Legal
Privacy Policy
Published: September 1, 2026 · Effective: September 15, 2026
This policy explains what data Harbor collects, who receives it, how long we keep it, and what you can require us to do about it. It covers the Harbor application, the desktop app, the CLI, the MCP server, and the website at gethrbr.com.
Harbor reads from tools your team already uses, turns what it finds into short written statements, and serves those statements back to your team and to the AI assistants your team runs. Every section below follows from that one sentence.
1. Who We Are
Harbor is operated by [LEGAL NAME PENDING], a sole trader registered in Israel, trading as Harbor, of [BUSINESS ADDRESS PENDING], Tel Aviv, Israel. Harbor is a trading name and not a separate company, so the person named here is the one you contract with, the data controller for the data described in section 3, and personally accountable for it. For the content you bring into Harbor from your connected tools, you are the controller and we act as your processor, on the terms set out in our Data Processing Agreement.
Privacy questions, and any request to exercise the rights in section 10, go to privacy@gethrbr.com. We have not appointed a data protection officer, because our processing does not meet the thresholds in Article 37 of the GDPR that require one.
We have not yet designated a representative in the European Union under Article 27 of the GDPR, or in the United Kingdom under the UK GDPR. Until we do, address anything you would send to a representative to the privacy address above, and we will answer it on the same timetable. We would rather tell you the appointment is outstanding than name someone who has not been appointed.
2. The Sources You Connect
You choose which tools Harbor may read. Today those are Slack, GitHub, GitLab, Linear, Jira, Confluence, Notion, Google Drive, Gmail, Outlook, Granola, and meeting transcripts from a Drive folder you nominate.
Data flows from these into Harbor, read only, under a credential you issue and can revoke at any time. They are where data enters, so they are on this page. They are not sub-processors, because we do not send your data to them.
Two of those sources are mail accounts and one is a record of meetings. Connecting them means Harbor reads the content of messages and transcripts that may concern people who have never used Harbor and never agreed to anything. Section 5 is written for those people, and section 6 sets out what you take on when you connect a source on their behalf.
3. What We Collect
- Account and identity. Your name, email address, and which organisation and workspace you belong to. Sign-in is handled by Clerk.
- Content read from your connected sources. The text of the messages, issues, documents, transcripts and mail that Harbor reads from the sources you connect, and the short written statements we derive from that text. This may contain personal data about anyone who appears in it.
- Embeddings and retrieval records. Vector representations that make statements searchable, and a record of which statement was served to which session, which is what the served and cited counts are computed from.
- Connector credentials. The OAuth tokens or API keys you issue us for each source, encrypted at rest. See section 7.
- Billing identity. Your plan, your subscription events and the billing details you give Paddle, our merchant of record. We never receive or store full card numbers.
- Product analytics. In-app events, pageviews and a pseudonymous identifier, via PostHog. Your workspace name and slug reach PostHog too. See the note in section 8.
- Crash reports. From the desktop app only, via Sentry, redacted before they are sent.
- Website. gethrbr.com runs no analytics and sets no cookies. See section 12.
4. Where Your Content Goes
When Harbor ingests from a connected source, the text it reads is sent to an AI provider so it can be classified, summarised into statements, and embedded. When you or an agent asks a question, the relevant statements and your question are sent to a provider so it can answer. There is no version of the product in which content stays only with us.
Claude Code runs locally on your device and talks to Anthropic directly, under your own account. Harbor does not route those prompts through its servers, and your source code is not uploaded to us.
We do not use your prompts, your content, your statements, or your knowledge graph to train AI models, and we have not granted any provider the right to use them for that purpose. What each provider does with what we send is governed by that provider's own API terms. We are completing written zero retention and no training terms with each of them, and we will name the position on this page once we hold it in contract. We will not tell you that a provider retains nothing until we can show you the document that says so, and we would suggest you ask the same of any vendor that tells you otherwise.
5. If Your Employer Uses Harbor
You may be reading this because your name, your messages or your mail have reached Harbor through a workspace your employer runs. In that case your employer is the data controller and we are its processor. We act on its instructions, so requests to access, correct or delete what Harbor holds about you are for your employer to decide, and you should send them there first.
Write to us at privacy@gethrbr.com anyway if you cannot reach them or they will not act, and we will pass the request to the controller and help them answer it. We will tell you that we have done so.
6. Who Can See What, Inside a Workspace
Nothing crosses a workspace boundary. Where you are a controller, deciding which sources to connect, on what legal basis, and what to tell the people whose data is in them is your decision to make, and the DPA sets out what you take on by making it.
7. How We Use Your Data, and On What Basis
- To operate the Service: ingest from the sources you connect, derive statements, serve them to your team and to the agents you run, and answer questions over them.
- To authenticate you and keep you signed in.
- To process payments and handle billing support, through Paddle.
- To send transactional messages, and product email you can unsubscribe from.
- To diagnose crashes and fix errors.
- To prevent abuse and enforce our Terms of Service.
- To meet legal, tax and accounting obligations.
We do not sell your personal data. We do not share it for cross-context behavioural advertising. We do not use your content to train AI models. We run no advertising pixels and no third-party trackers.
Where the GDPR or the UK GDPR applies, our legal bases are: performance of our contract with you, for providing the Service and processing billing; your consent, for product analytics and marketing email, which you may withdraw at any time; our legitimate interests in operating, securing and improving the Service, and in preventing abuse; and compliance with a legal obligation, for tax and accounting records. We do not carry out automated decision-making that produces legal or similarly significant effects, and we do not knowingly process special categories of personal data. We do not solicit special category data and we do not filter for it, so content drawn from a mailbox or a chat may contain it incidentally. You decide which sources to connect.
