HumanGate — Privacy Policy

NOTE
    This is a template. Review it with legal counsel and adapt it to your
    jurisdiction (GDPR, 152-FZ, etc.) and your actual deployment before relying
    on it in production.

WHO WE ARE
    HumanGate is a CAPTCHA verification gateway operated by the service that
    integrated it. It shows a verification challenge and reports the result
    (passed / failed) to that service. The integrating service is the data
    controller; HumanGate acts as a processor on its behalf.

WHAT WE COLLECT
    When you open a verification page we process:
      - IP address and a keyed hash of it (always stored)
      - User-agent string (always stored)
      - Device & display signals reported by your browser: screen and viewport
        size, device pixel ratio, color depth, platform, hardware concurrency,
        device memory, touch support, language(s), timezone, cookies-enabled
      - Network signals from the browser's Network Information API: estimated
        connection speed (downlink Mbps), effective type (e.g. 4g), round-trip
        time, and the data-saver flag
      - Page performance/timing signals: time to first byte, DOM-content-loaded
        and load times, transfer size, time to start the challenge
      - Anti-bot signals: canvas/WebGL fingerprint, headless markers
      - Interaction/timing of the challenge (duration, pointer/keyboard/focus
        counts) and the computed risk score
      - Approximate network data derived from the IP (country, ASN)
      - For Telegram Mini Apps: the signed initData (validated server-side to
        confirm the Telegram user; not used for advertising)
    We do NOT collect your name, email, password, message content, or the
    answer you type beyond what is needed to verify the challenge.

    The IP, user-agent and the device/network/timing signals above are returned
    to the integrating service together with the verification result, so it can
    make its own anti-fraud decision.

WHY WE PROCESS IT
    Solely to tell humans and automated bots apart, prevent spam and abuse,
    and protect the integrating service. This is a legitimate-interest /
    security purpose. Signals are not used for profiling or advertising.

THIRD-PARTY CAPTCHA PROVIDERS
    Depending on the configured provider, the verification widget may load
    code from and send the challenge token to:
      - Cloudflare Turnstile (challenges.cloudflare.com)
      - Google reCAPTCHA (www.google.com/recaptcha)
      - Yandex SmartCaptcha (smartcaptcha.cloud.yandex.ru)
    Those providers process the request under their own privacy policies.
    HumanGate-native captchas (image, proof-of-work, fingerprint) send no data
    to third parties.

RETENTION
    Verification records and signals are kept only as long as needed for abuse
    prevention and audit, then deleted or anonymized. Raw IP storage can be
    disabled per challenge (then only the hash is kept).

YOUR RIGHTS
    Subject to applicable law you may request access, correction, deletion, or
    restriction of your data. Direct such requests to the integrating service
    (the data controller), which will coordinate with HumanGate as processor.

CONTACT
    Through the service that presented this verification.

See also: Personal Data Processing Policy · home