The short version
- We collect what it takes to run your bots: your sign-in identity, your workspaces, what you and your bots say and make, and what it costs.
- We do not sell your data, show ads, or track you across apps. OneSignal processes mobile push delivery, app-session and notification-interaction analytics, as described below. We do not train models on your content.
- Our main account servers are in the United States. Other providers may process data in the locations listed below. To answer a message, what the bot is working on is sent to an AI model provider.
- You can download your data or close your account yourself in Settings. For anything else, write to privacy@harner.dev. We answer within 30 days.
This policy explains how Harner handles personal data. It covers harner.dev, the panel and API at api.harner.dev, the Harner mobile app, and apps published at harner.app. It is also the information notice (aydınlatma metni) required by Article 10 of Türkiye's Personal Data Protection Law No. 6698 (“KVKK”). For people in the EU or EEA, it is the information required by Articles 13 and 14 of the General Data Protection Regulation (“GDPR”).
Who is responsible
The data controller (veri sorumlusu) is Ugur Cekmez, an individual running Harner as a sole trader in the Republic of Türkiye (“Harner”, “we”, “us”). For anything in this policy, write to privacy@harner.dev.
Harner offers its service to people outside Türkiye too, including in the EU and EEA. So the GDPR applies to that processing as well (GDPR Article 3(2)).
Some data belongs to a workspace rather than to one person. For example, a company can invite its staff and have them work with the company's bots. Inside Harner, that workspace's owner decides who can see what. For data your bots process about other people, you or your workspace may be the controller, and Harner processes it for you. See Your bots and other people's data.
What we collect
| Category | What it includes | Where it comes from |
|---|---|---|
| Account and sign-in profile | Your verified account email and sign-in provider user id. Apple may give you a private relay email address. If you sign in with GitHub, we also receive your GitHub username, name and profile picture, and these public profile fields: profile URL, company, blog, location, bio, X (Twitter) handle, whether you are available for hire, public repository, gist, follower and following counts, and when your GitHub account was created and last updated. Any changes you make to these in Settings. | Apple, Google or GitHub, when you sign in. Apple and Google provide a verified email through OpenID Connect; GitHub provides your verified email and profile. We never see your provider password. We do not keep the GitHub access token after sign-in. |
| Workspaces and members | The workspaces you create or join, members' email addresses, roles and display names. Invitations, including the invited person's email address. Your place on the waitlist. | You, and the workspace owners who invite you. |
| What you and your bots do | Messages to and from bots and the files you attach. Tasks, goals and routines, and their results. What a bot remembers, and summaries of past conversations. Files a bot keeps in its workspace. Notifications. Pages and apps a bot publishes, and the data those apps store. | You, other members of your workspace, and your bots as they work. |
| Credentials you give your bots | Secrets, model provider keys and tokens for integrations you connect. When you sign a bot's browser into a website, that website's cookies and site data are kept in the bot's browser profile. We also log which stored credential a bot used, and where. | You. |
| Billing | Your Stripe customer id, the billing email, invoices and their lines, discounts and payment status. Card details are entered on Stripe's pages and stay with Stripe. We never receive the full card number. | You and Stripe. |
| Usage and metering | A record of each model call: time, workspace, bot, conversation id, provider, model, token counts and cost. Also how long bots held compute and disk. These records hold counts, not the text of your messages. | The service, as it runs. |
| Mobile app | Your device's name, the platform (iOS or Android) and the app version. A device session: we store only a hash of the phone's sign-in token. The OneSignal push subscription identifier and notification details used for delivery, if you turn notifications on. OneSignal's mobile SDK also processes device and subscription identifiers, IP and network details, device and operating system details, language, time zone, app use and session timing, and notification interactions, for mobile push delivery and related delivery, session and notification-interaction analytics. Photos you choose to attach: the app removes their location and other metadata before upload. | Your phone, when you sign in and use the app. |
| Lessons from the phone browser | When you teach a bot in the app's phone browser: the pages you opened, what you tapped, what you typed into ordinary fields, and the lesson's name. Never passwords, one-time codes, card numbers or cookies. See Your phone's browser. | You, from your phone, when you finish a lesson and send it. |
| The phone browser, when you share it with a bot | When you let a bot use the app's phone browser in a conversation: what the bot reads from the pages there (the address, the title, the visible text, and the buttons, links and fields with their labels and what is in them) and what it does on them. A record of each step: when it happened, which of your phones it ran on, the site, what kind of step it was, and whether you allowed it. Never passwords, one-time codes, card numbers or cookies. See When you share it with a bot. | Your phone, while you share the browser with a bot. |
| Support and email | Messages you send through Help, and email you send to our addresses (support@, security@, abuse@ and privacy@harner.dev), including the sender, the subject, the body and the headers. | You. |
| Technical logs | For each request: time, path, method, status, duration, request id, the signed-in account, IP address and browser user agent. Secrets are redacted from logs. | Your browser, app or API client. |
We do not ask for special categories of personal data (özel nitelikli kişisel veri), such as health or religious data. Please do not give them to your bots unless you have to and have the right to.
