Legal

Privacy Policy

This policy explains the document-processing data path, the history Harp retains, and the choices available to you.

Last updated: August 4, 2026

The short version

Harp is a desktop workflow, not an offline-only product. To extract information, the app sends document content to Harp's processing service and configured AI/OCR providers. Harp does not store the original uploaded file payload in its application database, but it does retain processing history—including file names and extracted results—until you clear that history or ask us to delete your account. Organizations with specific security, contractual, or data-residency requirements should evaluate the service against those requirements.

1. Scope

This policy applies to the Harp website, desktop application, and the Harp-operated services used to authenticate accounts, process documents, and provide product support.

2. Information We Collect

Depending on how you use Harp, we collect:

  • Account and session information: name, email address, authentication records, session details, IP address, and device/browser information associated with a session.
  • Workspace information: templates, extraction instructions, output settings, watch folder settings, and API-key identifiers or hashes needed to provide the service.
  • Processing history: file name, file type, template and output configuration, processing status, timestamps, page and usage counts, confidence information, and extracted results.
  • Billing and support information: subscription and payment-related records supplied by our payment providers, plus communications you send to support.

Harp's application database is not designed to store the original document file payload you submit for processing. That payload is handled in transit and in memory to perform the requested extraction. This does not mean the document is kept only on your device: it is sent to Harp and one or more processing providers while the request runs.

3. How Document Processing Works

When you initiate an extraction, Harp sends the document content and the template instructions needed for the request to Harp's processing service. That service may send relevant content to configured AI and OCR providers, including OpenAI or Azure OpenAI and Mistral-compatible OCR endpoints, depending on the selected processing path and deployment configuration.

These providers process document content to return OCR text or structured extraction results. Their handling of data is governed by the applicable provider terms, data-processing commitments, and the configuration of Harp's account with that provider. Harp does not use customer document content to train its own models.

4. How We Use Information

  • Authenticate users and operate the desktop application.
  • Process documents according to your templates.
  • Return, replay, and display processing results and history.
  • Measure usage, manage subscriptions, prevent abuse, and provide support.
  • Maintain, secure, and improve the service.

5. Service Providers and Disclosures

We do not sell or rent personal information for marketing. We disclose information only as needed to operate Harp, including to infrastructure, authentication, payment, email, and AI/OCR service providers; when required by law; to protect rights and safety; or in connection with a corporate transaction.

AI/OCR providers receive the content necessary to process a request. They are not used as advertising partners. Provider locations and subprocessors can change, so Harp does not make a standard-service promise that all processing stays in one country or region.

6. Retention and Deletion

DataCurrent retention
Original document payloadNot stored in Harp's application database; transmitted for the duration of processing.
Processing history and extracted resultsRetained until you clear processing history or we complete a verified account-deletion request. Harp does not currently apply a fixed automatic deletion period to this history.
Usage and subscription recordsRetained while needed to provide service, administer billing, prevent abuse, and meet legal or accounting obligations. Clearing history removes history items and scrubs related filename, confidence, and page-confidence metadata from usage records; aggregate metering remains.
BackupsDeleted data may remain in backups until the relevant backup cycle expires. We do not promise immediate removal from backups.

Use the application's clear-history control to remove completed and failed processing records. If you need account deletion, contact us using the address below. Legal, security, and financial records may be retained where required or permitted by law.

7. Security

We use administrative, technical, and organizational measures intended to protect the service. No system can guarantee absolute security. You are responsible for deciding whether the data you submit is appropriate for this service and for maintaining controls over your own devices, exports, and user access.

Customer-specific security, processing, or residency commitments apply only when included in a written agreement. Contact us if your organization needs additional information to evaluate Harp.

8. Your Choices and Requests

Subject to applicable law, you may request access, correction, deletion, or information about the personal data we hold about you. You may also opt out of non-essential communications. Contact us at privacy@harp.app to make a request. We may need to verify your identity before acting on it.

9. International Processing

Harp and its service providers may process information in countries other than the one where you live or work. Those countries may have different data-protection laws. Contact us if your organization needs to confirm processing locations for a particular workflow.

10. Changes and Contact

We may update this policy as the service changes. Material changes will be reflected by updating the date at the top of this page.

Harp

Privacy requests: privacy@harp.app

Website: getharp.app