HUMNLABS Privacy Policy
01 Overview & Scope
HUMNLABS ("we", "us", or "our") is an experimental research initiative exploring privacy-preserving trust signals and confidence in human presence. This Privacy Policy describes how technical and experimental data are handled when you visit our website and participate in the HUMNLABS Experiment (humnlabs.io/experiment/).
02 Experimental Behavioral Signals vs. Web Hosting Operations
We explicitly distinguish between two types of processing on this website:
- Experimental Behavioral Signals (Browser-Only): When you participate in the experiment, your browser temporarily measures session-level interaction signals (reaction timing latency, pointer/touch movement coordinates, and inter-keystroke intervals). This data is processed strictly within your browser’s volatile local memory (RAM). It is not transmitted to our servers, saved to persistent storage, or linked to your identity.
- Standard Web Hosting Operations: Like virtually all web applications, standard web hosting and network infrastructure automatically process technical request data (such as your IP address, browser user-agent, operating system, and request timestamps) to deliver web pages securely and prevent malicious traffic.
03 Data Processed
- No Identity Credentials (Experiment Only): The experiment does not require, ask for, or collect accounts, names, email addresses, phone numbers, or government identification credentials.
- No Biometric Profiles: The experiment does not create, store, or extract biometric signatures, facial templates, or persistent typing profiles.
- Volatile Interaction Metrics: Raw interaction values (timing deltas, cursor trajectories, typing rhythms) are calculated locally in your browser's JavaScript memory during your active session.
04 Purpose of Processing
- Research & Proof-of-Concept: Exploring whether privacy-preserving behavioral signals can establish reasonable confidence in human presence without identity disclosure.
- Privacy-First Demonstration: Demonstrating client-side, edge-computed alternatives to tracking-heavy CAPTCHAs.
- Infrastructure Security: Technical server logs (such as IP addresses) are processed solely for network delivery, server health monitoring, and DDoS protection.
05 Data Storage & Retention
- Experimental Signals: Session-only retention. Experimental signal metrics exist only in volatile RAM while your browser tab is active. The experiment's in-memory state is cleared when the page is refreshed or closed.
- Server Logs: Retention periods for standard web hosting and security logs are determined by the relevant infrastructure providers and may vary according to operational and security requirements.
06 Data Sharing & Third Parties
We do not sell, rent, or trade user data. Experimental signal data remains isolated inside your local browser sandbox and is not shared with third parties. Standard web hosting logs are processed solely by infrastructure providers for content delivery and network security.
07 Cookies & Tracking
The experiment does not intentionally use tracking cookies, advertising cookies, or persistent browser storage. No tracking pixels or third-party web analytics services (such as Google Analytics or Meta Pixel) are operated by the experiment.
08 Data Security
We follow a Privacy-by-Design architecture centered on data minimization and edge computation. By processing experimental signals exclusively inside your local browser memory, this architecture substantially reduces server-side exposure of experimental behavioral signals.
09 User Rights & Legal Frameworks
Depending on your jurisdiction (including under the General Data Protection Regulation / GDPR or state privacy statutes), you may have legal rights regarding personal data processed by hosting infrastructure (such as server log IP addresses). Because experimental signals are processed in local memory without identity identifiers or server storage, the experiment is not designed to associate session interaction scores with any specific individual.
10 Children's Privacy
Our experiment is not directed to children under 13 years of age (or 16 in applicable jurisdictions), and we do not knowingly collect personal information from children.
11 Changes to This Policy
We may update this Privacy Policy periodically to reflect research refinements or legal updates. The "Effective Date" at the top indicates when the latest revisions took effect.
12 Contact Us
If you have questions or feedback regarding this Privacy Policy or our research, please contact us:
Email: humnlabsio@gmail.com
Website: https://humnlabs.io