Privacy Policy
Last updated August 26, 2026
Harbor is a personal notes app made by Cloudmanic Labs, LLC, a small company in Oregon, USA. Your notes are some of the most personal data you have, so this policy is written to be read — plain English, no walls of legalese. If anything is unclear, email us at help@harbor.my and a real person will answer.
The short version
The whole policy in six bullets.
- Your notes are yours. We never sell your data, never show you ads inside Harbor, never share your notes with advertisers, and never use your content to train AI.
- We do run ads elsewhere, and we measure them. If you found Harbor through an ad, we tell that ad network the signup happened so we know which ads are worth paying for. They learn that someone who saw an ad signed up — never who you are inside Harbor, and never anything you’ve stored: advertising and measurement.
- We collect the minimum needed to run Harbor: your account details, the content you choose to store, payment records (handled by our payment processors — we never see your full card number), and a small amount of usage and log data.
- A few other companies handle parts of your data so Harbor can work — storage, OCR, transcription, analytics. We name every one of them and say exactly what each receives: who else touches your data.
- Optional zero-knowledge encryption lets you lock down notes so that even we cannot read them.
- You can export everything and delete your account at any time, whether you’re a paying subscriber or not.
- No ad trackers anywhere — not in the apps, not on this website.
Who we are
A small, independent US company. One product, one way we make money: subscriptions.
Harbor is operated by Cloudmanic Labs, LLC, a limited liability company based in Oregon, United States. Harbor’s servers are located in the United States. We make money one way: subscriptions. We are not in the data business.
For anything privacy-related, contact us at help@harbor.my.
What we collect
Account info, the content you store, payment records, and usage data tied to your account. That’s it.
Account information. Your name (if you provide one), email address, and sign-in credentials. Passwords are stored only as secure hashes — we cannot see them. If you sign in with Apple, Google, or a passkey, we receive only what’s needed to identify your account. Two-factor settings, session and device records (so you can see and revoke where you’re signed in) are stored with your account.
Your content. The notes, notebooks, tags, tasks, reminders, attachments,
audio recordings, web clips, and templates you store in Harbor — this is the
service. Emails you send to your private @m.harbor.my address become notes in
your account and are treated the same as any other content.
Payment information. Payments are handled by our payment processors — Stripe, Apple (App Store), or Google (Google Play), depending on how you subscribe. Your full card number goes directly to the processor; we never see or store it. We keep records of your subscription status, invoices, and transactions so we can run billing and support.
Usage data. We record product usage events — things like “a note was created” or “a clip was saved” — so we can understand which features matter and improve Harbor. These events are not anonymous, and we’d rather say so than call them “anonymous usage data.” They are keyed to your user ID, and your name and email are attached to your profile in the analytics tool we use (PostHog), so we can tell one account’s activity from another’s.
What each event contains is deliberately narrow: which part of the API was called, the method, whether it worked, how long it took, and which platform you were on. They describe actions, never the content of your notes — no titles, no bodies, no attachment names, no search terms. Requests from people who aren’t signed in are keyed to a one-way hash instead, and build no profile at all.
We also keep minimal server logs (IP addresses, timestamps, request metadata) for security, debugging, and abuse prevention such as rate limiting.
This website. The harbor.my marketing site uses Plausible Analytics, a privacy-friendly analytics tool that uses no cookies and collects no personal data. It also carries advertising measurement pixels — see the next section, which explains exactly what those are and what they send.
There are no ad trackers inside Harbor itself. No pixel, no advertising SDK, and no third-party tracker runs in the web app or in any of the Mac, iPhone, iPad, Android, or Windows apps. The measurement described below lives on the marketing site and in our own backend. Your notes are never involved.
Advertising and measurement
We buy ads. To know which ones work, we report signups back to the ad network. They never receive your notes.
Harbor is a small, self-funded product, and some people find it through ads we run on other platforms — currently Reddit, Meta (Facebook and Instagram), and X (Twitter). Advertising is only worth doing if we can tell which ads actually bring people who stay, so we measure it. Here is precisely how, because “we use an ad pixel” is not a real disclosure.