Why we use it, and on what legal basis
We collect data electronically: through GitHub sign-in, the website, the panel, the API, the mobile app, and the email you send us. The KVKK ground is the relevant item of KVKK Article 5(2). The GDPR basis is the relevant item of GDPR Article 6(1).
| Purpose | KVKK Art. 5(2) | GDPR Art. 6(1) |
|---|---|---|
| Creating your account, running your workspaces and bots, and delivering what you ask for. This includes sending your bot's work to model providers and the tools you connect. | (c) necessary for a contract with you | (b) contract |
| Metering use, invoicing, collecting payment, and keeping accounting and tax records. | (c) contract; (ç) legal obligation | (b) contract; (c) legal obligation |
| Service email and notifications: invitations, results of routines you schedule, account and billing notices, and push notifications you turn on. | (c) contract | (b) contract |
| Answering support, security, abuse and privacy messages. | (c) contract; (ç) legal obligation; (f) legitimate interest | (b), (c), (f) |
| Keeping the service secure: logs, rate limits, detecting abuse, enforcing the Acceptable Use Policy, suspending accounts. | (f) legitimate interest | (f) legitimate interest |
| Establishing, exercising or defending legal claims. | (e) establishing or protecting a right | (f) legitimate interest |
We do not send marketing email. We do not use your content to train AI models, and we do not sell or rent personal data. No decision with legal or similarly significant effects is made about you by automated means alone. The waitlist is a queue that a person approves.
Your bots and other people's data
Bots work on what you give them. What goes into a conversation can reach:
- The model provider that answers each turn (see Who we share data with).
- Other people and bots in the same workspace. A bot knows what it has done for each member of its workspace, and can tell other members about it in summary. What else a member can see depends on the role the workspace owner gives them.
- Anyone you or your bot send things to: a website the bot visits, an email it sends, a tool you connect, a public app it publishes.
If your bots process personal data about other people, for example your customers or contacts, you are responsible for having a lawful basis for it and for telling those people. For that data, Harner acts on your instructions as a processor (veri işleyen). If you need a data processing agreement, write to privacy@harner.dev.
People who use an app published on harner.app deal with that app's publisher, not Harner. The publisher is responsible for the data their app collects.
Your phone's browser
The Harner mobile app has a web browser of its own, the phone browser. Pages you open in it load straight from those websites to your phone, as in any browser. Harner receives nothing from them unless you teach a bot or share the browser with a bot, as described below. What you type in its address bar that is not an address goes from your phone to Google as a search. The sites you sign in to keep their cookies and site data on your phone, in the app's storage. We never read them, and they are not sent to Harner.
When you teach a bot
If you turn on Teach, the app records what you do, so that a bot can learn the task. The recording stays on your phone while you record. When you finish, you check every step, and only then does the app send the lesson to Harner. A lesson holds:
- the addresses of the pages you opened, with sign-in tokens, codes and similar values removed from them;
- what you tapped: the label, role and text of the button or link, and where it sits on the page;
- what you typed into ordinary fields, and the options you chose. A value that looks like an email address, phone number, IBAN, identity number, date of birth or address is left out and marked “ask each time”, unless you choose to keep it as typed;
- the Enter, Tab and Escape keys, when you pressed them;
- the lesson's name and when the bot should use it, when you started and finished, your phone's platform (iOS or Android), the app version, and which version of the Teach notice you accepted.
The app never reads what you type into password, one-time code or card fields. If a card number or a Turkish identity number (TCKN) is typed into another field, it is removed before the lesson is stored. Cookies, site storage and screenshots are never collected. The log line we write when a lesson arrives holds counts and your platform, not addresses or anything you typed.
Who sees a lesson
- Only you can see the recording.
- Harner turns it into a draft skill by fixed rules. No AI model reads the recording to write the draft. Values you kept as typed are written into the draft.
