Open standard · v0.1 draft

human.txt

robots.txt lets websites set rules for machines. human.txt lets you set rules for them. One file that tells every site, app and AI agent what they can use, what they can't, and how to treat you.

You write

Version: 0.1
Updated: 2026-10-09

[*]
Language: en-US
Tracking: disallow
Data-Sale: disallow
AI-Training: disallow
AI-Summarize: allow
Contact: none

[commerce]
Applies-To: shops, marketplaces
Personalization: allow
Retention: 90d
Contact: email
Contact-Frequency: weekly

[ai-agents]
Applies-To: assistants, chatbots, support bots
Disclose-AI: required
Human-Escalation: required
Memory: session-only
Act-On-My-Behalf: ask-first
Tone: direct, concise

A shop sees

Version: 0.1

[commerce]
Language: en-US
Tracking: disallow
Data-Sale: disallow
AI-Training: disallow
AI-Summarize: allow
Contact: email
Applies-To: shops, marketplaces
Personalization: allow
Retention: 90d
Contact-Frequency: weekly

Why

The internet is about to be read, summarised and acted on by AI on your behalf and about you. Every site has a privacy policy. Every app has terms. You have a cookie banner. human.txt flips that: your preferences, written once, in plain words, carried with you. Share the right layer with the right entity. Edit it as you change. It's yours.

How it works

Own. Layer. Share.

01

Own

Your human.txt lives on your device in the browser extension, not on a server. No account and no sign-up. Plain text you can read, edit and download any time.

02

Layer

Write a base layer for everyone, then layers for shops, AI agents, news, work and health. Each layer only overrides what it needs to. A support bot learns how to talk to you; a shop learns how often it can email.

03

Share

Sites ask through the extension. You see who is asking and why, approve each layer, and can revoke it later. Each site gets its own hashed ID, so nobody can follow you across the web with it.

Try it

Write your human.txt.

Edit the file on the left. Pick who's asking on the right to see exactly what they'd receive. Nothing you type leaves this page.

human.txtYou write
Valid human.txt v0.1
What they seeShared
# human.txt — https://humantxt.org
Version: 0.1
Updated: 2026-10-09

[commerce]
Language: en-US
Tracking: disallow
Data-Sale: disallow
AI-Training: disallow
AI-Summarize: allow
Contact: email
Applies-To: shops, marketplaces
Personalization: allow
Retention: 90d
Contact-Frequency: weekly

Only the [commerce] layer, merged with [*]. Nothing else in your file leaves your device.

For developers

Ask. Honour. Done.

If a visitor has the extension, navigator.humanTxt exists. Ask for the layer you need and say why. You get the merged preferences and a per-site ID.

// Visitors with a human.txt user agent send `Human-Txt: v=0.1`
if (navigator.humanTxt) {
  const me = await navigator.humanTxt.request({
    layers: ["commerce"],
    purpose: "Decide how often we email you.",
  });

  me.id;                            // "ht1_…" (this site only)
  me.layers.commerce["Contact"];     // "email"
  me.layers.commerce["Data-Sale"];   // "disallow"
}

FAQ

Fair questions.

Q1What is human.txt?

A small plain-text file that says what websites, apps and AI agents may do with your data and how you want to be treated: whether they can train AI on you, sell your data, email you, or act on your behalf. It is split into layers so a shop, an AI assistant and a news site can each see only what applies to them.

Q2Where does my file live?

On your device, inside the human.txt browser extension. Sites never download it on their own. They ask, you see who is asking and why, and you choose which layers to share. You can revoke access at any time.

Q3Does this make me easier to track?

No. Every site gets a different ID, derived from a secret that never leaves your device. A shop can recognise you when you come back, but two sites can't compare IDs to learn you're the same person. There is deliberately no global ID.

Q4Is my file encrypted?

Your identity is protected by hashing: sites only ever see a per-site ID. The file itself sits in the extension's private storage. A layer you choose to share is sent readable, because the site has to read it to honour it. Passphrase encryption and signed receipts are planned for v0.2.

Q5Do websites have to obey it?

Not yet. Like robots.txt, human.txt works when entities choose to honour it. Some of what it says already has legal weight: in several US states, sites must honour Global Privacy Control, an opt-out signal for selling or sharing data. human.txt goes further than that one signal. AI agents are the other big audience: an assistant acting for you can read your file before it acts.

Q6Didn't Do Not Track already fail?

Do Not Track was a single bit with no legal force, and it was easy to ignore. P3P asked people to read machine policies they never saw. human.txt is written by you, in your words, with per-entity layers, and it is aimed squarely at AI agents, which can read and follow instructions. Adoption is still the hard part, which is why this is open source and needs contributors.

Q7Isn't humans.txt already a thing?

humans.txt (with an s) is a file sites publish to credit the people who built them. human.txt is the reverse: a file a person keeps to set terms for the sites they visit. The singular name and the /.well-known/ path keep the two from colliding.

Q8Can I publish my file publicly?

Yes, optionally. Put your base layer at https://your-domain/.well-known/human.txt and any agent can read it. Only publish what you'd put on a public profile; the private layers stay in the extension.

Help write the rules for humans.

human.txt is an early, open draft. The format, the vocabulary and the extension all need people who care: privacy folks, AI builders, designers, lawyers, and anyone who wants a say.