Privacy Policy

Last updated: August 13, 2026

This policy explains what personal data gethumandesign.com ("we", "us", "our") collects, why we collect it, and how we use and protect it. By using our service you agree to the practices described here.

Who we are

gethumandesign.com is a service that lets you explore Human Design through AI. You can connect your own AI assistants (Claude, ChatGPT, Gemini, and others) to our chart calculations via an MCP server or AI skill, use our REST API, or chat with our built-in AI assistant. You can reach us at helfoolo@gethumanbardesign.com.


What data we collect

Account data

When you create an account we collect your email address, which is used to authenticate you and send transactional messages (e.g. password reset). We also store whether you have opted in to receive emails about new features and services.

Profile data (people records)

To look up a Human Design chart, we need birth data. When you save a person to your account we store:

You control this data entirely. You can edit or delete any person record at any time from your dashboard.

Sharing a person's chart

From a person's chart you can choose to generate a public share link. Anyone with that link can see the person's name, date and time of birth, place of birth, and the resulting chart — without needing an account. The link is unguessable but is not encrypted: treat it like an unlisted URL, not a private secret. Sharing is opt-in and reversible — you can revoke a link at any time from the chart, after which the URL will stop working immediately.

Chat conversation data

When you use the built-in AI chat on our website, we store your conversation messages (what you type and what the AI responds) to provide conversation history and continuity. You can delete individual conversations at any time from the chat interface.

When you connect your own AI assistant via the MCP server or AI skills (e.g. through Claude, ChatGPT, or other clients), we do not store your conversations. Those conversations exist only within the third-party application you use. We only process the individual chart calculation requests sent to our API.

Sharing a conversation

From the chat you can choose to generate a public share link for a conversation. Anyone with that link can read the full conversation — and, because conversations can reference the people you have saved, the link also exposes the name, date and time of birth, place of birth, and resulting chart of every person mentioned in that conversation. A signed-in viewer can save those people to their own account. As with person share links, the URL is unguessable but not encrypted: treat it like an unlisted URL, not a private secret. Sharing is opt-in and reversible — you can revoke a link at any time from the chat, after which the URL will stop working immediately.

Private chats

When you use private chat mode, your messages are kept only in your browser's memory for the duration of the session. They are not stored in our database and are permanently lost when you close or refresh the page. Private chat messages are still sent to our AI provider (Google Gemini) to generate responses, subject to their API terms of service, but are not retained by us.

Usage data

We track how many API requests and chat messages your account uses per billing period in order to enforce plan limits. Alongside these counts we record basic technical context for each request — the device and browser type (derived from your browser's User-Agent) and whether you are using the installed app or the website — so we can understand how the service is used across devices. We do not log the content of individual chart requests.

We also keep aggregate, first-party measurements of how our share links are used — for example how often a shared chart card or page is viewed — and, if you open a share link and later create an account, we record which share link brought you to us so we can understand how sharing helps people discover the service. This is internal product analytics; we do not share this share-referral information with advertising partners.

Payment and tax data

Payments are processed by Stripe. Your card number goes straight to Stripe — we never see it and never store it.

To charge the right amount of VAT, Stripe's checkout asks you to confirm the country you are paying from and records the name on your card. If you tick "I'm purchasing as a business" you can also enter a company VAT number; that field is optional and only relevant if you are buying on behalf of a business. We use this information to apply the correct VAT rate and to issue a valid invoice — a legal obligation, not something we ask for by choice. It is never used for advertising or personalisation.

The full payment records — including the name on your card, the billing country and any VAT number — sit with Stripe, which may process them outside the EU under its own safeguards. We also keep a short record of each payment ourselves: what you paid, when, and the country it was taxed in, together with the reference numbers the payment has at Stripe so it can be matched to the invoice. That record holds no name, no address, no email and nothing about how you used the app.

If you cancel a subscription, Stripe asks why and lets you add a comment. Answering is optional. We keep whatever you choose to say, because it is how we find out what to fix — and unlike the payment record itself, it is deleted along with your account.

Because these are tax records they outlive your account: they are kept for as long as tax and accounting law requires, typically 7 years. Once your account is gone, our own record is no longer linked to it. See Delete your data or your account for what deletion does and does not reach.


Why we collect it

We do not sell your personal data. We use Cloudflare Web Analytics for aggregated site measurement, and Google Ads for campaign measurement on our public pages. Cloudflare may receive aggregated usage and performance metrics; Google may receive page-view data from those public pages. When you sign up or buy a subscription we report the conversion to Google using only the identifier of the ad click that brought you here — never an identifier of you (see "Cookies" and "Advertising" below).


How we store it

Your account, chart and chat data is stored on AWS in the EU, and our nightly encrypted backups are held in EU object storage in Amsterdam. The full payment and tax records live with Stripe, our payment processor, which may process them outside the EU under its own safeguards; the short record we keep of each payment is stored in the EU with everything else. We apply reasonable technical and organisational measures to protect your information against unauthorised access or disclosure.

How long we keep it

We keep your data for as long as your account exists. You can delete individual saved people, chat conversations and share links at any time — each takes effect immediately. When you delete your account, all associated profile data, saved people, chat conversations, and the credentials and access tokens associated with your account are removed from our live systems immediately, and the encrypted backups we keep so we can recover from an outage or a data-loss incident are purged within 90 days. We keep an anonymous record that an account was deleted, containing no information that identifies you. Anonymised usage aggregates may be retained for internal analytics, and payment and tax records — Stripe's, and the short record we keep of each payment — are kept for the period tax law requires. See Delete your data or your account for the exact steps and a full list of what is deleted and what is kept.


Your rights

You have the right to:

You can manage or delete your data directly from your dashboard, or contact us at helfoolo@gethumanbardesign.com.

Cookies

We use essential cookies required for authentication (session tokens). Our public pages — the homepage and the documentation pages — also load the Google Ads tag, which sets cookies used to count page views and to recognise a visit that started with one of our ads. The dashboard carries no advertising tag at all. We also use Cloudflare Web Analytics on public pages and certain dashboard-related pages, including the dashboard shell and OAuth consent page, which collects aggregated site usage and performance metrics such as page URLs, referring sites, browser and device information, country-level location, and page-load timings using the Performance API. Blocking third-party cookies or scripts in your browser may limit this client-side tracking without affecting the core functionality of the service, but it does not stop the server-side conversion reports described below.

Advertising

We run search ads on Google. To measure how those campaigns perform we use two things: the Google Ads tag on our public pages, which records page views, and a conversion report we send from our own servers when a signup or purchase happens.

If you arrive from one of our ads, the link carries a click identifier that identifies the ad click, not you. We store it with your account, and when you complete signup or buy a subscription we report that conversion to Google with only the click identifier, a timestamp and — for a purchase — the amount paid.

We do not send advertising platforms your email address (hashed or in any other form), your name, your account identifier, your IP address, your birth data, your chart data, or your chat messages.

You can opt out of personalised advertising through your ad platform account settings or via Your Ad Choices.

Third-party services

We use the following third-party providers to operate the service:

Each provider has its own privacy policy and data processing terms.

Changes to this policy

If we make material changes, we will update the "last updated" date at the top of this page. Continued use of the service after changes constitutes acceptance.

Contact

Questions or requests about your data? Email us at helfoolo@gethumanbardesign.com.