Privacy Policy
What we collect, why we collect it, and the control you have over it.
Last updated September 6, 2026
Overview
Act More Human — a trading name of Fritter Factory Innovation Labs Inc. ("we," "us," or "our") — publishes free guides and prompt templates that help you make AI assistants sound more natural, sells software that builds a writing voice from your own writing, and offers paid consultation services. This policy explains what personal information we handle when you use actmorehuman.com, why we handle it, and the choices you have.
Two commitments run through everything below. Your writing is used to build your voice and nothing else. And nothing you give us is used to train an AI model, ours or anyone else's.
We keep data collection to what the product actually needs. Where the law requires your consent — non-essential cookies and analytics — we ask for it through a banner before those tools load, and you can change your mind at any time from the Cookie preferences link in the footer. There is no advertising on this site at all.
Information we collect
Your account
If you create an account, we store your email address and, when you sign in with Google, the name and profile picture Google returns. We store a record of sign-ins, of grants you give to AI assistants, and of API keys you create, so you can see and revoke them.
The writing you give us
To build a voice we need writing that is genuinely yours. You choose where it comes from: connecting Gmail so we can read your sent mail, pasting text, uploading a file (.mbox, .eml, .txt, or a Google Takeout archive), or pointing us at a website to crawl.
We do not keep the raw material. Message and document text lives only for as long as the build job runs, and is deleted when the job ends. An hourly sweep deletes anything a failed job left behind. What survives is the voice itself: the description of how you write, and the short evidence quotes that show why each observation was made. You can see every quote and remove any of them.
We also store the exclusions you set — the recipients or domains you mark as personal — as opaque identifiers rather than as addresses, so the list works without us holding a copy of your contacts.
Your requests and messages
When you book a consultation, request custom help, send feedback, or contact us, you may provide your name, email address, and the details of your request. When you pay, our payment processor collects your payment details; we never see or store full card numbers.
Whatever you give us should be true and current. If your email address changes, update it — it is how we reach you about a build, a receipt, or a security matter.
Information collected automatically
When you browse the site, analytics and error-monitoring tools may record usage data — pages viewed, referring links, approximate location derived from your IP address rather than stored as a precise location, device and browser type, and interactions. The exact tools and what each collects are listed under Cookies and analytics. We also log usage of the API and the Connector — which tool was called, by which client, whether it succeeded, and how long it took — so you can audit what an AI assistant did on your behalf.
Google user data
If you connect Gmail, we request one restricted scope, gmail.readonly, because it is the only scope that returns message bodies. We read your sent mail. We do not read your inbox beyond what that scope returns, and we never send, modify, or delete anything.
Act More Human's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In practice that means all of the following.
- Your Gmail data is used only to build your voice. It builds nobody else's.
- It is never used to train, fine-tune, or improve any AI or machine learning model, ours or a third party's.
- It is never used for advertising, and never sold or transferred for advertising.
- No human at Act More Human reads it. The only exceptions are the ones Google's policy allows: with your explicit consent, where necessary for security or to investigate abuse, or where the law requires it.
- The connection is temporary. Your Google refresh token is encrypted at rest with a key held outside the database, is used only for the duration of the build, and is then revoked at Google and deleted. To build again, you reconnect.
- The message text itself is deleted when the job ends, as described above. Only the voice and its evidence quotes remain.
You can disconnect at any time from your account page, or from your Google account permissions.
How we use your information
- To build, refine, and store the voice you asked for.
- To provide the guides, templates, and paid services you request.
- To let AI assistants you have authorized read your voice, and to show you what they did.
- To process payments and send related confirmations.
- To meter usage against your plan or credits, and to bill accurately.
- To respond to your questions, feedback, and support requests.
- To understand how the site is used so we can improve content and performance.
- To diagnose errors and keep the service secure and reliable.
