Plain words about your data.
withHuman sits between AI agents and the people who approve what they do. That means we hold requests, decisions, and the details of the people who make them. This page says what we collect, why, where it is kept, and how to get it back or have it removed.
Who we are
withHuman is operated by Metoro Inc, a Delaware corporation. Metoro Inc is the data controller for the marketing site and your account. For the contents of approval requests that your organization's agents send us, your organization is the controller and we process that data on its behalf.
Questions and requests about this policy go to [email protected].
What we collect
Account data: your name, work email address, the organizations you belong to, your role in each, and the sign-in method you use. When your organization uses single sign-on, we receive the identity your identity provider asserts and, if directory sync is enabled, the group memberships it publishes.
Contact methods you add for notifications: an email address, a phone number for text messages or WhatsApp, and the Slack or Discord account you link. Each is verified before it is used and you can remove it at any time.
Approval requests: the tool an agent wants to call, its arguments, the agent's stated reasoning, and any context the agent attaches. This can include your customers' data if an agent includes it; your organization decides what its agents send.
Decisions and audit records: who approved, denied, or claimed a request, when, from which channel, and any note they wrote. Audit records are append-only once a request is final.
Technical data: server logs with IP addresses, request identifiers, and timestamps, kept for security and debugging. The web app stores a session cookie; the iPhone app stores your session credential in the device Keychain and your last-known account details so it can open while offline.
Billing: the hosted edition bills through Stripe or AWS Marketplace. Stripe holds card details, AWS holds your marketplace account; we hold your plan, seat count, and invoice history.
What we do not do
We do not sell personal data. We do not run advertising or tracking on the website, the web app, or the iPhone app, and the iPhone app declares no tracking to Apple. We do not use approval requests, decisions, or notes to train models.
Text messages and WhatsApp
If you add a phone number for notifications, we use it for two things only: a one-time code to confirm the number is yours, and prompts telling you an approval request is waiting on you. Both are sent through Twilio. You choose to receive them by ticking a consent box that starts unchecked, and you can stop at any time by replying STOP, removing the number from your settings, or writing to [email protected].
We do not share, sell, or provide your mobile phone number or messaging consent data to third parties or affiliates for marketing or promotional purposes. The number and your consent are used only to send the messages described here, and the messages never contain the contents of an approval request. Message and data rates may apply; message frequency depends on how often an approval needs you. The full description of the program is at withhuman.ai/sms.
Why we process it
To provide the service: routing a request to the right people, telling them, recording their decision, and answering the agent. This is performance of our contract with your organization.
To keep the service secure and working: logs, rate limits, abuse prevention, and support. This is our legitimate interest, balanced against yours.
To bill hosted organizations and to keep the records the law requires us to keep.
To contact you about your account. You can ask us to stop at any time.
Where it lives and who else touches it
The hosted service runs on Microsoft Azure in the United Kingdom (Azure UK South). Data in transit is encrypted with TLS; stored credentials and third-party tokens are encrypted at rest with keys we hold.
We use a small number of processors, each only for the purpose named:
- Microsoft Azure: hosting and storage.
- Cloudflare: DNS and network protection in front of the service.
- Vercel: hosting for this website.
- Stripe and AWS Marketplace: payments for the hosted edition.
- Resend: transactional email.
- Twilio: text messages and WhatsApp notifications, when you add a phone number.
- Slack and Discord: direct message notifications, when you link an account.
- Apple: TestFlight and App Store distribution of the iPhone app, and crash reports if you opt in on your device.
Notification messages carry the tool name, the agent, the deadline, and a link. They never carry the request's arguments.
Self-hosted deployments of the open-source edition send us nothing.
How long we keep it
Account data for as long as your organization is active. When an organization is deleted, its data is purged after a short grace period. Approval requests, decisions, and audit records are kept for the life of the organization because they are the record your organization relies on. Server logs are kept for thirty days.
Your rights
Under UK and EU data protection law you can ask for a copy of your personal data, ask us to correct or delete it, object to or restrict processing, and take your data elsewhere. Write to [email protected] from the email address on your account and we will respond within one month. Where your organization is the controller, we will pass your request to it. You can also complain to the Information Commissioner's Office at ico.org.uk.
Changes
When this policy changes we update the date below and, for changes that matter, tell account holders by email. This version is effective 4 September 2026.
Need help with the product instead? Support.