Skip to content
harny
PlatformDevelopersBenchmarks
Get early accessEarly access↗︎
PlatformDevelopersBenchmarks

Harny / Legal

Privacy policy.

Last updated September 12, 2026Vexta Labs Inc.

How Harny handles information when an app connects your data. Find what is collected, how it is used, and how to contact us.

Website termsPrivacy policyDeveloper agreement
On this page
1. Who We Are2. What This Page Is — and Isn't3. What Data We Receive4. What We Store5. How Long We Retain It6. Who We Share With7. Your Rights8. Google API Services User Data Policy / Limited Use Compliance9. How to Request Deletion of Your Data10. International Data Transfers11. Children12. Cookies and Tracking on harny.ai13. Changes to This Policy14. Contact15. Lawful Basis for Processing (EEA/UK Users)16. Canadian Privacy Law (PIPEDA)

Questions about this policy?

Contact Harny ↗︎
On this page +
1. Who We Are2. What This Page Is — and Isn't3. What Data We Receive4. What We Store5. How Long We Retain It6. Who We Share With7. Your Rights8. Google API Services User Data Policy / Limited Use Compliance9. How to Request Deletion of Your Data10. International Data Transfers11. Children12. Cookies and Tracking on harny.ai13. Changes to This Policy14. Contact15. Lawful Basis for Processing (EEA/UK Users)16. Canadian Privacy Law (PIPEDA)

1. Who We Are

Harny is operated by Vexta Labs Inc., a company incorporated in British Columbia, Canada.

  • Address: Burnaby, British Columbia, Canada
  • Contact: support@harny.ai
  • Data Protection Officer: Not appointed. For data-protection inquiries, contact support@harny.ai.

2. What This Page Is — and Isn't

Harny is infrastructure that the app you connected uses to process context for AI features. Your contractual relationship is with that app's developer, not with Harny directly. The developer decides what reaches us and why; we process it on their instructions, as their processor. This page describes what Harny does with data that passes through our systems when you authorize a connection.

Harny does not maintain a direct account relationship with end users. You do not have a Harny account, and visiting this page does not create one.

3. What Data We Receive

Developer Account Data

If you are a developer using the Harny platform, we collect the account information you provide when you create your developer account: name, email address, and app configuration details. This data is collected through our authentication provider and stored for account management, billing, and platform communications.

End-User Data (via Connected Apps)

When you authorize a connection through an app that uses Harny, we receive data from your connected account. The specific data depends on the authorization you granted.

Google Account Data

We request the following Google scopes:

  • https://www.googleapis.com/auth/gmail.readonly — read your Gmail messages and metadata in order to derive structured context facts (such as calendar invites you've received, order confirmations, recurring sender patterns, and relevant correspondence summaries) that the app you connected uses to make AI responses personalized to you. We also keep a copy of the fetched messages for a limited period (see Section 4 and Section 5 below).
  • https://www.googleapis.com/auth/calendar.readonly — read your Google Calendar events and metadata in order to extract scheduling context (upcoming meetings, recurring events, time-zone awareness) that the app you connected uses to make AI responses more relevant and timely. We do not create, modify, or delete any calendar events.
  • https://www.googleapis.com/auth/drive.readonly — where the app you connected offers a Google Drive connection, read your Drive documents in order to derive context from their text. We do not create, modify, or delete any files.
  • https://www.googleapis.com/auth/userinfo.email — verify the email address of the Google account you authorized so the app you connected knows which Google account is linked.

Each connection asks only for the scopes that source needs. Google connections are made available to an app on approval, as described in the Developer Agreement.

We retrieve recent messages when a connection is first made, and continue to process new messages as they arrive while the connection remains active.

4. What We Store

We process the information described in this section to provide, personalize, improve, and develop the service; to derive aggregate insights; and to produce contextual recommendations.

When you authorize Harny to read from your connected account, the connected app's Harny integration derives structured context facts from each message (for example, "user received flight delay notification for reservation ABC, 2-hour delay"). We store:

  • Structured facts— the entities, relationships, and structured information drawn from your messages
  • Episode summaries— a short paraphrase of each message's meaning
  • Search representations— a mathematical representation of the material, used to search it
  • Metadata anchors— message ID, timestamp, sender domain, byte size, and category tier
  • Copies of the items we fetched— kept so we can serve and re-process them without going back to your account each time
  • Process audit trail— logs of the processing itself

What the fetched copies contain.Depending on the source, a copy holds either the item's text as received, including its subject line where it has one, or a set of fields extracted from the item. Where a piece of content is short enough that the whole of it is the fact, we keep it as it came in rather than deriving a separate summary from it.

