what we
keep.
What HUMBL collects across the app, this website, and the browser voice demo - what it stores, why, and for how long.
1. Who we are
This page is issued by QWR Interactive Solutions Pvt. Ltd. ("QWR", "we", "us", "our"), a company incorporated in India. We are the data controller (EU/UK GDPR), data fiduciary (India's Digital Personal Data Protection Act 2023, "DPDP Act"), and business (California's CCPA/CPRA) for the personal data described here.
Registered office: 301, 303, 304 The Golden Bell, Koregaon Park Annexe, Industrial Area, Mundhwa, Pune, Maharashtra 411036, India.
2. Contact
Privacy questions, requests, or complaints: [email protected]
General enquiries: [email protected]
3. What we collect
What's collected depends on whether you're using the browser voice demo on this site or the full HUMBL app, and which optional features and permissions you enable.
To verify you're a real person
Your phone number, used to send a one-time verification code. We keep the number to enforce a fair-use time limit (see Section 7).
Voice and conversation
Your voice is streamed to our AI voice provider to generate a response. On the web demo, audio is not recorded or stored - only a text transcript of each turn and session-level metrics are kept. In the app, voice recordings may also be kept if you've enabled that feature, and can be deleted individually.
Voice biometrics (app only)
If speaker verification is enabled, a biometric voice embedding is kept while that feature is on, and deleted when you disable it or delete your account.
Memory
If HUMBL learns a durable fact about you during a conversation (a preference, something you mentioned about your work), it may save that fact so a later conversation can refer back to it. You can view and delete this at any time (Section 7).
Device and connected-service data (app only, only if you grant the permission)
Calendar and task data via Google Calendar/Google Tasks - read, and, when you ask for it, create, edit, and delete; contacts, for call/message features you request; location; Bluetooth-connected device info; camera, for image-based features; notifications from other apps, to relay or act on them; music-playback control via Spotify or Apple Music; and sign-in via Google or Apple. Google data is covered in full in Section 14, and Apple data in Section 15. The web demo does not access any of these - see Section 7 of our Terms of Service for the full permissions list.
Error, performance, and crash data
Collected automatically, across the app and website, to keep the Service reliable.
4. Lawful basis for processing
Consent (GDPR Art. 6(1)(a) / DPDP Sec. 6) - for starting a voice session, enabling a device permission or connected service, and saving anything to memory. Legitimate interest (GDPR Art. 6(1)(f) / DPDP Sec. 7(f)) - for abuse prevention and reliability telemetry; we've concluded this doesn't override your rights, and you may object at any time.
If you're in California or elsewhere in the US: the CCPA/CPRA doesn't use a "lawful basis" framework the way GDPR and the DPDP Act do - instead it requires us to disclose what we collect and why (Section 3) and give you a right to opt out of any sale or sharing of your personal information, which we address directly in Section 9.
5. Who processes your data
We share data only with processors bound by data protection obligations, and we do not sell or share your personal information as those terms are defined under the CCPA/CPRA (including no cross-context behavioural advertising). Categories in use across the app and website: cloud backend, authentication, and storage providers; analytics, crash-reporting, and performance-monitoring providers; the AI providers that generate voice and text responses; SMS providers used to deliver verification codes; and, only for the features you enable, calendar, task, music, and messaging platforms, and sign-in providers. We don't publish exact hosting locations or infrastructure details for security reasons - data may be processed in India and other countries as described in Section 8.
6. Cookies and tracking on this website
This section covers heyhumbl.ai only - the marketing site, not the app or the voice demo, which are covered above.
We use cookies and similar technologies for two purposes: analytics (Google Tag Manager, Google Analytics 4, Microsoft Clarity, and Sentry for error monitoring) and advertising measurement (Google Ads, and pixels for Meta, LinkedIn, TikTok, X, Snap, and Pinterest, for whichever platforms we're actively running campaigns on). None of these load until you consent via the banner on first visit, and you can change your choice at any time using the "Privacy settings" control in the footer.
We honour Global Privacy Control (GPC) and Do Not Track (DNT) signals automatically: if your browser sends either, we treat that as an opt-out of both analytics and advertising cookies and never show the banner - this satisfies the CCPA/CPRA's requirement to honour an opt-out preference signal, and we apply it globally, not only to California visitors.
We do not use cookies of any kind on the browser voice demo or within the HUMBL app; consent for data collection there is handled as described in Section 3 and Section 4.
