Privacy Policy

Plain language. No legalese. Applies to all Harbor Privacy products.

Last updated: July 26, 2026  |  Applies to Harbor Privacy DNS, Harbor Booking, Harbor Money, Harbor Family, Harbor Privacy Fax, Career by Harbor Privacy, Harbor Neighbor, Harbor Scan, Harbor Breach Monitor, Harbor Stickers, Play Park, Harbor Burn, Harbor Snip, and Harbor Shield

The short version: We do not log your DNS queries, fax contents, resume submissions, or bank credentials. Harbor Money never connects to your bank — you forward us transaction emails and we parse them locally. Harbor Neighbor does not store any browsing data and erases device names when an account is deleted. Harbor Family is invite-only and private to your household — nothing you post there is visible outside your family's account. Harbor Burn always encrypts content in your browser before it ever reaches our servers — we store ciphertext only and cannot read a note's content at any point. Harbor Snip offers the same zero-knowledge encryption as its default "Private" mode, plus an opt-in "Fast" mode that trades that guarantee for a shorter, traditional-style link we can read. Harbor Shield runs entirely inside your browser and never sends us anything at all. We do not sell data. We do not share data with third parties except what is strictly required to deliver the service you paid for. The third parties we use are listed in full below.

1. Who We Are

Harbor Privacy operates twelve products: a DNS-based network protection service (Harbor Privacy DNS), a scheduling platform (Harbor Booking), a personal budgeting tool that reads forwarded transaction emails (Harbor Money), a private invite-only social app for a single family (Harbor Family), a secure anonymous fax service (Harbor Privacy Fax), an AI-powered career document tool (Career by Harbor Privacy), a multi-tenant neighbor portal for shared networks (Harbor Neighbor), a data broker opt-out service that finds and removes your personal info from people-search sites (Harbor Scan), a daily email data-breach checker (Harbor Breach Monitor), a zero-knowledge self-destructing note tool (Harbor Burn), a link shortener with an optional zero-knowledge encrypted mode (Harbor Snip, at snip.harborprivacy.com and hrbor.us), and a free browser extension that blocks trackers and ads locally (Harbor Shield). All products are operated under the Harbor Privacy brand from Pembroke, MA.

Questions: privacy@harborprivacy.com or open a ticket at help.harborprivacy.com.

2. What We Collect and Why

Harbor Privacy DNS

DNS queries are processed in memory only and never written to disk or retained. We collect:

Harbor Privacy Fax

Career by Harbor Privacy

Harbor Booking

Harbor Money

We never connect to your bank. Harbor Money does not request, store, or transmit any banking credentials. Instead you forward bank-issued transaction emails to a private address we generate for you.

What we explicitly do not store:

If we send your transaction text to an AI model as a fallback parser (when our built-in parsers fail), we send only the subject + plaintext body — no other account data — and the model provider's policy applies to that one request. AI parsing is opt-out in Settings.

Harbor Neighbor

Harbor Neighbor is a multi-tenant portal for shared physical networks. Each neighbor gets their own VLAN, SSID, and (where supported) WireGuard VPN peer. We collect only what is needed to provision and manage your slice of the network:

What we explicitly do not store:

Account deletion. When you delete your Harbor Neighbor account, all device names you entered are permanently removed along with the rest of your record. We do not retain device labels after deletion — there is no "soft delete" archive of device names tied to a former neighbor.

Harbor Scan

Harbor Scan finds your personal information on data broker / people-search sites (Spokeo, Whitepages, BeenVerified, etc.) and files automated CCPA opt-out requests on your behalf as your authorized agent under Cal. Civ. Code § 1798.135(c). To do this we must collect, store, and transmit the identifiers brokers use to index people. We do not minimize this data because brokers will not act on partial requests.

What we collect and store:

What we send to brokers (this is the entire point of the service):

What we explicitly do not do:

Retention & deletion. Harbor Scan honors two automatic deletion clocks:

Deletion is enforced by an automated nightly purge — there is no human review step that could keep your data around longer. Brokers may retain previously-filed opt-out requests in their own logs; you can re-request deletion from them directly under CCPA at any point.

Harbor Breach Monitor

Harbor Breach Monitor (breach.harborprivacy.com) checks the email addresses you choose to monitor against known data breach records once a day, and emails you the first time a new breach shows up. It is included free for any active Harbor Privacy customer, including Harbor Light, up to 3 monitored emails; a paid add-on raises that to 8.