Two boundaries apply to that stored content. It does not cross from one app to another: what another app can ever read about you is the abstracted facts described in Section 6, never the stored message text. And it is not returned as source content through our developer interface.

Harny counts which senders and categories write to a connected inbox (never the email content) to power personalization; this is stored separately from the user's memory.

In practice that means sender domain, category, and date. It is held separately from your extracted context and is never used to answer queries. Senders in sensitive categories, such as financial, medical, legal, and insurance, are excluded.

5. How Long We Retain It

Different material is kept for different periods.

  • Copies of items fetched from your connected account are kept for a set period, configurable per connection, defaulting to 90 days, after which they are deleted automatically. The period can be shortened, lengthened, or set to no expiry.
  • Structured facts, summaries, and search representations have no expiry. They exist until they are deleted. No timer and no sweep removes them. They go when your data is erased, or when a specific item is deleted.
  • Records of what an app's agent did are kept indefinitely.
  • Operational material— delivery attempts, query traces, and similar — is swept on shorter schedules.

Aggregated cohort statistics describing no individual (such as quality metrics and platform-level usage patterns) may be retained longer. They cannot be used to identify you or to reconstruct your original messages.

6. Who We Share With

We share user data only with:

  • Cloud infrastructure providersthat host and operate Harny's services. These providers process data on our instructions only and are bound by their own data-protection commitments.
  • Large-language-model (LLM) providers, for the purpose of deriving structured context from content, under our agreements with those providers.
  • The connected app's developer, and other applications on the Harny platform that you also use, in the form of the context requested: structured facts, summaries, and limited metadata (sender domain, timestamp, category tier). Other applications receive abstracted facts only, such as a preference, a habit, or an interest, and only about people who are already their users; stored message text is never shared between applications, including short content kept as written, and some facts are marked as not shareable between applications. No raw-content field is returned on our developer API. The context returned to the app you connected may quote a short excerpt of the material it was drawn from.
  • Authentication and integration services that handle authentication flows and connection brokering but do not receive your message content.

Section 8 sets out the additional restrictions that apply to data derived from your Google account.

7. Your Rights

You have the following rights regarding your data processed by Harny:

  • Access: You may request a copy of the context Harny holds about you. Contact the developer of the app you connected, or email support@harny.ai.
  • Rectification: To update your data, re-authorize the connection through the app you use. Harny will process the updated source data on the next sync cycle.
  • Erasure: You may request deletion of your data from Harny (see Section 9 below for the deletion path, and for what a deletion request reaches).
  • Restriction: You may request that we restrict processing of your data while a concern is being resolved. Contact support@harny.ai.
  • Portability:You may ask us for a copy of the context we hold about you, and we will provide it in a machine-readable form. This is a request path — you ask us and we produce it — not a self-serve download. Contact support@harny.ai.
  • Objection: You may object to processing by revoking the connection (see Section 9).
  • Automated decisions:Harny's extraction process is automated but does not produce decisions with legal or similarly significant effects on you. The extracted context is used by the app you connected to inform AI responses — not to make decisions about your eligibility for services, credit, employment, or similar outcomes. You may contact support@harny.ai if you have concerns about how extracted context is being used.

Because Harny operates as infrastructure beneath the app you use, these rights are exercised either through that app's developer or by contacting Harny directly at support@harny.ai. We respond to verifiable requests within 30 days.

8. Google API Services User Data Policy / Limited Use Compliance

Harny's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically:

  1. We do not use Google user data to serve advertisements, including re-targeting, personalized advertising, or interest-based advertising.
  2. We do not transfer Google user data to third parties except as necessary to provide or improve the integration the user authorized (the specific exceptions are listed in Section 6 above) and only under contractual terms that bind those third parties to equivalent restrictions.
  3. We do not allow humans to read Google user data except (a) with the user's affirmative consent for specific messages, (b) when necessary for security purposes (such as investigating abuse), or (c) when necessary to comply with applicable law.
  4. We do not use Google user data to develop, improve, or train generalized AI/ML models. Our use of third-party LLM providers (Section 6) is to derive context from user-authorized data on a per-request basis.

