Privacy Policy

Last updated: April 2026

Our approach

HumanLine is built to be as uninvasive as possible. We collect the minimum data needed to run the service. We do not sell your data, use it for advertising, or share it with anyone except as described here.

What we collect

  • Email address — only if you sign in. Used solely for authentication. We do not use it for marketing.
  • Submitted content — phone numbers, bypass steps, and reviews you voluntarily submit. These are stored to benefit the community.
  • Votes — upvotes and downvotes you cast on community submissions, tied to your account.
  • Session cookies — set by our authentication provider (Supabase) to keep you signed in. These are strictly necessary and expire when you sign out.

What we do not collect

  • No name, address, phone number, or payment information
  • No tracking pixels, advertising cookies, or third-party analytics
  • No device fingerprinting
  • If you sign in with Google, we receive only your email address from Google — nothing else

How we use your data

  • To authenticate you when you sign in
  • To attribute community submissions and votes to your account
  • To prevent abuse (e.g. one vote per submission)

Data storage and processors

Authentication and data storage is handled by Supabase, which stores data on servers within the EU. Supabase acts as a data processor under our instructions and is GDPR-compliant.

If you sign in with Google, authentication is handled by Google's OAuth service. We receive only your email address as a result of that flow.

Data retention

  • Your account data (email) is retained for as long as your account exists
  • Community submissions and reviews are retained as they provide ongoing value to the community
  • If you delete your account, your email is removed; submissions become anonymous

Your rights (GDPR)

You have the right to:

  • Access — request a copy of the personal data we hold about you
  • Rectification — ask us to correct inaccurate data
  • Erasure — request deletion of your account and personal data
  • Portability — receive your data in a machine-readable format
  • Object — object to processing of your data

To exercise any of these rights, contact us via our contact form (select “GDPR / data request” as the subject). We will respond within 30 days.

Cookies

We use only strictly necessary session cookies set by Supabase to keep you signed in. We do not use advertising or analytics cookies. No cookie consent banner is required for strictly necessary cookies under GDPR.

Changes to this policy

If we make material changes, we will update the date at the top of this page. Continued use of HumanLine after changes constitutes acceptance.

Contact

Questions about this policy? Get in touch via our contact form.