- When you save the lesson, the draft, as you edited it, becomes a skill in your workspace. Everyone in the workspace, and their bots, can use it. When a bot uses the skill, its text goes to that bot's AI model provider, like the rest of the conversation.
When you share it with a bot
In a conversation with a bot, you can tap Share to let that bot use the phone browser while you watch. It uses the browser with your sign-ins and your phone's internet connection, so the sites it opens see you, as they would if you opened them yourself. The browser tells sites it is the Harner app. Closing the browser panel while Harner stays in the foreground does not end sharing; the phone browser remains available while you use the chat. Sharing:
- starts only when you tap Share, and only for that conversation, for at most 30 minutes;
- continues on your phone while Harner is in the foreground, even if you close the browser panel;
- only if the app reports that Harner has entered the background and your version 3 sharing consent includes autonomous use can the bot continue in its own private server browser until you return Harner to the foreground, tap Stop, or the sharing time expires; closing the panel alone does not start this continuation;
- pauses when you touch the page;
- asks you to approve each action when you turn on Confirm every action. Without that setting, the bot does not ask you for every action.
The server browser has its own site sessions. Your phone browser's cookies, sign-ins and site data are not copied or transferred to it. Returning Harner to the foreground revokes the server-browser continuation. Tapping Stop or reaching the 30-minute limit ends sharing.
While you share, the bot can read the page open in the phone browser: its address, its title, its visible text, and its buttons, links and fields with their labels and what is in them. What it reads goes from your phone through Harner to the AI model provider the bot uses, and it stays in that conversation, like the rest of it. The page can hold anything the site shows you, such as balances, orders or messages, so share only the sites you want the bot to see.
Password, one-time code and card fields are always read as blank. Sign-in tokens, card numbers and Turkish identity numbers (TCKN) in the page are masked on your phone, and Harner masks them again. Cookies, site storage and screenshots are never read.
When sharing starts, the app also sends your phone's time zone, so the bot can tell you in your own time when the sharing ends.
Once a bot has read from your phone in a conversation, that conversation stays private, unless you allow otherwise from your phone:
- the bot cannot send email, message other bots, save to its memory, start goals or routines, publish or use connected tools from it;
- its general internet access and server browser are blocked, apart from the temporary private-browser continuation described above when you allow it;
- other members' bots are not told what the conversation is about;
- your other conversations with bots only see that the phone browser was used there, unless a bot there opens this conversation to recall it. That conversation then stays private in the same way.
For each step we keep a record of when it happened, which of your phones it ran on, the site, what kind of step it was, and whether you allowed it, and which version of the sharing notice you accepted. The record holds no page text and nothing the bot typed.
How long each part is kept is in How long we keep it.
Who we share data with
Service providers who process data for us
These companies run parts of Harner for us. They may use data only to provide their service to us. Some are listed by category rather than by name, as GDPR Article 13(1)(e) and KVKK allow. The current list of providers is available on request at privacy@harner.dev.
| Provider | What they do | Data | Location |
|---|---|---|---|
| Microsoft Azure | Hosts our servers: the database, bots' containers and files, backups and logs. | Everything described in this policy. | United States (East US 2) |
| An AI model provider | Powers Harner's built-in model (harner-v1). | The content of each model call: messages, files and context the bot sends. | United States |
| TypeSafe (System One API) | Classifies messages to decide how the bot responds. | Text from the turn in progress (up to a few thousand characters). | Outside Türkiye (per the provider) |
| Stripe | Card payments, the billing portal and payment records. | Billing email, Stripe customer id, amounts, card details (held by Stripe). | United States and other countries |
| Resend | Sends our email (invitations, routine results, notices) and receives mail sent to our @harner.dev addresses. | Email addresses and message content. | United States |
| Cloudflare | Runs harner.app: its website, database (D1) and file storage (R2), and its network. | Published pages and apps, their data, visitor sessions, and the owners' account ids. | Global network |
| Fly.io | Runs apps on harner.app that need a server, with daily volume snapshots. | The app's code and data. | Netherlands (Amsterdam) |
| Apple, Google and GitHub | Mobile sign-in. | Your verified email and provider user id; GitHub profile fields when you use GitHub, as described above. | United States and other countries |
| OneSignal | Mobile push delivery and related analytics about delivery, app sessions and notification interactions. | Push subscription and device identifiers, IP and network details, device and operating system details, language, time zone, app use and session timing, notification interactions, and notification content. | See OneSignal's privacy policy for its processing locations. |
Recipients you choose
Some services receive data because you or your bot send it to them. They handle it under their own terms and privacy policies, not ours:
- An AI model provider whose key you bring instead of harner-v1. You choose the provider, and your account with it.
