Trust & Transparency Report · Current as of 2 August 2026
Built for HR. Built for Trust.
We operate with full transparency about how your data moves, who processes it, and what rights you have as a user in the MENA region.
Saudi Arabia
Outputs are calibrated to Saudi Labour Law requirements, including Saudisation (Nitaqat) percentages, probation period caps, and end-of-service gratuity calculations.
United Arab Emirates
Compliant with UAE Labour Law and DIFC/ADGM considerations. Offer letters and JDs reflect UAE-specific statutory requirements.
Gulf (Kuwait, Bahrain, Qatar)
Core Gulf labour law framework applied across shared statutory provisions including probation caps and notice periods.
Jordan
Issued and operated from Amman, Jordan. Jordanian Labour Law applied for Jordanian market outputs.
Every piece of data that flows through Humanly Intelligent is protected by multiple, overlapping security controls.
TLS 1.3 in Transit
All data transmitted between your browser and our servers uses TLS 1.3 encryption. Connections are rejected if they do not meet this standard.
AES-256 at Rest
Uploaded files (including CV documents) are encrypted at rest using AES-256. Encryption keys are stored separately from the data they protect.
Encrypted Recall Memory
Your Recall memory — the professional context stored across tools — is encrypted per-user with a unique key. No other user can access your stored memory.
Strict Data Tenancy
Every database query is scoped to your account. Multi-tenancy isolation is enforced at the data layer — not just the application layer.
Audit Logging
All administrative actions are logged with timestamp, actor, and change summary. Logs are retained for 90 days and monitored for anomalies.
Rate Limiting
API endpoints are rate-limited per user and per IP to prevent abuse and protect service availability for all users.
Blind AI Inference
We do not log or retain your tool inputs beyond the active session. AI inference calls are ephemeral — the provider processes them and discards them after the response is returned.
Most privacy actions are available immediately from your account settings — no waiting, no forms.
Self-Serve (Instant)
Clear Recall Memory
Delete all stored professional context from Settings → Recall at any time.
Delete Account & All Data
Permanently delete your account and all associated data from Settings → Account.
Smart Shortlist Transparency
Request a bias-audit report on any shortlisting run — available from the Shortlist workspace.
Correct Data / Request Audit
Update your name or email in Settings. For output corrections or audit requests, contact our Privacy Desk.
| Processor | Role | Privacy Terms |
|---|---|---|
| Replit | Infrastructure & hosting | View Terms |
| hCaptcha | Bot protection on sign-in & sign-up | View Terms |
| Email Provider | Transactional email delivery (provider being finalized) | — |
| Lemon Squeezy | Payment processing & Merchant of Record | View Terms |
| Anthropic | AI language model inference | View Terms |
| Plausible Analytics | Privacy-first analytics (no cookies, no PII) | View Terms |
| OAuth sign-in (optional — only if you choose to sign in with Google) | View Terms |
If you discover a security vulnerability, please report it responsibly to info@humanlyintelligent.com. We commit to acknowledging receipt within 48 hours and providing a resolution timeline within 14 days.
In the event of a confirmed data breach affecting personal data, we will notify affected users and relevant supervisory authorities in accordance with applicable law — within 72 hours of becoming aware of the breach where required.
