Draft for legal review

This is a plain-English draft for the Human Made pilot. A lawyer has not reviewed it yet, and it may change before the final version.

Privacy Policy

What personal data Human Made collects, why, who sees it, how long we keep it, and how to get a copy or delete it.

Version 2026-10-02. Last updated 2 October 2026. Human Made, operated by Kyle Yeoman.

1. Who we are

Human Made is run by Human Made, operated by Kyle Yeoman, an individual, until a company is formed to run it. We decide how the personal data in this policy is used. Contact us at kylepyeoman@gmail.com.

This policy covers the Human Made website and app. When a brand receives a designer's contact details through Human Made, that brand is responsible for its own use of them, and we handle that data for the brand under our Data Processing Agreement.

2. What we collect

WhatDetails
AccountYour name, email address, whether you verified it, and your account status. Your password is stored only as a one-way hash, never as the password itself.
Sign-in and securityTwo-factor secrets (encrypted), recovery codes (hashed), and for each session your IP address, browser and device, rough location (city and country, from our host's network), and sign-in and last-active times. Failed sign-ins are counted against a hash of your email or IP address.
Designer profileDisplay name, designer code, country, portfolio link, and counts of your work across brands (submitted, approved, live, top 10 finishes, brands worked with).
Payee detailsLegal name, country and a payment contact email. No bank details.
Briefs you acceptYour name and contact email at the time, the version of the brief's terms, and when, from which IP address and browser you accepted.
Your workSubmitted files, file names, your notes, the product and angle, status history, feedback, statements and earnings, and questions you raise about a statement. Images are re-saved when uploaded, which removes hidden data such as camera details and location.
Brand team membersName, email, role, invitations, and what you do in the brand's workspace.
Brand access requestsName, work email, company, website, job title, rough monthly ad spend, statics needed per month, your note, and part of your IP address.
Policies you acceptWhich version of each policy you accepted, when, and from which IP address.
EmailYour email preferences, and a record of each email we send: the kind of email and whether it was delivered, with a hash of the address instead of the address.
Reports and requestsReports you file about a brief or brand, and your data export and deletion requests.
Audit logWho did what and when, with IP address and browser. It shows you your own security events.
Error logsTechnical errors, with email addresses, passwords, tokens and sign-in links removed before they are stored.

We do not collect payment card or bank details, and we do not buy data about you from anyone.

3. Why we use it

  • To run your account and sign you in, because you asked us to (our agreement with you).
  • To connect designers and brands, and track briefs, submissions, reviews and what brands owe designers (our agreement with you, and with brands).
  • To keep Human Made and its users secure: two-factor sign-in, bot checks, rate limits, the audit log and fraud and abuse checks (our legitimate interest in a safe service).
  • To send emails you need: sign-in links, security alerts, invites and work updates. You can turn off work notifications in Account, then Notifications. Security emails cannot be turned off.
  • To meet our legal duties, such as keeping records and answering lawful requests.

We do not sell personal data, we do not use it for advertising, and we do not track you across other websites.

4. Who sees your data

  • Brands see a designer's display name and designer code, and the counts of their work across brands, but never which other brands they worked with.
  • When you accept a brand's brief, that brand sees your name and contact email.
  • When a brand finalizes a statement for you, its Owners, Admins and Finance members see your payee details.
  • If a brand shows its leaderboard to designers, other designers can see your live ads on it, each ad's rank and your display name. Never any money.
  • People on a brand's team see each other's names, emails and roles.
  • The operator can see data to run and support Human Made. Looking inside a brand's workspace needs a written reason, lasts at most 60 minutes and is recorded in that brand's audit log.
  • Our service providers, listed in section 5, handle data for us.
  • We share data when the law requires it, or to protect people from harm or fraud.

If a company is formed to run Human Made, your data moves to it and this policy still applies. We will tell you.