- Tools you connect, such as Slack, Google, Microsoft, Telegram, WhatsApp, Notion, Linear, Atlassian, Asana, HubSpot, Salesforce, Dropbox, Box, ClickUp, Trello and GitLab.
- Websites your bot visits, people it emails, and visitors to apps you publish.
- Websites you open in the app's phone browser, or that a bot opens there while you share it, and Google, for what you search from its address bar.
Others
- Members of your workspace, as described above.
- Authorities, when the law requires it and only as much as the law requires.
- A successor. If Harner is transferred, for example to a company set up to run it, your data moves with it under this policy. We will tell you first.
Transfers abroad
Our main servers are in the United States. So is most of the processing above. So using Harner means your personal data is transferred outside Türkiye (KVKK Article 9) and, for EU and EEA users, outside the EEA (GDPR Chapter V). Some providers run global networks (Cloudflare).
We make these transfers under the safeguards the law provides. These are the standard contracts announced by the Personal Data Protection Board under KVKK Article 9, the European Commission's standard contractual clauses, and, for US providers certified under it, the EU–U.S. Data Privacy Framework. Some transfers happen occasionally at your request, for example to a tool you connect. For those, we rely on the transfer being necessary for our contract with you. To ask about the safeguards for a given provider, write to privacy@harner.dev.
How long we keep it
| Data | Kept |
|---|---|
| Account, profile, workspaces and memberships | Until you close your account (or leave or delete the workspace). |
| Conversation transcripts | 30 days after each part is written. After that they are deleted automatically. |
| Bot memory, conversation summaries, files in a bot's workspace, routines and goals | Until you or a workspace owner delete them, delete the bot or workspace, or close the account. |
| Finished task records | 7 days. The most recent 100 are kept longer. |
| Browser sign-ins held for a bot | Until you sign the bot's browser out of everything (in its browser panel), delete the bot, or close the account. |
| Secrets, model keys and integration tokens | Until you remove them. The log of where a credential was used: 90 days. |
| Invoices, billing records and usage metering records | For as long as tax and commercial law requires, including after your account is closed. In Türkiye that is up to 10 years (Turkish Commercial Code Art. 82; Tax Procedure Law Art. 253). These records hold amounts and token counts, not conversation content. |
| Mobile device sessions | Until you sign out on the phone or remove it, after 90 days unused, or until you close your account. Sent push notifications: 7 days. |
| Lessons from the phone browser | A lesson you leave unreviewed for 7 days expires. What you typed is removed from the recorded steps when you save the lesson, throw it away, or it expires. Its draft, which holds any values you kept as typed, is emptied as soon as you throw the lesson away, and when it expires. The rest of the recording (the pages you opened and what you tapped) is kept until the workspace is deleted or you close your account. A saved skill, which holds the draft as you saved it, is kept until someone in the workspace deletes it. |
| Sharing the phone browser with a bot | What the bot read and did there is part of the conversation's transcript, kept as above. What the bot said about it can also be in that conversation's summary, kept as above. The record of each step (when it happened, which of your phones it ran on, the site, what kind of step it was, and whether you allowed it), which holds no page text: 90 days. The mark that keeps a conversation private after the bot read from your phone: as long as the conversation exists. |
| Mail to our @harner.dev addresses | 365 days. |
| Messages sent through Help | Until we have handled them and no longer need them. They are not yet deleted automatically when you close your account. Ask us at privacy@harner.dev and we will delete them. |
| Server logs | Rotated by size, not by date, so older lines are overwritten as new ones arrive. Usually days to a few weeks. |
| Database backups | Taken every 6 hours, kept about 7 days. |
| Pages and apps on harner.app | Until you remove them, or 7 days after they expire. Server volume snapshots: 14 days. |
When you close your account (Settings → Close my account on the web, or Close account in the app), we delete your account, its workspaces that no one else is in, your bots, conversations, memory, files, secrets, integrations and device sessions straight away. Some things stay:
- Invoices, and metering records we need for them.
- In workspaces that go on without you, usage records, with your name replaced by “(erased)”. Also what a bot there learned from you, no longer linked to you.
- A suspension record, if your account was suspended, so the suspension still applies.
- Copies in backups, until they roll off, which takes about 7 days.
