Historical policy: September 10, 2026. Retained for reference; applicability depends on your agreement.

Legal

Privacy Policy

Effective September 10, 2026 · Version 2026-09-10

Harbor (the “Service”) is operated by Harbor Office, Inc., a Delaware corporation with its principal office at 4506 Laverne Ave, Klamath Falls, OR 97603 (“Harbor,” “we,” “us,” or “our”). This Privacy Policy describes how we collect, use, disclose, and safeguard information when therapy practices (“Customers”) and their patients interact with the Service.

Harbor handles Protected Health Information (PHI) on behalf of its Customers under the Health Insurance Portability and Accountability Act of 1996, as amended by HITECH (the “HIPAA Rules”). We act as a Business Associate to each Customer. A signed Business Associate Agreement (BAA) governs the permitted uses and disclosures of PHI and is referenced from this Policy.

1. Information we collect

We collect three categories of information:

(a) Customer account data — practice name, clinician name, NPI, business email, phone, billing address, and Stripe customer/subscription identifiers. We do not store full payment card numbers; payment processing is performed by Stripe.

(b) Protected Health Information (PHI) — patient demographics, appointment details, clinical notes, assessment scores (PHQ-9, GAD-7, C-SSRS), call and SMS transcripts, voicemail audio, intake form responses, and any other PHI the Customer chooses to enter, generate, or receive via the Service.

(c) Usage data — on our public marketing pages only, a count of pages viewed and a coarse country and region. This is recorded by Harbor’s own software into Harbor’s own database, and is described in full in section 8. No usage analytics of any kind run on the signed-in application or the patient portal.

2. How we use information

We use information to:

We do not use PHI to train general-purpose AI models, sell PHI, or share PHI with advertising networks.

3. Subprocessors

We use the following subprocessors. Each that receives PHI has signed a BAA with Harbor where required (see status below).

SubprocessorPurposeBAA
Amazon Web Services (AWS)Hosting, RDS, KMS, Cognito, S3, Chime SDK, BedrockExecuted
PauboxHIPAA-aligned transactional email deliveryExecuted
StripePayment processing (Customer subscriptions only; no PHI)Not applicable (no PHI)
SignalWireVoice telephony and SMS transportExecuted
Retell AIReal-time voice agent runtimeExecuted
Anthropic (via AWS Bedrock)LLM inference for crisis analysis and note draftingCovered under AWS BAA (Bedrock); no PHI used for training
Stedi270/271 eligibility and 837/835 claim transactionsExecuted

All subprocessors that transmit or process PHI have executed BAAs with Harbor. Customers may request current BAA documentation before signing.

4. Data retention, and what happens when a practice leaves

Harbor keeps records for seven (7) years. That period is enforced automatically, once a day, across call records, text-message conversations, and audit logs. Seven years is the strictest of the periods that apply to us: HIPAA requires six for compliance documentation, and the strictest state behavioral-health record rule we operate under requires seven.

Harbor does not record therapy sessions. Telehealth sessions are not recorded, and there is no setting that turns recording on. Phone calls answered by Harbor’s AI receptionist are recorded — the caller is told so at the start of the call — and those recordings follow the seven-year period above. Voicemail audio is stored in Harbor’s encrypted storage and is not deleted on a schedule; the copy held by our telephone carrier is deleted as soon as we have verified our own copy. Operational system events that are not part of a clinical record — routine heartbeats and status messages — are cleared after 30 days.

Clinical records are never deleted by an automated job. Charts, notes, treatment plans, and assessments are retained for at least the period required by the law of the state where the practice operates and by the clinician’s licensing board. Harbor honors whichever of those periods is longest. Harbor does not decide when a clinical record expires, and Harbor does not delete one out from under the practice that owns it.

The operational retention schedules above are Harbor defaults, not limits on legally required clinical-record retention. Harbor does not currently offer a per-practice retention setting. If a practice needs a different period to satisfy a state or board requirement, contact us and we will handle it as a documented, individual request.

When a subscription ends, patient data remains available for 90 days so the practice can export it, hand off continuity of care, and answer any patient’s HIPAA right-of-access request. After that window, access to the application ends, but clinical records, audit logs, and billing records are preserved for the retention periods described above rather than destroyed. The full terms are in our Cancellation and Refund Policy, which governs if there is any difference between the two documents.

Where a Customer instructs us in writing to return or destroy PHI, and no law or licensing-board rule requires us to keep it, we will do so and confirm in writing. Destruction follows NIST SP 800-88 media-sanitization guidance.

5. Security

PHI is encrypted in transit (TLS 1.2+) and at rest (AWS KMS, customer-managed keys per HIPAA §164.312(a)(2)(iv)). Production access requires SSO with enforced MFA; standing access is limited to designated workforce members and is reviewed quarterly. See our Security page for technical and administrative safeguard detail mapped to the HIPAA Security Rule.

6. Breach notification

Harbor will notify the affected Customer of a suspected or confirmed Breach of Unsecured PHI without unreasonable delay and in no event later than the timeline specified in the executed BAA (typically within 30 days of discovery). Notification will include the information required by 45 CFR §164.410(c).

