Human of One Labs

Privacy

What we store, what we never see, who else touches it, and the one thing on this page that will surprise you.

Who we are

Human of One Labs, Inc. operates the HumanOfOne MCP server at humanofonelabs.com. We are the controller of the data described here.

A commissioned question is not private

Read this before you ask anything. Commissioning a question adds it, and the rating derived from it, to a corpus that every subscriber reads and that is published on the wiki. That is deliberate: it is why a question someone has already asked costs nothing to read, and why the library gets better as it is used.

It also means the text of your question is not confidential. Do not put anything into a question that you would not publish — no personal details, no patient information, no unreleased product names, nothing under an NDA. We do not attach your name or account to a published question, but the question itself is visible.

What we store

Only what the service needs to work:

  • Your email address, when you subscribe or write to us.
  • Your subscription — plan, status, monthly allowance, billing period, and the Stripe customer and subscription identifiers.
  • The questions you commission — the question, outcome and scope, and whether the job succeeded. See above.
  • Anything you type into the contact form, with the address you gave.
  • Your answer, if we ask why you are leaving. On the pricing and connect pages we sometimes ask one question of a visitor who is about to go, and follow it up once or twice if they answer. What you type is kept; nothing identifying is kept with it — no name, no address, no account, no IP. It cannot be joined to anything else on this list, including by us.
  • Access tokens, as hashes only. We store a one-way hash, never the token. We cannot recover or show you a token after it is issued — if one is lost, it has to be reissued.
  • Connected client registrations — the name and redirect address of an application you authorise over OAuth.

What we never see

Card details never reach this server. Payment happens on a page hosted by Stripe; what comes back to us is a customer identifier and a subscription status. We could not show you your own card number if you asked.

There are no cookies, no analytics, no advertising pixels and no third-party scripts anywhere on this site. Nothing follows you between pages. Two things are kept in your browser — whether you chose the light or dark theme, and whether you have already been asked the question above, so that you are not asked it twice. Neither ever leaves your machine.

Your IP address is held in memory for a few minutes to rate-limit the contact form and that question. It is not written to the database, never stored beside anything you wrote, and not used for anything else.

Who else processes it

WhoWhat they get
Fly.ioHosting and the database. All of the above.
StripeYour email, and the card details you give them directly.
AnthropicThe text of a commissioned question and the studies retrieved for it, to assess them. Also your answer to the question above, to write the follow-up — with nothing identifying attached.
ElicitThe text of a commissioned question, to search the literature.

We do not sell anything to anyone, and we do not share your data with anyone not on this list.

Where it lives

The service runs in Los Angeles, California, on Fly.io. Your data stays in the United States. Stripe, Anthropic and Elicit each operate their own infrastructure and may process what they receive elsewhere.

How long we keep it

Account and subscription records last as long as the account, and for seven years after it closes where tax law requires it. Contact-form messages are kept until they are dealt with and then for up to two years. Answers to the question on the pricing and connect pages are kept for up to two years, and there is nothing in them to identify afterwards. Tokens die when they expire or are revoked. A published question and its rating stay in the corpus — removing one would break the ratings that cite it.

What you can ask us to do

You can ask for a copy of what we hold on you, ask us to correct it, or ask us to delete it and close your account. Depending on where you live you may also have the right to object to processing or to complain to a regulator. Ask through the contact form and we will answer within 30 days.

Deletion covers your account, subscription and messages. It cannot cover a question already published in the corpus, for the reason above — which is why the warning is at the top of this page rather than the bottom.

Security

Everything is served over TLS. Tokens are stored as hashes. Connecting an application uses OAuth 2.1 with PKCE, so no key is ever pasted into a configuration file. Credentials are held in the host’s secret store, not in our code.

Children

The service is sold to businesses and professionals and is not intended for anyone under 18. We do not knowingly collect anything from a child.

Changes

If we change this page in a way that matters, we will say so here and date it. Continuing to use the service after that means accepting the change.

Contact

Anything on this page goes through the contact form.

Last updated 27 August 2026.