5. Service providers

ServiceWhat it does for Human MadeWhat it handles
Vercel Inc.Hosts the website and app, runs the server code, and stores uploaded files (Vercel Blob).Everything the app shows or stores passes through it, including uploaded files, and request logs with IP addresses.
Neon (Postgres database)Stores the database: accounts, briefs, submissions, statements, logs, and its backups.All account and workspace records.
Google LLC (Gmail)Sends account, security and work emails during the pilot, from a Human Made Gmail account.Recipient name and email address, and the email's content, which can include sign-in links.
Cloudflare, Inc. (Turnstile)Checks that a person, not a bot, is signing up, requesting brand access, resetting a password, or signing in after failed tries.IP address and browser signals during the check.

When you choose a new password, we check it against a public list of breached passwords (Have I Been Pwned). Only the first 5 characters of a one-way hash of the password leave our servers, never the password or your email.

These providers are based in the United States and may process data there and in other countries.

6. How long we keep it

During the pilot we delete data by hand. Nothing below is removed on a timer yet. When automatic clean-up starts, we will add its time limits to this policy, and you will see what changed the next time you sign in.

DataHow long
Your account and profileWhile your account is open. When you ask us to delete your account, you have 7 days to cancel. After that we remove your name, email and sign-in data by hand, within 30 days of your request, and show you as "Former designer" with your code.
Submissions never approvedDeleted when we delete your account.
Approved and live workKept by the brands you licensed it to, under the brief's terms, shown as "Former designer" with your code after you delete your account.
Finalized statements and payee details on them7 years, for tax and accounting records.
Sessions and sign-in recordsWhile your account is open. Deleted when we delete your account.
Audit logKept as a security record, with IP addresses.
Error logs and failed sign-in countersUntil we delete them by hand. Error logs have email addresses, passwords, tokens and sign-in links removed before they are stored, and the counters hold only a hash of an email or IP address.
Brand access requestsKept as the record of how a brand joined. If we decline a request, we delete it when you ask.
Brand workspacesUntil the brand closes. After a 30-day grace period we delete the brand's content by hand, within 30 days, and keep finalized statements.
BackupsDeleted data can remain in backups until they expire.

7. Your choices and rights

  • Get a copy of your data: Account, then Privacy, then Download my data. During the pilot we prepare the file by hand and email you when it is ready, within 30 days.
  • Delete your account: Account, then Privacy, then Delete my account. You have 7 days to cancel. After that we delete it by hand, within 30 days of your request.
  • Correct your data: change your name and profile in Account, and your email or password in Account, then Security.
  • Choose your emails: Account, then Notifications, or the unsubscribe link in any work email.
  • Ask us anything else, such as to stop or limit a use of your data: write to kylepyeoman@gmail.com.

We answer every request within 30 days and may need to confirm it is you. Depending on where you live, you may have more rights, and you can complain to your local data protection authority.

For contact details a brand received when you accepted its brief, you can also ask that brand directly. We will help it answer.

8. Cookies

We use only cookies that Human Made needs to work and stay secure. We use no analytics, advertising or tracking cookies, so there is no cookie banner.

CookieWhat it doesHow long
__Host-hm_sessionKeeps you signed in.Until you sign out or the session ends: up to 30 days for designers, 12 hours for brand and operator accounts.
__Host-hm_mfaHolds the two-factor step between your password and your code.10 minutes.
__Host-hm_inviteRemembers a team invite while you sign in or create an account.30 minutes.
__Host-hm_signupTies your email verification to the browser you signed up in.24 hours.
__Host-hm_wsRemembers the last workspace you opened.1 year.

When a bot check appears, Cloudflare Turnstile runs it in a frame from Cloudflare. It is used only for the check, not for tracking.

9. Security

We protect your data with encryption in transit, two-factor sign-in, separation of every brand's data in the database, and an audit log. Our Security page has more, and how to report a problem.

10. Children

Human Made is for people aged 18 and over. We do not knowingly collect data from anyone younger. If you think we have, write to kylepyeoman@gmail.com and we will delete it.

11. Changes to this policy

When we change this policy, you will see a short summary of what changed the next time you sign in, and you accept the new version before you go on.

12. Contact

Questions or requests about your data: kylepyeoman@gmail.com.