What we collect and store:

Every monitored email address and breach record is stored as AES-256-GCM ciphertext, not plain text — the same encryption pattern used for personal data across Harbor's other products. We do not store breach contents (passwords, personal details exposed in a given breach), only the fact that an email appeared in a named breach.

To check a monitored email, we send that email address to XposedOrNot, a third-party breach-lookup service, once per day. See the third-party table below for what that service receives.

What we explicitly do not do:

Deleting your data. Remove a monitored email from your dashboard at any time and its record (including breach history) is deleted immediately. If you've purchased the extra-emails add-on, cancelling it (via the link in your confirmation email or by contacting support@harborprivacy.com) stops that $2.99/month charge without affecting your underlying Harbor Light, Harbor Remote, or Harbor ad-blocking subscription — they are billed and cancelled independently. Losing Breach Monitor eligibility (for example, cancelling your Harbor Privacy plan entirely) does not by itself delete already-stored monitored emails; remove them from the dashboard first, or ask support to delete them for you.

Harbor Stickers (Shop)

We do not run the checkout — Stripe does. When you preorder or buy a sticker, the whole payment and order form is hosted and processed by Stripe. Stripe collects your name, email address, shipping address, and payment details directly. We never see or store your card number.

Harbor Family

Harbor Family (harborfamily.us) is a private, invite-only social app for a single family: a photo/update feed, comments and reactions, shared photo albums, a shared calendar, and 1:1/group messaging. It has its own Privacy Policy; in summary:

Harbor Help (Support Tickets)

Support tickets opened at help.harborprivacy.com contain only what you write to us: your email, an optional name, a category, a subject, and a message body. We use this to reply to you and nothing else — never for marketing, never shared with third parties.

Retention. Tickets are automatically deleted 30 days after they are closed. Open tickets stay until they are resolved or you ask us to discard them. The same nightly purge that enforces the Harbor Scan deletion clocks also enforces this one.

Play Park (Games)

Play Park (harborplay.us) is a family games site you can play with no account and no personal information. It has its own privacy policy and no-logs policy; in summary:

Harbor Burn

Harbor Burn (burn.harborprivacy.com) is a zero-knowledge, self-destructing note tool. Encryption and decryption happen entirely in your browser — the key lives in the link's URL fragment (the part after #), which browsers never send to any server. We cannot read a note's contents at any point, before or after you create it. Harbor Burn is text-only and does not accept file, image, or attachment uploads.

Harbor Snip

Harbor Snip (snip.harborprivacy.com and hrbor.us) is a link shortener with two modes you choose per link. Private mode is zero-knowledge: the destination URL is encrypted in your browser before it is sent, and the decryption key lives only in the shortened link's URL fragment (the part after #), which browsers never send to any server. We cannot read where a Private link points, before or after it is created — the trade-off is a longer link, since the key has to travel with it. Fast mode stores the destination as plain text on our server, like a traditional URL shortener (e.g. Bitly), so it can issue an instant server-side redirect and produce a short link with no key attached. We can read a Fast link's destination; a Private link's, we cannot.

Harbor Shield (Browser Extension)

Harbor Shield is a free Chrome/Edge extension that blocks trackers and ads and strips tracking parameters from links. Every bit of that runs locally in your browser using Chrome's built-in declarativeNetRequest blocking engine — Harbor Shield has no account, no login, and no server of its own. Install it and it runs standalone.

3. Third-Party Services — Full Disclosure

We use a minimal, carefully chosen set of third-party services. Here is every external service that touches your data across all Harbor Privacy products:

ServicePurposeProductsData SharedTheir Policy
Stripe Payment processing DNS, Booking, Fax, Career, Money, Neighbor, Stickers, Burn, Breach Monitor (where billing applies) Payment card details, transaction amount, email, and (for sticker orders) shipping name and address. We never see or store raw card numbers. Harbor Burn Pro purchases use a random token instead of an email or account. stripe.com/privacy
XposedOrNot Data breach lookup Breach Monitor The email address being checked, sent once per monitored email per day. XposedOrNot returns which named breaches (if any) that email appears in; we do not send or receive passwords or other breach contents. xposedornot.com/privacy
Cloudflare Turnstile Bot/abuse verification at note or link creation Burn, Snip A verification token and your IP address are sent to Cloudflare to confirm you are not a bot. No note content or destination URL is ever sent — Turnstile runs before your content is encrypted or created. cloudflare.com/privacypolicy
Cloudflare Email Routing Receives transaction-alert emails forwarded by users to their private Harbor Money address Money The complete forwarded email (from address, subject, body) en route to our parser. Cloudflare acts as a conduit and does not retain forwarded mail after delivery. cloudflare.com/privacypolicy
Anthropic (Claude Haiku) Fallback transaction parser when our built-in parsers can't read an email, and extraction for uploaded bank/card statement files (PDF, photo, or screenshot) Money (optional, can be disabled) For email fallback: only the subject + plaintext body of the single email being parsed. For statement uploads: the statement file content (text or page images). No account login credentials are ever involved — Money never connects to your bank. Uploaded files auto-delete from our storage after 7 days. anthropic.com/privacy
Telnyx Fax transmission (T.38 FoIP) Fax Your document (temporarily, for transmission only), destination fax number, delivery status. Telnyx operates as a conduit and does not retain document contents after transmission. telnyx.com/privacy-policy
Anthropic AI document generation (Claude API) Career Resume text and job description submitted for document generation. Subject to Anthropic API data handling policies. We do not send identifying information beyond document content. anthropic.com/privacy
Resend Transactional email (receipts, login links, fax delivery, parse-failure notes, neighbor invitations, family invites and password resets) DNS, Booking, Fax, Career, Money, Neighbor, Family Your email address and the content of the transactional email (receipt or delivery notification). Not used for marketing. resend.com/privacy
Umami Analytics Privacy-respecting page view analytics (self-hosted by us) DNS, Booking, Fax, Career, Money, Neighbor, Family Aggregate page view counts and referrer sources only. No cookies, no fingerprinting, no individual tracking, no personally identifiable information collected. umami.is/privacy
Oracle Cloud Server infrastructure hosting DNS, Booking, Fax, Career, Money, Neighbor, Family All Harbor Privacy services run on Oracle Cloud Infrastructure (OCI) in the US. Oracle provides the compute environment but does not access application-level data. oracle.com/legal/privacy
AdGuard Home DNS filtering engine (self-hosted) DNS Self-hosted on our Oracle Cloud infrastructure. No data leaves our servers. AdGuard Home is open source (GPL v3). Query logs are disabled. adguard.com/privacy

We do not use Google Analytics, Meta Pixel, or any advertising technology on any Harbor Privacy property. We do not sell, rent, or share your data with advertisers or data brokers.

4. Cookies and Analytics

We use Umami Analytics -- a cookieless, privacy-respecting analytics platform. It collects no personally identifiable information, uses no cookies, and does not fingerprint your browser. It gives us aggregate traffic counts only.

No advertising or tracking cookies, and no tracking scripts, are present on any Harbor Privacy property. The only cookies we ever set are first-party functional ones — a session cookie to keep you logged in on account-based products, and a cookie that remembers a Play Park Pro purchase on your device.

5. Data Retention

6. Security

All data in transit is encrypted via TLS. Our servers run hardened Ubuntu instances on Oracle Cloud with restricted SSH access and no unnecessary open ports. API keys and secrets are stored in systemd environment variables, never in source code or logs. We do not operate shared hosting environments.

7. Your Rights

Because we collect so little, there is very little to act on -- but you have the right to request deletion of your account and associated data, ask what data we hold about you, and correct any inaccurate account information. Email privacy@harborprivacy.com and we will respond within 5 business days.

8. Law Enforcement

Because we do not log DNS queries, fax contents, or document submissions, there is nothing substantive to hand over. In the event of a valid legal request, we can only provide what we actually retain: account email addresses and Stripe payment records for DNS subscribers. We have no ability to produce browsing history, fax contents, or document contents because we do not store them. For Harbor Burn, we can provide only the ciphertext blob (which we cannot decrypt), an IP hash, and Stripe payment records for Pro purchases — never plaintext note content, because we never have it. For a Harbor Snip Private-mode link, we can provide only the encrypted destination blob, which we cannot decrypt, and no IP address, because the rate-limit hash is deleted after one hour and our web server keeps no access logs for the service. For a Fast-mode link, we can provide the destination URL as stored, since we can read it — but still no IP address, for the same reason.

9. Children

Harbor Privacy services are not directed at children under 13. We do not knowingly collect data from children.

10. Changes to This Policy

If we make material changes, we will update the date above and notify active DNS subscribers by email. Continued use after an update constitutes acceptance.

11. Contact

Harbor Privacy  |  privacy@harborprivacy.com  |  harborprivacy.com

MORE FROM HARBOR PRIVACY

Adblock — block ads on every device · Fax — send a fax anonymously · Money — budget without bank login · Booking — staff scheduling · Family — a private space for your family · Career — AI resume + cover letter · Scan — remove your name from data brokers · Help — docs & support tickets