Legal
Privacy policy
Harbor is operated by Yelle Software LLC. This page describes what we collect to run the waitlist, the portal, and hosted apps.
Waitlist
If you join the waitlist, we store the email you submit and the fact that you consented to Harbor updates. That profile lives in Klaviyo. No Harbor account is created from the waitlist form.
Accounts and billing
- Sign-in is handled by Logto (email and user id)
- Paid plans and invoices are handled by Stripe. Card numbers stay with Stripe
- We store membership, app records, and billing status in the Harbor control plane
Apps you host
You own your application code, database contents, and environment variables. We store git remotes, deploy credentials, and secrets so we can build and run the app. Secrets live in Infisical under isolated Harbor paths. Database dumps follow the backup policy.
Site analytics
Harbor uses a self-hosted Umami instance for page analytics. Session recording may also run so we can see how the public site and portal are used. We do not sell this data.
Who processes data
- Klaviyo: waitlist email
- Logto: authentication
- Stripe: payments
- Cloudflare: DNS, proxy, TLS, and off-site backup storage
- Infisical: secrets
- Teleport: dedicated-app SSH
Cookies
We use cookies to keep you signed in through Logto and to complete Stripe checkout returns. Analytics scripts may set their own cookies.
Retention
Waitlist emails stay until you unsubscribe or ask us to delete them. Account and billing records stay while you have a membership, then for as long as we need them for invoices and operations. On cancellation, apps enter a deprovision grace period so you can export data. After that window, we remove the app and its backups per the backup policy.
Requests
Email [email protected] to access, correct, or delete waitlist or account data we hold. We may need to keep records required for billing or security.
Effective 15 September 2026. This is how Harbor is run, not legal advice. We will update this page when the practices change.