Privacy Policy
Last updated 6 September 2026
Draft pending legal review. The processing described here is what the product actually does today. Operator details must be configured and the whole text reviewed by a qualified lawyer before it is relied upon.
Who we are
Operator details pending verification, registered address pending verification, operates Human In Circuit. For the account data described below we are the data controller. For the review content your systems send us, you are the controller and we are your processor.
What we collect
Account data
Your email address, your organisation’s name, your role, and — if you sign in with Google — the name and profile picture Google supplies. We do not receive or store your Google password.
Review content
Whatever your systems send us: review titles, context, field values, reviewer decisions and corrections, and any files attached. We do not inspect this content except as needed to operate the Service, and we do not use it to train any model.
Website analytics
On our public pages — the home page, pricing, documentation, and the sign-in and sign-up pages — we record which page was viewed and a few named actions such as starting a sign-up, together with the referrer and any campaign parameters in the link you followed. This is processed by PostHog on our behalf.
It is configured without cookies or persistent browser storage and does not follow you between visits. Inside the signed-in application we send only named business milestones such as project creation, review creation, decision completion, and callback delivery. Identifiers are pseudonymous and properties are allowlisted. We do not send page addresses, email addresses, review content, attachments, credentials, or arbitrary error text.
Operational data
Usage counts for billing, callback and notification delivery attempts, audit-log entries for administrative actions, and server logs. Sentry receives redacted browser, server, and worker errors so we can diagnose failures. Session recordings are disabled. Push notification subscriptions, where you enable them.
What we do not do
- We do not sell personal data, and we do not share it for advertising.
- We do not use your review content to train machine-learning models.
- We do not run advertising trackers, and we do not track you across other websites.
- We do not set analytics cookies. Sign-in uses a first-party cookie that is necessary for the Service to work.
Why we process it
- To provide the Service — performance of our contract with you.
- To bill you — performance of the contract, and our legal obligation to keep financial records.
- To keep the Service secure and working — our legitimate interest in operating it safely.
- To understand acquisition and product use — our legitimate interest in improving onboarding, retention, and reliability. We use explicit events without recordings or customer content.
- To contact you about the Service — legitimate interest for operational messages; consent for anything promotional, which you can withdraw at any time.
Who else processes it
These are all the sub-processors we use. We will give notice before adding another.
| Processor | Purpose |
|---|---|
| Supabase | Database, authentication, and file storage |
| Railway | Application and worker hosting |
| Lemon Squeezy | Payments, as merchant of record |
| Resend | Transactional email delivery |
| Sign-in, where you choose to use it | |
| PostHog | Explicit website and pseudonymous product events |
| Sentry | Redacted application error monitoring and uptime checks |
| GitHub | Encrypted seven-day backup storage and deployment automation |
Data is processed in the regions selected in our service-provider accounts. Where data leaves your region, transfers rely on the transfer safeguards offered by the relevant processor.
How long we keep it
- Review content — for the retention window of your plan, after which decided reviews and their attachments are deleted automatically.
- Account data — while your organisation exists, and for a short period afterwards so that an accidental deletion can be reversed.
- Billing records — for as long as the law requires us to keep them.
- Server logs and error events — for the configured provider retention period, reviewed and reduced as the beta grows.
Encrypted beta backups are retained for seven days and then overwritten in the ordinary course.
Your rights
Depending on where you live you may have the right to access, correct, delete, or receive a copy of your personal data, to object to or restrict some processing, and to complain to a supervisory authority. Analytics and exports are available in the product; for anything else, write todsp+hic+support@dspsolves.com and we will respond within the period required by applicable law.
An organisation Owner can request deletion of the whole organisation from the admin area.
Security
Access is controlled by role and checked on the server for every request, with row-level security in the database as a second layer. API keys are stored only as hashes. Callback secrets and stored credentials are encrypted. Attachments are private and restricted by file type. Callbacks are sent over HTTPS only, signed, and blocked from reaching private networks.
No system is perfectly secure. If we discover a breach affecting your personal data we will notify you and any regulator as required by law.
Children
The Service is not intended for anyone under 16, and we do not knowingly collect their data.
Changes
We will post any update here and change the date above. If a change materially affects how we handle your data we will give notice in the product or by email.
Contact
dsp+hic+support@dspsolves.com · Operator details pending verification, registered address pending verification