PRIVACY POLICYClose

Privacy Policy

Last updated: August 6, 2026

humanagentic is a service of Applied AI Development Company. This Privacy Policy describes Our policies and procedures on the collection, use, and disclosure of Your information when You use the Service, and tells You about Your privacy rights and how the law protects You.

We use Your Personal Data to respond to You and to operate and improve the Service. By using the Service, You agree to the collection and use of information in accordance with this Privacy Policy.


Interpretation and Definitions

Interpretation

The words whose initial letters are capitalized have meanings defined under the following conditions. The following definitions shall have the same meaning regardless of whether they appear in singular or in plural.

Definitions

For the purposes of this Privacy Policy:

  • Business, for the purpose of the CCPA/CPRA, refers to the Company as the legal entity that determines the purposes and means of the processing of Consumers' personal information and that does business in the State of California.
  • CCPA / CPRA refers to the California Consumer Privacy Act as amended by the California Privacy Rights Act of 2020.
  • Client Services means consulting, development, and related professional services the Company performs for a client under a written agreement.
  • Company (referred to as "the Company", "We", "Us", or "Our") refers to Applied AI Development Company, a Virginia corporation, at 215 N Payne St STE 84334, Alexandria, VA 22314. humanagentic is a service of the Company. For the purposes of the GDPR, the Company is the Data Controller. For the purposes of the VCDPA, the Company is the controller.
  • Consumer means, for the purpose of the CCPA/CPRA, a natural person who is a California resident; and, for the purpose of the VCDPA, a natural person who is a Virginia resident acting only in an individual or household context.
  • Cookies are small files placed on Your Device by a website.
  • Country refers to: the Commonwealth of Virginia, United States.
  • Device means any device that can access the Service, such as a computer or phone.
  • GDPR refers to the EU General Data Protection Regulation (and, where applicable, the UK GDPR).
  • Personal Data (or "Personal Information") is any information that relates to an identified or identifiable individual, as further defined under the GDPR, VCDPA, and CCPA/CPRA.
  • Service means the Website, including its contact flow, and related communications with Us.
  • Service Provider means any natural or legal person who processes data on behalf of the Company (a "processor" under the GDPR and VCDPA; a "service provider" under the CCPA/CPRA).
  • Usage Data refers to data collected automatically, generated by the use of the Service or from the Service infrastructure itself.
  • VCDPA refers to the Virginia Consumer Data Protection Act, Va. Code § 59.1-575 et seq.
  • Website refers to humanagentic, accessible from https://humanagentic.dev.
  • You means the individual accessing or using the Service, or the entity on whose behalf such individual is acting. Under GDPR, You may be referred to as the Data Subject or User.

What This Policy Covers

This Privacy Policy applies to the Website and to Your communications with Us as a visitor, prospective client, or business contact.

Client Services are different. When We perform Client Services, We handle information, including any Personal Data it contains, under the written agreement for that engagement, acting as a service provider or processor on the client's behalf. That agreement, not this Privacy Policy, governs the data inside an engagement. If You believe a client of Ours holds Personal Data about You, please direct Your request to that client; if We receive a request that belongs with a client, We will forward it.


Collecting and Using Your Personal Data

Types of Data Collected

Personal Data You provide

When You use the contact flow on the Website ("send Us a note") or contact Us by email, We may collect:

  • Your email address, which We verify with a one-time code before You can send a note
  • Your practice or business website, in some cases, when You use a personal email address and We ask for a website instead
  • Your name, role, and a description of Your practice or business
  • Your answers to Our questions about Your work: where the day goes, what You want off Your plate, why it matters, what is in the way, what You have tried, and what made today the day

The answers are free text. Please do not include information You would not put in a business email; whatever You write is what We receive and store.

If We schedule a call with You, the call may be recorded or transcribed using third-party software, for note-taking and quality purposes. Where required by law, You will be notified or asked for consent before recording begins.

Your draft stays in Your browser

Until You press send, everything You type in the contact flow is stored only in Your own browser (localStorage), for up to seven days, and is deleted when You send the note or when the seven days pass. No answer text reaches Our servers, Our logs, or any third party before You press send. There is no account, so there is nothing to sign into and nothing to sign out of.