7. Retention and deleting your data
| Data | Retention |
|---|---|
| Account data | Kept for the life of your account; deleted within 30 days of account deletion |
| Voice recordings & transcripts | Kept while the relevant feature is enabled; individually deletable at any time |
| Voice biometric embeddings | Kept while speaker verification is enabled; deleted on disable or account deletion |
| Memory facts | Kept until you delete them or delete your account |
| Error / performance telemetry | Up to 90 days |
| Infrastructure logs | ~30 days (provider defaults) |
| Audio sent to AI providers for real-time processing | Not retained by the provider, per our agreements with them |
Your phone-verification record (used for the fair-use time limit) is kept for as long as the demo or your account is active.
To delete your data
If you still have a verified session, go to your conversations and use "Delete all my conversations & memories" - this hides your data immediately and permanently erases it within 30 days, no app or login elsewhere required. If you no longer have the app or can't verify your phone, email [email protected] with the phone number you used; we verify and delete it, aiming for the same 30-day window.
What we retain after deletion
A minimal, non-identifying record that an erasure happened - a timestamp and a reference id, nothing that identifies you. That record is what lets us prove the erasure took place; it contains no personal data.
8. International transfers
QWR is based in India. Data may be processed by service providers in India, the EU, the UK, the US, and other regions depending on the service involved.
Transfers out of the EU/UK use Standard Contractual Clauses or another GDPR Art. 46 safeguard where required. Transfers out of India follow the DPDP Act's own mechanism (Sec. 16), which works differently from GDPR's: rather than an adequacy/safeguards test per transfer, the Indian government maintains (or may maintain) a restricted list of countries data fiduciaries cannot transfer personal data to; transfers to any country not on that list are permitted by default.
9. Your rights
If you're in India, the EU/EEA, or the UK (GDPR / DPDP Act rights): access, rectification, erasure, restriction, portability, objection, and withdrawal of consent at any time. To exercise these, email [email protected]. You may also lodge a complaint with your local supervisory authority (in India, the Data Protection Board of India once established; in the EU/EEA, your local authority; in the UK, the ICO).
If you're in California or elsewhere in the US (CCPA/CPRA rights, which are named and scoped differently): the right to know what personal information we've collected and why, the right to delete it, the right to correct inaccurate information, the right to opt out of any sale or sharing (see Section 5 - we don't currently do either, but you can still register the preference), the right to limit use of sensitive personal information, and the right not to be discriminated against for exercising any of these. To exercise these, email [email protected].
How quickly we respond
We aim to respond to any privacy request within 30 days. Where a specific law sets its own deadline - GDPR gives us up to 30 days (extendable to 90 for complex requests), CCPA/CPRA up to 45 days (also extendable) - we follow whichever applies to you, and will tell you if we need the extension.
10. Children's privacy
The Service is not directed at, and we do not knowingly collect data from, anyone under 18 - our eligibility requirement (see Terms of Service, Section 2) is set at the age of majority specifically so it sits above every child-specific threshold below, rather than relying on a separate children's-data exception.
This is higher than the age thresholds set by the US Children's Online Privacy Protection Act (COPPA, under-13), the EU/UK GDPR's digital age of consent (Art. 8 - 16 by default under EU GDPR, 13 under UK GDPR/the Data Protection Act 2018), and India's DPDP Act 2023 (Sec. 9, under-18, which additionally requires verifiable parental/guardian consent and prohibits behavioural tracking and targeted advertising directed at children). If we learn a user is under 18, we will delete their account and associated data.
11. Security
The DPDP Act (Sec. 8(5)) requires us to take "reasonable security safeguards" to prevent a personal data breach; the measures below are how we meet that duty (and the equivalent security requirements under GDPR Art. 32 and the CCPA/CPRA).
Encryption in transit (TLS) and at rest, row-level access controls so no one account can read another's data, and multi-factor authentication for anyone with administrative access to production systems.
12. Changes to this page
We may update this page as the app, website, or demo change. Material changes will update the version and date above and, where required by law, we'll seek renewed consent.
13. Governing law
Governed by the laws of India, subject to the exclusive jurisdiction of the courts at Mumbai, Maharashtra - without prejudice to any rights you have under the GDPR, the DPDP Act, the CCPA/CPRA, or other applicable law in your jurisdiction.
