# Rehumanize Privacy Policy *Last updated: 8 July 2026* Rehumanize is a browser extension and Android app that checks whether posts in your social feed read as human-written or AI-generated, and marks likely AI posts with an amber indicator. It is an independent research project studying synthetic content on social media. This policy describes what the software actually does — it is written against the running code, not a template. ## The short version Post text is analysed in the moment and immediately discarded — it is never stored, anywhere. We never know who you are. If you opt in, we keep anonymous counts and derived labels about flagged posts for research; if you don't, we keep nothing about those posts beyond anonymous daily totals. You can change your mind at any time in settings. ## What happens when a post is checked The visible text of a post is sent over an encrypted connection to our server, which forwards it to AI-classification models hosted on Hugging Face's inference service to score how likely it is to be AI-generated. The text lives only for the duration of that check — it is not written to disk on your device, on our server, or by the research pipeline. What comes back is a score, and the score is all that remains. ## What we collect from everyone (no opt-in) Anonymous daily totals only: how many posts were scanned and how many were flagged, per platform (Reddit, X, Threads), per day. These are plain counters — they contain no text, no usernames, no account details, and nothing that could identify a person or a post. They power the public statistics on our website. We also keep standard operational measurements about our own server (request latency, error rates) — these are about our infrastructure, not about you. ## What we collect only with your consent During onboarding you are asked — as a separate, explicit yes/no choice, never a pre-ticked box — whether you want to contribute anonymized detection data to the research project. If you say yes, then for each post flagged as likely AI-generated we record: - the platform it appeared on - the day and hour (never a precise timestamp) - the detection score - derived labels from classification models, each with its confidence value: sentiment (negative/neutral/positive), topic (19 broad categories), emotion, irony, hate speech, and offensive language Explicitly **never** collected: the post's text, the author's username or any account identifier, your identity, your browsing history, anything about posts that were not flagged, and anything at all if you have not opted in. To make consent revocable, your installation generates a random ID (a string like `5f6645a5-…`) that is stored with your consent choice. It is created randomly on your device, is shared with no other service, and cannot be connected to your name, accounts, or device identity by us or anyone else. ## Declining changes nothing Detection and the amber indicators work identically whether or not you opt in. Consent gates only the research data contribution. ## Withdrawing consent Flip the research toggle off at any time — in the extension popup's settings or the Android app's settings screen. From that moment, nothing further is contributed. Because the data already collected is anonymous, we have no way to identify which records came from you, and therefore cannot selectively delete past contributions — this is a direct consequence of not being able to identify you (GDPR Article 11). ## Where data lives and who can access it Collected data is stored in a managed PostgreSQL database hosted by Render (also our application host), in the EU-adjacent regions Render provides. Post text is transiently processed by Hugging Face's hosted inference API during classification, subject to their privacy terms; we transmit no identifiers alongside it. Access to the stored research data is limited to the project's research team via authenticated, token-protected endpoints. ## Legal basis (GDPR) - Research data contribution: **consent** (Article 6(1)(a)), captured explicitly during onboarding and revocable at any time. - Anonymous counters and operational metrics: **legitimate interests** (Article 6(1)(f)) — operating and improving the service. These contain no personal data. - Post text in transit: processed transiently as strictly necessary to perform the detection you installed the software to do, and never retained. ## Changes and contact Material changes to this policy will be reflected in the extension/app before they take effect. Questions or concerns: rehumanize-project@tuta.com.