Verification, session, and security data

To verify Your email address and protect the contact flow from abuse, We collect and store:

  • The one-time code We email You, which expires after ten minutes
  • A session record and a session cookie, valid for seven days, so You do not have to re-verify while You write
  • The IP address and browser identifier (user-agent) associated with Your verification, kept with the session record for security and abuse prevention
  • Timestamps of code requests per email address, used to enforce sending limits

Usage Data

When You visit the Website, Our infrastructure provider automatically collects request data such as IP address, browser type, pages visited, and timestamps, incident to serving the Website and keeping it secure. We also use aggregate, cookieless web analytics that record page views, referring pages, country, device and browser type, and page performance. This analytics data is not tied to a profile of You, and We do not use advertising or cross-site tracking of any kind. If We adopt additional analytics tools, We will update this Privacy Policy before they go live.

Bot protection

The contact flow uses Cloudflare Turnstile, an invisible bot check, to distinguish people from automated traffic. When the contact section loads, Cloudflare processes device and browser signals, including Your IP address, to make that determination. Cloudflare's handling of this data is described in the Cloudflare Turnstile Privacy Addendum and Cloudflare's own privacy policy.

Cookies

The Website sets one essential cookie: the contact session cookie described above, used to keep Your email verification active for up to seven days. We do not use advertising cookies, analytics cookies, or cross-site tracking cookies.

No AI reads Your note

Your note is delivered to Us exactly as You wrote it. No AI model reads, scores, summarizes, or filters Your answers, and no AI-generated commentary is attached to them. If that ever changes, We will update this Privacy Policy first.

Use of Your Personal Data

The Company may use Personal Data to:

  • Respond to Your note and evaluate and discuss working together.
  • Operate the contact flow, including verifying Your email address and enforcing sending limits.
  • Maintain security, prevent fraud and abuse, and enforce Our terms.
  • Improve the Service using aggregate analytics.
  • Send transactional messages, such as the verification code email. We do not currently send marketing email. If We introduce marketing communications, any newsletter will be opt-in, every marketing message will include a working unsubscribe link, and Our commercial email will comply with applicable email-marketing law (including CAN-SPAM).
  • Comply with legal obligations and for business transfers, as described below.

Sharing Your Personal Data

We may share Personal Data with the following categories of recipients:

  • Service Providers / processors who process data on Our behalf under terms that restrict their use of Your data to providing services to Us. We currently use: a website hosting, serverless infrastructure, and web analytics provider (Vercel); a managed database provider (Neon); a transactional email delivery provider (Resend); and a bot-protection and network-security provider (Cloudflare).
  • For business transfers, in connection with a merger, acquisition, financing, or sale of assets, with notice as required.
  • To comply with law, respond to lawful requests by public authorities, protect rights and safety, and enforce Our agreements.
  • With Your consent, for any other purpose.

We do not sell Your Personal Data, and We do not share it for cross-context behavioral advertising.

Retention of Your Personal Data

We retain Personal Data only for as long as necessary for the purposes set out in this Privacy Policy, to comply with legal obligations, resolve disputes, and enforce Our agreements. Specifically:

  • Notes You send Us (Your name, role, practice, answers, and email address) are retained for as long as We continue to have a business or operational purpose to retain them, for example while We evaluate or serve a working relationship or keep a record of Our correspondence.
  • Verification codes expire after ten minutes. Session records, including the IP address and browser identifier, expire after seven days. Code-request timestamps are retained to enforce sending limits and prevent abuse.
  • When We no longer have an ongoing business or operational purpose or legal reason to retain Personal Data, We will delete it or anonymize it, or, if that is not practicable (for example, because the data is stored in backups or is needed to keep the Service secure and working), We will securely store it and isolate it from further use until deletion is possible.
  • Drafts live only in Your browser and expire after seven days.

Transfer of Your Personal Data

We are based in the United States, and Your information is processed in the United States and wherever Our Service Providers operate, where data-protection laws may differ from Your state or country. Where required by law, We use appropriate safeguards for international transfers (see the GDPR section). The Company takes reasonable steps to ensure Your data is treated securely and in accordance with this Privacy Policy.

