Legal

Privacy Policy

Effective September 11, 2026 · Version 2026-09-11b

Previous production policy · Earlier September 11 revision. Existing agreements retain their applicable notice and amendment protections.

Harbor (the “Service”) is operated by Harbor Office, Inc., a Delaware corporation with its principal office at 4506 Laverne Ave, Klamath Falls, OR 97603 (“Harbor,” “we,” “us,” or “our”). This Privacy Policy describes how we collect, use, disclose, and safeguard information when therapy practices (“Customers”) and their patients interact with the Service.

Harbor handles Protected Health Information (PHI) on behalf of its Customers under the Health Insurance Portability and Accountability Act of 1996, as amended by HITECH (the “HIPAA Rules”). We act as a Business Associate to each Customer. A signed Business Associate Agreement (BAA) governs the permitted uses and disclosures of PHI and is referenced from this Policy.

This version applies to new Customers accepting it. Existing Customers keep their agreed protections and advance-notice rights. Material changes apply to them only after the required notice period or a valid agreed amendment; publication alone does not change an executed BAA.

1. Information we collect

We collect three categories of information:

(a) Customer account data — practice name, clinician name, NPI, business email, phone, billing address, and Stripe customer/subscription identifiers. We do not store full payment card numbers; payment processing is performed by Stripe.

(b) Protected Health Information (PHI) — patient demographics, appointment details, clinical notes, assessment scores (PHQ-9, GAD-7, C-SSRS), call and SMS transcripts, voicemail audio, intake form responses, and any other PHI the Customer chooses to enter, generate, or receive via the Service.

(c) Usage data — on our public marketing pages only, a count of pages viewed and a coarse country and region. This is recorded by Harbor’s own software into Harbor’s own database, and is described in full in section 8. Marketing analytics are excluded from the signed-in application and patient portal. Operational, security, and authorized clinical records are described separately below.

2. How we use information

We use information to:

  • Provide, operate, and improve the Service for the Customer that submitted it;
  • Generate appointment confirmations, intake forms, and post-call summaries;
  • Screen supported messages and screening responses for possible safety concerns and attempt configured alerts to the care team. Call-transcript analysis occurs after the call ends. Screening may miss concerns or produce false alerts; notification delivery and response are not guaranteed;
  • Maintain audit logs of PHI access in support of HIPAA §164.312(b);
  • Bill Customers and prevent fraud;
  • Comply with legal obligations and respond to lawful requests.

We do not use PHI to train general-purpose AI models, sell PHI, or share PHI with advertising networks.

3. Subprocessors

We use the following subprocessors. Each that receives PHI has signed a BAA with Harbor where required (see status below).

SubprocessorPurposeBAA
Amazon Web Services (AWS)Hosting, RDS, KMS, Cognito, S3, Chime SDK, BedrockExecuted
PauboxHIPAA-aligned transactional email deliveryExecuted
StripePractice subscriptions and patient payments; payment data is processed by Stripe. Clinical notes and therapy content must not be included in payment descriptions or metadata.Payment processing; not represented as a PHI-hosting BAA service
SignalWireVoice telephony and SMS transportExecuted
Retell AIReal-time voice agent runtimeExecuted
Anthropic (via AWS Bedrock)LLM inference for crisis analysis and note draftingCovered under AWS BAA (Bedrock); no PHI used for training
Stedi270/271 eligibility and 837/835 claim transactionsExecuted

All subprocessors that transmit or process PHI have executed BAAs with Harbor. Customers may request current BAA documentation before signing.

4. Data retention, and what happens when a practice leaves

Harbor uses a seven-year operational retention default for call-log records, text-message conversation records, and audit logs. A scheduled process applies the configured cutoffs to those records. This is not a universal legal retention period, a statement that every stored copy is deleted at the cutoff, or a guarantee that a scheduled run completed. Clinical records, recordings, backups, legal holds, and records subject to longer requirements need their own disposition assessment.

Harbor does not record therapy sessions. Telehealth sessions are not recorded, and there is no setting that turns recording on. Phone calls answered by Harbor’s AI receptionist are recorded — the caller is told so at the start of the call. Recording storage and vendor copies are separate from the call-log database record; a call-log cutoff does not establish deletion of every audio copy. Voicemail audio is stored in Harbor’s encrypted storage and is not deleted on a schedule; the copy held by our telephone carrier is deleted as soon as we have verified our own copy. Operational system events that are not part of a clinical record — routine heartbeats and status messages — are cleared after 30 days.

Clinical records are never deleted by an automated job. Charts, notes, treatment plans, and assessments are retained for at least the period required by the law of the state where the practice operates and by the clinician’s licensing board. Harbor honors whichever of those periods is longest. Harbor does not decide when a clinical record expires, and Harbor does not delete one out from under the practice that owns it.

