Privacy
What we collect, who else sees it, and how to get it back or get it deleted. Short version: an email address, a payment record held by Stripe, and the words you trace.
Last updated 26 July 2026
01What we collect
Account. Your email address, a display handle, and a profile image if your sign-in provider supplies one. Passwords and any social sign-in tokens are held by Clerk and never reach us.
Billing. A Stripe customer reference, your subscription status, and the period end date. Card numbers are entered directly into Stripe and never touch our servers or our database.
Use. The words you submit, the analyses they produce, your votes and corrections, and a credit ledger recording every grant and every spend. The ledger is append-only, which means a spend is never deleted, only offset.
We do not run advertising trackers, we do not sell anything to data brokers, and we do not build advertising profiles.
02What is public
The corpus is public by design. A word you trace, the derivation it lands on, the vote counts, and the handle credited as first tracer are all visible to anyone, with no account required, and are indexed by search engines.
Your email address is never shown publicly. Your handle is. Change it in your account settings if you would rather not be identifiable, and write to team@protohuman.xyz if you want an attribution removed from an entry.
Treat anything you type into the bench as something that may become public. Do not put personal or confidential information into a word field.
03Where your data goes
OpenAI. The word you submit is sent to OpenAI to run the analysis. That is the core function of the service and cannot be turned off while still using it. Your identity is not sent with it.
Clerk. Authentication and account identity.
Stripe. Payments, card storage and invoicing.
Neon. The database holding everything described in clause 1.
These providers process data on our behalf under their own terms, and each may store data outside your country. We do not pass your data to anyone else except where the law requires it.
04Cookies
We set a cookie for your signed-in session, handled by Clerk, and one for your Stripe checkout session while you are paying. Both are necessary for the service to work.
Your light or dark theme preference is kept in local storage on your own device and is never sent to us.
We do not use analytics or advertising cookies.
05How long we keep it
Account and billing records are kept while your account is open, and billing records for as long afterwards as tax and accounting law requires.
Corpus entries, votes and corrections are kept indefinitely. They are the record the service exists to build, and removing one retrospectively would change results other people have relied on. Closing your account detaches your identity from them rather than deleting them.
06Your rights
Depending on where you live, you may have the right to access a copy of your data, to correct it, to have it deleted, to restrict or object to how we use it, and to take it elsewhere in a portable form. If you are in the UK or the EU, these are UKGDPR and GDPR rights. If you are in California, the CCPA gives you comparable ones.
Write to team@protohuman.xyz and we will act within the time the applicable law allows. We may need to confirm who you are first.
Where deletion conflicts with clause 5, we will tell you exactly what we are keeping and why rather than quietly ignoring the request.
If you are not satisfied with how we handle a request, you can complain to your local data protection authority.
07Security
Traffic runs over TLS. Credentials and card data are held by Clerk and Stripe, not by us, which is deliberate: the safest data to hold is the data you never hold.
No service is perfectly secure. If we discover a breach affecting your data, we will tell you and any relevant regulator as the law requires.
08Children
The service is not directed at children, and we do not knowingly collect data from them. If you believe a child has created an account, write to team@protohuman.xyz and we will remove it.
09Changes and contact
We may update this notice. The date at the top shows when it last changed materially, and we will give notice in the product for a change that meaningfully affects you.
The data controller is the operator of ProtoHuman, reachable at team@protohuman.xyz.
Questions about anything on this page go to team@protohuman.xyz.