Delete Your Personal Data

You have the right to delete, or request that We assist in deleting, the Personal Data We have collected about You, subject to the legal bases for retention described in this Policy. In some cases We may be unable to delete specific records, for example where We must retain them to comply with law, resolve disputes, prevent fraud, or enforce Our agreements, or where the records are needed to keep the Service secure and working (such as records used to enforce sending limits). Where that is the case, We will tell You, and where practicable We will anonymize the data or isolate it from further use. Residual copies may also remain in backups or archives for a limited period. Contact Us at privacy@humanagentic.dev to request access to, correction of, or deletion of Your Personal Data. Drafts You have not sent can be discarded directly in Your browser using the delete option in the contact flow.

Disclosure of Your Personal Data

Business Transactions

If the Company is involved in a merger, acquisition, or asset sale, Your Personal Data may be transferred. We will provide notice before Your Personal Data is transferred and becomes subject to a different Privacy Policy.

Law Enforcement and Other Legal Requirements

Under certain circumstances, the Company may be required to disclose Your Personal Data if required to do so by law or in response to valid requests by public authorities, or in the good-faith belief that such action is necessary to comply with a legal obligation, protect and defend the rights or property of the Company, prevent or investigate possible wrongdoing, protect the personal safety of users or the public, or protect against legal liability.

Security of Your Personal Data

The security of Your Personal Data is important to Us, but no method of transmission over the Internet or method of electronic storage is 100% secure. We use commercially reasonable administrative, technical, and physical safeguards appropriate to the volume and nature of the data We process, including encryption in transit, scoped credentials, rate limiting, and server-side validation, but We cannot guarantee absolute security.


U.S. State Privacy Rights

Several U.S. states, including Virginia, California, Colorado, Connecticut, and Utah, among others, have comprehensive privacy laws granting their residents rights over personal data. Some of these laws apply only to businesses exceeding volume or revenue thresholds, which the Company may not currently meet. Regardless of strict applicability, We extend the core rights below to all U.S. residents as a matter of policy: the right to know/access, correct, delete, and obtain a portable copy of Your Personal Data, and the right to opt out of targeted advertising, "sales" of personal data, and profiling in furtherance of decisions that produce legal or similarly significant effects.

We do not sell Personal Data, do not process it for targeted advertising, and do not engage in profiling that produces legal or similarly significant effects.

To exercise any right, contact Us at privacy@humanagentic.dev with the email address You used with the Service. We may ask You to verify Your identity (and an authorized agent must provide proof of authorization). We will respond within 45 days, extendable once by an additional 45 days where reasonably necessary, with notice to You. We will not discriminate against You for exercising Your rights.

Virginia (VCDPA)

If You are a Virginia resident acting in an individual or household context, You have the rights described above under the VCDPA (Va. Code § 59.1-575 et seq.), including the rights to confirm processing, access, correct, delete, obtain a portable copy, and opt out of targeted advertising, sale, and profiling. We do not process Personal Data for any of those opt-out purposes, and We do not process "sensitive data" as defined by the VCDPA except to the extent You cause it to appear in content You submit.

Appeals. If We decline to act on Your rights request, You may appeal Our decision within a reasonable period by replying to Our decision or emailing privacy@humanagentic.dev with the subject line "Privacy Appeal." Within 60 days of receipt, We will inform You in writing of any action taken or not taken in response to Your appeal, with a written explanation. If Your appeal is denied, You may contact the Virginia Attorney General to submit a complaint (https://www.oag.state.va.us).

California (CCPA/CPRA)

This subsection supplements the Policy for California residents. The CCPA/CPRA applies to businesses meeting statutory thresholds; the Company may not currently meet these thresholds, but provides the following disclosures and honors the following rights as a matter of policy.

Categories collected (last 12 months):

  • Category A, Identifiers (name, email, IP address, online identifiers): Yes.
  • Category B, Customer Records (Cal. Civ. Code § 1798.80(e)) (name, contact information): Yes.
  • Category F, Internet or other network activity (Website usage data, aggregate analytics): Yes.
  • Categories C, D, E, G, H, I, J, K, L (protected classifications, commercial information, biometric, geolocation, sensory, professional, education, inferences, sensitive personal information): No.

The free-text answers You submit could, depending on what You write, contain additional categories; We use them only to read and respond to Your note.