7. Your rights (Patient PHI)

Under the HIPAA Privacy Rule (45 CFR Part 164, Subpart E), patients have the right to request access to, amendment of, and an accounting of disclosures of PHI held about them. These requests are administered by the Covered Entity — your treating practice — not directly by Harbor. Patients should contact their practice to exercise these rights. Harbor will support the practice in responding within the regulatory timeline.

Patients may opt out of SMS at any time by replying STOP to any message. STOP is honored for every subsequent message to that number from that practice, including appointment confirmations and reminders. The number is added to a suppression list that is checked before each send; a suppressed send is logged and not delivered. Patients who later want messages again can reply START.

Patients can reply HELP to any message for help and contact details. Message frequency varies with appointments and reminders; standard message and data rates may apply. Messages are sent only after a patient opts in through intake, a form, or by asking on a call. Full programme details — opt-in, opt-out, HELP, frequency and rates — are set out on the SMS Messaging Program page, which forms part of this policy.

8. Analytics, cookies, and tracking

Nothing tracks you inside Harbor. The signed-in application, the patient portal, and the admin console load no analytics tag, no session-replay tool, no heatmap, and no advertising pixel. This is enforced in code as an allowlist: analytics may load only on a short, named list of public marketing pages, so any page not on that list — including every page added in the future — gets nothing by default. PHI never leaves the application boundary to an analytics vendor.

On our public marketing pages, Harbor records a small amount of first-party usage data into its own database. When you first visit, your browser generates a random identifier and stores it in the browser’s local storage. It is a random number. It is not tied to your name, your email, or any account, and it never leaves our own systems.

Every one of those records passes through a filter before it is stored. The filter drops anything that looks like an identifier, an IP address, or a page address from inside the application. Automated crawlers are discarded. If your browser sends a Global Privacy Control signal, we record nothing at all.

Google Tag Manager and Google Analytics also run on those same public marketing pages, subject to the same allowlist and the same Global Privacy Control signal. They are never loaded on the application, the portal, or any page that could contain patient information. Those services set their own cookies; you can block them in your browser without affecting how Harbor works.

The application itself uses cookies only to keep you signed in.

Separately from analytics, our servers keep standard access logs that include the IP address a request came from. These are a security and troubleshooting record, not an analytics record; they are retained for up to 400 days and are not used to build a profile of you.

9. Your data choices, and the per-patient AI opt-out

A patient can refuse AI entirely and still be treated. Every patient record in Harbor carries an AI opt-out. When it is set, Harbor stops using that patient’s information for anything beyond their direct care.

How to set it. Ask your therapist. The switch lives on your chart in your therapist’s dashboard, so that the decision is made in a conversation with the clinician who treats you rather than buried in a settings menu. Your therapist records a reason with the change, and every change is written to the audit log with who made it, when, and why. You can turn it back on the same way.

What stops when you opt out:

What does not stop:

What the opt-out does not do. It stops future use. It does not erase information already recorded — that information is part of your medical record, and HIPAA gives you the right to obtain it. Once you have opted out, that information is no longer surfaced in analytics or AI features, but it is retained under the periods in section 4. If you want records deleted rather than suppressed, that is a separate request, and it is made to your practice, which owns the record.

Aggregate, de-identified use. Harbor measures how the Service performs across practices using data with direct identifiers removed. Patients who have opted out are excluded from this at the source. This is the opt-out referenced in section 10 of our Terms of Service.

If a decision fails, it fails closed. If Harbor cannot confirm a patient’s preference — an unknown record, a database error — it treats that patient as opted out and declines to run the AI feature. We would rather drop a prediction than assume a consent we cannot verify.

10. Google API Services & Limited Use

Harbor integrates with Google Calendar to schedule, reschedule, and cancel therapy appointments on behalf of the therapy practice that has authorized the connection. When a practice connects their Google account, Harbor requests the openid, email, and profile scopes (to identify the authorizing account), calendar.readonly (to read free/busy availability so the AI receptionist can offer open slots), and calendar.events (to create, update, and cancel appointment events on the therapist’s primary calendar).

Limited Use. The use and transfer of raw or derived user data Harbor receives from Google APIs, including Google Workspace APIs, will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: Harbor uses Google user data only to provide and improve user-facing features prominent in Harbor’s interface (scheduling, rescheduling, and cancellation for the authorizing practice); Harbor does not transfer Google user data to third parties except as necessary to provide or improve those features, to comply with applicable law, or as part of a merger or acquisition with notice to users; Harbor does not use Google user data for advertising of any kind; Harbor does not use Google user data, raw or derived, to develop, improve, or train generalized AI and/or ML models; and Harbor does not allow humans to read Google user data except with the authorizing user’s affirmative agreement, for security purposes, to comply with applicable law, or on data that has been aggregated and anonymized for internal operations.

Calendar data is held in memory only for the duration of a call or booking action.

11. Children

The Service is used by therapy practices, some of which treat patients under 18. When a minor is the patient, the Customer is responsible for obtaining consent from a parent or legal guardian as required by their jurisdiction and clinical standards. Harbor does not knowingly collect information directly from children outside the treatment context established by the Customer.

12. Changes

We may update this Policy. Material changes will be communicated to Customers by email at least 30 days before they take effect.

13. Contact

Privacy questions, BAA requests, and data-rights inquiries:

Harbor Office, Inc.
4506 Laverne Ave
Klamath Falls, OR 97603
chance@harboroffice.ai

See also: Terms of Service · HIPAA · Security