Legal

Privacy Policy

Last updated 10/07/2026

The Human Vector LLC ("we," "us") provides a platform that runs simulated phishing campaigns and security awareness training for organizations and the managed service providers who serve them. This policy explains how we handle personal data.

1. Two different roles

2. Data we handle as controller

Our marketing website uses no analytics, advertising, or tracking technologies and sets no third-party cookies. The signed-in console sets only the strictly necessary cookies for sign-in and form security. A display preference (light or dark) and any conversation with the console's assistant stay in your own browser and are not sent to us as stored records.

We use this data to respond to you, provide and improve the service, secure it, and run our business. We do not sell personal data, and we do not share it for cross-context behavioral advertising.

3. Data we handle as processor (customer employee data)

On our customers' instructions we process their workforce's name, work email, department, manager, group membership, simulation results (whether a simulated message was opened, clicked, had credentials entered, or was reported), and training status.

Two facts about how the platform is built:

4. The Report phishing button, and Google and Microsoft data

Customers can give their people a Report phishing button in Gmail, Outlook, Front, Missive, or Thunderbird. When a person clicks it, the button reads only the one email they chose to report, and only at that moment. It sends us that email's sender, subject, and content, and the reporter's work email address, so the report can be attributed to the right organization and person. We use that data only to classify the report (a simulation, one of our own training emails, or a genuine threat), to show a genuine threat to the organization's security administrators for triage, to count the report in the person's training record, and, where the customer has enabled it, to remove that email from the organization's other mailboxes. We do not use it for advertising, and no person at The Human Vector reads reported email except to support a customer who asks.

Where a customer connects a Google Workspace or Microsoft 365 directory, we read the directory to keep the customer's roster current: names, work emails, departments, managers, and group membership. We do not read mail through a directory connection.

The Human Vector's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

5. Where data is stored, and who else processes it

Data is hosted in the United States. We use a small set of sub-processors, each bound by contract to protect personal data:

ProviderPurposeLocation
RenderHosting the platform and its databaseUnited States
VultrThe mail server that sends simulation emailUnited States
ResendAccount, notification, and report email (never simulations)United States
AnthropicThe AI features described in Section 6United States

We will update this list before adding a sub-processor that handles personal data.

6. AI features

The platform's AI features interpret an administrator's typed request and draft simulation content from a brief. What they send to our AI provider is the organization's name, its headcount, the names of its templates and groups, and the text the administrator typed. The employee roster is never sent.

Reported-email triage (optional, Pro). When a customer turns on AI triage, each real email its people report is sent to our AI provider so it can label the email Safe, Unsafe or Unsure with a one-line reason: the sender, subject and body of that one email, nothing from anyone's mailbox. The AI only labels; it has no access to any mailbox and cannot move, delete or send mail. When several people report the same email, the platform (not the AI) alerts the addresses the customer chose and, where the customer has granted mailbox access, counts how many mailboxes hold that email and can remove it on an administrator's instruction.

Your data is never used to train AI models: not by us, and not by our AI provider, whose commercial terms prohibit training on customer content. This applies to all customer data, including aggregated or de-identified data.

7. How long we keep it

Customer data is kept for as long as needed to provide the service and as the customer instructs. When an agreement ends we delete or return it on the customer's instruction, except where law requires retention. Data we hold as controller is kept only as long as needed for the purpose it was collected for.

8. Your rights

Depending on where you live, you may have rights to access, correct, delete, or port your personal data, or to object to or restrict certain processing.

We do not sell personal data or share it for cross-context behavioral advertising, so there is nothing to opt out of on that count.

9. Security

We use technical and organizational measures to protect personal data, including encryption in transit, encrypted storage of secrets, mandatory two-factor authentication for every console account, least-privilege access to customer systems, and an audit trail of administrative actions. No system is perfectly secure. If a breach affects personal data we hold, we notify affected customers as our Data Processing Addendum requires.

10. Changes and contact

We will update this policy as the platform and the law evolve, and we will post each new version here with a revised date.

Questions: legal@thehumanvector.io
The Human Vector LLC, 7533 S Center View Ct, Ste N, West Jordan, UT 84084