Clear by design
Privacy Policy
Last updated 1 August 2026
Who we are
Humans.lk — The Ceylon Human Library — is a directory of people in and connected to Sri Lanka, and the data controller for everything described below. To reach us about anything on this page, write to privacy@humans.lk or use the contact page.
What we collect, and why
If you create a profile
- Your account — email address, a password we never see in plain form, and your display name.
- Your profile — name, photograph, headline, biography, professions, skills, interests, languages and your city. All of this is published. That is the point of a directory. Nothing appears until you submit it and a moderator approves it.
- Contact details — phone, WhatsApp, email, website, social links. Every one is private by default. Each has its own switch, and nothing is published until you turn that switch on. You can turn any of them off again from your privacy settings, and it takes effect immediately — no waiting for anyone to approve it.
- Your location — described separately below, because it works differently from everything else here.
If you send someone an inquiry
Your name, email address, an optional phone number and your message, so the recipient can answer. Also a hashed form of your IP address, to detect abuse — the hash uses a secret key held only by us, and your actual IP address is never stored.
Automatically
A daily count of how many times each profile was viewed, with nothing attached that identifies a viewer. No advertising trackers, no third-party analytics.
Your location, in detail
This is the part that most deserves explaining, so here is exactly what happens.
- City only — we publish the centre of your city and store nothing more precise. There is no exact point to leak, because we never keep one.
- Approximate — we store the point you placed somewhere no public query can reach, and publish a different point, moved between 300 and 1200 metres in a direction fixed for your profile. The offset never changes, deliberately: a point that moved every time somebody looked could be averaged over several looks until it landed on your door.
- Exact — we publish the point you placed. This is meant for a shop, clinic or office, and the site says so when you choose it.
Photographs are stripped of all embedded metadata — including the GPS coordinates most phone cameras record — on our servers, before the image is stored anywhere. The original file is never kept.
Identity verification
Everyone confirms once that they are a real, contactable person. There are two routes and they collect different things.
- Sri Lankan citizens verify a mobile number by SMS. We store the number and the fact that it was verified. The one-time code is stored only as an irreversible hash and expires within ten minutes.
- Everyone else gives a passport number and issuing country, which a member of our team reviews by hand. We store the number, the country, the outcome and who decided.
Neither is ever published. Your profile shows only whether you are Sri Lankan or international, and whether verification succeeded. Your phone number and passport number are not visible to other users and appear in no export or contact card.
Identity documents. The service is built to accept a scanned document, stored privately and readable only by you and our review team. That feature is switched off and nothing can currently be uploaded. We are telling you now rather than later so that if we do enable it, this policy already covers it: any such scan would be deleted within 90 days of the verification decision, whatever that decision was, and would never be published or shared with anyone.
Who else sees your data
We do not sell data and we do not share it for advertising. We use these providers, each processing data only on our instructions:
- Supabase — database, authentication and file storage.
- Vercel — hosting and delivery.
- Resend — sending the emails described here.
- Notify.lk — sending SMS verification codes, to Sri Lankan numbers only.
- Geoapify — optional place-name search while you place your map pin. Only the text you type into that box is sent.
- Jitsi Meet — video calls arranged through the site. We generate a random room link; we do not record, store or attend calls, and pass them no personal data.
- OpenFreeMap — map tiles.
- Cloudflare Turnstile — checking that form submissions come from a person rather than a robot.
Several of these operate outside Sri Lanka, so your data may be processed abroad.
How long we keep things
- Your profile and account — until you delete them.
- Inquiries — 24 months.
- Verification codes — the hash expires in ten minutes and the row is cleared within 30 days.
- Hashed IP addresses — 12 months, for abuse investigation.
- Identity documents, if ever enabled — 90 days after the decision.
- Moderation records — kept permanently in an append-only log, because being able to show why a profile was removed is itself a protection. It records the decision and who made it, not the contents of your profile.
Your rights
Under the Personal Data Protection Act No. 9 of 2022 you may:
- See what we hold. Everything about you downloads as a single file from your settings, immediately, without asking anyone.
- Correct it. Edit your profile whenever you like. Changes to your name, photograph or headline are checked before they go live; everything else applies at once.
- Have it deleted. Also from your settings. Your profile leaves the directory within seconds. You then have 14 days to change your mind, after which your personal details are permanently removed.
- Withdraw consent. Every published field is one you switched on, and you can switch it off again.
- Complain. Write to us first — we would rather fix it. You may also complain to the Data Protection Authority of Sri Lanka.
What deletion actually removes
After the 14 days we delete your profile, photograph, contact details, stored location, verification records, any permissions you granted other people, and your meeting history. Inquiries you sentto other people are anonymised rather than deleted, because they are also part of the recipient’s record of a conversation they took part in.
Security
Personal data lives in tables that public queries cannot reach at all; everything shown to the public is served through a small number of deliberately written views, so publishing a new field requires somebody to type its name into one of them. Passwords are handled by Supabase and never reach us. Verification codes and IP addresses are stored only as hashes, with a secret key.
Children
This service is not intended for anyone under 18 and we do not knowingly create profiles for children. If you believe we have, tell us and we will remove it.
Changes
If we change this policy in a way that affects how we use your data, we will email you before it takes effect rather than quietly changing the date at the top.