Why we are allowed to
If you are in the EEA or the UK, the law requires us to name a legal basis for each thing we do with your data. Ours are these four.
| What we do | Legal basis |
|---|---|
| Build, store, refine, and serve your voice; run your account; take payment | Performance of a contract. You asked us for these things and we cannot deliver them otherwise. |
| Keep the service secure, prevent abuse, diagnose errors, understand how the site is used, and improve it | Legitimate interests. Running a service that works and is not abused. We weighed this against your privacy and limited what we collect accordingly. |
| Read your Gmail to build a voice; load non-essential cookies and analytics; send you marketing email | Consent. Each is asked for separately, and each can be withdrawn. |
| Keep billing records for seven years | Legal obligation. Tax law requires it. |
You can withdraw consent at any time — disconnect Google from your account page, change your cookie choice from the Preferences link in the footer, or unsubscribe from any marketing email. Withdrawing does not make what we did beforehand unlawful, and it does not affect anything we process on one of the other three bases.
AI providers and training
Building a voice means sending your writing to a large language model. We use Anthropic. Under our organization's settings, Anthropic retains prompts for 30 days for abuse monitoring and then deletes them, and does not use them to train its models.
We do not train models either. We do not build a general model from customer writing, we do not pool one customer's writing with another's, and we do not use your writing to improve anything beyond your own voice.
Do Not Track and Global Privacy Control
There is no advertising on this site. No ad tags load, no advertising cookies are set, and nothing you give us to build a voice is ever used for advertising. Google user data never is, under any circumstances.
Most browsers offer a Do Not Track setting. No common standard for honouring it was ever agreed, so like most services we do not respond to DNT signals. We do respond to the signal that replaced it: if your browser sends a Global Privacy Control signal, we treat it as a decision to decline non-essential cookies and analytics, and you are not asked again.
Payments and donations
Payments for subscriptions, one-off purchases, credit top-ups, and consultations are processed by Stripe. Donations are processed by Ko-fi. These providers handle your payment details under their own privacy policies; we receive confirmation and limited details, such as your name and email, needed to deliver the service and to keep tax records.
Who processes your data
We do not sell your personal information, and we do not share it in the sense California law gives that word — we have never disclosed anyone's data for cross-context behavioural advertising, and since there is no advertising here at all, we have no way to start.
We disclose personal information to the service providers below, who process it on our behalf under contract, and otherwise only when the law requires it or to protect our rights. Each provider receives only what it needs.
We have no affiliates and no business partners. Many privacy policies reserve the right to pass your data to a parent company, a joint venture, or a partner running a promotion. We have none of those, and this policy grants no such right.
If the business is sold. If we merge with another company, sell the business or its assets, raise financing, or go through an acquisition, customer data may transfer as part of that. If it does, we will tell you before it happens, and the buyer is bound by this policy until you are given notice of any change to it.
| Provider | What it does for us | What it can see |
|---|---|---|
| Supabase | Database, file storage, and background jobs | Everything we store: accounts, voices, evidence quotes, usage records |
| Anthropic | The AI models that build and use your voice | The writing sent for a build, and prompts at generation time. 30-day retention, no training |
| Vercel | Hosting and the functions that serve every request | Request metadata and anything in transit |
| Stripe | Payments, subscriptions, and invoices | Name, email, billing details, purchase history |
| Resend | Transactional email — sign-in links, receipts, alerts | Email address and message content |
| Sentry | Error and performance monitoring | Error reports with identifying fields scrubbed |
| PostHog | Product analytics | Usage events, with text masked in replays |
We will list new sub-processors here, and in the Data Processing Agreement, at least 30 days before they start handling your data. The DPA is published in full and is incorporated into a company-tier agreement automatically; a signed copy is available by emailing hello@actmorehuman.com.
Your privacy rights
Depending on where you live, you may have the right to access, correct, delete, or export your personal information; to object to or restrict certain processing; and to withdraw consent. If you are in the EEA or UK, you may also lodge a complaint with your data protection authority. If you are in California, you have the right to know, delete, and opt out of any "sale" or "sharing" of your data — we do not sell personal information.
