data (private, minimal): only the result of the identity check (verified yes/no), its date and a session reference from the identity provider. We never receive or store your identity document.
- Asset data: a record can carry one asset, and what we keep depends on its type. An uploaded image is re-encoded in your own browser to a 512×512 WEBP before it is sent, so its metadata (including any EXIF location) never leaves your device and never reaches us. An uploadedaudio file is never sent at all: your browser draws a waveform image from it and only that image is uploaded, so we do not hold the recording or the voice in it. A declared agent description (
agent.md) is stored as plain text, never executed and never rendered as code, and it stays private to your panel. Assets follow the visibility of their record: nothing is published while the record is only Registered. - Earlier versions of an agent's instructions: when you edit a record's
agent.md, the previous version is kept whole, with its date and its fingerprint, in an append-only ledger. That is what lets you show which instructions you declared and since when, which is the point of the registry. This history is private: only you can read the text, and it is not published even when the record is Verified. If you need the content of a specific version withdrawn, write to us: we can blank the text while keeping its date and fingerprint, so the proof survives. - Technical data: the server and security logs strictly needed to keep the service safe (abuse prevention, rate limiting).
- Service key usage (if you create any): for each request made with an API key we record which key was used, when, what it asked for, and aprefix of your IP address (the final segments are discarded, so it does not identify a specific machine). It is used to rate-limit requests and to let you audit what each key did. We keep it for 90 days and then delete it.
6. What we deliberately do not do
- We never publish or sell your email address, or any other data.
- We never store identity documents.
- We do not build biometric databases of any kind and we do not process facial images or biometric identifiers; the identity check is performed end-to-end by the specialised provider.
- We do not run advertising trackers on this website. We do measure visits, withCloudflare Web Analytics: it sets no cookies, builds no identifier for your browser and cannot follow you across sites (see the cookie policy).
7. Processors and sub-processors
To provide the service we rely on providers acting as data processors, with the safeguards of Art. 28 GDPR:
- Supabase: database and storage (EU region).
- Cloudflare: hosting, content delivery network, security andaudience measurement (Cloudflare Web Analytics).
- Resend: transactional email delivery.
- Contabo GmbH: server (France, EU) holding the daily database backups, always encrypted before they leave Supabase, and running the registry's daily timestamping job.
- Stripe Payments Europe, Ltd. (Ireland) and Stripe, Inc. (United States): payments, payouts to professionals through Stripe Connect, and identity verification through Stripe Identity. The integration is deployed on the platform. Stripe processes payment data and, for verification, the identity document and image you provide; TheHumanBehind stores neither. Transfers to the United States rely on the European Commission's Standard Contractual Clauses.
8. International transfers
The registry database is hosted in the European Union. Some providers (such as Cloudflare) operate global networks; where any transfer outside the EEA occurs, it is covered by the European Commission's Standard Contractual Clauses or an equivalent safeguard.
9. Retention
A record's data is kept while the record is active, since its value lies in the priority date; it becomes public only once the record is verified. If you unpublish a verified record, we stop publishing its data and keep only the minimal trace described in thedatabase policy, plus what is necessary to comply with legal obligations. Contact data is kept while you maintain your account.
10. Your rights
You may exercise your rights of access, rectification, erasure, objection, restriction and portability, and withdraw your consent at any time, by writing to privacy@thehumanbehind.com. We answer within the deadlines set by the GDPR.
11. Complaints
If you believe we have not handled your rights properly, you may lodge a complaint with the Spanish Data Protection Agency (aepd.es) or your local supervisory authority. We would appreciate hearing from you first so we can try to resolve it.
12. Security
Row-level security in the database, HttpOnly session cookies, EU hosting and immutable record evidence are described in plain language on thesecurity page and in theTrust Center.
13. Changes
We may update this policy. We will publish the current version on this page with its update date and, for material changes, notify registered users.
See also the terms of use, thecookie policy and theconfidentiality commitment.