How we protect it
All traffic is encrypted in transit (TLS). The following are encrypted at rest with AES-256-GCM:
- secrets, model keys and integration tokens
- conversation transcripts and summaries
- several other stores of conversation content
Other data, such as bot memory, task text and a bot's browser profile, is stored without that extra layer. It relies on the server's own protections. Encryption at rest protects against a stolen disk or backup. It does not stop the people who run the server from reaching the data.
Bots run in isolated workspace environments, with access controls for each bot. Only the operator has administrative access, and we look at your content only to run the service, to help you when you ask, to investigate security or abuse, or when the law requires it.
No system is perfectly secure. If a breach affects your data, we will tell you and the authorities as the law requires. You can report a vulnerability to security@harner.dev.
Your rights
Under KVKK Article 11 you may:
- learn whether we process your personal data, and if so, request information about it;
- learn the purpose of processing and whether data is used for that purpose;
- know the third parties, in Türkiye or abroad, to whom it is transferred;
- ask for incomplete or inaccurate data to be corrected;
- ask for data to be deleted or destroyed under the conditions of KVKK Article 7;
- ask for correction and deletion to be passed on to the third parties who received the data;
- object to a result against you that arises only from automated analysis;
- claim compensation if unlawful processing causes you damage.
Under the GDPR you also have the rights of access, rectification, erasure, restriction, data portability, and objection to processing based on legitimate interests. Where we rely on consent, you can withdraw it at any time.
How to use them
- Download your data: Settings → Download my data gives you a JSON file of your account, conversations, memory and usage.
- Correct your profile: Settings.
- Close your account and delete your data: Settings → Close my account on the web, or Close account in the app.
- Sign a bot's browser out of every site: in that bot's browser panel.
- Anything else: email privacy@harner.dev from the address on your Harner account, so we can tell it is you. Otherwise we may ask you to confirm who you are. You can also apply by any other method the Communiqué on the Procedures and Principles of Application to the Data Controller allows.
We answer as soon as we can, and within 30 days (KVKK Article 13; under the GDPR, within one month, which can be extended by two months for complex requests, and we will tell you if we need to). It is free, unless a request is unusually costly and the law lets us charge for it.
If you are not satisfied, you can complain to the Personal Data Protection Board (Kişisel Verileri Koruma Kurulu, kvkk.gov.tr). If you are in the EU or EEA, you can complain to your local data protection authority.
Children
Harner is for adults: you must be at least 18 to use it. It is a paid tool that acts for you and spends money on your behalf, and that needs someone who can enter a contract alone. We do not knowingly collect data from anyone under 18. If you believe a child has an account, write to privacy@harner.dev and we will close it.
Cookies and storage in your browser
We use only the cookies the service needs to work. There are no analytics, advertising or tracking cookies, and no third-party scripts. That is why there is no cookie banner.
| Name | What it is for | Lasts |
|---|---|---|
harner_session | Keeps you signed in to api.harner.dev. | 7 days |
harner_oauth_state, harner_oauth_invitation | Protect GitHub sign-in and carry an invitation through it. | 10 minutes |
harner_invitation | Holds an invitation while you accept it. | 15 minutes |
harner_mobile_sign_in, harner_handoff | Signing in from the mobile app, and opening a page from the app in your browser. | 5 minutes, 1 minute |
__Host-harner_app, __Host-harner_artifact, __Host-harner_guest |
On harner.app: your dashboard session, access to a private page, and a guest's access to a shared app. | 1 hour, 15 minutes, up to 1 day |
The site also keeps a few preferences in your browser's local storage: theme, reduced motion, the layout of the side rail. It also keeps a message you have typed but not yet sent, so a reload does not lose it. These stay on your device.
The phone browser in the Harner app keeps the cookies and site data of the sites you open on your phone. We never read them. See Your phone's browser.
If you are in California
We do not sell or share personal information as the California Consumer Privacy Act defines those terms, and we do not use sensitive personal information to infer characteristics. The categories we collect, their sources and purposes are listed above. You may ask to know, correct or delete your personal information, and we will not treat you differently for asking. Write to privacy@harner.dev.
Changes to this policy
If we change this policy in a way that matters, we will tell you by email or in the product before the change takes effect. The version and date at the top show which text applies. Earlier versions are available on request.
Contact
Privacy: privacy@harner.dev. Security: security@harner.dev. Abuse: abuse@harner.dev. Everything else: support@harner.dev.
See also the Terms of Service and the Acceptable Use Policy.