Privacy Policy

We practice what we preach.
Human-centered AI starts with human-centered data.

The Irony We Refuse to Accept

Here's the uncomfortable truth about most "privacy policies":

"We value your privacy" → followed by 47 paragraphs of legal jargon that essentially say "we'll do whatever benefits us most."

At LASTHUMAN Foundation, we find this ridiculous.

If we're fighting for a future where AI serves humanity — not exploits it — we can't exploit your data while preaching ethics.

This policy is different. We'll explain what we do, what we don't do, and why it matters — in plain language, without hiding behind legalese.

Last Updated: December 31, 2025 | Next Review: June 30, 2026

Why This Actually Matters

Every day, millions of people mindlessly click "I Accept" on privacy policies they'll never read. Why? Because:

  • They're written to confuse, not clarify
  • The real consequences are buried in subsection 7.4(b)(ii)
  • You need a law degree to understand your own rights

The result? Your data gets:

What Usually Happens

  • Sold to data brokers
  • Used to train AI without consent
  • Shared with "partners" (aka advertisers)
  • Stored indefinitely "just in case"
  • Profiled to manipulate your decisions

What We Actually Do

  • Never sold. Ever.
  • Never used for AI training
  • No "partners" get your data
  • Deleted when no longer needed
  • No profiling, no manipulation

Privacy isn't about hiding. It's about dignity, autonomy, and power. When your data is misused, you lose all three.

Our Three Privacy Principles

Our tagline isn't just marketing. It's our framework for everything — including how we handle your data:

For Humans

Meaning: Your data exists to serve you, not our analytics dashboard.

In practice: We collect the absolute minimum needed. No creepy tracking. No "we might need this someday" data hoarding.

Example: We don't track which article you read at 2 AM last Tuesday. We don't need to know that to support our mission.

With Humans

Meaning: Complete transparency. No hidden trackers, no "legitimate interest" loopholes.

In practice: This policy is written in plain language. We explain not just what we do, but why.

Example: When we use cookies, we tell you exactly which ones and let you decide. No forced consent.

Around Humans

Meaning: We protect your data the way we'd want ours protected if roles were reversed.

In practice: Strong encryption, minimal retention, zero tolerance for data breaches.

Example: We encrypt everything in transit and at rest. Because "hope nobody hacks us" isn't a security strategy.

What We Actually Collect (And Why)

The Technical Stuff We Need

To run a functional website, we collect some basic information automatically:

Your IP address (anonymized after 24 hours)
Why: Security, spam prevention, understanding geographic reach
What we don't do: Track your location or build browsing profiles
Browser and device type
Why: Ensure the site works on your device
What we don't do: Fingerprint your device to track you across the web
Pages you visit
Why: Understand which topics matter most to our community
What we don't do: Track how long you spend on each paragraph or where you click
How you found us
Why: Know if you came from a search engine, social media, or direct link
What we don't do: Buy "audience insights" from third parties

Real talk: We use 0 tracking pixels, 0 third-party trackers, and 0 fingerprinting scripts.

Most websites have 20-50. We have zero.

Information You Choose to Share

This is entirely in your control. We collect it only if you actively provide it:

  • Email address — If you subscribe to updates or contact us
  • Name — If you register for events or programs
  • Professional info — If you want to collaborate with us
  • Research data — If you participate in our studies (always anonymized)

You can request deletion of any of this at any time. No questions asked.

About Those Cookies...

Let's be honest: "cookies" sound delicious, but privacy cookies are often toxic.

The Cookies We Use (Just 2)

Language Preference

So the site remembers if you prefer Polish, English, Spanish, etc.

Lifespan: 1 year | Can you refuse it? Yes, but you'll need to select language every visit

Cookie Consent

Ironically, we need a cookie to remember that you accepted/rejected cookies.

Lifespan: 1 year | Can you refuse it? Technically yes, but then we'll ask again every visit

What We Absolutely Don't Do

  • No advertising cookies — We don't show ads, so we don't need them
  • No social media pixels — Facebook/Twitter/LinkedIn don't need to know you visited
  • No cross-site tracking — We don't follow you around the internet
  • No "legitimate interest" BS — If it's optional, we ask permission. Period.

How We Use Your Data (The Whole Truth)

We use your information for exactly five purposes. Not 47. Not "as described in our vendor agreements." Five.

  1. Communication — Answer your questions, send updates you asked for
  2. Community — Connect people working on similar challenges (always with permission)
  3. Research — Understand which AI governance topics matter most (aggregated data only)
  4. Improvement — Fix bugs, improve accessibility, make the site more useful
  5. Legal Compliance — Meet our obligations under GDPR, RODO, and other laws

That's it. Nothing else. No hidden purposes.

Who We Share Your Data With

Short answer: Almost nobody.

Long answer: Still almost nobody.

What We DON'T Do (Worth Repeating)

We do not sell your data. We do not rent your data. We do not trade your data.

If a company offers us money for your information, we tell them to fuck off. (Yes, really.)

The Only Exceptions (Required for Operations)

1. Essential Service Providers

  • Email service (to send newsletters you subscribed to)
  • Web hosting (to keep the site online)
  • Privacy-focused analytics (aggregated data only, no personal tracking)

All providers are GDPR-compliant, use encryption, and sign strict confidentiality agreements. We audit them regularly.

2. Legal Requirements

If a court orders us to disclose data, we're legally obligated to comply. But we'll:

  • Challenge overly broad requests
  • Notify you unless prohibited by law
  • Provide only the minimum data required

3. With Your Explicit Consent

If you ask us to share your info (e.g., connecting you with a research partner), we will — but only with your clear, informed permission.