Most of these you can exercise yourself from your account page: see your voices and every evidence quote in them, remove quotes, revoke a grant or an API key, disconnect Google, and delete your account. For anything else, use the data request form: it records what you asked for, gives you a reference number, and commits us to a date. Emailing hello@actmorehuman.com works exactly the same way, it just leaves you nothing to quote back at us. For analytics, see the opt-out options under Cookies and analytics.
How long we keep things
Rather than a general statement, here is the actual schedule, column by column.
| What | How long | Deleted by |
|---|---|---|
| Message and document text gathered for a build | The life of the job | The worker at job end, plus an hourly sweep |
| Files you upload | The life of the job | The same sweep, removed from storage |
| Your Google refresh token | The life of the job | Revoked at Google and deleted at job end |
| Voices, versions, and evidence quotes | Until you delete them | You, or account deletion |
| Exclusions you set | Until you delete them | You, or account deletion |
| Drift reports | Until you delete them | You, or account deletion |
| Build job records — status, stage, counts, error codes | 90 days after the job finishes | Automatic sweep |
| API and Connector call logs | 180 days | Automatic sweep |
| Billing and usage records | 7 years, as tax law requires | Never deleted, but detached from you: your account identifier is removed at deletion. These records hold counts and amounts, never your text |
| Payment records at Stripe | Stripe's own schedule | Stripe |
| Prompts sent to Anthropic | 30 days | Anthropic |
One honest caveat about every row above: encrypted database backups roll on their own schedule and cannot be edited. Something deleted from the live database may persist in a backup for a short period, isolated from any further processing, until that backup expires.
Deleting your account
You can delete your account from your account page. When you do, three things happen at once: every grant you gave an AI assistant is revoked, every API key stops working, and any Google connection is revoked at Google.
The account itself is then held for 30 days and deleted permanently after that. During those 30 days you can undo the deletion by signing in again — nothing is lost. After 30 days, your voices, versions, evidence quotes, exclusions, and drift reports are gone and cannot be recovered.
The 30-day window applies to the account, not to your raw writing. Mail and documents gathered for a build are deleted when the build ends, whatever else you do.
What survives deletion is the billing record required by tax law, with your account identifier removed. It contains amounts and dates, never your writing.
Security
Traffic is encrypted in transit. Data is encrypted at rest. OAuth tokens are encrypted before they are stored, and the Google refresh token is encrypted again with a separate key that is never kept in the database. API keys are hashed, so we cannot read them back — the raw key is shown once, at creation.
Every table enforces row-level security, and the application connects with a database role that cannot bypass it, so one account's rows are not reachable from another account's session.
No method of transmission or storage is completely secure. If you find a vulnerability, please tell us: our contact and disclosure preference are published at /.well-known/security.txt.
International transfers
Our service providers may process data in countries other than yours, including the United States. Where required, these transfers rely on appropriate safeguards such as standard contractual clauses.
Children's privacy
You must be at least 16 to use the service. It is not directed to anyone younger, we do not knowingly collect their personal information, and we never sell it. If we learn that an account belongs to someone under 16, we delete the account and the data behind it. If you believe a child has given us data, email hello@actmorehuman.com and we will remove it.
Changes to this policy
We may update this policy as the product evolves or the law changes. When we do, we will revise the "Last updated" date above and, for significant changes, provide a more prominent notice.
Contact us
Questions about this policy or your data? Email hello@actmorehuman.com. Security reports go to security@actmorehuman.com.
By post, and for anything a regulator needs to send us:
Fritter Factory Innovation Labs Inc.1 Stan MacPherson Way, Unit 303
Charlottetown, PE C1A 0B4
Canada
German readers: the provider identification required by § 5 DDG is on the Impressum.
Signing in with Google
If you sign in with Google rather than an emailed link, Google returns your name, email address, and profile picture. We use them to create and identify your account, and for nothing else. We do not receive your contacts, your calendar, or anything you have made public on other Google services.
Signing in with Google is separate from connecting Gmail; you can do either without the other. We do not control how Google itself uses your data — their privacy policy covers that — and you can review or revoke what you have granted us on your Google account permissions page.