Last updated: August 8, 2026 ยท Effective: August 8, 2026
HumanityU ("we," "us," or "our") is an environmental impact tracking platform. This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use the HumanityU mobile application (iOS and Android) and related services (the "Service").
By using HumanityU, you agree to the practices described in this policy.
Our commitment: HumanityU does not sell your personal data, we do not use it for advertising, and we do not share it with data brokers. Your environmental measurements belong to you.
When you create an account: Email address (authentication only) and Username (display name on community posts).
When you use calculators, we store measurements you enter (gallons saved, kg COโ reduced, trees planted) to build your own impact record. These are figures you report yourself, and we describe them that way wherever they appear.
When posting to the Community feed, v1 supports text posts and comments only. Text posts are automatically screened before publication. Photo and video uploads are disabled until moderated media review ships.
We collect no usage data at all. HumanityU contains no analytics SDK, no crash-reporting SDK, and no telemetry. Errors are handled inside the app and are not transmitted to us or anyone else. We do not collect device fingerprints, advertising IDs, browsing history, or cross-app tracking data.
HumanityU does not request location permission and does not collect location data of any kind. If you choose to set a region in your Profile, you select it yourself from a list. Your device's location services are never accessed.
| Data Type | Linked to Identity | Used for Tracking | Purpose |
|---|---|---|---|
| Email address | Yes | No | Authentication & account recovery |
| Username | Yes | No | Community display name |
| Region (self-selected, optional) | Yes | No | Showing content relevant to your area |
| Environmental measurements | Yes | No | Your personal impact record |
We never use your data for advertising, profiling, selling to third parties, or any purpose not listed above.
Powers our backend database (PostgreSQL) and user authentication. Data is encrypted in transit (TLS 1.2+) and at rest. It is not end-to-end encrypted โ your community content is processed by our systems for safety moderation and app functionality, and is readable by authorized infrastructure. Supabase is SOC 2 Type II compliant.
Supabase Privacy Policy โProvides large language model capabilities for community moderation, the Conservation Advisor Q&A, and crisis news curation through the configured owner-controlled gateway. Text is processed transiently and not retained beyond the immediate request. No personal account data is shared. Inference is performed by Google Gemini models, accessed through a managed API gateway under commercial terms. Prompts are not used to train models.
The Crisis Map tab loads topographic tiles from OpenTopoMap servers. Tile requests include approximate viewport coordinates โ the area of the map you are looking at, which is not your location. No personal identifying information is transmitted. Data is available under CC-BY-SA 3.0.
Push notifications are delivered via Apple APNs (iOS) and Google FCM (Android). Your push token is stored solely for delivering notifications you have opted into. Revoke at any time via device settings or Profile โ Notification Settings.
We do not sell, rent, or trade your personal information. We may share data only with sub-processors (Section 4), as required by law, or in a business transfer (with notice and policy continuity guaranteed).
What other people can see: Your username and anything you post to the community feed are visible to other signed-in users. Your email address is never publicly visible. Your environmental measurements are private to you and are not shown to anyone else.
| Data Type | Retention Period |
|---|---|
| Account data (email, username) | Until account deletion |
| Environmental measurements | Until account deletion |
| Community posts & comments | Until deleted by user or account deletion |
| Offline queue (device-local) | Cleared on successful sync or manual clear |
You can delete your account from inside the app, in Profile. Deletion removes your account and all associated data. If you would rather not use the in-app route, email support@humanityu.app with the subject "Delete My Account" and we will complete it within 30 days. You can also delete individual posts and comments within the app at any time.
You can request an export of your data before deleting โ see Section 9.
HumanityU is intended for users aged 13 and older. It is not directed to children under 13, and we do not knowingly collect personal information from children under 13.
HumanityU is rated for a teen audience because it includes user-generated content (community posts and comments). Direct messaging is disabled in this version. We collect only email and username โ no location, no behavioral tracking, and no advertising. HumanityU is a paid app: a single purchase, with no in-app purchases and nothing further to buy. Text posts are automatically screened before publication; photo and video uploads are disabled until moderated media review ships. If you are a parent or guardian and believe a child under 13 has provided us personal information, contact support@humanityu.app and we will delete it promptly.
California (CCPA): You have rights to know, delete, and opt out of sale. We do not sell personal information.
EU/EEA (GDPR): Legal basis is performance of contract. You may lodge a complaint with your local data protection authority.
HumanityU is a mobile application and does not use browser cookies. The app uses AsyncStorage (device-local only) for onboarding state, offline submission queue, and notification preferences. This data is never transmitted to third parties. We do not use advertising identifiers, analytics SDKs, or any third-party tracking.
Data may be processed in the United States and European Union where our service providers maintain infrastructure. For EEA users, transfers are governed by Standard Contractual Clauses (SCCs) as required by GDPR Article 46.
Material changes will be notified via in-app notification or email at least 14 days before they take effect. The "Last updated" date above reflects the most recent revision.
We respond to privacy inquiries within 5 business days and fulfill data requests within 30 days.