Draft for legal review
This is a plain-English draft for the Human Made pilot. A lawyer has not reviewed it yet, and it may change before the final version.
Privacy Policy
What personal data Human Made collects, why, who sees it, how long we keep it, and how to get a copy or delete it.
Version 2026-10-02. Last updated 2 October 2026. Human Made, operated by Kyle Yeoman.
1. Who we are
Human Made is run by Human Made, operated by Kyle Yeoman, an individual, until a company is formed to run it. We decide how the personal data in this policy is used. Contact us at kylepyeoman@gmail.com.
This policy covers the Human Made website and app. When a brand receives a designer's contact details through Human Made, that brand is responsible for its own use of them, and we handle that data for the brand under our Data Processing Agreement.
2. What we collect
| What | Details |
|---|---|
| Account | Your name, email address, whether you verified it, and your account status. Your password is stored only as a one-way hash, never as the password itself. |
| Sign-in and security | Two-factor secrets (encrypted), recovery codes (hashed), and for each session your IP address, browser and device, rough location (city and country, from our host's network), and sign-in and last-active times. Failed sign-ins are counted against a hash of your email or IP address. |
| Designer profile | Display name, designer code, country, portfolio link, and counts of your work across brands (submitted, approved, live, top 10 finishes, brands worked with). |
| Payee details | Legal name, country and a payment contact email. No bank details. |
| Briefs you accept | Your name and contact email at the time, the version of the brief's terms, and when, from which IP address and browser you accepted. |
| Your work | Submitted files, file names, your notes, the product and angle, status history, feedback, statements and earnings, and questions you raise about a statement. Images are re-saved when uploaded, which removes hidden data such as camera details and location. |
| Brand team members | Name, email, role, invitations, and what you do in the brand's workspace. |
| Brand access requests | Name, work email, company, website, job title, rough monthly ad spend, statics needed per month, your note, and part of your IP address. |
| Policies you accept | Which version of each policy you accepted, when, and from which IP address. |
| Your email preferences, and a record of each email we send: the kind of email and whether it was delivered, with a hash of the address instead of the address. | |
| Reports and requests | Reports you file about a brief or brand, and your data export and deletion requests. |
| Audit log | Who did what and when, with IP address and browser. It shows you your own security events. |
| Error logs | Technical errors, with email addresses, passwords, tokens and sign-in links removed before they are stored. |
We do not collect payment card or bank details, and we do not buy data about you from anyone.
3. Why we use it
- To run your account and sign you in, because you asked us to (our agreement with you).
- To connect designers and brands, and track briefs, submissions, reviews and what brands owe designers (our agreement with you, and with brands).
- To keep Human Made and its users secure: two-factor sign-in, bot checks, rate limits, the audit log and fraud and abuse checks (our legitimate interest in a safe service).
- To send emails you need: sign-in links, security alerts, invites and work updates. You can turn off work notifications in Account, then Notifications. Security emails cannot be turned off.
- To meet our legal duties, such as keeping records and answering lawful requests.
We do not sell personal data, we do not use it for advertising, and we do not track you across other websites.
5. Service providers
| Service | What it does for Human Made | What it handles |
|---|---|---|
| Vercel Inc. | Hosts the website and app, runs the server code, and stores uploaded files (Vercel Blob). | Everything the app shows or stores passes through it, including uploaded files, and request logs with IP addresses. |
| Neon (Postgres database) | Stores the database: accounts, briefs, submissions, statements, logs, and its backups. | All account and workspace records. |
| Google LLC (Gmail) | Sends account, security and work emails during the pilot, from a Human Made Gmail account. | Recipient name and email address, and the email's content, which can include sign-in links. |
| Cloudflare, Inc. (Turnstile) | Checks that a person, not a bot, is signing up, requesting brand access, resetting a password, or signing in after failed tries. | IP address and browser signals during the check. |
When you choose a new password, we check it against a public list of breached passwords (Have I Been Pwned). Only the first 5 characters of a one-way hash of the password leave our servers, never the password or your email.
These providers are based in the United States and may process data there and in other countries.
6. How long we keep it
During the pilot we delete data by hand. Nothing below is removed on a timer yet. When automatic clean-up starts, we will add its time limits to this policy, and you will see what changed the next time you sign in.
| Data | How long |
|---|---|
| Your account and profile | While your account is open. When you ask us to delete your account, you have 7 days to cancel. After that we remove your name, email and sign-in data by hand, within 30 days of your request, and show you as "Former designer" with your code. |
| Submissions never approved | Deleted when we delete your account. |
| Approved and live work | Kept by the brands you licensed it to, under the brief's terms, shown as "Former designer" with your code after you delete your account. |
| Finalized statements and payee details on them | 7 years, for tax and accounting records. |
| Sessions and sign-in records | While your account is open. Deleted when we delete your account. |
| Audit log | Kept as a security record, with IP addresses. |
| Error logs and failed sign-in counters | Until we delete them by hand. Error logs have email addresses, passwords, tokens and sign-in links removed before they are stored, and the counters hold only a hash of an email or IP address. |
| Brand access requests | Kept as the record of how a brand joined. If we decline a request, we delete it when you ask. |
| Brand workspaces | Until the brand closes. After a 30-day grace period we delete the brand's content by hand, within 30 days, and keep finalized statements. |
| Backups | Deleted data can remain in backups until they expire. |
7. Your choices and rights
- Get a copy of your data: Account, then Privacy, then Download my data. During the pilot we prepare the file by hand and email you when it is ready, within 30 days.
- Delete your account: Account, then Privacy, then Delete my account. You have 7 days to cancel. After that we delete it by hand, within 30 days of your request.
- Correct your data: change your name and profile in Account, and your email or password in Account, then Security.
- Choose your emails: Account, then Notifications, or the unsubscribe link in any work email.
- Ask us anything else, such as to stop or limit a use of your data: write to kylepyeoman@gmail.com.
We answer every request within 30 days and may need to confirm it is you. Depending on where you live, you may have more rights, and you can complain to your local data protection authority.
For contact details a brand received when you accepted its brief, you can also ask that brand directly. We will help it answer.
9. Security
We protect your data with encryption in transit, two-factor sign-in, separation of every brand's data in the database, and an audit log. Our Security page has more, and how to report a problem.
10. Children
Human Made is for people aged 18 and over. We do not knowingly collect data from anyone younger. If you think we have, write to kylepyeoman@gmail.com and we will delete it.
11. Changes to this policy
When we change this policy, you will see a short summary of what changed the next time you sign in, and you accept the new version before you go on.
12. Contact
Questions or requests about your data: kylepyeoman@gmail.com.