Harbour
Features Pricing Terms Download

Legal

Privacy Policy

Last updated: August 17, 2026

Harbour ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains what information we collect, how we use it, and your choices. By using the Harbour app, you agree to the practices described here.

1. Information We Collect

1.1 Information You Provide

During onboarding you provide:

  • Your name, age, pronouns, and who you are interested in
  • Your interests, personality and communication quiz responses, relationship preferences, and companion preferences

This profile is stored locally, included as needed when generating personalized AI replies, and linked to your randomly generated Harbour user ID in PostHog and Supabase so we can personalize and understand use of the service.

1.2 Chat Messages

When you send a message, its text, a limited recent-history window, relevant conversation memory, your personalization summary, and the companion profile are sent through our Supabase Edge Function and OpenRouter to the selected AI model to generate a reply. Your complete in-app message history remains in the app's private local storage.

We retain the message you send and the corresponding AI response in a restricted Supabase table linked to your randomly generated Harbour user ID. This can include intimate or Spicy Mode content. Conversation-quality transcripts are automatically deleted within 30 days and are never sent to PostHog.

1.3 Device & Usage Information

When you purchase a subscription, Apple processes the transaction and we receive confirmation of your entitlement through RevenueCat, our subscription-management provider. We do not receive your payment card details.

We collect usage events through PostHog and Supabase, including screens visited, onboarding fields and choices, subscription actions, the name and identifier of companions you swipe left or right on, whether a message used Normal or Spicy Mode, model route, token/cache totals, and estimated model cost. These events are linked to a random identifier generated on your device. Raw message and AI-response text are not included in PostHog product analytics.

If you use Leave Feedback, we store the text you submit in Supabase together with the app version, build, iOS version, locale, subscription tier, and your random Harbour user ID so we can investigate and respond through product improvements. Feedback remains until it is resolved, archived, or deleted with your account.

1.4 Advertising Identifier (IDFA)

Harbour uses the Meta (Facebook) SDK for ad measurement. If you grant tracking permission via Apple's App Tracking Transparency (ATT) prompt, your device's advertising identifier (IDFA) may be shared with Meta to measure whether you downloaded the app after seeing a Harbour ad. This is used solely for ad attribution — it does not affect in-app content or companion behavior. You can withdraw consent at any time under Settings → Privacy & Security → Tracking on your iPhone.

2. How We Use Your Information

  • To run and personalize the app. Your onboarding answers drive matching, companion selection, and reply personalization.
  • To generate AI replies. Chat context is sent through Supabase and OpenRouter to DeepSeek models for standard and explicit Spicy routes.
  • To manage your subscription. We verify your entitlement through Apple and RevenueCat to unlock Gold or Platinum features.
  • To improve the app. Linked product analytics help us understand feature use and model cost, while short-retention transcripts help us evaluate conversation quality.
  • To measure ad performance. Only if you grant ATT permission, IDFA may be shared with Meta to attribute app downloads to ad campaigns. Anonymized purchase and trial events may also be shared with Meta to measure and improve our own advertising.

3. Third-Party Services

3.1 Supabase

Our chat backend and analytics database run on Supabase (supabase.com) in the United States. Product analytics are retained for up to 24 months. Conversation-quality transcripts are held in a service-role-only table and automatically deleted within 30 days. Feedback is retained until resolved, archived, or deleted with your account. Supabase's privacy policy is at supabase.com/privacy.

3.2 OpenRouter and AI Model Providers

We use OpenRouter as the API gateway for AI replies. We request provider routing that denies provider data collection where supported. Standard routes use DeepSeek Chat and explicit Spicy routes currently use DeepSeek V4 Flash; ordinary messages sent while Spicy Mode is enabled may still use the lower-cost standard route. OpenRouter and the selected model provider receive the chat context required to generate a response. OpenRouter's privacy policy is at openrouter.ai/privacy.

3.3 Meta (Facebook SDK)

We include the Meta iOS SDK for advertising attribution. If you opt in to tracking, the SDK may share your IDFA and app-event signals (e.g., app install) with Meta. You can opt out at any time via iOS Settings. Meta's Data Policy is at facebook.com/privacy/policy.

3.4 Apple

In-app purchases and subscription management are handled by Apple. Apple's privacy policy is at apple.com/legal/privacy.

3.5 RevenueCat

We use RevenueCat to manage subscriptions and entitlements. RevenueCat receives your purchase history and an anonymous app-user identifier — never your name, email, or chat content. RevenueCat's privacy policy is at revenuecat.com/privacy.

3.6 PostHog

PostHog receives profile/onboarding properties and product events keyed to your random Harbour user ID. PostHog does not receive raw chat message or AI-response text from Harbour. PostHog's privacy policy is at posthog.com/privacy.

4. Data Storage & Security

Your profile, companion matches, and full chat history are stored in your app's private local storage, protected by iOS data protection. Analytics and conversation-quality data are also stored as described above. We limit transcript access to the backend service role and automatically enforce the stated retention period, but no internet transmission or storage system can be guaranteed completely secure.

5. Children's Privacy

Harbour is intended for users aged 17 and older. We do not knowingly collect personal information from anyone under 13. If you believe a child under 13 has used the app, please contact us and we will take steps to address it. The Spicy Mode feature requires users to be 18+ and is gated by an explicit opt-in.

6. Your Choices & Rights

  • Delete your data. Use Settings → Data → Reset All Chats for local chats, or Delete Account to erase local data and request deletion of linked Supabase analytics and research rows. Contact us for access or deletion requests involving other processors.
  • Opt out of ad tracking. Go to iOS Settings → Privacy & Security → Tracking and disable tracking for Harbour.
  • Manage subscriptions. Go to iOS Settings → [Your Name] → Subscriptions to cancel or change your Harbour subscription.

If you are a resident of the EU, UK, or California and have questions about your rights (access, deletion, portability), contact us at privacy@getharbour.app.

7. International Users

Harbour is operated from the United States. Data may be processed in the United States and in countries where Supabase, OpenRouter, PostHog, DeepSeek, and their subprocessors operate.

8. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will update the "Last updated" date above. Continued use of the app after changes constitutes acceptance of the updated policy.

9. Contact Us

Questions about this policy? Reach us at:
privacy@getharbour.app
getharbour.app

Harbour
Home Privacy Policy Terms of Service Support

© 2025 Harbour. All rights reserved. Harbour companions are fictional AI characters, not real people.