HumanRank legal alpha
Privacy
This policy explains how HumanRank handles public editorial data, cohorts, product analytics, and opt-in ranking data. It is not legal advice and should be reviewed by counsel before the product scales.
Operating Principle
HumanRank does not use ranking for credit, employment, housing, insurance, government eligibility, law enforcement or automated decisions with legal effect. The site is editorial, versioned and correctable.
Data We Handle
- Editorial profiles of living public figures: name, public role, country or region, public sources, editorial score, confidence, uncertainty, model and corrections.
- Cohort estimates without a public name: base city, age band, and declared gender used to estimate an aggregate position. We do not describe them as anonymous while a session or account can still link them.
- Opt-in identity and profile: Firebase Auth and the login provider handle UID and email and may provide a name or photo. Firestore stores UID, basic profile, timestamps, consent, and voluntary evidence; editorial forms may store an email the person enters.
- Opt-in personal ranking: non-protected responses, binned protected attributes in a separate database, test results, peer feedback, comparisons, ratings, and attributable score derivatives. Ratings and comparisons are pseudonymous, not anonymous. Protected attributes are not inputs to the served score.
- Feedback invitations: Firestore stores an HMAC of the recipient email, token, and state. The token becomes invalid after 14 days and the document becomes eligible for asynchronous TTL deletion. The raw address, requester name, and requested domain are sent to Resend to deliver the email. After erasure, an HMAC without the raw address may remain to block future invitations until fresh consent.
- Opt-in weekly digest: when the private runner is enabled, Firebase Auth will resolve the email only for sending and Resend will receive the message. Firestore will retain a UID hash, week, and technical delivery state to prevent duplicates; that outbox is erased with ranking data and becomes TTL-eligible after 120 days.
- Pseudonymous first-party analytics: a random session ID, minimized paths/referrers, source, locale, age band, gender, place, selected signals and, depending on the event, score, rank, or confidence. Events become eligible for TTL deletion after 90 days and do not include Firebase UID as a field.
- Model feedback: votes on weights, optional rationale, language, optional website and timestamp.
- Editorial requests: name, email, source, detail and request type when someone asks for correction, claim, source addition or appeal.
How We Use Data
- Display editorial rankings with sources, uncertainty and model version.
- Enable claims, corrections, appeals and profile improvement.
- Store revocable consent and claim traceability in Firestore.
- Audit the model, investigate abuse, deduplicate claims and improve source quality.
- Measure product funnels, reliability, and usage with minimized first-party analytics. Browser requests with DNT=1 or Sec-GPC=1 do not receive new server-side funnel events.
- Publish aggregates or statistics that do not identify private people.
Sharing and Selling Data
We do not sell personal data. We use Google Cloud, Firebase, Firestore, BigQuery and Cloud Run to operate and analyze the service. Resend receives only the addresses and content needed for transactional email. We do not share this data for behavioral advertising or data partnerships; this policy must change before that use changes.
Your Choices and Rights
- Anyone can request a correction, additional source, appeal or claim through the editorial form.
- An authenticated person can request access, rectification, export, unpublishing, or deletion of their opt-in data.
- From /me, withdrawing compute-my-score blocks the score and publications in the accepted transaction and starts durable deletion of responses, protected attributes, social signals, and attributable derivatives in Firestore and BigQuery. Status remains in progress until verification completes.
- That control erases ranking data linked by UID and the currently verified email; it does not delete Firebase Auth or the basic profile. For historical aliases, logs, backups, provider records, or full account deletion, email apps@brainystack.co.
- Session events without a UID that are no longer reasonably linkable to an account become eligible for TTL deletion after 90 days and are outside the UID cascade. Aggregate parameters in already published models may remain without individual attribution; attributable source rows are deleted, but we do not promise to untrain every historical release.
- An email claimed by the provider immediately before withdrawal may remain in flight. Withdrawal removes pending tokens it can discover but does not erase records already retained by the provider.
- Voluntary evidence can be revoked. If evidence affects score, the change may enter an editorial queue and remain versioned.
- Public figures can dispute factuality, source, context, uncertainty and editorial category.
- For privacy requests, email apps@brainystack.co from the email tied to the claim or include sufficient identity evidence.
Retention and Security
Issued pairs become invalid after 10 minutes, invitations after 14 days, first-party analytics becomes TTL-eligible after 90 days, and the pseudonymous digest outbox after 120 days. Physical TTL deletion is asynchronous and may occur after logical expiry. On ranking withdrawal, the score and its publications are blocked in the accepted transaction; a private job cuts protected storage, deletes sources, and verifies Firestore and BigQuery before marking the request complete. The basic profile, pseudonymous anti-resurrection fences, and technical or audit records may remain under separate schedules. Backups, logs, providers, and legal obligations may also follow their own schedules.
Public Data and Public People
A source being public does not make every use fair or correct. HumanRank limits named profiles to living public figures with verifiable evidence, shows sources and accepts corrections. Private people are not published by name unless they opt in to claim; cohort or session data remains described as pseudonymous while it can be linked.