On the marketing site. If you visit harbor.my, the advertising pixels for Reddit, Meta, and X load and record the page view. They set third-party cookies and let each of those networks recognize a browser that has seen or clicked one of our ads. These are standard ad trackers and we are not going to describe them as anything softer than that. They run only on harbor.my — never in the app, and never on a page where you are signed in.
Carrying the click across. When you arrive from one of our ads, the link carries a click identifier — Reddit, Meta and X each put their own on it. We store it in your browser for up to 30 days and attach it to the link if you go on to create an account, so we can connect the signup to the ad. Each network only ever receives its own identifiers — a Reddit click is never mentioned to Meta. It is a random campaign identifier. It says nothing about you.
Reporting the signup. Most people who see an ad on their phone go on to sign up in one of our apps, where no browser pixel exists. So the signup itself is reported from our servers to the ad network’s conversions API — Reddit’s today, with Meta’s and X’s being brought onto the same footing.
That report contains the campaign identifier above and — where we have it — a one-way hashed version of your email address, which lets the network match the signup to the click without ever receiving the address itself. It also contains your IP address and your browser’s user agent string. Those two are how a network recognises a person whose click identifier did not survive the trip, and without them a large share of signups would go uncredited; we would rather tell you they are in there than quietly leave them out of this page. The report contains no notes, no attachments, no file names, no search terms, and nothing you have stored in Harbor. It says, in effect: someone who clicked this ad became a customer.
None of this happens at all if you send a Global Privacy Control signal, or ask us to exclude you — see below.
What we get out of it. Aggregate campaign numbers — this ad produced twelve signups, that one produced none. We do not receive a list of who you are on Reddit, Facebook, Instagram, or X, and we cannot see your activity on any of them.
If you would rather not be measured. Any of these work, and none of them affect your Harbor account:
- Block trackers in your browser, or use a content blocker. We do not work around blockers, and the site works perfectly without the pixel. Be aware this stops the pixel only — a signup reported from our servers does not pass through your browser, so a blocker cannot prevent it. The two below can.
- Adjust ad personalisation in your Reddit account settings, your Meta ad preferences, or your X ad settings.
- Send a Global Privacy Control signal — we honour it.
- Email help@harbor.my and ask us to exclude your account from conversion reporting, and we will.
How we use your data
To run Harbor for you. Nothing else.
We use your data to:
- Store, sync, back up, and display your content across your devices.
- Make your content searchable (see the next section on OCR and transcription).
- Process payments, send receipts, and manage your subscription.
- Send you transactional email — verification, password resets, billing notices, reminders you set, and warnings before anything is deleted.
- Send you Harbor news. Creating an account adds your name and email to our mailing list, which runs on a server we operate. Every message carries an unsubscribe link, and one click is enough.
- Keep the service secure: detect abuse, enforce rate limits, investigate problems.
- Improve Harbor, using the action-level usage data described above.
- Answer you when you write to us.
Things we never do with your data:
- Sell it or rent it. To anyone. Ever.
- Share your notes, attachments, file names, or search terms with advertisers or data brokers. The ad measurement described in advertising and measurement reports that a signup happened and nothing about what you store.
- Show you ads inside Harbor.
- Use your notes or attachments to train AI models — ours or anyone else’s.
Processing that makes your content searchable
We run OCR and transcription on your files so search works. Encrypted content is excluded.
Part of what you pay Harbor for is finding things. To deliver that:
- OCR — automatic, on upload. When you add a photo, image, or PDF, we send it to Google Cloud Vision to pull out the text inside it, so search can find words in your files. This happens as soon as the file lands, without you asking — search that only covered typed text wouldn’t be the product we promised. PDFs are turned into page images on our own servers first, and those page images are what Vision sees. It returns the text and where it sat on the page; we store that alongside your file.