14. Google user data
This section applies only if you connect a Google account in the HUMBL app. It adds to the sections above and, where it is more specific, it governs.
Our Limited Use commitment
HUMBL's use and transfer of raw or derived user data received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
What we request, and what it does
Nothing below is requested until you turn the matching feature on, and each permission is used only for the purpose stated beside it.
| Permission | What it does, and the feature it powers |
|---|---|
| Sign-in (email, profile) | Lets you sign in to HUMBL with Google, and shows your name and picture in the app. Reads no Google service data. |
| Google Calendar | Reads your schedule so HUMBL can answer questions about it, checks free/busy time to find you a slot, and - only when you ask - creates, edits, or deletes an event. |
| Google Tasks | Reads your task lists so HUMBL can tell you what's due, and - only when you ask - adds, edits, completes, or deletes a task. |
Google's consent screen describes these permissions in their broadest form, which is how Google words them rather than a description of what HUMBL does. In practice HUMBL works with the events on your primary calendar and with your task lists: it does not create or delete calendars themselves, and does not read or change their sharing settings.
We do not train AI on your Google data
To answer a question about your schedule or tasks, the relevant entries are sent to our AI provider to generate that one response. Under our agreements with them they do not retain it and do not train on it - and neither do we. No Google Workspace data, raw or derived, is ever used to train or improve any AI model. This is the commitment in Section 6 of our Terms of Service, applied specifically to Google data.
Derived data and memory
If HUMBL saves a durable fact drawn from your calendar or tasks - that you meet a particular client on Thursdays, say - that fact is derived Google user data, and the same Limited Use commitment covers it. It is used only to personalise your own later conversations, and is never transferred, sold, or used for advertising. You can view and delete it at any time (Section 7).
Human access
No one at QWR reads your Google Calendar or Google Tasks data. The only exceptions are the narrow ones the Limited Use requirements permit: with your explicit consent (for example, if you ask us to look into a problem), where it is necessary for security, or where the law requires it.
Never sold or shared
We do not transfer Google user data to advertising platforms, data brokers, or information resellers, and we do not sell or share it as those terms are defined under the CCPA/CPRA.
Turning it off
Disconnect the integration in the HUMBL app, or revoke HUMBL's access directly from your Google Account permissions page. Revoking stops all future access immediately; anything already stored is deleted as described in Section 7.
15. Apple user data
This section applies only if you sign in with Apple, or connect Apple Music, in the HUMBL app. It adds to the sections above and, where it is more specific, it governs.
Our commitment
HUMBL's use of data received through Apple's sign-in and media services is limited to providing the features described below. We do not use it for advertising or cross-app tracking, we do not sell or share it, and we never use it to train or improve any AI model. Our handling of it follows the Apple Developer Program License Agreement and the App Store Review Guidelines.
What we request, and what it does
Nothing below is requested until you turn the matching feature on.
| Permission | What it does, and the feature it powers |
|---|---|
| Sign in with Apple | Creates your HUMBL account and signs you in. We receive your name and an email address, and nothing else from your Apple account. |
| Apple Music | Lets HUMBL play the music you ask for, control playback (play, pause, skip), and read the track currently playing so it can tell you what it is or show it on your glasses. |
If you chose "Hide My Email"
Apple then gives us a private relay address ending in privaterelay.appleid.com instead of your real one. We treat that as your email address and use it only to contact you about your account. We make no attempt to discover, infer, or link the real address behind it. If you later turn off forwarding at Apple, our email will stop reaching you - your account still works, but you may want to add another way for us to contact you.
Your music library
Apple's prompt asks for access to your media library, because that is how iOS gates music playback. HUMBL uses it to start and control playback and to read the track currently playing. It does not browse, catalogue, copy, or upload your music library, and it does not build a profile of your listening. When you ask for a song by name, the search runs against Apple's public catalogue, not your library.
Device permissions on iPhone and iPad
Microphone, camera, contacts, location, Bluetooth, photos, speech recognition, and local network are iOS device permissions rather than Apple account data. Each is explained at the moment you grant it, is used only for the feature it powers, and can be withdrawn at any time in iOS Settings. Section 3 covers what each one collects.
Turning it off
Disconnect Apple Music in the app, or withdraw the permission in iOS Settings. You can review or stop HUMBL's use of Sign in with Apple on your device under Settings, your name, then "Sign in with Apple". To remove your data from HUMBL entirely, delete your account as described in Section 7.