Last updated: August 2026
This policy explains what Harbor collects, why, and the choices you have. It covers two kinds of people: creators (people who build on Harbor) and end-users (people who sign into or use an app someone built on Harbor).
Creators:your email and name; the projects you build and the prompts you write; billing details (handled by Stripe — we never see full card numbers); and basic usage/logs to run and secure the service. Published apps also record anonymous, aggregate visit counts (used for the Explore gallery's rankings) — not visitor profiles.
End-users of “Sign in with Harbor”: your email and a display name/avatar. The apps you sign into only ever see your display name and avatar — never your email. Any data an app saves for you (for example game progress or preferences) is stored so that app can show it back to you.
To provide and improve Harbor, build and host your projects, process payments, prevent abuse, and communicate with you about your account. We do not sell your personal data.
Harbor runs on trusted providers who process data on our behalf: Supabase (accounts and database), Railway (application hosting), Cloudflare (hosting and content delivery), E2B (secure build sandboxes), Anthropic and OpenRouter (the language models that build your projects and power in-app features), Stripe (payments), and Resend (email). Your prompts and the text your app sends to those features are processed by these model providers to generate responses. Under our API agreements, they do not use your code, prompts, or content to train their models. Your code stays yours.
To make the builder better over time, Harbor learns from usage in two narrow, disclosed ways. Platform lessons: when a bug a creator reported gets fixed, we distill a short, generalized technical rule from the fix (for example, “physics pauses must also pause timers”) that helps every future build — these rules never contain your code, content, or anything identifying. Your build preferences: Harbor keeps short notes about how youlike things built (style, tone, genre preferences), which are used only for your own workspace's builds, never anyone else's. You can see exactly what Harbor has noted and delete any or all of it under Settings → Memory. Neither mechanism trains any AI model, and neither ever shares your code or content with other users.
Harbor uses essential cookies only — to keep you signed in and secure. We don't use advertising or cross-site tracking cookies. Because they're strictly necessary to run the service, no consent banner is required, but you can clear them anytime in your browser.
If you buy access to a published app, that app sets one cookie on its own address as your proof of purchase, so it stays unlocked when you come back; signing into a published app stores a sign-in token in your browser for the same reason. Both exist only to deliver something you asked for.
On our public marketing pages we measure visits with a privacy-focused analytics service (mylastlap.com) that sets no cookies, stores nothing in your browser, and does no fingerprinting. Visit counts are derived from a hash that rotates daily, so visitors cannot be tracked across days or across sites, and page addresses are recorded without query strings (which can carry emails or tokens). It also honors your browser's “Do Not Track” setting. We don't run any analytics scripts from advertising companies, and the fonts and assets on our pages are served by us, not fetched from third parties.
Only you and the people you share a workspace with. When you publish an app, the built files go on the web — that is the point of publishing, and they are meant to be public. Your source code and your version historydo not: they are kept in private storage that has no public address, and the only way to them is a request Harbor checks against who you are. Someone who knows your app's web address, or its id, cannot read the code behind it.
The two exceptions are both your own choice, and both say so where you make them: downloading your source or pushing it to your GitHub, and marking a free app as a template so other people can start from a copy of it.
You can export your data and delete your accountat any time from your Account page — deletion removes your projects, personal data, and any accounts you created inside Harbor-built apps. Every app's complete source codecan also be downloaded (or pushed to your own GitHub) from that app's settings — your code is yours, before, during, and after Harbor. Depending on where you live (for example the EU/EEA under GDPR, or California under CCPA/CPRA) you may have additional rights to access, correct, delete, or restrict processing of your data; email [email protected]and we'll help. Marketing emails include an unsubscribe link; account/transactional emails are required to run the service.
We keep data for as long as your account is active or as needed to provide the service and meet legal obligations, then delete or anonymize it. We use industry-standard safeguards, though no method is perfectly secure.
Harbor isn't directed at children under 13, and we don't knowingly collect their data. If you believe a child has given us personal data, contact us and we'll remove it.
We'll post updates here and announce material changes. Questions or requests: [email protected].
This is a plain-language template provided for transparency and is not legal advice. Have it reviewed by counsel for your jurisdiction before relying on it.