9. How to Request Deletion of Your Data

The Harny integration is invisible to you in normal use — you interact with the app you signed up for, not with Harny directly. To request deletion of your data from Harny:

  1. Contact the developer of the app you connected. They can revoke the Harny integration on your account, which removes Harny's access immediately and triggers data deletion within 30 days.
  2. What a deletion request reaches.Erasure removes the structured facts, summaries, and search representations held about you, the copies of items fetched from your connected account, and the records of what an app's agent did for you. Two things are kept: the record we hold for you survives in scrubbed form with name and email removed; and a minimal record that the erasure happened survives, in a form that does not identify you.
  3. If you cannot reach the app developer, or want a deletion path that does not depend on them, email support@harny.aiwith: (a) the email address you authorized, (b) the name of the app you connected, and (c) "deletion request" in the subject. We will execute the deletion within 30 days and email you when complete.
  4. Revoke Google access directly at https://myaccount.google.com/permissions. This immediately stops Harny from receiving any further data from your Google account. Existing extracted data still requires the deletion request above to remove from Harny's storage.

10. International Data Transfers

Harny's infrastructure operates from the United States. When you use a Harny-powered app from outside the US (including from the European Economic Area, the United Kingdom, or Switzerland), the data extracted from your authorized accounts will be processed in the US.

We rely on the following legal mechanisms for these transfers:

  • EU/UK/CH to US:Standard Contractual Clauses (SCCs) with our cloud infrastructure and LLM providers, per the European Commission's 2021 modernized SCCs and the UK ICO's International Data Transfer Addendum.
  • Adequacy decisions: Where applicable, such as an adequacy decision covering the receiving jurisdiction.

11. Children

Harny does not knowingly process data of users under 13 years of age. The apps you connected are responsible for age-appropriate use of their products. If you believe data belonging to a child under 13 has been processed by Harny, contact support@harny.ai and we will delete it promptly.

12. Cookies and Tracking on harny.ai

The harny.ai website sets no cookies. We do not use Google Analytics, Facebook Pixel, advertising trackers, or cross-site marketing cookies.

If cookies are introduced in the future (for example, for bot-management or analytics purposes), this section will be updated before they are deployed.

The legal pages on harny.ai (this Privacy Policy and the Terms of Service) will never load marketing or advertising cookies.

13. Changes to This Policy

We will update the "Last Updated" date at the top of this page when we make changes. For material changes that affect your rights or how we handle your data, we will provide notice at least 30 days before the change takes effect by disclosing the change to the developers of apps that use Harny, who will inform their users through their own communication channels.

Previous versions of this policy are maintained in our version history and available upon request.

14. Contact

For questions about this Privacy Policy or your data:

  • Email: support@harny.ai
  • Response time: We aim to respond within 30 days to verifiable requests.

If you are unsatisfied with our response, you may lodge a complaint with your local data protection authority.

15. Lawful Basis for Processing (EEA/UK Users)

For users located in the European Economic Area or United Kingdom, we process your data on the following legal bases:

  • Legitimate interest(GDPR Art 6(1)(f)) — the developer of the app you use has a legitimate interest in providing personalized AI features to you, and you authorized the connection that enables this processing. Our processing does not produce decisions with legal or similarly significant effects on you.
  • Contract performance(GDPR Art 6(1)(b)) — where the processing is necessary to perform the service you authorized through the app you connected.

We do not rely on consent as our lawful basis for processing. Your authorization of the connection through the app's OAuth flow is a functional authorization, not a GDPR consent mechanism. The lawful basis flows from the developer's relationship with you.

16. Canadian Privacy Law (PIPEDA)

Vexta Labs Inc. is incorporated in British Columbia, Canada. The Personal Information Protection and Electronic Documents Act (PIPEDA) and British Columbia's Personal Information Protection Act (PIPA) govern our collection, use, and disclosure of personal information in the course of commercial activities.

Under PIPEDA and PIPA:

  • Purpose: We collect and process personal information to provide, personalize, improve, and develop the service described in this policy; to derive aggregate insights; and to produce contextual recommendations.
  • Consent: Your authorization of the OAuth connection through the app you use constitutes meaningful consent to the processing described in this policy.
  • Access and correction: You may request access to the personal information we hold about you, or request correction, by contacting support@harny.ai.
  • Complaints: If you have concerns about our handling of your personal information, you may contact the Office of the Privacy Commissioner of Canada (www.priv.gc.ca) or the Office of the Information and Privacy Commissioner for British Columbia (www.oipc.bc.ca).
harny

Agent harness infrastructure.
Context, connection, continuity.

Show us what you’re building.

Products, partnerships, or the story behind Harny. Talk directly with the team.

support@harny.ai ↗︎
BenchmarksPrivacy policyTerms of serviceDeveloper agreement
© 2026 Harny · Vexta Labs Inc.