The operational retention schedules above are Harbor defaults, not limits on legally required clinical-record retention. Harbor does not currently offer a per-practice retention setting. If a practice needs a different period to satisfy a state or board requirement, contact us and we will handle it as a documented, individual request.

When a subscription ends, patient data remains available for 90 days so the practice can export it, hand off continuity of care, and answer any patient’s HIPAA right-of-access request. After that window, access to the application ends, but clinical records, audit logs, and billing records are handled under their applicable retention requirements and the signed BAA’s return or destruction provisions. The full subscription exit terms are in our Cancellation and Refund Policy. The signed BAA controls PHI return, destruction, and continued protection; the subscription policy does not override it.

We handle written return or destruction instructions under the executed BAA and applicable requirements, including legal holds. We confirm the outcome or document why a particular return or destruction is infeasible, with continuing protections and limits on further use. Retained backups and vendor copies require their own disposition assessment. Our disposal policy calls for appropriate media-sanitization methods; a request is not proof that all copies have been destroyed.

5. Security

PHI is encrypted in transit (TLS 1.2+) and at rest (AWS KMS, customer-managed keys per HIPAA §164.312(a)(2)(iv)). Harbor’s workforce access policy requires named accounts, appropriate authentication, least privilege, and quarterly access reviews. These are policy requirements; the completion of an individual review is documented separately. See our Security page for technical and administrative safeguard detail mapped to the HIPAA Security Rule.

6. Breach notification

Harbor will notify the affected Customer of a suspected or confirmed breach of unsecured PHI without unreasonable delay. Harbor’s operational target is notification within 72 hours of discovery; the standard BAA sets an outside limit of 60 calendar days. A shorter applicable legal deadline or written commitment controls. Neither period is permission to wait. Notification includes the information required by 45 CFR §164.410(c), with supplements as required information becomes available.

7. Your rights (Patient PHI)

Under the HIPAA Privacy Rule (45 CFR Part 164, Subpart E), patients have the right to request access to, amendment of, and an accounting of disclosures of PHI held about them. These requests are administered by the Covered Entity — your treating practice — not directly by Harbor. Patients should contact their practice to exercise these rights. Harbor will support the practice in responding within the regulatory timeline.

Patients may opt out of SMS at any time by replying STOP to any message. STOP is honored for every subsequent message to that number from that practice, including appointment confirmations and reminders. The number is added to a suppression list that is checked before each send; a suppressed send is logged and not delivered. Patients who later want messages again can reply START.

Patients can reply HELP to any message for help and contact details. Message frequency varies with appointments and reminders; standard message and data rates may apply. Messages are sent only after a patient opts in through intake, a form, or by asking on a call. Full programme details — opt-in, opt-out, HELP, frequency and rates — are set out on the SMS Messaging Program page, which forms part of this policy.

8. Analytics, cookies, and tracking

Marketing analytics are excluded from signed-in areas. The signed-in application, the patient portal, and the admin console load no analytics tag, no session-replay tool, no heatmap, and no advertising pixel. This is enforced in code as an allowlist: analytics may load only on a short, named list of public marketing pages, so any page not on that list — including every page added in the future — gets nothing by default. PHI never leaves the application boundary to an analytics vendor.

On our public marketing pages, Harbor records a small amount of first-party usage data into its own database. When you first visit, your browser generates a random identifier and stores it in the browser’s local storage. It is a random number. It is not tied to your name, your email, or any account, and it never leaves our own systems.

  • We do not use cookies for this, and we do not read cookies to identify you.
  • We do not store your IP address in these records.
  • We do not fingerprint your device.
  • We do not link this data to a Harbor account or to any patient.
  • We record only the page path, a coarse country and region supplied by our content network, whether the browser is a phone, tablet, or desktop, and the campaign tags on the link you arrived through.

Every one of those records passes through a filter before it is stored. The filter drops anything that looks like an identifier, an IP address, or a page address from inside the application. Automated crawlers are discarded. If your browser sends a Global Privacy Control signal, we record nothing at all.

Google Tag Manager and Google Analytics also run on those same public marketing pages, subject to the same allowlist and the same Global Privacy Control signal. They are never loaded on the application, the portal, or any page that could contain patient information. Those services set their own cookies; you can block them in your browser without affecting how Harbor works.

The application itself uses cookies only to keep you signed in.

Separately from analytics, our servers keep standard access logs that include the IP address a request came from. These are a security and troubleshooting record, not an analytics record; they are retained for up to 400 days and are not used to build a profile of you.

9. Your data choices, and the per-patient AI opt-out

Patients may decline optional AI assistance without losing care.The patient-level preference limits the AI uses described below. It does not disable the automated receptionist, erase earlier records, or turn off the safety processing described here. Ask the practice for an alternative contact method if you do not want to speak with its AI receptionist.