8. Sub-processors
Ten, split by the distinction that decides most reviews: five receive your content, and five receive identity, billing or telemetry only. We give at least 14 days' notice before adding or replacing one. The DPA carries the same list with locations and retention, and sets out your right to object.
Receive your content:
- OpenAI. The bulk of the pipeline: text read from your connected tools during extraction, the statements derived from it, the embeddings that make them searchable, and, by default, your assistant's conversation turns.
- Anthropic. Question and answer turns over your stored knowledge, and longer multi-step assistant runs.
- Google (Gemini). Content only if you select it as your provider, or as a last-resort failover.
- Amazon Web Services (S3). The stored text of each statement, and your workspace index. United States, us-east-1.
- Amazon Web Services (managed database). Our primary datastore, which we run: statements, metadata, sessions, retrieval records, and your encrypted connector tokens. United States, us-east-1.
Receive identity, billing or telemetry only:
- Clerk. Names, email addresses, organisation membership. Authentication.
- Paddle. Billing identity, plan, subscription events. Merchant of record. Paddle is an independent controller for the payment and tax data it collects.
- Amazon Web Services (SES). Email addresses and the bodies of transactional messages.
- PostHog. Product events, pageviews, a pseudonymous identifier, and your workspace name and slug. United States.
- Sentry. Crash reports from the desktop app only, redacted before they are sent.
9. Retention
How long we keep knowledge statements follows the plan your workspace is on. It is not configurable by you today, and we would rather you read that here than discover it in an audit.
- Knowledge statements
- Free: 30 days. Pro: 365 days. Premium and Enterprise: no expiry.
- Raw payloads fetched from your sources
- 7 days, then purged automatically. This is our setting, not yours.
- Stored statement text
- Deleted with the statement it belongs to.
- Account and identity data
- For as long as your account is active, then removed within 30 days of deletion.
- Product analytics and crash reports
- Retained by PostHog and Sentry under their own retention settings, and not used to build a profile of you outside the product.
- Billing and tax records
- Retained by Paddle for as long as tax law requires, typically seven years. We cannot delete these on request.
Deleting a workspace removes the workspace and its data. When you delete your account we remove your personal data from our records and instruct our providers to do the same within 30 days, except where law requires us to keep it.
10. Your Rights
Depending on where you live, you may have the right to access the personal data we hold about you, to correct it, to have it deleted, to restrict or object to processing, to receive it in a portable form, to withdraw consent at any time without affecting processing already carried out, and not to be treated worse for exercising any of these.
Email privacy@gethrbr.com. We answer within the period the applicable law allows, which is one month under the GDPR and 45 days under US state privacy law, and we will tell you if we need an extension the law permits. You may use an authorised agent. If we refuse a request you may appeal it by replying to our decision, and we will respond to the appeal within 45 days.
You may also complain to a supervisory authority: your local data protection authority in the EEA, the Information Commissioner's Office in the UK, or the Privacy Protection Authority in Israel. We would rather you came to us first, but nothing here requires you to.
11. Security
We protect data in transit with TLS and at rest with industry-standard encryption. Connector tokens are encrypted with AES-256-GCM and cryptographically bound to the record they belong to, so a ciphertext lifted from one record and pasted into another fails the check rather than decrypting into the wrong account. Credentials are stripped before anything is written to a log, by one shared pattern catalogue rather than per-call guesswork. Access to production is limited to the people who need it.
We run no third-party analytics in our backend, no session replay and no autocapture, in the web app or the desktop app. We respect Do Not Track, and product analytics are disabled outside production builds.
We do not hold a SOC 2 report, an ISO 27001 certificate, or a third-party penetration test today, and we do not claim one anywhere on this site. We will start that work the day a customer needs it. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
12. Cookies and Tracking
The website at gethrbr.com runs no analytics, sets no cookies, and loads no third-party scripts. There is no consent banner because there is nothing to consent to. If we add analytics to the website, we will ask visitors in the EEA and the UK before anything non-essential loads, and we will update this section before it ships rather than after.
The application uses a session cookie to keep you signed in, which is strictly necessary and cannot be turned off without signing you out. It also uses PostHog for product analytics, which sets a first-party identifier. We use no advertising cookies and no third-party advertising pixels anywhere.
13. International Transfers
We are in Israel, which the European Commission has recognised as providing an adequate level of data protection, so personal data may be transferred to us from the EEA without an additional transfer mechanism.
Adequacy covers the transfer into Israel. It does not cover onward transfers. Our sub-processors process data in the United States and elsewhere, as set out in section 8, and those transfers rely on Standard Contractual Clauses approved by the European Commission, with the UK International Data Transfer Addendum where applicable, on the EU-US Data Privacy Framework where the recipient is certified, or on another lawful transfer mechanism.
14. Israeli Privacy Protection Law
As an Israeli trader we are also subject to the Privacy Protection Law, 5741-1981, as amended. You are not legally required to give us any of the data described in section 3, but without it we cannot provide the Service. You may ask to review data we hold about you, and to correct or delete data that is incorrect, incomplete or out of date, by writing to the privacy address above.
15. Children
Harbor is not directed at children, and we do not knowingly collect data from anyone under 16. If you believe a child has given us personal data, write to us and we will delete it.
16. Changes to This Policy
We will publish any material change here and notify account holders by email at least 14 days before it takes effect. The publication and effective dates at the top of this page are the record of when we last did so.
17. Contact
privacy@gethrbr.com, or write to [LEGAL NAME PENDING], [BUSINESS ADDRESS PENDING], Tel Aviv, Israel.