- Audio transcription — only when you ask. Recordings sit untranscribed until you ask for a transcript. Then the audio is sent to AssemblyAI, which returns the text with speaker labels and timings. Nothing is transcribed in the background, so nothing is sent unless you asked for it.
This processing exists solely to power features in your account. Content you encrypt with Harbor’s optional zero-knowledge encryption is never OCR’d, transcribed, or indexed — we can’t read it, so we can’t process it.
Who else touches your data
Every company that handles any of it, what each one gets, and why. The whole list, not a footnote.
Harbor is a small company. We don’t run our own data centers, OCR engines, or payment rails, so a handful of other companies handle pieces of your data on our instructions. Each gets only what its job requires, under its own contract and security obligations. None of them may use your data for their own purposes. We do not have “data partners” — there is no such thing at Harbor.
Here is the whole list.
They handle your notes and files
- Backblaze B2 — storage. This is the big one, so we’ll be exact: your attachments live there, and so do continuously replicated backups of the databases holding your notes. In practice, a copy of everything you keep in Harbor sits at Backblaze. It’s encrypted at rest, and anything you locked with your own passphrase is unreadable there — same as it is to us.
- Google Cloud Vision — OCR. Receives your images and PDF page images to extract their text. Automatic on upload, as described above.
- AssemblyAI — audio. Receives a recording when you ask for a transcript, and that transcript when you ask for a summary. Only on request.
- OpenAI — note text, to write a title. Receives up to the first 8,000 characters of one note and hands back a title. Two ways it happens: you tap “Suggest title” on a note, or a watched folder you switched it on for does it for each file it imports. That folder switch is off unless you turn it on, folder by folder. Nothing else is ever sent, and never an encrypted note.
- Amazon Web Services — email. Transactional mail goes out through Amazon
SES. Mail you send to your private
@m.harbor.myaddress arrives through SES, rests briefly in storage there, and is then pulled into your account as a note — so inbound email passes through AWS on its way to you.
They get account details, but never your notes
- PostHog — product analytics. Gets your user ID, name, and email, plus the action-level events described above. Hosted in the United States.
- Stripe — payments, if you subscribe on the web. Subscribe through the App Store or Google Play instead and Apple or Google handles the payment; we only check the receipt.
- Slack — our own team chat. A new signup posts a name and email into a private channel so we actually see it, and support requests land there too.
- Better Stack — log hosting. Receives our server logs, which include IP addresses, request paths, and browser user agents. No note content.
- Reddit, Meta and X — advertising measurement. Each network’s pixel on harbor.my records that a browser viewed a page here. If you arrived from one of our ads and then create an account, that network also receives the campaign identifier from the ad you clicked, a one-way hashed version of your email address, your IP address and your browser’s user agent, so it can credit the signup to the right ad. Each is only ever sent its own identifiers. None of them ever receives your email in readable form, your name, or anything you have stored. See advertising and measurement.
Only if you switch them on
- Dropbox and Google Drive — optional watched folders. Connect one and Harbor reads files out of the folder you picked and imports them. Disconnect whenever you like.
- Sign in with Apple and Google sign-in — only if you use them, and only to confirm who you are.
Infrastructure
- Harbor’s application servers are ours, in the United States. DigitalOcean runs the reverse proxy that traffic passes through on the way to them.
One clarification, because it’s the kind of thing that’s easy to get wrong: the summary of a recording is written by a Claude model, but that model runs on AssemblyAI’s own systems. Harbor sends nothing to Anthropic and has no relationship with them. AssemblyAI is the company we contract with, and the one answerable to us for that data.
If we add a company to this list, or change what one of them receives, that is a material change and we’ll tell you before it takes effect — see changes to this policy.
Encryption
Everything is encrypted in transit and at rest. Optionally, you can encrypt notes so even we can’t read them.
All traffic between your devices and Harbor is encrypted in transit with TLS, and your data is encrypted at rest on our storage infrastructure.