How We Protect Your Data

Security isn't a checkbox. It's an ongoing commitment:

End-to-End Encryption

All data transmission uses HTTPS/SSL. Your browser → our servers = encrypted.

Access Controls

Only authorized team members can access personal data. We log every access. We review logs monthly.

Minimal Retention

We delete data as soon as it's no longer needed. No "let's keep everything forever" hoarding.

Regular Audits

Quarterly security reviews. Annual penetration testing. Continuous monitoring for vulnerabilities.

Breach Response

If a breach occurs, we'll notify affected users within 72 hours (GDPR requirement). Not "eventually." Within 72 hours.

Reality check: No system is 100% secure. Anyone who claims otherwise is lying.

We can't guarantee absolute security, but we can guarantee we'll do everything reasonable to protect your data — and be transparent if something goes wrong.

Your Rights (And We Mean It)

These aren't theoretical rights buried in legal footnotes. They're real powers you can actually use:

Right to Access

What it means: See all data we have about you.

How to use it: Email privacy@lasthuman.org with "Data Access Request"

When you'll get it: Within 30 days, free of charge

Right to Rectification

What it means: Fix any wrong or incomplete data.

Example: We have the wrong email? Tell us. We'll fix it immediately.

Right to Erasure ("Right to be Forgotten")

What it means: Delete your data. All of it.

Exceptions: We must keep some data if required by law (e.g., financial records for tax purposes). We'll tell you what and why.

Right to Restriction

What it means: Pause our use of your data while you verify something.

Example: You think we have wrong info? Ask us to stop using it until it's corrected.

Right to Data Portability

What it means: Get your data in a machine-readable format to take elsewhere.

Format: JSON or CSV, your choice

Right to Object

What it means: Say "stop" to certain types of data processing.

Example: Unsubscribe from newsletters, opt out of analytics

Right to Withdraw Consent

What it means: Change your mind at any time.

No penalty: Opting out won't affect your access to our resources or community.

To exercise ANY of these rights:

Email: privacy@lasthuman.org
Response time: Maximum 30 days (usually much faster)
Cost: Free

No verification gauntlet. No "processing fees." No runaround.

The AI Promise (This One's Important)

We're a foundation focused on AI governance. So let's be crystal clear about AI and your data:

What We Will NEVER Do:

  • Train AI models on your data without explicit, informed consent
  • Sell your data to AI companies for algorithm development
  • Use AI-based profiling to categorize or judge you
  • Apply automated decision-making that affects your rights
  • Share data with surveillance tech companies — ever

What We Might Do (With Your Permission):

  • Analyze aggregated, anonymized data to understand trends (e.g., "which AI topics concern people most")
  • Use AI tools for accessibility (e.g., automated alt-text generation for images)
  • Research purposes — but only if you explicitly opt-in to studies

The difference? Consent. Transparency. Control. You'll always know what we're doing and have the option to opt out.

Why this matters: Many organizations claim to care about "ethical AI" while selling your data to train the very systems they claim to regulate. That's not just hypocritical — it's destructive.

We refuse to participate in that charade.

Children's Privacy

Our website isn't designed for kids under 13. We don't knowingly collect their data.

If you're a parent/guardian and think your child shared info with us, contact us immediately at privacy@lasthuman.org. We'll delete it within 48 hours.

Third-Party Links

We link to:

  • Academic research papers
  • Policy documents
  • Open-source projects
  • Partner organizations

We can't control their privacy practices. Before sharing info on external sites, check their policies. (We know, it's tedious. But it matters.)

International Data Transfers

LASTHUMAN Foundation is based in Poland (EU). If you're accessing from outside the EU, your data crosses borders.

Protections in place:

  • Standard Contractual Clauses (approved by EU Commission)
  • GDPR-compliant service providers only
  • Encryption during transit

Your rights remain the same regardless of where you're located.

Changes to This Policy

Technology evolves. Laws change. Our practices might need to adapt.

If we update this policy, we'll:

  1. Post the new version here
  2. Update the "Last Updated" date at the top
  3. Email subscribers about significant changes (before they take effect)
  4. Give you time to review and opt-out if you disagree

We review this policy every 6 months. Next review: June 30, 2026.

Contact Us (We Actually Respond)

Questions? Concerns? Requests? We're here.

Privacy Officer:
privacy@lasthuman.org
Response time: Usually within 48 hours (30 days maximum by law)

General Inquiries:
contact@lasthuman.org

Mailing Address:
LASTHUMAN Foundation
Aleja Prymasa Tysiąclecia 83
01-242 Warszawa, Poland

Complaints:
If we screw up and don't resolve it, you can file a complaint with:
Urząd Ochrony Danych Osobowych (UODO) — Poland's Data Protection Authority
uodo.gov.pl

A Final Word

Privacy isn't a feature. It's a right.

Most organizations treat it as a legal obligation to minimize. We treat it as a moral obligation to maximize.

We're building a future where:

  • Technology empowers humans, not exploits them
  • Your data is yours — not a commodity to be traded
  • Transparency is the default, not the exception
  • Ethics aren't optional add-ons, but foundational principles

That future starts with how we treat your data today.

If you think we're falling short of these commitments — tell us. We're accountable to you, our community, and the mission we serve.

Because protecting humanity in the age of AI isn't just about algorithms and regulations.

It's about treating people like people — starting with you.

— The LASTHUMAN Foundation Team