LEGAL
Privacy Policy
Your agents work with your data — that only works if the handling of it is boring, predictable, and yours to control. Here's what we collect, why, and what we never do with it.
Last updated · July 2, 2026
01What this covers
This policy describes how Harby, Inc. handles personal data when you use the Harby platform, apps, and websites. Where you connect third-party services, those services' own policies also apply to data inside them.
02What we collect
- Account data — name, email, workspace membership, authentication identifiers.
- Customer content — the files, instructions, messages, and work product in your spaces, including data your agents access through connectors you authorize.
- Run records — transcripts of agent sessions: actions taken, approvals given, tokens used, costs incurred. These exist so you can audit your agents.
- Usage & device data — logs, app version, and diagnostics needed to keep the Service reliable.
- Billing data — handled by our payment processor; we don't store full card numbers.
03How we use it
- To operate the Service: run your agents, sync your spaces, deliver notifications and approvals.
- To route model inference to the AI providers you've configured, with the minimum context each task needs.
- To secure the Service: abuse detection, isolation enforcement, incident response.
- To support you and to bill accurately (usage analytics are also shown to you, per run).
- To improve the product using aggregated, de-identified usage patterns.
04What we don't do
- We don't sell personal data. No advertising trackers, no data brokers.
- We don't train foundation models on your customer content, and the model providers we route to are contractually prohibited from doing so.
- Agents in one space can't see another space's data, and no agent can see data behind a connection you haven't granted it.
05Who we share with
Only subprocessors needed to run the Service, under data-protection agreements:
- Cloud infrastructure and edge network providers (hosting, storage, delivery).
- AI model providers, per your configuration (e.g., Anthropic, OpenAI, and others you enable).
- Payment processing and email delivery providers.
We also disclose data if required by law, with notice to you where legally permitted. The current subprocessor list is available with our DPA.
06Retention
Customer content and run records are retained while your account is active so your agents keep their memory and you keep your audit trail. When you delete content, a space, or your account, associated data is deleted from production systems within 30 days and from backups within 90 days, except where retention is legally required.
07Your rights
Depending on your location, you may have rights to access, correct, export, delete, or restrict processing of your personal data. Export tools are built into the product; for anything else, email privacy@harby.app and we'll respond within 30 days. If you're in the EEA/UK, you may also lodge a complaint with your supervisory authority.
08Security
Encryption in transit and at rest, isolated per-agent sandboxes, permission gates on every connector action, and audited access to production. Details live on the Security page; report issues to security@harby.app.
09Changes & contact
We'll notify you of material changes to this policy before they take effect. Privacy questions: privacy@harby.app.