On top of that, Harbor offers optional zero-knowledge encryption for the notes you choose. When you turn it on, your content is encrypted on your device (Argon2id-derived key, AES-256-GCM) before it ever reaches us. We never hold your keys or passphrase. That means:
- We cannot read, recover, OCR, index, or search your encrypted content — and neither can anyone who compromises our servers.
- Encrypted content is excluded from search, OCR, and the API/CLI/MCP.
- If you lose your passphrase, we cannot restore that content. Nobody can. That’s the point — but it’s your responsibility.
AI in Harbor
Two AI features. Both opt-in. Plus anything you connect yourself.
Harbor has two AI features, and neither runs without your say-so:
- Suggest title — you tap it on a note, that note’s text goes to OpenAI, a title comes back. If the note is only a recording or a scan, we send its transcript or OCR text instead, because that’s the only text there is.
- Summarize a recording — you tap it on a transcript, AssemblyAI writes the summary, you get it back.
Suggest title has one automatic form: a watched folder can name each note it imports from what’s on the page. It is the only place Harbor hands your note text to an AI without you pressing a button, so you turn it on per folder and it is off by default. While it’s on, the OCR text of each file that folder imports goes to OpenAI — nothing else in your library goes there on its own, and there is no assistant reading your notes in the background.
Both features refuse encrypted content outright.
Using these features does not turn your notes into training data. The promise above holds here too: we don’t use your content to train AI models, and we don’t let anyone else.
You can also connect your own AI tools to your account via our API, CLI, or MCP server using access tokens you create. When you do, your AI provider receives whatever your tools request from your account — that access is initiated and controlled by you, governed by your agreement with that provider, and revocable by you at any time (delete the token). Encrypted content is never reachable this way.
Public share links
If you publish a note, it’s public. Unpublish it anytime.
You can publish a note as a read-only public page. Anyone with the link can view it — no account required — so don’t publish anything you want to keep private. You can unpublish a note at any time, which disables the link.
How long we keep data, and how deletion works
Deleted means deleted. Lapsed accounts keep their data. Only long-abandoned free accounts get cleaned up — after plenty of warning.
- Trash: deleted notes go to your trash first, where you can restore or permanently expunge them.
- Account deletion: you can delete your account yourself, from settings, at any time. There’s a 30-day grace window in which you can change your mind; after that, everything — notes, attachments, account records — is permanently erased from our systems. Residual copies in encrypted backups age out shortly after.
- If your subscription lapses: your account becomes read-only, but your data stays put. You can still export everything and delete your account. We never hold data hostage to a payment.
- Inactive free accounts: a free account that goes completely unused for about six months may be deleted — but only after a series of email reminders and warnings over several months, so nothing disappears by surprise. Paid accounts are never subject to this.
- Logs and billing records: operational logs are kept briefly; billing and tax records are kept as long as the law requires.
Your rights: export, access, correction, deletion
Take your data with you anytime. Full stop.
At any time, subscriber or not, you can:
- Export everything — as HTML, Markdown, or Evernote ENEX, including a full account export — right from the app.
- Access and correct your account information in settings.
- Delete your account and all of its data, as described above.
If you’re in a region with formal privacy rights (such as the GDPR or CCPA), these tools cover the core of them — access, portability, correction, and erasure. For anything they don’t cover, email help@harbor.my and we’ll handle it directly. Because we are a US company with US servers, using Harbor means your data is transferred to and processed in the United States.
Children
Harbor is not for kids under 13.
Harbor is not directed at children under 13, and we don’t knowingly collect data from them. If you believe a child under 13 has an account, contact us and we’ll delete it.
Changes to this policy
If something meaningful changes, we’ll tell you — not bury it.
We may update this policy as Harbor evolves. The date at the top always shows the latest revision. If we make a material change — anything that affects what we collect or how we use it — we’ll notify you by email or in the app before it takes effect. We will never quietly change this policy to start selling data; that’s not a loophole we’re leaving open.
Contact
Questions, concerns, requests — email help@harbor.my. A real person at Cloudmanic Labs, LLC reads every message.