Privacy Policy — Human:AI (H2AI)
Last updated: July 14, 2026
Who we are
Human:AI (H2AI) is a Canadian platform that turns documents, images, and other inputs into structured, agent-readable data and public endpoints, and that runs AI assistants which help operate your business across channels you connect. H2AI is operated by SYSTEMshift AI Strategy Inc. (Canada Corporation No. 1690016-0), based in Ontario, Canada.
Contact: hello@human2ai.ca
Quick summary
- You control what’s public vs. private. We give you visibility toggles and PII flags, but you are responsible for what you publish.
- We process your content with AI providers (e.g., OpenAI and Anthropic) to extract structure and run assistants. We don’t sell your data and we don’t use it to train foundation models.
- You can sign in with Google. If you connect Google services (Calendar or Gmail), we access only what’s needed for the feature you turned on, and our use follows Google’s Limited Use requirements (see Section 5).
- Payments run through Stripe and/or Square. We don’t store full card details.
- You can delete your datasets and account, and disconnect any connected service at any time. Some logs/records stay as required by law or for backups.
1) Scope & Definitions
This policy covers personal information handled by H2AI across our web app, dashboard, AI assistants, APIs (including Model Context Protocol “MCP” endpoints), and public dataset pages.
- Personal Information (PI/PII): Info that identifies or can reasonably identify a person.
- Content/Data: Files, images, text you upload; extracted JSON and metadata.
- Public Endpoint: A URL (often with QR) that serves the structured output you chose to publish.
- MCP: Our JSON-RPC access endpoints that let compatible AI agents use your published tools/data (access controlled by your settings).
- Connected Service: A third-party account you link to H2AI (e.g., Google, Meta, Stripe, Square) so a feature can read from or write to it on your behalf.
We follow Canadian privacy law (PIPEDA) and aim to align with GDPR/UK GDPR, CPRA (California), and Quebec Law 25 where applicable.
2) What We Collect
Account & Authentication
- When you sign in with Google, we receive your name, email address, and basic profile information (such as your profile picture and Google account ID) to create and secure your account.
- Session cookies for authentication (HTTP-only, secure).
Connected Google Services (optional)
- Google Calendar: if you grant access, we list calendars, read busy times, and create, update, or cancel appointment events through the scheduling features and approval rules you enable.
- Gmail: if you grant access, we search and read relevant messages, send or reply to messages you ask H2AI to handle, and apply or remove mailbox labels for workflows you enable.
- Access tokens are stored only to keep the feature working and can be revoked by you at any time (see Sections 5 and 9).
Content You Provide
- Uploads (images, PDFs, docs), pasted text, and any dataset metadata.
- Extracted JSON (schema.org-aligned where applicable).
- Visibility/ACL settings and PII flags for fields/columns.
Voice & Call Data (where enabled)
- If you use AI call features (inbound/outbound), we may process call audio, transcripts, caller details, and call outcomes to deliver, summarize, and log the interaction. You are responsible for any call-recording notices required in your jurisdiction.
Usage & Telemetry
- Basic device/browser data, event logs (e.g., upload started/succeeded, visibility tree saved), API usage and rate-limit events.
- Error reports and performance metrics.
Payments
- Via Stripe and/or Square: customer ID, status, plan, invoices. We do not store card numbers.
Communications
- Support emails or in-app messages.
- Transactional emails (sign-in, plan changes, receipts).
MCP/Developer Interfaces
- JSON-RPC requests/responses and associated logs for allowed tools.
3) Sources of Data
- Directly from you (account, files, text, settings).
- Automatically via our app (telemetry, logs, cookies).
- From services you connect, with your authorization (e.g., Google for sign-in, Calendar, and Gmail; Meta for social; Stripe/Square for billing).
- Third parties acting as processors (e.g., OpenAI and Anthropic for AI processing, Stripe/Square for billing).
4) How We Use Data
- Provide the service: process documents to structured JSON; host datasets; serve public endpoints/QR; run AI assistants; power API/MCP access and connected-service features you enable.
- Safety & moderation: run PII checks and risk flags (advisory only).
- Improve reliability: troubleshoot, prevent abuse, secure accounts.
- Billing & account: manage subscriptions, send receipts, notify about plan or policy changes.
- Legal compliance: tax records, fraud prevention, regulatory requests.
Legal bases (GDPR where applicable): performance of contract, legitimate interests (security, debugging), consent (marketing, optional features, connected services), legal obligations.