How to set it. Ask your therapist. The switch lives on your chart in your therapist’s dashboard, so that the decision is made in a conversation with the clinician who treats you rather than buried in a settings menu. Your therapist records a reason with the change, and every change is written to the audit log with who made it, when, and why. You can turn it back on the same way.

What stops when you opt out:

  • AI-assisted drafting on your chart — note drafts, treatment-plan drafts, and summaries. Your therapist is told to work manually for you instead.
  • AI predictions about you, such as appointment-attendance estimates. None are generated and none are stored.
  • Your therapist’s ratings and corrections of AI output about you. Those are training signal, and we stop collecting them too.
  • Screening scores captured by the phone assistant flowing into long-term tracking. The conversation is still saved to your record for your therapist to read; it simply does not become a data point.
  • Your inclusion in any aggregate analysis, product measurement, or model-training set.

What does not stop:

  • Your care. Your therapist keeps their full record of you — calls, transcripts, intake, notes — because they need it to treat you. You are not opting out of your own chart.
  • The ordinary running of the practice: appointments, reminders, intake forms, and billing.
  • Safety screening. The optional AI preference does not disable safety screening of supported communications or attempts to alert the care team. Screening can miss concerns or produce false alerts. It does not guarantee notification, receipt, response, or safety. Harbor does not initiate clinical outreach based on these signals; a qualified care-team member determines the response. For immediate danger, call 911; for crisis support, call or text 988. Do not wait for a Harbor alert.

What the opt-out does not do. It stops future use. It does not erase information already recorded — that information is part of your medical record, and HIPAA gives you the right to obtain it. Once you have opted out, that information is no longer surfaced in analytics or AI features, but it is retained under the periods in section 4. If you want records deleted rather than suppressed, that is a separate request, and it is made to your practice, which owns the record.

Aggregate, de-identified use. Harbor measures how the Service performs across practices only within the permissions in the applicable BAA. Information is treated as de-identified only after the specified HIPAA de-identification requirements are met; removing direct identifiers alone is insufficient. Until then it remains PHI. Patients who have opted out and records subject to 42 CFR Part 2 are excluded from these analytics at the source. De-identified use is limited to service measurement, improvement, and aggregate service analytics under the revised standard BAA. This is the opt-out referenced in section 10 of our Terms of Service.

If a decision fails, it fails closed. If Harbor cannot confirm a patient’s preference — an unknown record, a database error — it treats that patient as opted out and declines to run the AI feature. We would rather drop a prediction than assume a consent we cannot verify.

10. Google API Services & Limited Use

Harbor integrates with Google Calendar to schedule, reschedule, and cancel therapy appointments on behalf of the therapy practice that has authorized the connection. When a practice connects their Google account, Harbor requests the openid, email, and profile scopes (to identify the authorizing account), calendar.readonly (to read free/busy availability so the AI receptionist can offer open slots), and calendar.events (to create, update, and cancel appointment events on the therapist’s primary calendar).

Limited Use. The use and transfer of raw or derived user data Harbor receives from Google APIs, including Google Workspace APIs, will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: Harbor uses Google user data only to provide and improve user-facing features prominent in Harbor’s interface (scheduling, rescheduling, and cancellation for the authorizing practice); Harbor does not transfer Google user data to third parties except as necessary to provide or improve those features, to comply with applicable law, or as part of a merger or acquisition with notice to users; Harbor does not use Google user data for advertising of any kind; Harbor does not use Google user data, raw or derived, to develop, improve, or train generalized AI and/or ML models; and Harbor does not allow humans to read Google user data except with the authorizing user’s affirmative agreement, for security purposes, to comply with applicable law, or on data that has been aggregated and anonymized for internal operations.

Calendar connections retain integration credentials and relevant booking or event identifiers so authorized scheduling and synchronization can continue. API responses may be processed temporarily, while appointment and integration records persist under the applicable retention rules. Disconnecting a calendar does not erase the practice’s existing appointment records.

11. Children

The Service is used by therapy practices, some of which treat patients under 18. When a minor is the patient, the Customer is responsible for obtaining consent from the patient or an authorized representative as applicable. A minor may have independent consent and confidentiality rights; being a parent does not automatically authorize access to every record. The practice must verify the appropriate signer and access rights under applicable law. Harbor does not knowingly collect information directly from children outside the treatment context established by the Customer.

12. Changes

We may update this Policy. Material changes will be communicated to Customers by email at least 30 days before they take effect for existing Customers, unless the parties validly agree otherwise. Existing contractual protections remain in force until the applicable change takes effect. Prior signatures and accepted versions are preserved.

13. Contact

Privacy questions, BAA requests, and data-rights inquiries:

Harbor Office, Inc.
4506 Laverne Ave
Klamath Falls, OR 97603
chance@harboroffice.ai

See also: Terms of Service · HIPAA · Security