← Back to Harbor

Privacy Policy

Effective date: March 2026

1. Overview

Harbor ("we", "us", "our", or "Company") operates the Harbor AI receptionist platform. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.

Please read this Privacy Policy carefully. If you do not agree with our policies and practices, please do not use our service.

2. Information We Collect

We collect information in the following ways:

  • Practice Information: Practice name, therapist name, location, specialties, insurance accepted, office hours
  • Contact Information: Email address, phone number for your practice
  • Call Data: Phone numbers of callers, call duration, transcripts of calls, summaries generated by our AI
  • Patient Information: Patient phone numbers, appointment information, crisis indicators from calls
  • Intake Screenings: PHQ-2 and GAD-2 scores collected during calls
  • Billing Information: Stripe customer ID and subscription status (not credit card details)

3. How We Use Your Information

We use the information we collect for the following purposes:

  • Providing and maintaining the Harbor AI receptionist service
  • Generating call summaries and sending them to your practice email
  • Tracking crisis indicators and alerting you when detected
  • Managing your subscription and billing
  • Improving and optimizing our service through AI model updates
  • Communicating with you about your account or service updates
  • Complying with legal obligations

4. Data Retention

We retain call logs and transcripts for 90 days by default. After 90 days, call data is automatically deleted unless you request an extended retention period.

Your practice information (name, contact details, settings) is retained as long as your account is active. After account deletion, we retain data for 30 days to comply with legal requirements.

5. HIPAA and Patient Privacy

Harbor is designed to help therapy practices comply with HIPAA. However, we recommend that each practice:

  • Execute a Business Associate Agreement (BAA) with Harbor before using the service
  • Ensure patients consent to calls being answered by AI
  • Use secure patient phone numbers and avoid sharing PHI over phone
  • Regularly review crisis alerts and call summaries for accuracy

Please contact privacy@harbor.ai to execute a BAA if your practice hasn't already.

6. Data Sharing

We do not sell or trade your practice data or patient information. We may share data only in these circumstances:

  • Service Providers: With third parties (Vapi, Twilio, ElevenLabs, Stripe) who help us operate Harbor. These are bound by confidentiality agreements.
  • Legal Requirements: If required by law, court order, or government request
  • Account Protection: If necessary to protect the safety, rights, and property of Harbor, our users, or the public

7. Security

We implement industry-standard security measures including encryption, secure authentication, and regular security audits. However, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security of your data.

8. Your Rights

You have the right to:

  • Access: Request a copy of all data we hold about your practice
  • Deletion: Request deletion of your account and associated data (subject to legal retention requirements)
  • Export: Export your data in a portable format
  • Correction: Correct inaccurate information about your practice

To exercise these rights, contact privacy@harbor.ai.

9. Third-Party Links

Harbor may contain links to third-party websites. We are not responsible for the privacy practices of these external sites. Please review their privacy policies before providing any information.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email. Your continued use of Harbor after changes constitutes acceptance of the updated policy.

11. Contact Us

If you have questions about this Privacy Policy or our privacy practices, please contact:

Harbor Privacy Team

Email: privacy@harbor.ai