5) Google User Data & Limited Use
Limited Use disclosure. H2AI’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
When you choose to sign in with Google or connect a Google service, we request only these scopes:
- Sign-in (
openid,email,profile): to authenticate you and create your account. - Calendar (
calendar.events,calendar.calendarlist.readonly): to list the calendars you can use, read busy times, and create, update, or cancel appointments that you ask H2AI to manage. Calendar changes are limited to the scheduling features you enable and remain subject to the approval rules in your workspace. - Gmail (
gmail.modify): to search and read relevant messages, send or reply to messages you ask H2AI to handle, and apply or remove mailbox labels for the email workflows you enable.
For Google user data specifically, we affirm that we:
- use it only to provide and improve the user-facing features described above;
- do not use it for advertising;
- do not sell it, and do not transfer it to others except as needed to provide the feature, to comply with law, or as part of a merger/acquisition with notice, consistent with the Limited Use requirements;
- do not use it to train, fine-tune, or develop generalized/AI/ML models; and
- do not allow humans to read it, except with your consent, for security or to comply with law, or where the data has been aggregated and anonymized.
You can revoke H2AI’s access at any time at myaccount.google.com/permissions or by disconnecting the service in your H2AI settings. Revoking access stops future syncing; previously synced data is removed on request (see Section 9).
6) Sharing & Disclosures
We don’t sell personal information. We share it only with:
Service providers / subprocessors (bound by contract):
- OpenAI and Anthropic (AI processing of your content upon your request)
- Stripe and Square (payments, invoices)
- Cloudinary (image/file/object storage and media delivery)
- Managed PostgreSQL provider (application database)
- Render (application hosting/runtime)
- ElevenLabs (conversational voice / AI call features, where enabled)
- Email/SMTP provider (transactional email delivery)
Services you connect (acting on your behalf):
- Google (sign-in, and Calendar/Gmail if you connect them — see Section 5)
- Meta / Instagram (only if you link social accounts for posting)
- Legal & safety: if required by law, court order, or to protect rights, property, safety, or prevent fraud/abuse.
- Public by your choice: when you set datasets or profile fields to Public, those fields are available at public endpoints, embeddable, QR-scannable, and accessible by agents or crawlers. We cannot control third-party caching or re-use.
7) International Transfers
Your data may be stored/processed in Canada, the U.S., or other countries where our providers operate. We use contractual safeguards (e.g., Standard Contractual Clauses) where required.
8) Data Retention
- Account & datasets: kept until you delete them or your account is closed.
- Connected-service data (e.g., Google Calendar/Gmail): held only while the connection is active and refreshed on access; deleted when you disconnect or on request.
- Public caches: third-party caches (search engines, bots) are outside our control.
- Logs/telemetry: typically up to 90 days (longer if needed for security, billing, or legal reasons).
- Billing/tax records: retained as legally required (often 6–7 years).
9) Security
Encryption in transit (HTTPS) and at rest for stored data. Access controls, least-privilege principles, audit logging, rate limiting. OAuth tokens for connected services are stored securely and used only to deliver the features you enabled. Regular dependency updates and vulnerability management. No method is 100% secure, but we work to protect your data.
10) Your Choices & Rights
Depending on where you live, you may have rights to:
- Access, correct, or delete your personal information.
- Port your data (machine-readable export).
- Object to or restrict certain processing.
- Withdraw consent (e.g., marketing) and disconnect any connected service.
- Lodge a complaint with your local authority (e.g., OPC in Canada, EU supervisory authority).
Requests: hello@human2ai.ca. We may verify your identity before acting.
11) Cookies & Similar Tech
Essential cookies: session/auth, CSRF, load balancing. Preferences/analytics (if enabled): to improve UX; we’ll disclose and get consent where required. You can manage cookies in your browser; blocking essential cookies may break sign-in.
12) AI Processing & Model Providers
We process your content through AI services (including OpenAI and Anthropic) to extract structure and run assistants. Training: We do not sell your content. We do not use customer content — and never use Google user data — to train foundation models or our own models. Where third-party providers offer a “no training” setting, we enable it.
AI outputs can be wrong or incomplete. Always review before publishing.
13) Children
H2AI is not for children under 13 and not directed to minors. Do not create accounts for children or upload children’s personal data without proper legal basis and consent.
14) Changes to this Policy
If we make material changes, we’ll notify you in-app or by email and update the “Last updated” date.
15) Contact
SYSTEMshift AI Strategy Inc.
Email: hello@human2ai.ca
Jurisdiction: Ontario, Canada