Home

Privacy Policy

Last updated 2026-09-20

xHuman is operated by Twin3 AI. It lets a person publish a Human ID: a page and a machine-readable record stating which accounts they control and how agents may contact them. This describes exactly what the service stores, why, and how to have it deleted.

What we store

DataWhy
Your Human ID, the profile URLs you link, the platform and handle, and the timestamps of when a link was first and last checked This is the Human ID itself — the public record the service exists to publish
A rendered image of your card So a link to your Human ID shows a preview when shared
Your in-progress session: the draft card, the accounts you connected, a wallet address if you supplied one, and the material proving you control the session So an unfinished Human ID survives a page reload

We do not store passwords. When you connect an account through that platform's own login, the access token is used to read the profile and media you authorised and is not kept.

The handoff between that login and this site — the profile and media just read — is held in memory for up to one hour and then discarded. It is not written to disk and does not survive a restart. Because it is keyed to the login attempt rather than to your Human ID, deleting your Human ID does not reach it; it expires on its own within the hour.

What is public

Your Human ID page and its machine-readable versions are public by design — that is the point of publishing an identity. They state that account control has been established. They do not claim that you are a person, and do not claim that you are unique; those remain explicitly not established, and no part of this service asserts otherwise.

Rights you declare

Where you declare terms for your content, those terms are published so that people and AI systems can read them. Publishing a term is not the same as enforcing it: we state what you have declared, and we do not represent that any third party is bound by it.

Deleting your data

You can have everything above deleted. It removes the Human ID record, the rendered card image, and the session data — not a flag marking them hidden. See https://xhuman.id/data-deletion.

If you withdraw an account connection at the platform you connected it from, the data we derived from it is deleted within 90 days.

Automatic cleanup status

Automatic cleanup is not enabled. The 90-day platform-withdrawal commitment remains in place, but the automated withdrawal-to-deletion path has not been verified end to end. Please use the deletion control or contact us for manual handling; do not assume that withdrawing access alone has completed deletion.

The planned lifecycle rules are separate: an unclaimed draft expires after 24 hours; a previously verified profile connection that is confirmed lost starts a 30-day observation period. A provider outage is not proof that a connection was withdrawn. Neither clock replaces the 90-day commitment.

Name reservation after deletion

New deletions create a private keyed-hash marker that reserves the erased Human ID name permanently against reassignment. The marker contains a deletion timestamp, not your profile, photo, resume, social links or wallet. It is not a backup of your card. Older markers require a separate retention migration. Name-only recovery is not yet enabled.

Who else sees it

The service runs on Google Cloud, which stores this data on our behalf. We do not sell it and do not share it with anyone else for their own purposes. Reading a public profile involves fetching pages and media from the platform you linked, which that platform can observe.

Contact

Email privacy@twin3.ai.

This page describes the service as implemented. If you find anything here that does not match what the service actually does, that is a defect and we want to know.