Sources: directly from You (the contact flow, email); automatically from You (Website usage data, aggregate analytics, verification/session data). Purposes: as described in "Use of Your Personal Data." Disclosure: only to Service Providers under terms meeting CCPA/CPRA service-provider requirements, and as otherwise described in "Sharing Your Personal Data."

No sale or sharing. We do not "sell" Personal Information and do not "share" it for cross-context behavioral advertising, as those terms are defined in the CCPA/CPRA, and We have not done so in the preceding 12 months. We do not sell or share the Personal Information of consumers under 16 years of age. We do not use or disclose sensitive personal information for purposes requiring a "limit" option under the CPRA. Because We do not sell or share Personal Information, no "Do Not Sell or Share" link is required; should that change, We will honor opt-out preference signals (including the Global Privacy Control) as required by law.

Your CCPA/CPRA rights: notice; know/access; correct; delete (subject to statutory exceptions); portability; opt out of sale/sharing (not applicable, as stated); limit sensitive personal information (not applicable, as stated); and non-discrimination. Exercise them via privacy@humanagentic.dev. We will verify and respond within 45 days (extendable once by 45 days). Disclosures will cover the 12-month period preceding the request.

Other U.S. States

Residents of Colorado, Connecticut, Utah, and other states with comprehensive privacy laws have substantially similar rights (access, correction, deletion, portability, and opt-outs), which We honor as described at the top of this section. Where a state law grants an appeal right, the Virginia appeal process described above applies equally.


GDPR Privacy

Legal Basis for Processing Personal Data under GDPR

We may process Personal Data under the following bases: Consent; Performance of a contract or steps at Your request prior to a contract (responding to Your note about working together); Legal obligations; and Legitimate interests (securing the Service, preventing abuse, and understanding aggregate use of the Website). The Company will gladly clarify the specific legal basis that applies.

International Transfer of Personal Data

We are based in the United States, and Personal Data is processed in the United States and wherever Our Service Providers operate. Where We transfer Personal Data from the EEA, UK, or Switzerland to a country not recognized as providing an adequate level of protection, We rely on appropriate safeguards: several of Our Service Providers participate in the EU-U.S. Data Privacy Framework (and its UK Extension and the Swiss-U.S. DPF), and We otherwise rely on the European Commission's Standard Contractual Clauses (and the UK IDTA or UK Addendum) together with supplementary measures such as encryption, access controls, and data minimization. You may contact Us for further information about these safeguards.

Your Rights under the GDPR

You have the right to: request access to Your Personal Data; request correction; request erasure; request restriction of processing; object to processing (including direct marketing); request data portability; and withdraw consent. To exercise these rights, contact Us using the details in the "Contact Us" section. We may ask You to verify Your identity. We generally respond within one month and may extend by two further months where necessary. You also have the right to lodge a complaint with Your local Data Protection Authority.


"Do Not Track" and Opt-Out Preference Signals

Our Service does not currently respond to legacy "Do Not Track" browser signals. Because We do not sell or share Personal Information, opt-out preference signals such as the Global Privacy Control (GPC) do not currently change any processing We perform; if We ever engage in "selling" or "sharing" as defined by applicable law, We will honor GPC signals as legally required.


Children's Privacy

The Service is intended for users 18 years of age or older and is not directed to children under 13. We do not knowingly collect Personal Data from anyone under 18, and We do not knowingly collect personal information from children under 13 within the meaning of the Children's Online Privacy Protection Act (COPPA). We do not sell the personal information of any consumer, including consumers under 16. If You are a parent or guardian and believe Your child has provided Us with Personal Data, please contact Us at privacy@humanagentic.dev, and We will take steps to delete that information.


Links to Other Websites

The Service may contain links to third-party websites not operated by Us. We have no control over, and assume no responsibility for, the content, privacy policies, or practices of any third-party sites. We advise You to review the privacy policy of every site You visit.


Changes to this Privacy Policy

We may update this Privacy Policy from time to time. We will notify You of material changes by posting the new Privacy Policy on this page, updating the "Last updated" date, and, where appropriate, via email and/or a prominent notice on the Service prior to the change becoming effective. If We materially expand the purposes for which We use previously collected Personal Data, We will provide notice and obtain consent where required by law. You are advised to review this Privacy Policy periodically.


Contact Us

If You have any questions about this Privacy Policy or wish to exercise any privacy right, You can contact Us: