1. Our Commitment
ThesisHuman is committed to protecting the privacy and rights of individuals in the European Union and European Economic Area in accordance with the General Data Protection Regulation (GDPR).
2. Data Controller
ThesisHuman acts as the data controller for personal data collected through our platform. For all data protection inquiries, contact our team at support@thesishuman.com.
3. Lawful Basis for Processing
We process personal data under the following legal bases:
- Contract performance: Processing your account data and subscription is necessary to deliver the services you have purchased.
- Legitimate interest: Anonymized analytics help us improve the platform without impacting your privacy.
- Consent: Marketing communications are sent only with your explicit opt-in consent.
4. Data We Collect
- Identity data: Name, email address
- Authentication data: OAuth tokens
- Subscription data: Plan type, billing cycle, word usage
- Technical data: Anonymized browser type, session analytics
5. How We Store Your Documents
Your documents are stored securely in your account so you can access them from your dashboard. When you humanize or generate text through ThesisHuman, the document is saved to your account. It is private to you, protected by encryption in transit and database row-level security, and is never sold or shared with third parties. You can delete any document, or your entire account, at any time (see your GDPR rights and our retention policy below).
We never use your text to train, or improve any AI models, public or private. Your intellectual property remains exclusively yours.
6. Your Rights Under GDPR
As an EU/EEA resident, you have the right to:
- Access: Request a copy of the personal data we hold about you
- Rectification: Request correction of inaccurate or incomplete data
- Erasure: Request deletion of your personal data (“right to be forgotten”)
- Restriction: Request that we limit how we process your data
- Portability: Receive your data in a structured, machine-readable format
- Objection: Object to processing based on legitimate interest
- Withdraw consent: Withdraw previously given consent at any time
To exercise any of these rights, email us at support@thesishuman.com. We will respond within 30 days.
7. Data Transfers
Our infrastructure providers may process data outside the EU/EEA. All providers maintain adequate safeguards including Standard Contractual Clauses (SCCs) and SOC 2 compliance.
8. Data Retention
We retain account data for as long as your account is active. Upon account deletion, all personal data is permanently removed within 30 days. Anonymized analytics data may be retained indefinitely as it cannot be linked back to any individual.
9. Data Breach Notification
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and affected individuals without undue delay.
10. Contact Our Data Protection Team
For any GDPR-related requests, concerns, or complaints, please contact us at support@thesishuman.com.