Privacy

Humber is built so that the data we would least like to leak does not exist. This page describes what that means concretely.

What is published

For every verified number: a keyed one-way fingerprint, a status, and an expiry date. It contains no phone number, no name, and no other personal data, and the fingerprint cannot be reversed.

Humber is designed to publish that record to a public blockchain, so the answer can be checked without trusting us. That is not yet switched on. Today the record is held by Humber and served from our own systems. We will update this page when it changes, rather than describing something that has not happened.

What we hold

Your phone number, encrypted, so we can renew and support your attestation; and a payment record held by our payment processor. Card details never touch our servers.

Deleting your data

Revoking your attestation marks it revoked and stops the billing. The fingerprint record itself is kept, marked revoked, so a lookup can tell “withdrawn” apart from “never verified” — it reveals nothing about you.

Revoking does not by itself erase everything else. We keep your encrypted phone number and your account record until you ask us to erase them. Email michael@resignal.net and we will complete the request within 30 days. Payment records are kept for as long as tax and accounting law requires, and anything held by Stripe is subject to Stripe’s own retention.

Once publication to a public chain is enabled, a revoked record will also be permanent there, because a public chain cannot be rewritten.

Bulk use

Humber is a personal-use lookup. There is no public or bulk API, no export, and no automated access. Automated querying is blocked.

Who we are, and how to reach us

Humber is operated by RESignal, Inc., 8 The Green, Ste A, Dover, DE 19901, United States. Email michael@resignal.net — or write to that address — to ask what we hold about you, to correct it, or to have it erased.